Certix

Daily good practices for a restaurant team to protect data

Certix
Certix®
· 30 May 2026 · 8 min read

Informative article. It does not replace individualised professional advice.

Data protection in a restaurant is not won in the paperwork, it is won on the shift. A booking sheet forgotten on the bar, a photo of an order ticket sent to the staff group, a TPV PIN shared with a casual hired the day before: each everyday gesture defines what the restaurant really does with the information of its customers and its team.

This guide gathers concrete routines for the dining room, kitchen and admin. It is not a legal course: it is habits that bring order to the operation and, along the way, comply with the RGPD, the LOPDGDD and the applicable employment rules.

Why daily good practices are the best investment

Art. 32 RGPD requires the controller to implement technical and organisational measures appropriate to the risk. In a restaurant, the everyday risk is not big cyberattacks: it is day-to-day slip-ups. The booking sheet left on the lectern, the piece of paper with customers' phone numbers passing from hand to hand, the Gmail account left open on the kitchen computer at the shift handover.

Working on good practices brings an immediate reward: the team gains peace of mind, the customer perceives professionalism and management knows where its data are without the need for constant audits. There is no need to think of this in terms of fear: think of it in terms of craft.

TPV passwords and access: one code per person

The TPV is the operational heart of the restaurant. It concentrates receipts, payment methods, voids, discounts, loyalty and, in many cases, also the customer record and allergies. Every access must be traceable.

  • One access code per person (PIN, card or user account). Never shared between shifts.
  • Role-based permissions: waiter, head waiter, manager, admin. Only the role that needs to void receipts or view customer lists has access to those options.
  • Log out when leaving the station (even to fetch a tray: a TPV with an open session is an open door).
  • User on-boarding and off-boarding on the same day: when someone joins, they get an account; when they leave, it is revoked that same day.
  • Immediate password change on any suspicion of a leak or loss of a staff device.

The basic rule: if an operation is recorded under Juan's code, Juan should be the one who made it. That traceability protects everyone — the customer, the team and the controller.

Allergies: a note for the kitchen, not a medical record

The golden rule on the floor is simple: an allergy is a vital note for the kitchen during service. The chef needs to know what cannot go in the dish. Once the customer leaves, that data is removed from the docket and the slip is destroyed. Three operating rules:

  • Collect only what is needed. Only what the kitchen needs to know to prepare the dish safely. No medical history required.
  • Communicate discreetly. Note it down on the docket or in the system, do not call it out across tables.
  • Wipe it at end of service. If the allergy was noted for that dinner, it should not be left on a loose sheet on the bar the next day.

If the restaurant wants to keep the allergy permanently (in the CRM, on the POS customer card or in a loyalty programme), the customer's explicit consent is required: a specific tick-box, unticked by default, on the online booking engine ("I consent to my allergy details being kept for future visits"), or a specific signature on the physical loyalty card. A generic "I accept the terms" is never enough.

Handled with care, it is professional ethics and attention to detail: the customer returns because they have felt looked after.

Bookings and customer communications: WhatsApp only with a basis and a verified channel

Calling the customer to confirm a booking or to flag a change of time is service. But the channel matters. WhatsApp on the waiter's personal number is not a corporate channel; it groups personal numbers of the staff and the customer, outside the controller's control.

Basic good practices:

  • A restaurant number (corporate line) for booking messaging, separate from staff mobiles.
  • Minimal messages: name, time, number of diners, table. No allergies, medical data, payment data or past complaints.
  • Confirmations by email or booking system when the customer provides them: traceability and information clause at the end of the message.
  • Marketing and promotions only to those who have provided a basis to receive them (consent under art. 6.1.a or, where it fits, the scenario under art. 21.2 LSSICE for existing customers with similar products).
  • Accessible unsubscribe in every commercial communication.

Paper documents: locked cabinets, secure destruction

Although almost everything is digitised, a fair amount of paper survives in hospitality: order tickets, the day's booking sheets, shift rotas, printed loyalty lists, copies of delivery notes. Basic habits:

  • A working surface, not a filing cabinet. Service paperwork is processed at closing and is not left visible at the bar or pass.
  • Locked cabinet for documents that must be kept temporarily (rotas, forms, copies of delivery notes).
  • Secure destruction at the end of the cycle: in-house shredder or a contract with a confidential collection and destruction company.
  • Do not throw entire order tickets in the dining-room bin: not in the general paper bin.
  • Digital backup of what is critical: rotas, incident reports, training.

CCTV in the dining room and kitchen: what can be recorded, 30-day retention, signage

CCTV is a legitimate security and prevention tool, but it is subject to clear rules. The main rule of reference in Spain is art. 22 LOPDGDD:

  • Defined purpose: safeguarding the security of persons, property and premises.
  • Maximum retention period: one month from capture, except where retained at the request of a court, the police, or to evidence the commission of acts against persons or property (art. 22.3 LOPDGDD).
  • Information device in a visible area (sign) with the essential information under art. 13 RGPD and a system to access the full information (art. 22.4 LOPDGDD).
  • Do not record audio as a general rule in the restaurant's public areas.
  • Excluded areas: changing rooms, toilets, staff dining room or any space reserved for rest (art. 89.1 LOPDGDD in the employment sphere).
  • Kitchen: if it is recorded for the purpose of employment monitoring, staff must be expressly informed and art. 89 LOPDGDD must be observed; it cannot be used for other purposes (for example, to assess the team's mood).

Regional rules and sectoral collective bargaining may modulate the scope and the information to be provided, especially in matters of employment monitoring.

Employee data: time tracking, payroll, no WhatsApp for sensitive matters

The restaurant team is also a holder of personal data that the controller must protect with the same diligence. Operational good practices:

  • Digital clocking. Clocking can be carried out with PIN, RFID card, mobile app or NFC. The time record is kept for four years (art. 34.9 ET and art. 20 bis ET), accessible to the worker, the legal representation and the Labour Inspectorate. Regional regulations and applicable collective agreements may add further requirements.
  • Payroll and contracts in a controlled system (ideally, the payroll firm's platform with individual access). Not by generic email, not by WhatsApp.
  • Sick leave, medical incidents and sensitive employment data: never in the staff WhatsApp group. Direct channel with the responsible person and controlled written support.
  • Rotas and holidays: visible to the team only as needed; the personal reasons behind a change are not shared.
  • Welcome training: every new joiner receives, with their contract, the art. 13 GDPR information clause and a short internal good practice guide.

What to do in the event of a security breach

A security breach is any incident that causes the accidental or unlawful destruction, loss or alteration of personal data, or unauthorised access to them (art. 4.12 RGPD). In a restaurant, typical examples are: loss of a USB stick containing the loyalty database, theft of an office laptop, sending an email with visible copy to recipients who should not see each other, impersonation of the head waiter's email.

The basic protocol, condensed into steps:

  1. Identify and contain: what happened, which systems or documents are affected, how to cut the exposure.
  2. Assess the risk: what data, of which people, with what reasonable impact.
  3. Document internally: art. 33.5 RGPD requires an internal record of all breaches, even those that are not notified.
  4. Notify the AEPD where appropriate: as an indicative guide, within 72 hours of becoming aware, where there is a risk to rights and freedoms (art. 33 RGPD).
  5. Notify the data subjects if the risk is high (art. 34 RGPD).
  6. Review and learn: which controls failed, what changes from today.

The most expensive mistake in the face of a breach is usually not the breach itself, but not having detected it in time or not knowing what to do with it. Having the protocol in writing, even on a single page, makes the difference.

"El cumplimiento en hostelería no se firma en una carpeta, se ejecuta en cada turno. Un PIN individual, una comanda destruida y un WhatsApp que no se manda valen más que diez políticas perfectas guardadas en un cajón."

Mario P. Talamillo · Managing Partner, Certix®

If you run a restaurant or restaurant group and want to review your data protection documentation, at Certix we work specifically with hospitality. No salespeople: from the very first contact, you will speak with a specialist.


This content is for general guidance and information purposes only; it does not in any case constitute specialised legal advice. Regional sectoral rules may extend or modify the deadlines and requirements of national legislation. The application of the rules to each specific case requires individual analysis.

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →