Franchising your business

Data Protection Before Franchising Your Business

Prepare to handle applicant, employee and customer data before expanding your business into a franchise network in the Philippines.

Published

Data Protection Before Franchising Your Business

When you franchise an existing business, you pass on more than a brand and a way of selling. Personal data also flows through the network: applicants’ identity details, employee records, customers’ telephone numbers and transaction histories. Within a franchise network, it must be clear who may access, use and share this information. Before taking on your first franchisee, put a practical data protection system in place.

1. Map the data you actually need

Start with your existing business. List every place where personal information is collected or stored: paper application forms, payment devices, customer loyalty schemes, cameras, delivery records and messages sent to the shop’s social media page.

For each set of records, answer five questions:

  • Whose data is being collected?
  • What is its specific purpose?
  • Who is authorised to access it?
  • Who receives it?
  • When will it be deleted or securely destroyed?

Separate the data the brand owner needs from the data needed only by the outlet operator. For example, aggregated sales figures may be enough to assess a shop’s performance. The name, address and telephone number of every customer are not automatically necessary.

When assessing franchise applications, do not immediately ask for multiple copies of identity documents and a complete financial history. Match the documents requested to the stage of the assessment. Collecting less unnecessary data reduces the risk if paperwork goes missing or a device is compromised.

2. Define responsibilities under the law

The Philippines has no single comprehensive franchise law. General contract and intellectual property laws apply, alongside specific rules such as Executive Order No. 169, series of 2022. For personal information, the key legislation is Republic Act No. 10173, or the Data Privacy Act of 2012, together with the rules of the National Privacy Commission (NPC).

The law covers personal data processing, from collection to deletion. Its key principles include transparency, legitimate purpose and proportionality in the information collected. Processing must have an appropriate legal basis; consent is not the only possible basis, nor does it remove other obligations.

Identify who decides the purposes and means of processing. The brand owner and the franchisee operating the outlet may have separate responsibilities. If one processes data solely on the other’s instructions, a different arrangement is needed. Assess what actually happens in practice, not just the labels used in the contract.

Appoint someone responsible for privacy compliance and check whether registration with the NPC is required under the applicable criteria. Having a franchise arrangement does not automatically mean that all compliance requirements have been met.

3. Prepare the documents and limits on use

Before connecting the first outlet to a central system, prepare a clear privacy notice. Explain what data is collected, why, who will receive it, how long it will be kept and how people can submit requests or complaints about its use.

Do not bury everything in a broad statement agreeing to “any use” of the information. Data collected to deliver a product should not simply be used for another purpose without reviewing the legal basis and providing the appropriate notice.

In the franchise agreement or a separate data agreement, clarify:

  • permitted access and sharing;
  • security measures and responsibilities relating to external service providers;
  • responses to requests to access or correct information;
  • incident reporting and handling;
  • the return, retention or secure deletion of data when the relationship ends.

Ask a lawyer to assess whether a data sharing or data processing agreement is needed. A general promise to keep information confidential is not enough. Also ensure that the documents reflect what the systems you use can actually do.

4. Test security before expanding

Use your own shop to test the controls. Give each authorised user an individual system account; avoid sharing a single password across the team. Restrict the information users can see according to their role, and promptly remove access when employees leave.

Run a simulated incident: a phone containing customer records has gone missing. Who should be contacted first? Who will block access? How will you establish which data has been exposed? Who will assess whether the NPC and affected individuals must be notified? Some notification obligations have deadlines, so planning should not begin only after an incident occurs.

Record the results and address weaknesses before opening more outlets. Practical reminder: do not share data until there is a clear purpose, an assigned person responsible, defined access limits and a secure deletion method.

Sources

Free guide

Get the free guide to franchising your business

Enter your details and we'll email you the guide. You can also download it straight away.

We use your details to send the guide and to understand interest in franchising. You can unsubscribe at any time.

Latest articles