Franchise networks present one of the most complex architectures in data protection. The franchisor is the brand owner and system designer; the franchisee is an independent business operating under that brand; and the end customer enters a store or channel where they often cannot tell where one ends and the other begins. Over that relationship operate the GDPR (Regulation (EU) 2016/679), the LOPDGDD (Spain's Organic Law 3/2018) and, depending on the sector, specific regulations.
This article explains how to allocate GDPR figures in a franchise network, what contractual models to use, where the joint controllership of art. 26 GDPR appears and how liability is distributed when something goes wrong.
The starting point: each company is a controller
The franchisee is an independent company or business that signs a contract with the end customer, issues the invoice, manages the commercial relationship and decides in its day-to-day operations which data to request, how to keep it and what to use it for. That operational autonomy makes it by default the controller of its customers' and personnel's data. The franchisor, in turn, is the controller of the data it processes for its own purposes: management of the franchisee network, data of franchise partners and corporate staff, institutional brand marketing, system quality control, training.
What breaks that clean separation is the shared operation: a single brand website where customers across the entire network book, a centralised CRM, a single loyalty programme, a consumer app, national advertising campaigns, a corporate payment gateway. There, end-customer data is processed simultaneously by franchisor and franchisee, and the appropriate figure ceases to be independent controllership.
The three GDPR figures applied to a franchise
| GDPR figure | When it applies in a franchise | Instrument |
|---|---|---|
| Independent controller | Each party decides for its own purposes on its own data. | Each party complies with GDPR separately. |
| Joint controllers | They jointly determine purposes and means (single loyalty programme, shared CRM, brand app). | Art. 26 GDPR arrangement. |
| Controller and processor | One party provides the other with a data processing service on its behalf (centralised management, tech support). | Art. 28 GDPR contract. |
| Transfer between controllers | One party hands over data to the other to use for its own different purposes (independent campaigns, prospecting). | Own legal basis (consent, legitimate interest) and information to the data subject. |
When joint controllership applies (art. 26 GDPR)
Art. 26 GDPR regulates joint controllers: two or more entities that jointly determine the purposes and means. In a franchise it is typically triggered when:
- Single brand-wide loyalty programme: the customer registers in a common programme (points, rewards, app), data is collected by the franchisee in its store but feeds a centralised database used by the franchisor for campaigns and analytics. Both decide purposes and means.
- Centralised corporate CRM or ERP: where the franchisee's customer data flows into a shared database that the franchisor consults for its own brand purposes (segmentation, national communications).
- Consumer app issued by the brand, where the customer books, pays, leaves reviews or orders at any point in the network.
- Central brand website with booking or purchase that routes the operation to the relevant franchisee and centralises user registration.
- National campaigns capturing leads that are then distributed among franchisees.
In all those cases the art. 26 GDPR arrangement must document who informs the data subject and where, who handles rights under arts. 15 to 22 GDPR, who notifies breaches to the AEPD (the Spanish Data Protection Authority), how data is retained and for how long, what security measures apply and what the customer's point of contact is. The essential part of the arrangement is made available to the customer (typically in the privacy policy of the programme or the app).
When there is a processor relationship (art. 28 GDPR)
A processor relationship exists when one party processes data on behalf of the other, without deciding for its own purposes. Typical cases in a franchise:
- The franchisor provides the franchisee with a centralised tech support service (hosting of the management software, maintenance, backup) and only accesses the data for that purpose, without using it for its own ends.
- A central booking office operated by the franchisor processes customer data exclusively to execute the booking on behalf of the franchisee that will deliver the service.
- The franchisee performs a one-off task on behalf of the franchisor (brand survey, corporate event), processing franchisor data under precise instructions.
The art. 28 GDPR contract covers: subject-matter, duration, purpose, type of data, categories of data subjects, processor obligations (confidentiality, security, assistance, breaches, sub-processors with authorisation, return or deletion at the end) and audit.
"In a well-designed franchise network, the customer understands who is processing their data and for what. The beauty of the brand is that the customer doesn't notice the border between franchisor and franchisee. The seriousness of GDPR is that the border has to be drawn in ink somewhere, and that somewhere is the data protection annex to the franchise contract."
Mario P. Talamillo · Managing Partner, Certix®
Joint and several liability and reputational exposure
Art. 82 GDPR allows the data subject to bring action against any of the controllers or processors involved in the processing to obtain full compensation for damage. Afterwards, they apportion the cost among themselves according to the share of responsibility of each. It is the closest equivalent to classic joint and several liability under civil law applied to a network of companies.
In parallel, an AEPD sanction on a franchisee for bad data handling has reputational impact on the whole brand network, which justifies the franchisor imposing minimum verifiable standards in the manual: approved clauses, authorised tools, mandatory staff training, common breach procedure, periodic compliance audit per outlet.
Data protection annex to the franchise contract: recommended content
- Definitions and figures: identifying which processing activities are independent controllership, joint controllership or processor relationships.
- Individual obligations of each party as independent controller (RoPA, clauses, art. 28 with its suppliers, security policy, breach handling, rights handling over its own data).
- Art. 26 GDPR arrangement for shared processing: loyalty programme, app, shared CRM, joint campaigns.
- Art. 28 GDPR contract for centralised services provided by the franchisor or between franchisees.
- Common breach notification procedure with internal deadlines consistent with the 72 hours of art. 33 GDPR.
- Rights handling procedure: where the customer can go, internal response timeline between the parties.
- Minimum standard of information clauses that the franchisee must give to the end customer, approved by the franchisor.
- Marketing communications policy: when the franchisor may communicate with the franchisee's customers and on what basis.
- Data handling at the end of the franchise: what is returned, what is retained by legal obligation, what is deleted.
- Audit: right of the franchisor to verify compliance with the brand standard.
Common mistakes in franchise networks
- Assuming the franchisor is always the franchisee's processor (or vice versa) without analysing who decides on what.
- Sharing customer databases between franchisees of the same brand without a joint controllership arrangement or a clear legal basis.
- Collecting leads in a national campaign and distributing them to franchisees without having informed the data subject of that distribution.
- Imposing a corporate CRM without defining whether the data belongs to the franchisee, the franchisor or both.
- Not anticipating in the contract what happens to customer data when the franchise ends (ownership, export, legal retention).
- Confusing the franchise manual with a data protection contract: the manual is an operating standard, not a legally enabling document.
Frequently asked questions
Who is the controller in a franchise: the franchisor or the franchisee?
By default, the franchisee controls the data of its customers and staff; the franchisor controls the data of the network, brand marketing and partners. In shared processing activities (loyalty, CRM, brand app, joint campaigns) there is joint controllership under art. 26 GDPR.
Can the franchisor impose a CRM and templates and each remain an independent controller?
Yes, if the franchisor does not access end-customer data for its own purposes. If it does access for brand marketing, corporate analytics or loyalty, joint controllership or a controller-to-controller transfer applies and must be documented.
Is there joint and several liability between franchisor and franchisee before the AEPD?
Not automatic before the AEPD: each controller answers for its own non-compliance. Civilly, art. 82 GDPR allows the customer to claim full damages from any of them. In joint controllership the data subject may approach any of them. Reputationally, a sanction affects the whole network.
What contractual model should franchisor and franchisee sign on data protection?
A data protection annex to the franchise contract distinguishing three blocks: independent controllership, joint controllership under art. 26 GDPR (loyalty, app, shared CRM) and processor relationships under art. 28 GDPR (centralised services). Plus common procedures for breaches, rights and communications.
This content is informational and educational in nature and does not constitute specialised legal advice. Applying the regulation to a specific case requires individual analysis. Spanish regional and sector-specific rules may extend or modify requirements.
Want to clarify the GDPR allocation of responsibilities across your franchise network?
At Certix we assign you an expert in franchise networks and joint controllership. No commercial intermediaries, no generic templates.
Talk to an expert