BusinessApril 12, 20269 min read

GDPR for Restaurants — What You Need to Know About Customer Data

GDPR for restaurants explained — what data you can legally collect, how Plattr handles tenant isolation and consent flows, and what stays your responsibility.

Vlad Shytov

Vlad Shytov

91 views

GDPR for Restaurants — What You Need to Know About Customer Data

GDPR arrived in 2018 and most restaurants in the EU still have a complicated relationship with it. Some treat compliance as a paperwork exercise — a privacy policy on the website, a cookie banner, and hope for the best. Others have gone the other direction and avoided collecting any guest data at all, which means no loyalty programs, no booking analytics, no way to know who their regulars are.

Neither approach is right. GDPR is designed to protect guests, not to prevent restaurants from running sensible operations. Understanding what it actually requires — rather than the most anxious reading of what it might require — makes compliance manageable and keeps your data collection legitimate.

Data privacy compliance restaurant GDPR

What data restaurants typically collect

The data a restaurant collects in the course of normal operations includes: names and contact details from booking forms, visit history and spending patterns from loyalty programs, dietary preferences and allergen information from booking notes, payment data from deposits, and potentially photos if you run social media.

All of this is personal data under GDPR. Collecting it is legal — restaurants have legitimate business interests and, where required, explicit consent. The obligation is to be transparent about what you collect, why, how long you keep it, and who you share it with. For a complete overview of what loyalty programs specifically collect and why, see the complete guide to loyalty programs.

The two legal bases restaurants use most

GDPR requires a legal basis for processing personal data. The two that apply most often in restaurant contexts:

Contractual necessity. When a guest books a table, you need their name, email, and party size to fulfil that booking. Collecting and using this data is covered by contractual necessity — you are not required to ask for separate consent to use a guest's email address to send them a booking confirmation.

Legitimate interests. This covers situations where you have a reasonable business purpose that does not override the guest's privacy rights. Sending a booking reminder 24 hours before service is a legitimate interest. Sending weekly promotional emails to everyone who ever made a booking is not — that requires explicit consent.

Consent. For marketing communications — newsletters, promotional offers, loyalty program enrollment — you need explicit, freely given consent. This means a clear opt-in checkbox at the point of data collection, not a pre-ticked box, and a straightforward way to withdraw consent at any time.

How Plattr handles GDPR compliance

Plattr is built for EU restaurants and GDPR compliance is part of the architecture, not an add-on.

Tenant isolation. Every restaurant on Plattr has completely separate data storage. There is no scenario where one restaurant can see another restaurant's guest data. This is enforced at the database level with row-level security, not just at the application level.

Data processing agreement. When you use Plattr, you get a DPA automatically. This covers the relationship between you (the data controller — you decide what data to collect and why) and Plattr (the data processor — Plattr processes the data on your behalf). You do not need to negotiate this separately.

Consent flows. Loyalty enrollment through Plattr includes an explicit consent step. Guests see what data will be collected, confirm consent, and receive a copy of what they agreed to. The consent record is stored in your Plattr account with a timestamp. This applies whether guests enroll via QR code, link, or NFC tap.

Right to erasure. If a guest requests that their data be deleted — their right under GDPR Article 17 — you can action this from the Plattr dashboard. All their personal data is removed from your account. Anonymized aggregate statistics are retained for your reporting, but nothing that can identify the individual.

Data export. Guests have the right to receive a copy of their data. Plattr supports data export so you can provide this within the 30-day response window GDPR requires.

What you are responsible for that Plattr does not cover

Plattr handles the data processing on your behalf, but you are still the data controller. That means certain obligations stay with you.

Privacy notice. Your website needs a privacy notice that explains what data you collect, why, how long you keep it, and guests' rights. Plattr can be listed as a data processor in this notice with a link to Plattr's own privacy policy.

Staff training. Anyone who handles booking information, loyalty data, or guest communications needs to understand the basics of data handling — do not share guest contact details, do not keep handwritten booking notes longer than necessary, know what to do if a guest makes a data access request. The staff onboarding guide includes a section on data handling responsibilities.

Third-party tools. If you use other tools alongside Plattr — a reservation platform, a POS system, an email marketing service — each one needs its own DPA and needs to be disclosed in your privacy notice.

Common mistakes to avoid

Pre-ticked marketing opt-ins are not valid consent and have been the basis of GDPR enforcement actions across the EU. Use unchecked boxes with clear labeling.

Keeping booking data indefinitely is not justified. Most restaurants delete guest personal data from booking records after 12-24 months. For loyalty members, data is retained while the membership is active and for a period after it lapses.

Sending marketing emails to anyone who has ever dined with you, without separate consent for marketing communications, is not covered by contractual necessity or legitimate interests. If you want to run email marketing, collect explicit consent at the point of enrollment.

GDPR and your loyalty program

Loyalty programs collect more data than a single booking and typically maintain that data over a longer period. This makes the consent and retention policy more important to get right.

The Plattr loyalty enrollment flow handles consent collection correctly. Guests see what the loyalty program involves, what data is collected, and what they are agreeing to before they submit their details. The consent is recorded with a timestamp. If you are building a VIP tier program or launching your first 100 loyalty members campaign, the compliance infrastructure is already in place.

GDPR compliance is not a competitive disadvantage — it is a foundation of guest trust. Guests who know their data is handled carefully are more willing to share it, which means better data for you and a more personalized experience for them.

If you are evaluating Plattr for your restaurant, the 14-day trial includes the full compliance infrastructure. Check the plan details for what is covered at each tier, and reach out if you have specific questions about your data setup.

#GDPR#data privacy#compliance#EU law#customer data

Ready to grow your restaurant?

Join hundreds of restaurants using Plattr to manage their business.

Start Free Trial
GDPR for Restaurants — Customer Data Guide — Plattr Blog