Plan Customer Data Access Before Franchising in New Zealand
Decide how customer information will be collected, shared and protected before opening your first New Zealand franchise.
Published

Franchising an existing business means deciding who can see and use the customer information you have already collected. A shared booking system or customer database may look straightforward, but independent franchisees introduce new responsibilities. Before granting your first franchise, establish a practical data-sharing arrangement that protects customers and gives your franchise community the access it genuinely needs.
1. Map customer information before sharing it
Start with the customer journey, not the software contract. Follow an enquiry through booking, payment, service delivery, follow-up and complaint handling. For each stage, record what personal information is collected, where it goes and who can access it.
Include less obvious records: staff notes, photographs, recorded calls, loyalty accounts and information held on personal devices. A customer database audit that ignores spreadsheets and messaging applications will miss important risks.
Build a simple register containing:
- The information collected and its business purpose.
- The business responsible for collecting it.
- The systems and service providers holding it.
- The people who need access and why.
- The retention period and deletion process.
Separate identifiable customer records from management reporting. A franchisor monitoring booking volumes may need totals rather than customer names, contact details and service histories.
Then test a realistic scenario: a customer books centrally but receives service from a franchisee. Can you explain clearly which business receives the information and what each will do with it? If not, resolve that uncertainty before recruitment begins.
2. Understand New Zealand’s legal framework
New Zealand has no franchise-specific legislation or government franchise registration requirement. General laws still apply, including the Fair Trading Act 1986, the Commerce Act 1986 and, for personal information, the Privacy Act 2020.
The Privacy Act’s information privacy principles govern matters including collection, security, access, correction, retention, use and disclosure. Franchise businesses should collect personal information only where it is necessary for a lawful purpose connected with their functions or activities. Customers should receive appropriate information about its collection and intended use.
A franchise agreement cannot make an otherwise unlawful disclosure lawful simply by describing the franchisor as the database owner. Nor does sharing a brand automatically mean every franchisee may browse every customer record.
Each business should understand its role under the Privacy Act and appoint a privacy officer. Ask a New Zealand privacy lawyer to assess the proposed arrangement, particularly where one business holds information on another’s behalf.
The Franchise Association of New Zealand’s Code of Practice and Ethics is a membership requirement, not legislation applying to every franchise. It does not replace privacy obligations. Likewise, customer-facing statements about confidentiality and security must not be misleading under the Fair Trading Act.
3. Set access rules and contractual responsibilities
Create an access matrix before configuring your shared systems. Define permissions for franchise owners, outlet employees, central support staff and external providers. Give each role only the access needed for its work.
For example, an outlet might need its own customers’ appointment histories, while central support needs limited access to resolve escalated complaints. Access to another outlet’s customers should require a defined reason, not merely a convenient search function.
Have your solicitor align the franchise agreement, privacy notices and technology contracts. Address:
- Permitted uses of customer information, including marketing.
- Responsibility for answering access and correction requests.
- Security requirements and incident reporting.
- Approval of additional applications and service providers.
- Retention, deletion and access removal when a franchise ends.
Do not assume that customers who gave their details to your original business agreed to every future use across a franchise community. Check whether proposed uses and disclosures fit the original purposes or require another lawful basis.
Review overseas hosting and support access too. Overseas storage is not automatically the same as disclosure to an overseas recipient; the provider’s role matters. Obtain advice on when the Privacy Act’s overseas disclosure requirements apply.
4. Test the arrangement before launch
Use fictional customer records to test permissions. Confirm that an employee cannot export the entire database, a former user loses access promptly, and central staff can complete legitimate support tasks without unnecessary visibility.
Run a short breach exercise. Suppose a franchisee emails customer records to the wrong recipient. Establish who contains the incident, preserves evidence, assesses the risk and coordinates communications.
Under the Privacy Act, a breach that has caused, or is likely to cause, serious harm must be notified to the Privacy Commissioner and affected individuals as soon as practicable, subject to statutory exceptions. Your internal reporting process should support that assessment without delay.
Finally, test a customer access request and a departing franchisee’s account closure. Keep a record of failures, corrective actions and retesting.
Practical takeaway: Before sharing live customer information, complete a data map, agree responsibilities, obtain legal review and test access controls. Treat customer trust as a responsibility shared across your franchise community, not as a database feature.



