Certix

Data protection in a restaurant: where to start

Certix
Certix®
· 30 May 2026 · 7 min read

Informative article. It does not replace individualised professional advice.

Opening a restaurant means, from day one, processing personal data: of the customer booking a table, of the supplier delivering raw materials, of the front-of-house employee clocking in in the morning. Data protection is not a formality bolted on at the end of the project; it is part of the operation. And, properly set up, it does not get in the way of service: it brings order.

This guide summarises the minimum documentation any hospitality controller should have available from day one — whether to open a new venue, regularise an existing one or review the position of a restaurant group — under the framework of the RGPD (EU Regulation 2016/679) and the LOPDGDD (Organic Law 3/2018).

Why a restaurant processes personal data

An average restaurant manages three large flows of personal data on a daily basis:

  • Customers: bookings (name, phone, email, number of diners, time), allergy or intolerance data, loyalty (birthdays, preferences), invoicing, communications via WhatsApp or email, reviews, photographs on social media.
  • Employees: hiring and payroll, time tracking (via PIN, card or app), training, internal communications, staff meal allowance, and where applicable health data linked to sick leave or workplace accidents.
  • Suppliers and third parties: contact persons at wineries, distributors, payroll/accounting firms, marketing agencies, booking platforms, cleaning and maintenance companies, the technician who services the cold room.

However small the venue, the controller is always the owner of the restaurant (the natural or legal person). That figure is the one who decides what data are collected and for what purpose, and therefore the one who takes on the obligations under the RGPD.

The minimum documentation of the controller

These are the documents a restaurant should, at the very least, have ready before the first service. Some are mandatory; others are good practices that save trouble when a complaint comes in or a provider changes.

Document Legal basis Purpose
Record of Processing Activities (RAT) Art. 30 RGPD Internal inventory of what is processed, for what purpose, for how long and with what safeguards.
Information clause for customers Art. 13 RGPD Information given to the customer when booking, leaving an email or filling in an allergy form.
Information clause for employees Art. 13 RGPD Information delivered with the employment contract and with the digital tools used in the role.
Privacy policy (website/QR menu) Arts. 13 and 14 RGPD Public, full version of the information the controller provides to the user.
Website legal notice Art. 10 LSSICE Identification of the site owner: name, NIF, address, email, commercial register.
Cookie policy and banner Art. 22.2 LSSICE Information layer and consent mechanism for cookies that are not strictly necessary.
Processor contracts Art. 28 RGPD Agreement signed with each supplier processing data on behalf of the restaurant (POS, bookings, payroll, marketing).
Security policy Art. 32 RGPD Technical and organisational measures: passwords, role-based access, backups, retention periods.
Breach protocol Arts. 33–34 RGPD Procedure to detect, assess and, where applicable, notify the AEPD and the data subjects.
Data subject rights procedure Arts. 15–22 RGPD Channel to handle access, rectification, erasure, objection, portability and restriction.

RAT (Record of Processing Activities) in hospitality

Art. 30 GDPR requires keeping an internal record of processing activities. Although paragraph 5 provides an exception for organisations with fewer than 250 employees, that exception falls away if the processing is not occasional or if it may affect rights and freedoms. In hospitality, CCTV, loyalty and staff management are rarely occasional, so the recommended practice is to keep a RAT in almost all cases.

A realistic RAT for an average restaurant includes, at the very least, these activities:

  • Bookings and customer management. Basis: art. 6.1.b (performance of contract). Allergies noted on the docket are part of providing the service; if the restaurant wants to keep them on a customer record for future visits, the customer's specific explicit consent is required.
  • Invoicing and tax obligations. Basis: art. 6.1.c (legal obligation): General Tax Law, accounting rules.
  • HR management (hiring, payroll, training). Basis: art. 6.1.b + art. 6.1.c.
  • Time tracking and, where applicable, the staff meal allowance. Basis: art. 6.1.c (art. 34.9 ET) + art. 6.1.b. Via systems such as PIN, card, mobile app or NFC.
  • CCTV in the dining room, entrances and kitchen. Basis: art. 6.1.f (legitimate interest) in the terms of art. 22 LOPDGDD.
  • Marketing and loyalty (newsletter, diners' club). Basis: art. 6.1.a (consent) or art. 6.1.f (legitimate interest with existing customers for similar products, art. 21.2 LSSICE).
  • Supplier management. Basis: art. 6.1.b or art. 6.1.f.
  • Handling of data subject rights. Basis: art. 6.1.c.
  • Handling of complaints and claims. Basis: art. 6.1.c + art. 6.1.b.

Each RAT entry should identify: purpose, legal basis, categories of data and data subjects, recipients and, where applicable, international transfers, retention periods and security measures. Regional rules on consumer protection, tourism and food safety may extend or qualify some retention periods.

Legal notice and privacy policy on the website and QR menu

The restaurant's website — even a simple landing page — needs, at a minimum, three documents:

  • Legal notice: required by art. 10 LSSICE. Identifies the owner, NIF, address, contact details and, where relevant, commercial register and administrative authorisation.
  • Privacy policy: full development of the information under art. 13 RGPD (controller, purposes, legal basis, recipients, retention periods, rights, supervisory authority).
  • Cookie policy and banner: required by art. 22.2 LSSICE. Consent must be informed, granular and revocable; analytics, advertising or social media cookies cannot be loaded before it is obtained.

The QR menu deserves specific attention. If it opens a static PDF, it does not add new obligations. But if the menu platform allows ordering, paying, recording the customer's email or sets analytics cookies, it is processing personal data and must link to the privacy policy and the cookie notice from the screen itself, before the first interaction.

Information clause for customers and employees (art. 13 RGPD)

The duty to inform under art. 13 RGPD is mandatory even where the legal basis is not consent. It is a common mistake to think that, because bookings rely on the performance of a contract, nothing needs to be handed over. It does. The information clause must be available at the usual collection points:

  • Alongside the booking form (paper or digital).
  • On the QR menu screen if data are requested.
  • On the loyalty or newsletter form.
  • In the annex to the employment contract and in the staff welcome handbook.
  • On CCTV signage (information device in a visible area, in accordance with art. 22.4 LOPDGDD).

Before handing over their data, the customer must know who processes them, for what purpose, on what basis, to whom they are disclosed, how long they are kept and how to exercise their rights. The same requirement applies to the employee on day one.

Typical processors in hospitality (art. 28 RGPD)

The restaurant decides what to do with the data; but, in practice, it stores and processes them through suppliers. Each of those suppliers, where it processes data on behalf of the controller, is a processor and requires a contract signed in accordance with art. 28 RGPD.

Supplier Data processed Key document
TPV Receipts, payment methods, loyalty Art. 28 RGPD contract + PCI-DSS security measures
Booking software Name, phone, email, time, number of diners, comments (allergies) Art. 28 RGPD contract + server location
Payroll / HR advisor Staff data, payroll, contracts Art. 28 RGPD contract
Marketing agency / community manager Newsletter databases, advertising audiences Art. 28 RGPD contract + verification of collection sources
Loyalty platform Visit history, preferences, birthdays Art. 28 RGPD contract + accessible unsubscribe channel
Transactional email provider Email addresses, content of confirmations Art. 28 RGPD contract + control of international transfers
CCTV provider Images of the dining room, entrances, kitchen Art. 28 RGPD contract + 30-day retention (art. 22.3 LOPDGDD)

A recurring note: at the end of the contract, the processor must return or export the data to the controller, and only then delete them (art. 28.3.g RGPD). That allows the restaurant to continue complying with its legal retention periods — tax, employment, accounting — without depending on the outgoing supplier.

Good practices for getting started on day one

  • Who's who: identify the controller (the restaurant owner) and the team member who coordinates rights requests and incidents.
  • Inventory of suppliers: list TPV, bookings, payroll, marketing, loyalty, email, CCTV. Check that an art. 28 RGPD contract is in place with each one.
  • A single source of truth: avoid duplicating the customer database in personal spreadsheets, staff mobile phones or unsupervised paper diaries.
  • Clauses ready and delivered: short versions for customers and employees, accessible in the dining room and available on the website/QR menu.
  • Properly signed CCTV and configured to retain images for 30 days maximum (art. 22.3 LOPDGDD).
  • Individual TPV accounts (one code per person, never shared).
  • Action plan for an incident: who to alert if a USB stick is lost, the website goes down or an erasure request comes in.

The aim is not to generate folders: it is that the day a complaint, an access request or a change of provider comes in, the restaurant knows exactly where each piece of data is and who manages it.

"En un restaurante, la protección de datos se gana en sala: con cláusulas claras, contratos firmados con cada proveedor y un equipo que sabe dónde apuntar la alergia y dónde no apuntarla."

Mario P. Talamillo · Managing Partner, Certix®

If you run a restaurant or restaurant group and want to review your data protection documentation, at Certix we work specifically with hospitality. No salespeople: from the very first contact, you will speak with a specialist.


This content is for general guidance and information purposes only; it does not in any case constitute specialised legal advice. Regional sectoral rules may extend or modify the deadlines and requirements of national legislation. The application of the rules to each specific case requires individual analysis.

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →