Privacy notice for a franchise network
A privacy notice for a franchise network, drafted for the franchisor and adaptable by franchisees, with the cookie notice and consent guidance, £595 in five working days.
Privacy notice for a franchise network
Buy now, £595A franchise network has a brand that runs the website, the booking system, the loyalty scheme and the central marketing, and franchisees that run the shops, the vans or the studios where the customers are, each a separate business, each a controller of something and often a joint controller with the franchisor of the customer data that flows through the central systems. The privacy notice has to say who controls what, explain the central systems and the joint control arrangement, deal with marketing across the network, give franchisees a notice they can adapt, and say what happens to the customer data when a franchise ends. The business receives the privacy notice, the cookie notice and consent guidance within five working days for a fixed £595.
Who this is for
Franchisors in England and Wales with networks in food, retail, fitness, home services, education, care and other sectors, and franchisees who want to know what the brand's notice means for them.
What matters in a franchise network privacy notice
Who is the controller in a franchise network
Article 13 of the UK GDPR obliges the business as controller to tell customers what it does with their data, and in a franchise network the franchisor is the controller for the brand's website, its central marketing database, the loyalty scheme and the data it analyses across the network, each franchisee is the controller for the customers it serves (their orders, bookings, records and the local marketing it does), and where the franchisor and a franchisee jointly decide the purposes and means (a shared customer database both use for their own purposes) they are joint controllers under Article 26; the notice should state the structure in its first section, because a customer who complains needs to know whose notice applies and who answers.
The central systems and the customer data that flows through them
Most networks run a central website, booking or ordering system, point of sale, customer relationship management and loyalty platform, through which customer data is collected at the franchisee's premises or online and held centrally, and the notice should describe the systems, what each holds, which party collects the data and which party uses it for what (the franchisee for the service, the franchisor for the network's analytics, the loyalty scheme, the brand's marketing and the franchise agreement's reporting), the processors behind the systems and the international transfers under Article 46; the franchise agreement and the systems' terms should say who may access what, and the notice should match them.
Joint control, the arrangement and what each party tells customers
Where the franchisor and franchisees are joint controllers, Article 26 of the UK GDPR requires an arrangement between them setting out their respective responsibilities (who gives the notice, who answers requests, who reports breaches, who is the contact point), the essence of which must be made available to customers, and the notice should contain that essence: the franchisor handles the central systems, the website and the loyalty scheme, the franchisee handles the customer's local relationship, and a customer may exercise rights against either; the arrangement itself is a schedule to the franchise agreement or a separate data sharing agreement, which the pack does not include but the note that comes with it describes.
Marketing across the network and who may contact whom
Email and text marketing to individuals is permitted by regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 only with consent or the soft opt-in, and in a network the question is who obtained the consent or the soft opt-in and for whose marketing: a customer who bought from a franchisee and was offered the chance to refuse may receive similar marketing from that franchisee under the soft opt-in, but the franchisor's central marketing needs the customer to have consented to the brand's marketing (or the soft opt-in obtained in the brand's name where the brand is the seller online), and the notice and the sign-up forms across the network should obtain the consent in terms that cover the brand and the local franchisee as the network's practice requires; the website's cookies under regulation 6 of those Regulations need the consent mechanism the pack provides guidance on.
Franchisees as separate businesses with their own obligations
Each franchisee is a controller of the data it holds for its own business (its customers' local records, its staff, its suppliers), must be registered with the Information Commissioner's Office under the Data Protection (Charges and Information) Regulations 2018 where the fee applies, needs a privacy notice for its own processing (which the pack's notice is drafted to be adapted for, with the local details completed), and is responsible for its own compliance, with the franchise agreement's brand standards setting the data protection requirements the franchisor expects (the systems used, the notice adopted, the training completed, breaches reported to the franchisor); the notice should say that franchisees are independent businesses and name the franchisee as controller for the local relationship in the adapted version.
The end of a franchise and the customer data that stays or goes
The notice should say what happens to customer data when a franchise is sold, transferred or terminated: the central systems' data stays with the franchisor and passes to the incoming franchisee for the territory under the joint control arrangement, the outgoing franchisee's own local records are retained or deleted as the franchise agreement and the retention periods provide, customers are told of the change where the controller changes, and the outgoing franchisee may not take the customer list for a competing business; it should cover each right the individual can exercise (access, correction, erasure, restriction, portability, objection), how, within what time (a month), and the right to complain to the Information Commissioner's Office, with the franchisor's registration stated and the retention periods for the central systems set out.
What it costs
Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
Are we and our franchisees joint controllers?
For a shared customer database both use for their own purposes, yes, and Article 26 requires an arrangement between you with its essence published. For the brand's website and the franchisee's local records, each is a sole controller. The notice states the structure.
Can the brand email customers who bought from a franchisee?
Only with consent to the brand's marketing, or the soft opt-in obtained in the brand's name where the brand was the seller. The network's sign-up forms should obtain consent in terms that cover both, and the notice says so.
Do franchisees need their own privacy notice?
They do, as separate controllers for their local processing, with their own registration. The pack's notice is drafted to be adapted for each franchisee with the local details completed.
Related guidance and services
- Data protection agreements and privacy terms, £595, the service this page describes
- Terms and conditions drafting, £995
- SaaS and technology contracts, £995
- Shareholders agreement for a franchisee company
- Reviewing a franchise agreement before you sign
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.