One of the questions that creates the most doubts in franchise networks is whether customer data can move between franchisees of the same brand. Business intuition says yes: we are the same brand, we share identity, it would be absurd not to be able to reuse customers. The legal intuition of the GDPR says the opposite: each franchisee is an independent company, controller of its customers' data, and sharing it with another franchisee is a transfer to a separate third party that requires its own legal basis.
This article clarifies when data transfer between franchisees is lawful and when it is not, on the basis of the GDPR (Regulation (EU) 2016/679) and the LOPDGDD (Spain's Organic Law 3/2018).
The starting point: each franchisee is a separate controller
The customer who walks into franchisee A's premises enters into a contract with franchisee A's company. Their data is managed by that franchisee as an independent controller. Franchisee B, even if it operates under the same brand in another city, is a legally distinct company. The shared brand is a commercial asset; it is not a GDPR legal basis for moving data between the two companies.
Belonging to the same franchise network therefore does not, on its own, generate authorisation to transfer customer data. The transfer is governed by the same rules that would apply if they were two unrelated companies: it needs its own legal basis and must comply with the duty to inform the data subject.
The two legitimate paths for data to move within the network
| Path | What it consists of | Key document |
|---|---|---|
| Joint controllership through a common programme | Single loyalty programme, brand CRM, consumer app: data is processed jointly and the customer knows from sign-up. | Art. 26 GDPR arrangement + specific information clause. |
| Explicit customer consent | The customer specifically accepts that their data be transferred to other franchisees of the same brand for a defined purpose. | Specific tick box unticked by default, revocable. |
| Legitimate interest (narrow path) | Only in very specific and limited cases, after a documented balancing test; rarely applicable to commercial marketing between franchisees. | Written legitimate interest test + reinforced information. |
Single brand-wide loyalty programme: the typical case
The single loyalty programme is the most natural architecture for data to circulate lawfully in a franchise network. Its logic is: the customer registers once, their points accumulate at any establishment of the brand and the database is accessible for centralised campaigns and to recognise the customer at any point. Requirements for it to be correct:
- Art. 26 GDPR arrangement between the franchisor and the participating franchisees, allocating obligations on information, rights, breaches, retention and security.
- Specific information clause on programme sign-up: identifying the franchisor and franchisees as joint controllers, explaining what data is processed, for what purpose and for how long, and clarifying that the customer can exercise rights against any of the joint controllers.
- Single point of contact for customer rights: the customer goes wherever is most convenient and the network's internal system handles the response.
- Separation of purposes: programme data is used for programme purposes. If a franchisee wants to use it for its own campaigns outside the programme, it needs additional legal basis.
Shared CRM: clean architecture or covert transfer
It is common for the franchisor to impose a common brand CRM on the franchisee. There are two possible readings of the same CRM, depending on how it has been designed:
- CRM as a franchisee tool, with the franchisor as provider: each franchisee has its space in the CRM, only accesses its own data, and the franchisor is a processor under art. 28 GDPR providing the technological service. There is no transfer between franchisees.
- CRM as a common brand database: all franchisees see the same data, feed the same database and the brand uses it centrally for campaigns and analytics. Here we are in joint controllership under art. 26 GDPR and the customer must have known this on sign-up.
The problem appears when the CRM has been sold to the customer as a local tool of the franchisee but in practice all franchisees access the database. That is a covert and uninformed transfer.
Franchisor communications to franchisee customers
The franchisor often wants to communicate directly with customers across the network for brand campaigns, institutional newsletter, launches. The legal basis for that communication depends on the origin of the data:
- If the data is in a common programme (loyalty, app, shared CRM) where the franchisor is a joint controller and the information clause already included that purpose, the communication is lawful within the informed terms.
- If the data belongs to the franchisee and the franchisor wants to receive it to communicate, explicit customer consent for that transfer and communication is needed, or joint controllership must have been correctly arranged beforehand.
- Art. 21.2 of LSSICE (Spain's Law 34/2002) only covers communications about similar products or services when there is a prior contractual relationship with the sender itself. If the customer only contracted with the franchisee, that prior contract is not with the franchisor.
"In franchises, the important question is not whether data can be moved: it almost always can, if you design it well. The question is whether the customer knows it is being moved. When the answer is no, it doesn't matter how many contracts exist between franchisor and franchisee: the transfer is invisible and ceases to be lawful."
Mario P. Talamillo · Managing Partner, Certix®
Data from one franchisee to another at the end of activity
When a franchisee ends or changes brand, the fate of the data depends on who collected it and under what figure. Basic rules:
- Data of customers contracted by the outgoing franchisee as an independent controller belongs to the franchisee and stays with it for its own legal obligations (tax, commercial, civil) and, where applicable, for continuity of activity in another form.
- Data from the single loyalty programme, corporate CRM and centralised brand platforms remains within joint controllership and the outgoing franchisee loses access at the end of the relationship.
- If the franchisor takes over the premises with a new incoming franchisee, the customer data of the former franchisee is not automatically transferred to the new one: own legal basis is needed (typically customer consent for that transfer).
- If the incoming franchisee also acquires the outgoing company (commercial transaction), the regime is different (business succession) and is governed by its own rules.
- The data protection annex to the franchise contract must anticipate all these scenarios before they occur.
Typical mistakes in transfers between franchisees
- Assuming that belonging to the same brand enables sharing the customer database.
- Collecting data at a franchisee's premises and uploading it to the brand CRM without informing the customer.
- Sending leads captured in a national campaign to franchisees without the lead having been informed of that distribution.
- Letting the franchisor access the franchisee's local database for its own campaigns without legal basis or covering clause.
- Inheriting data from the outgoing franchisee to the incoming franchisee without consent or legal continuity.
- Using loyalty programme data for the individual franchisee's commercial campaigns outside the programme, without additional legal basis.
Practical checklist
- Identify which databases exist in the network and which GDPR figure applies to each (independent, joint controllership, processor).
- If there is a common programme, draft an art. 26 GDPR arrangement and the specific information clause of the programme.
- If the franchisor provides a technological service to the franchisee, sign an art. 28 GDPR contract.
- If there is a transfer not framed in a common programme, obtain explicit customer consent for that transfer.
- Anticipate the scenario of termination and franchisee change in the franchise contract.
- Train point-of-sale staff on which database is being fed with each customer data point.
- Review information clauses so they faithfully reflect what happens in the network.
Frequently asked questions
Can a franchisee share its customer database with other franchisees of the same brand?
Not by default. It is a transfer to a third party. Explicit customer consent for that specific transfer is needed, or a formal joint controllership under art. 26 GDPR (common programme, brand CRM, app) with an information clause reflecting it.
How does a single brand-wide loyalty programme work under GDPR?
As joint controllership under art. 26 GDPR. It requires a written arrangement between franchisor and franchisees, a specific information clause at sign-up identifying all joint controllers and the purpose, a single point of contact for rights and clear separation of purposes.
What happens to data when a franchisee ends or changes brand?
Data of customers contracted by the franchisee as an independent controller belongs to it and stays with it for its legal obligations. Data from the common programme and centralised platforms remains in the network. The new incoming franchisee does not automatically inherit the outgoing one's data.
Can the franchisor send communications to customers acquired by its franchisees?
Only if it has its own legal basis: joint controllership in a common programme with an information clause covering it, specific customer consent or, restrictively, art. 21.2 LSSICE with a prior contractual relationship with the franchisor itself. Belonging to the network does not enable automatic communication.
This content is informational and educational in nature and does not constitute specialised legal advice. Applying the regulation to a specific case requires individual analysis. Spanish regional and sector-specific rules may extend or modify requirements.
Is your franchise network sharing data without having formalised it correctly?
At Certix we assign you an expert in loyalty programmes, shared CRM and brand joint controllership. No commercial intermediaries, no generic templates.
Talk to an expert