DPDP

What DPDP asks of a franchise network

The Digital Personal Data Protection Act, 2023 changes what you are allowed to do with the enquiries, candidates and staff records a franchise network accumulates. This page explains the obligations in operator's terms, and what the platform does about each one.

This is an explanation, not legal advice, and the rules and their timelines have moved more than once — confirm your own position with counsel rather than with a software vendor's website.

The obligations, in order

What has to be true

Who is the fiduciary

For the records your organisation keeps — leads, investors, franchisee candidates, outlet staff — your organisation is the Data Fiduciary and FranOpero is the processor acting on your instructions. For your own account and billing data, FranOpero is the fiduciary. Most franchise networks have never had that split written down before, and it decides who answers a data principal who writes in.

Notice and consent

Consent has to be asked for at the point of collection, in clear terms, for a stated purpose — which for a franchise network means the expo form, the enquiry page and the shareable link, not a policy nobody opened. The platform records purpose-tagged consent receipts in an append-only ledger, so what someone agreed to and when is a record rather than a recollection.

Rights people can exercise

Access, correction, erasure and nomination. Those requests arrive from investors and candidates you may have spoken to once, years ago, and they carry a clock. The platform has a rights queue with identity verification and SLA tracking so the request is worked rather than forwarded.

Erasure without losing the ledger

Erasure and record-keeping pull in opposite directions: you must stop holding personal data, and you must keep invoices and agreements. The platform de-identifies the personal data while preserving the legally retained record, rather than deleting rows and breaking the audit trail.

Suppression that actually holds

A "do not contact me" that only stops the newsletter is not compliance. Suppression is enforced where it matters — at capture, in communications and in matchmaking — so a withdrawn consent is not quietly re-used by another part of the system.

What we hear

Four things franchisors get wrong

“It only applies to big tech”

The Act applies to anyone processing digital personal data in India, at any size. A franchise network holding investor enquiries is squarely in scope.

“Our franchisees are responsible for their own data”

They are fiduciaries for what they collect — but the brand that specifies the form, receives the data and stores it is not outside the frame. The split needs writing down, not assuming.

“We will fix it when someone asks”

Rights requests carry timelines. A network that cannot find every record about one person across leads, outlets, documents and chat cannot answer one on the clock.

“Buying compliant software makes us compliant”

It does not. The tooling can record consent, work a rights queue and de-identify on erasure. Appointing a grievance officer, writing your notices and training your team stay yours.

The operative pages

Where the real documents live

This page explains. The privacy policy is the document that binds, and the rights channel is where a data principal actually files — both are served from the platform, with the grievance officer's details rendered from live configuration rather than copied into a static page.

Being straight about it

  • The legal pages are marked as pending review until counsel signs them off.
  • A grievance officer has to be a named person. Until one is appointed, the notice says so rather than naming a placeholder.
  • Consent-manager registration under the Act is a separate regime we are not part of, and we do not imply otherwise.

See how consent and rights work in the product

The consent ledger, the rights queue and the erasure model are shipped features, not a roadmap slide.