Franchise data protection: who is responsible for shared customer data?
One brand, separate businesses: how to organise customer data processing, access rights and responsibilities before launching a franchise in Hungary.
Published

When you turn an existing business into a franchise network, a shared booking system, online shop or loyalty programme can seem like standard equipment. But customer data does not become freely shareable simply because every franchisee uses the same brand. Before your first franchisee joins, you need to establish who processes which data, for what purpose and with what responsibilities. Without this groundwork, even an otherwise effective central system can create data protection risks.
1. Map the data journey, not just the software
Start with a real customer scenario: someone books an appointment on the central website, visits a franchisee’s premises, pays and then receives a satisfaction survey. Each step may involve a different business and a different purpose for processing personal data. Owning the software does not necessarily make a business responsible for all the processing carried out through it.
Create a simple data flow table, with a separate row for each process. Record at least the following:
- what personal data is generated;
- which business collects it and who has access;
- the purpose and lawful basis for processing;
- how long the data needs to be retained;
- whether data is transferred to an external service provider or another franchisee.
Treat service delivery, invoicing, complaints handling and marketing as separate activities. Just because an email address is needed to confirm a booking does not mean it can automatically be used for marketing emails from head office. Equally, a franchisee’s invoicing obligations do not justify giving every other outlet access to its entire customer list.
During planning, ask whether head office really needs data identifying individual customers. Aggregated reports are often sufficient to analyse sales or capacity utilisation. Bear in mind, however, that simply replacing a customer identifier with a code does not necessarily make the data anonymous.
2. Allocate roles according to how the business actually operates
Data protection roles depend on who actually makes the decisions, not on the labels used in the franchise agreement. A controller determines the purposes and means of processing personal data; a processor acts on the controller’s behalf and follows its instructions.
It is useful to distinguish between three common situations:
- Independent controllers: the franchisee contracts with its own customers, handles its own invoicing and independently fulfils its related obligations.
- Processing on behalf of a controller: head office operates a customer management function solely on the franchisee’s documented instructions, without using the data for its own purposes.
- Joint controllers: head office and the franchisee jointly determine, for example, the purposes and essential means of processing data for a shared loyalty programme.
A business can have different roles in different processes. Do not classify a franchisee as a processor across the board simply because it must follow the network’s operating rules.
Where there is joint controllership, responsibilities must be set out in an arrangement under Article 26 of the GDPR, particularly for handling individuals’ rights and providing privacy information. The essence of that arrangement must also be made available to customers. Processing on behalf of a controller requires a contract or another binding legal instrument that complies with Article 28 of the GDPR. Where data is shared between independent controllers, the lawful basis and transparency of the transfer must be assessed separately.
3. Align your documents with Hungarian law
Hungary has no standalone, comprehensive franchise act, but it would be inaccurate to say that franchise agreements are unregulated. Act V of 2013, the Hungarian Civil Code, regulates franchise agreements in Sections 6:376–6:381. General contract law rules also apply.
The primary framework for processing customer data is the European Union’s General Data Protection Regulation, or GDPR, which applies directly in Hungary. It is supplemented by Act CXII of 2011 on Informational Self-Determination and Freedom of Information, commonly known as the Infotv. The supervisory authority is the Hungarian National Authority for Data Protection and Freedom of Information, or NAIH. Electronic marketing must also comply with Hungarian advertising law; assessing the lawful basis under the GDPR alone is not enough.
There is no general compulsory franchise registration requirement or prescribed US-style Franchise Disclosure Document (FDD) regime. Nevertheless, the Civil Code’s pre-contractual information duties and the obligation to provide customers with privacy information still apply. An industry code of ethics does not replace these legal requirements.
Before launch, align the franchise agreement, data protection arrangements, customer privacy notices and internal access rules. Specify who receives customer requests, who locates the relevant data and who responds. Appointing a central contact does not remove a franchisee’s own legal responsibilities.
4. Test access controls and incident handling before launch
Contracts need to be backed by technical restrictions. By default, a franchisee should only be able to see the data needed for its own operations. Use individual user accounts, appropriate authentication and access levels; avoid shared passwords. Promptly update or revoke access when an employee changes role or leaves.
Use synthetic test data to work through three scenarios: a customer requests access to their data, a message goes to the wrong recipient, and an unauthorised person exports a customer list. Make sure it is clear who takes action, what information they pass on and how they document the event.
In the event of a personal data breach, the controller must notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. A processor must notify the controller without undue delay. Internal reporting therefore cannot wait until the next routine meeting.
Practical takeaway: before your first franchisee joins, have a data flow map, clearly allocated roles for each process and a tested breach response procedure in place. Protect trust in the shared brand by ensuring that every use of data has a clear purpose, every access permission has a justification and every task has someone responsible for it.
Sources
- Jogi, pénzügyi és operatív szempontok a gyakorlatban - SZRFK
- Tapasztalatlanok esélye a franchise
- A franchise szerződés
- Franchise vállalkozás – Az üzleti modell minden előnye és ...
- Mátyás Melinda: A franchise szerződés időszerű ...
- Milliárdos üzlet világszerte: te is meg tudod csinálni - Pénzcentrum
- A franchise szabályozási háttere – a magyar és nemzetközi ...
- A franchise rendszer - Debreceni Jogi Műhely



