Hong Kong Franchise Customer Data Guide: Clarifying System Access, Privacy Responsibilities and Data Exports Before Signing
A customer list held in a brand’s system is not necessarily yours to use freely as a franchisee. Before signing, check permitted uses, access rights, system costs and handover arrangements to avoid having customers you cannot lawfully contact.
Published

When buying a franchise in Hong Kong, the brand’s loyalty programme and point-of-sale system are often seen as ready-made advantages. Yet questions such as who may contact customers, whether transaction records can be downloaded and how refunds are handled once system access ends can all affect day-to-day operations. Across a franchise network, shared technology should rest on clear rights and responsibilities, not simply an assurance that “head office manages the data”.
1. Map the data flows, rather than simply asking who owns the list
“The brand owns the customer data” is not enough to resolve privacy and operational questions. Personal data is not an ordinary asset that can be used at will: even where a contract claims ownership, its use remains subject to legal restrictions.
Before signing, ask the brand to demonstrate the full process, from customer registration and payment to earning loyalty points and receiving refunds, and to provide a data flow diagram. Check each of the following:
- What data is collected: names, telephone numbers and purchase histories, or dates of birth and preferences too?
- Which organisations can access it: the franchisee, Hong Kong head office, the overseas brand owner or the system supplier?
- What can each party do: view only your outlet’s transactions, or download the entire loyalty programme membership list?
- Where is the data stored: on local servers, in an overseas cloud service or across several platforms?
Ask the brand to show you the actual access permissions, rather than just a sales presentation. Then speak to existing franchisees: can they find the records they need when handling customer complaints? Must they request permission each time they download a report? These answers are often more useful than claims that the system is “comprehensive”.
2. Hong Kong has no franchise-specific disclosure regime, but privacy obligations still apply
Hong Kong has no dedicated franchise legislation, nor a generally applicable franchise registration or statutory pre-contract disclosure regime. The parties’ rights are governed mainly by their contract and general law, including common law contract principles, the Misrepresentation Ordinance and, where applicable, the Personal Data (Privacy) Ordinance. Do not assume the brand must proactively disclose all system information in a prescribed statutory format.
The Personal Data (Privacy) Ordinance (Cap. 486) is particularly important. A party that controls the collection, holding, processing or use of personal data may be a “data user”. A contractual clause placing all responsibility on the other party will not necessarily change the actual legal position.
Before signing, obtain the current Personal Information Collection Statement, privacy policy and loyalty programme registration screens. Check the purposes of collection, the classes of recipients to whom data may be transferred, and the contact arrangements for data access and correction requests. If a proposed new use falls outside the original purpose or a directly related purpose, the individual’s prescribed consent will generally be required.
Direct marketing is subject to additional statutory requirements. If the brand collects telephone numbers to issue electronic receipts, that does not automatically allow franchisees to use them for promotional messages. Providing data to another organisation for direct marketing is also subject to additional rules. Do not treat joining a loyalty programme as blanket consent to all marketing.
3. Put system access, charges and outage procedures in a contract schedule
Ask the brand for a separate system and data schedule setting out the minimum access rights needed for daily operations. These should include viewing your outlet’s transactions, processing refunds, checking loyalty points and exporting financial reports. Financial reports may not need to include information identifying customers, so limit the data included to what is genuinely necessary.
Costs should also be itemised: equipment purchase or hire, monthly account charges, per-user fees, storage charges, upgrade costs and data export fees. Establish whether the brand can change platforms unilaterally, and who will bear the resulting equipment, data preparation and downtime costs.
The contract should cover at least the following:
- Service interruptions: notification channels, response and recovery arrangements, and how offline transactions will be entered into the system afterwards.
- Access management: disabling accounts when staff leave, restricting bulk downloads and maintaining activity logs.
- Security incidents: responsibility for investigating, preserving evidence, co-ordinating remedial action and assessing notification arrangements.
- Supplier management: using contractual or other measures when outsourcing data processing to prevent excessive retention or unauthorised access.
Do not settle for “handled in accordance with head office policy”. Ask for the relevant version of the policy and agree procedures for notification and consultation on significant changes.
4. Test data exports and handover arrangements before signing
Whether data can be exported should be established before buying the franchise, not left for a dispute when the relationship ends. Ask the brand for a sample export containing no real customer data. Check that it includes sufficient fields, such as transaction dates, refunds, loyalty points and payment methods, and that commonly used software can read the file.
The contract should distinguish between three categories of data: transaction and accounting records the franchisee must retain; data needed to fulfil outstanding orders; and brand loyalty programme data that cannot continue to be used after the relationship ends. Keeping records does not confer a right to continue marketing, and a handover should not become an unrestricted copying of customer lists.
Also specify export deadlines, formats, charges, read-only access arrangements, and procedures for deleting data and handling backups. Ask a solicitor and an accountant to help define which records are subject to legal retention duties, rather than applying blanket deletion or permanent retention.
Practical takeaway: Before signing, complete a system demonstration, review the privacy documentation and secure an enforceable data schedule. Data is a genuinely useful operational resource only when it is obtained lawfully, used as needed and handed over properly.



