Certix

DPO in franchise networks: shared appointment, individual appointment and allocation of responsibilities

Certix
Certix®
· 2 Jun 2026 · 8 min read

Informative article. It does not replace individualised professional advice.

A franchise network raises a double question regarding the Data Protection Officer: is the franchisor obliged? are the franchisees obliged? And, if the answer to either is yes, can there be a single DPO for the entire network? Business intuition pushes towards simplification: one common DPO for the whole brand. The regulation is more nuanced and requires case-by-case analysis.

This article explains the applicable rules: art. 37 GDPR on the appointment obligation, art. 37.2 GDPR on a single DPO within a group of undertakings, art. 34 LOPDGDD on additional scenarios in Spanish law, and the figures of art. 38 and art. 39 GDPR on position and functions.

When the DPO is mandatory: art. 37 GDPR and art. 34 LOPDGDD

Art. 37.1 GDPR requires the appointment of a DPO in three scenarios:

  • When the controller or processor is a public authority or body (not applicable in a private franchise).
  • When the core activities consist of processing operations which, by their nature, scope or purposes, require regular and systematic monitoring of data subjects on a large scale.
  • When the core activities consist of large-scale processing of special categories under art. 9 (health, etc.) or of data under art. 10 (criminal records and offences).

Art. 34 LOPDGDD complements GDPR with an additional list of scenarios where appointment is mandatory in Spain (financial entities, healthcare centres required to keep medical records, energy distributors, information society service providers carrying out large-scale profiling, among others).

In a franchise network, the question splits in two: the situation of the franchisor and that of each franchisee must be analysed separately, because they are legally distinct companies with distinct processing activities.

When the franchisor typically needs it

The franchisor frequently centralises large-scale processing activities that do not exist in isolation at each franchisee: consumer app with millions of downloads, national loyalty programme, unified CRM, customer profiling, advanced analytics, mass campaigns. When those processing activities constitute a core activity of the franchising company (or of the group's service company), DPO appointment is typically mandatory under art. 37.1.b GDPR.

If the brand operates in sectors where special categories of data are processed centrally (for example, a healthcare services franchise), art. 37.1.c GDPR is also triggered.

When the franchisee typically needs it

The franchisee, given its local scale, generally does not carry out large-scale processing that would trigger the general obligation of art. 37.1.b GDPR. The obligation appears when the franchise sector is one of those listed in art. 34 LOPDGDD or when, individually, the franchisee performs mass processing on its own. In general-purpose sectors (restaurants, retail, standardised services), the individual franchisee is rarely obliged.

Although this is the general rule of the sector, the final requirement will depend on the scale, volume and exact typology of each entity's processing. Each case requires individual analysis.

Art. 37.2 GDPR: single DPO in a group of undertakings

Art. 37.2 GDPR allows a group of undertakings to appoint a single DPO, provided they are easily accessible from each establishment. The operational question is: is a franchise network a group of undertakings under art. 37.2 GDPR?

Scenario Art. 37.2 GDPR? Common solution
Franchisor's group of undertakings (parent + subsidiaries) Applicable. Single DPO within the group, appointed and notified by the parent entity.
Independent franchisor and franchisees Not directly applicable: they are not a group under art. 4.19 GDPR. Each company appoints separately. Possible common external DPO contracted individually by each one.
Franchisees that are subsidiaries of the franchisor parent Applicable among those that do belong to the group. Single DPO between parent and subsidiaries; franchisees outside the group, separately.

The practical formula: common external DPO separately contracted

The most widespread solution in obliged franchise networks is coordinated appointment: the franchisor appoints its DPO (internal or external), and each franchisee that is obliged contracts individually with the same external DPO as the franchisor. Each company makes its own appointment, its own notification to the AEPD and its own contract.

Operational advantages: the DPO knows the network, the common procedures, the providers and the tools; franchisees benefit from the brand standard; incident coordination is easier. What does not change is that each company remains an autonomous controller of its compliance and the DPO works with each one in a bilateral relationship, with the functional independence of art. 38.3 GDPR.

Position and functions of the DPO (art. 38 and art. 39 GDPR)

Whichever model is chosen, the DPO appointed in any company of the network must enjoy the safeguards of art. 38 GDPR: proper and timely involvement in all data protection matters, sufficient resources to perform tasks, no instructions on the exercise of tasks, no sanctions for performing them, reporting to the highest management level and duty of secrecy.

Their functions, under art. 39 GDPR, are to:

  • Inform and advise the controller, the processor and their employees about GDPR obligations.
  • Monitor compliance with GDPR and internal policies, including assignment of responsibilities, awareness and training of staff and related audits.
  • Provide advice on the data protection impact assessment and monitor its performance.
  • Cooperate with the supervisory authority (the AEPD in Spain).
  • Act as the contact point for the supervisory authority on issues relating to processing and prior consultations.

"In a franchise network, the coordinated DPO works very well as long as each company understands that the DPO works for it, not for the brand. Same DPO, same tools, same procedures, same criteria. But individual appointment, individual contract and individual supervision. What always fails is assuming the franchisor's DPO covers the franchisee by contagion."

Mario P. Talamillo · Managing Partner, Certix®

Voluntary appointment of the DPO

Art. 37.4 GDPR allows any controller that is not obliged to appoint a DPO voluntarily. If it does, all the rules of art. 38 and art. 39 GDPR apply equally to a mandatory DPO: it is not a second-class DPO. The AEPD recognises voluntary appointment as evidence of the principle of accountability under art. 24 GDPR.

In a franchise, voluntary appointment may make sense when franchisees are not technically obliged but want to align with the brand standard for reputational reasons, contractual reasons (the franchise contract requires it) or internal organisation.

Notification to the AEPD

Art. 37.7 GDPR requires the publication of the DPO's contact details and their communication to the supervisory authority. In Spain notification is made through the AEPD's electronic registry. Each company appointing a DPO files its own notification, including when it is a common external DPO shared with others.

Checklist for allocating DPO across the network

  • Separately analyse the situation of the franchisor based on the scale and centralisation of its processing.
  • Separately analyse the situation of each franchisee (or, at minimum, model typical profiles: small, medium, large franchisee).
  • Verify whether the franchise sector triggers scenarios under art. 34 LOPDGDD.
  • If the franchisor is obliged: appoint a DPO, notify the AEPD, provide resources and independence.
  • If some franchisees are obliged: offer them the possibility to contract the same external DPO (coordinated individual appointment).
  • Document the non-obligation analysis when the conclusion is that no DPO is needed, as evidence of accountability.
  • Include in the franchise contract a commitment from the franchisee to assess its own obligation and communicate to the franchisor any appointment made.
  • Coordinate common procedures (handling rights, breaches, training) while respecting the formal independence of each appointment.

Frequently asked questions

Is it mandatory to appoint a DPO in a franchise network?

It depends on individual analysis of the franchisor and each franchisee under art. 37 GDPR and art. 34 LOPDGDD. The franchisor with large-scale centralised processing is usually obliged; franchisees, depending on scale and sector. Each case requires individual analysis.

Can the franchisor appoint a single DPO for the entire network?

Art. 37.2 GDPR applies to a group of undertakings in the strict sense (parent and subsidiaries), not to the franchise network between independent companies. The practical formula is coordinated appointment: the same external DPO separately contracted by franchisor and obliged franchisees.

What responsibilities does the DPO have in a network with joint controllers and cross processor arrangements?

Those of art. 39 GDPR with respect to the company that appointed them. They are not personally liable for the controller's decisions: art. 38.3 GDPR guarantees functional independence. Ultimate compliance responsibility always lies with the controller.

What if the franchisor has a DPO and the franchisee does not, or vice versa?

It is the usual situation and is not problematic if each company has analysed its obligation. The franchisor with mass processing may be obliged and franchisees not, or vice versa in sectors that individually trigger art. 34 LOPDGDD. What matters is that each appoints if required.

This content is informational and educational in nature and does not constitute specialised legal advice. Applying the regulation to a specific case requires individual analysis. Spanish regional and sector-specific rules may extend or modify requirements.

Does your franchise network need a coordinated DPO serving the brand and obliged franchisees?

At Certix we assign you an external DPO expert in brand networks. Coordinated appointment, no commercial intermediaries, no generic templates.

Talk to an expert

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →