GDPR in franchising: prepare your shared CRM before launch
A shared CRM does not mean shared ownership of data. Check roles, access rights and documentation before bringing your first franchisee on board.
Published

In an established business, the customer database often develops around a single owner, a shared reception team and one booking system. Turning that business into a franchise network changes the picture: independent businesses become involved in serving customers. Before giving your first partner access to the CRM, establish who is responsible for the data, who can see it and for what purpose. A confidentiality clause in the franchise agreement is not enough.
1. Map data flows, not just system features
Start by tracing one real customer journey: from the website form, through choosing a location and receiving the service, to a reminder about the next appointment. At each stage, record which organisation receives the data, why it needs it and how long it intends to keep it.
Prepare a simple table covering:
- the data source, such as a form, a phone call or a visit to the premises;
- the information collected, such as a name, phone number and booking history;
- the purpose of using it, such as delivering a service, billing or marketing;
- the organisations with access and the justification for that access;
- the date for deleting the data or the criteria for determining it.
Do not automatically share your entire existing database with every location. A customer of your company-owned outlet does not become a customer of every partner simply because you launch a franchise. Sharing data requires an appropriate lawful basis and compatibility with the purpose for which it was collected, not just the technical ability to export it.
Separate the data needed to serve customers from the data used for analysis. Head office may need information about appointment numbers and capacity utilisation, but not necessarily customers’ names. If genuinely anonymous statistics are sufficient, do not grant access to full customer records.
2. Assign legal roles to specific activities
In Poland, a franchise agreement is not a separately regulated, specifically defined type of contract. It rests on the principle of freedom of contract under Article 353¹ of the Polish Civil Code, subject to the limits of that principle. There is no separate requirement to register a franchise system, nor a statutory, franchise-specific deadline for providing a disclosure document. This does not, however, remove the obligation to comply with generally applicable law.
For a shared CRM, the key rules are the GDPR — Regulation (EU) 2016/679 — and the Polish Personal Data Protection Act. Electronic direct marketing also requires compliance with Poland’s Electronic Communications Law. A franchise code of ethics is no substitute for these laws.
Determine roles according to who actually makes the decisions, rather than the labels used in the agreement:
- Separate controllers: the partner independently determines the purposes and means of processing its customers’ data, while head office processes certain data for its own, separate purposes. Each party needs a lawful basis for its activities.
- Controller–processor relationship: head office handles data solely on the partner’s documented instructions, for example by providing technical administration of the CRM. This requires an agreement compliant with Article 28 of the GDPR.
- Joint controllers: the parties jointly determine the purposes and means of processing. This requires an arrangement allocating responsibilities under Article 26 of the GDPR, with the essence of that arrangement made available to the individuals concerned.
A single relationship can involve different roles for different activities. Head office might manage bookings on a partner’s instructions while also acting as the controller for data relating to members of its own loyalty programme. Do not cover both processes with one generic statement about processing data on another party’s behalf.
3. Prepare documents and settings before granting partner access
Identify a lawful basis for each purpose. Managing bookings, meeting accounting obligations and sending promotional offers need not all rely on the same basis. Consent is not a universal solution, and marketing consent should not be a condition of receiving a service if it is not necessary to provide that service.
Privacy notices should reflect how the parties actually work together. Customers must be told, among other things, who the controller is, the purposes and lawful bases for processing, who their data may be disclosed to and how to exercise their rights. A vague reference to “our network” is no substitute for correctly identifying the controller.
In the franchise agreement and data-related documentation, establish:
- who creates accounts and revokes access rights;
- who responds to customers’ requests and how these are passed to the appropriate party;
- how incidents are reported and evidence is preserved;
- what happens to the data when the relationship ends;
- who is responsible for the CRM provider and for assessing any transfers outside the European Economic Area (EEA).
Then translate the documentation into system settings. Use individual user accounts, multi-factor authentication and access rights limited to what each role needs. Staff at one location should not be able to see other partners’ customers by default. Also check that exports are logged and that data can be deleted while respecting retention obligations.
4. Test how requests and incidents are handled
Before enabling access, run a trial using test data. Simulate a request for a copy of personal data, withdrawal of marketing consent and a report accidentally sent to the wrong partner. Check not only that the software works, but also that staff know whom to notify.
The incident procedure should recognise that, where the GDPR requires it, the controller must notify the supervisory authority of a personal data breach, where feasible, within 72 hours of becoming aware of it. A processor must notify the controller without undue delay. Not every incident requires notification to the authority, but every suspected incident should reach someone able to assess the risk promptly.
Practical takeaway: before inviting your first partner into the CRM, approve the data flow map, legal roles and access rights matrix. Only then activate accounts. Trust within a franchise network depends on clear access boundaries, not unrestricted visibility.
Sources
- [PDF] PRZEDSIĘBIORCA W SYSTEMIE FRANCZYZOWYM - PARP
- Franczyza - Dudkowiak & Putyra
- Biznes pod cudzą marką
- Franczyza - co to takiego [Umowa, opłaty, pomysł na biznes]
- Franczyza w Polsce
- W sprawie potrzeby uregulowania umowy franczyzy w ...
- Sprawdzony przepis na sukces, czyli wszystko o umowie franczyzy
- Przedsiębiorca w systemie franczyzowym



