Resources · Compliance
The DPDP Act for franchise networks
A franchise network collects personal data at every stage, from an expo enquiry to an outlet's staff records. Here is how the Act divides responsibility between brand, master and outlet, and what each has to be able to do.
Read by a professional adviser on 21 August 2026. It is still general information rather than advice on your situation, and rates, thresholds and rules change after a review — check anything you intend to rely on against the source.
A franchise network is an unusually data-heavy business and rarely thinks of itself that way. In a single month a brand might collect enquiry forms at an expo, candidate financials during qualification, franchisee KYC at signing, and staff records from every outlet — most of it personal data belonging to people who are not customers and never become franchisees.
The Digital Personal Data Protection Act, 2023 governs that. This guide explains what it asks of a network, and how the obligations divide between brand, master franchisee and outlet.
On timelines: the Act was passed in 2023, and the rules and compliance dates under it have moved more than once. Any date you read online — including in older versions of guides like this one — should be checked against the current notified position rather than relied on.
Two roles, and which one you are
The Act works through roles, and a franchise network contains both.
A Data Fiduciary determines the purpose and means of processing. A Data Processor processes on a fiduciary’s behalf. The Data Principal is the individual the data is about.
In a typical network:
| Data | Fiduciary | Notes |
|---|---|---|
| An investor enquiry captured on the brand’s form | The brand | Even if the form was filled at a franchisee’s outlet |
| An outlet’s staff records | The outlet entity | The employer is the fiduciary |
| Sub-franchisee candidate data held by a master | The master | Its own recruitment, its own purpose |
| Your account and billing data with a software vendor | The vendor | For the vendor’s own relationship with you |
| Your business records inside a software vendor’s system | You | The vendor processes on your instructions |
That last pair is the one to be clear about with any vendor: for the records you keep in their system, you are the fiduciary and they are your processor. A vendor claiming to be the fiduciary for your leads is claiming rights over your data.
Consent, at the point it is collected
Consent under the Act must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and accompanied by a notice describing what is collected and why.
For a franchise network, the awkward truth is that consent is collected in the least controlled places: an expo counter, a phone call, a WhatsApp message, a form on an aggregator’s site. Three practical consequences:
- The notice has to be where the collection happens. A privacy policy on the website does not cover a paper slip at a stall.
- Purpose has to be specific. “For marketing” is not a purpose. “To assess your suitability as a franchisee for this brand and contact you about it” is.
- You need a record of what was agreed. Consent you cannot evidence is consent you did not get, and a receipt written at the moment of collection is the only version that is trustworthy later.
Consent can also be withdrawn, as easily as it was given. A network whose withdrawal path is “email us and someone will remember” has not implemented withdrawal.
The rights that carry a clock
Data principals can seek access to a summary of their data and the processing, correction and completion, erasure, and nomination of someone to exercise their rights.
Two of these are operationally hard for franchise networks:
Access. Answering “what do you hold about me?” means finding one person’s data across leads, activity logs, documents, chat, outlet records and email. A network that keeps this in seven systems cannot answer honestly inside a deadline.
Erasure. The person asking has usually had one conversation with you years ago. Finding every copy — including the spreadsheet a regional manager exported — is the real work.
Requests also arrive at whatever address the person can find, which is often an outlet rather than head office. Outlet staff need to know that a request must be routed rather than answered.
Erasure against record-keeping
Erasure and retention pull in opposite directions, and this is where naive implementations break.
You must stop retaining personal data once the purpose is served and retention is not required by law. You must also keep invoices, agreements and tax records for statutory periods.
The workable answer is de-identification rather than deletion: strip or irreversibly obscure the personal identifiers while preserving the record the law requires you to keep. The invoice survives with its amounts and dates; the person stops being identifiable from it. Deleting the row instead breaks the ledger and the audit trail, and satisfies neither obligation.
Suppression has to hold everywhere
A withdrawal that stops the newsletter but not the follow-up call has not been honoured. Suppression needs to be enforced at three points at least:
- Capture — a suppressed person re-entering through a new form should not silently create a fresh record to be marketed to.
- Communication — every channel, including WhatsApp and calls, not just email.
- Matching and reporting — a suppressed investor should not surface in a matchmaking shortlist.
Obligations that are not the software’s job
Buying compliant tooling does not make an organisation compliant. These remain yours:
- Appointing a grievance officer and publishing their contact details — a named person, not a role mailbox with nobody behind it.
- Writing your notices for the places you collect data.
- Having a breach process, since notification obligations run to short timelines.
- Training the people who actually meet data principals — outlet managers and expo staff.
- Deciding retention periods, purpose by purpose.
What franchise-specific looks like in practice
- Every capture point carries a notice, including the shareable link and QR used at expos.
- Consent receipts are recorded with purpose and timestamp, in an append-only form.
- One person can be found across the system, not just in the leads table.
- Erasure de-identifies and preserves what statute requires.
- Suppression is enforced at capture, communication and matching.
- The brand/outlet fiduciary split is written down, so a request arriving at an outlet has a known route.
The uncomfortable question worth asking now
Pick a name from an expo you attended two years ago. Ask your team to produce, within a week, every record your network holds about that person — across leads, email, documents, chat, and whatever exports exist on laptops.
The answer to that exercise is your actual compliance position. Everything else is documentation.
Sources
- Digital Personal Data Protection Act, 2023
- Rules and notified timelines under the Act — check the current position, which has changed more than once