Customer data before launching your first franchise in Slovenia
Before expanding your franchise network, establish customer data access rules, responsibilities and how your shared customer relationship management system will be used.
Published

When an existing business develops into a franchise network, its customer database does not automatically become the shared property of everyone involved. Bookings, purchase histories and contact details serve different purposes, so a shared IT system does not mean unrestricted access. Before bringing in your first franchisee, establish who needs which data, the legal basis for using it and who is accountable to customers.
1. Map data flows first, not software
Start with how your existing outlet actually operates. Follow the customer journey from the initial enquiry through service delivery, invoicing, any complaints and subsequent marketing messages. At each stage, record the data involved, the purpose of processing, who uses it and the planned retention period.
A simple review should answer the following questions:
- Does the customer place an order with the central company or directly with the local franchisee?
- Which company provides the service, issues the invoice and handles complaints?
- Does the central company need individual customer data or just an aggregate report?
- Can another outlet see a customer's visit history, and why would it need to?
- Who sends marketing messages and manages unsubscribe requests?
Pay particular attention to free-text fields. Staff may inadvertently enter health information, personal circumstances or other details that are not needed to provide the service. When a business model is rolled out across a franchise network, this habit can quickly become a recurring problem.
The practical outcome of this step is a map of processing activities, not just a list of software. Only then should you select or adapt a shared customer relationship management system.
2. Assign roles according to who actually makes decisions
Slovenia has neither a dedicated law comprehensively governing franchise agreements nor a specific mandatory franchise register. Contractual relationships are assessed primarily under the Slovenian Obligations Code and other relevant general legislation. For personal data, the key legislation is the General Data Protection Regulation (GDPR) and Slovenia's Personal Data Protection Act (ZVOP-2). The Electronic Communications Act (ZEKom-2) is also relevant to electronic direct marketing.
For each processing activity, establish the roles of the companies involved:
- Independent controllers: each company determines the purposes and essential means of its own processing. A local franchisee may, for example, be the controller for data used in its invoicing.
- Joint controllers: two companies jointly determine the purposes and essential means of a particular processing activity, such as a shared loyalty programme. They then need an arrangement allocating responsibilities under Article 26 of the GDPR, the essence of which must be made available to the individuals concerned.
- Controller and processor: one company processes data on behalf of another and on its instructions. This relationship requires a contract or another appropriate legal instrument under Article 28 of the GDPR.
Roles may differ between processing activities. A franchisor is not automatically the controller of all data simply because it provides the software or brand. Nor is a franchisee automatically a processor because it follows an operations manual.
A contractual label cannot override the actual circumstances. The assessment should therefore be carried out jointly by someone familiar with the business processes, the IT system administrator and a legal adviser.
3. Separate service delivery from shared marketing
Identify an appropriate legal basis for each purpose. Data needed to deliver a service ordered by a customer may be processed for the performance of the contract with that customer; legally required invoice retention is based on a legal obligation. Neither basis, on its own, permits every subsequent marketing use.
If your existing database contains consent to receive offers from your company, do not assume that it also covers offers sent by a new, legally independent franchisee. Check the wording of the consent, the controllers named, the purposes and the evidence of how consent was obtained. For emails and messages, also comply with the conditions under ZEKom-2; any exceptions for marketing to existing customers are not blanket permission for the whole network.
Make it clear to customers which company they are dealing with and how their data is used. The privacy notice should reflect the actual allocation of responsibilities, data recipients, retention periods and how customers can exercise their rights.
As a rule, use aggregate data first when comparing outlet performance. A franchisor can monitor booking numbers or repeat-visit frequency without always needing customers' names. Bear in mind, however, that removing a name does not guarantee anonymity if the individual can be identified from other data.
4. Test access controls and response procedures before opening
Put the agreed rules into practice through system settings and a short schedule to the contract. This should define permitted uses, access rights, retention periods, cooperation on requests from individuals and procedures for security incidents. Where an arrangement under Article 26 or 28 of the GDPR is required, a general confidentiality clause is not enough.
Each user should have their own account. Restrict access according to duties, introduce multi-factor authentication where appropriate and log significant actions. Also check the system provider, its subcontractors and any transfers of data outside the European Economic Area.
Before opening, run a test using fictitious data: a customer requests access to their data, an employee moves to another outlet, someone exports the database or loses a device. Establish who takes action and whom they notify. Internal reporting must allow a timely assessment of whether a breach needs to be reported to Slovenia's Information Commissioner; where notification is required, the GDPR generally gives the controller 72 hours from becoming aware of the breach.
Practical takeaway: before launching your first franchise, prepare a map of processing activities, allocate legal roles and test your access permissions. A shared brand connects the franchise network, but it does not grant unrestricted rights to its customers' data.
Sources
- International Franchise Handbook: Focus on Slovenia
- Open a Franchise Business in Slovenia
- Franšize: Priložnost ali past?
- Predpogodbena dolžnost razkritja informacij in franšizno razmerje
- Franšiza – franšizing
- Franšizna pogodba je le ustaljena poslovna praksa
- Treba nam reda
- Franšizing in franšiza: vse informacije na enem mestu



