Certix

Hospitality & restaurants

Data protection for
hospitality and restaurants

From video surveillance on the premises to reservation data, loyalty programmes and delivery platforms, the hospitality sector handles more personal data than it might appear. The GDPR applies from the very first customer.

30 days

maximum video surveillance retention

Art. 21

LSSI — commercial communications

4 years

invoicing data retention

24 h

personalised proposal

Sector challenges

General obligations for hospitality and restaurants

Video surveillance on the premises

Installing cameras in a hospitality venue requires analysing the proportionality in each area, providing an information sign, and documenting the system in the RoPA (Record of Processing Activities). Each case must be assessed individually.

Reservation data

The name, telephone number and email of the customer making a reservation are personal data. The booking platform (TheFork, El Tenedor) may act as a data processor.

Loyalty programmes

A points card or customer club requires a clear legal basis and separate consent for sending commercial communications.

Delivery platforms

Home delivery apps (Glovo, Just Eat, Uber Eats) may act as data processors or as independent controllers. The relationship must be documented.

Special diets and health data

Managing allergies and food intolerances in reservations involves the processing of health data with enhanced protection.

Employee data

Payroll, contracts, schedules and occupational health data for hospitality staff require the same level of compliance as in any other sector.

The service

What the service for your hospitality business includes

RoPA (Record of Processing Activities)

Tailored Record of Processing Activities: customers, employees, video surveillance and delivery platforms.

Information clauses

Texts for reservation forms, loyalty programmes and on-site data collection.

Privacy policy and legal notice

Documentation for the business website or social media.

Data Processing Agreements (DPA)

DPA for booking platforms, delivery services and venue management software.

Data breach protocol

Response procedure with notification within 72 hours.

Data subject rights management

Procedure for handling requests from customers and employees.

Document management platform

Access to a private platform with documents and electronic signature.

Ongoing support

Unlimited queries. Updates in response to regulatory changes.

External DPO (if applicable)

As a general rule, hospitality businesses are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis. Separate contract.

Do you need a proposal for your business?

Tell us the type of venue and the number of employees. Proposal in under 24 hours.

Request a proposal

FAQ

Frequently asked questions about data protection in hospitality

Can a restaurant install video surveillance cameras?

Video surveillance in a hospitality establishment may be justified in certain circumstances, but its installation requires a prior proportionality assessment, a clearly visible information sign, documentation in the RoPA (Record of Processing Activities) and compliance with retention periods. As a general rule, it is prohibited in spaces where people have a reasonable expectation of privacy. Each case must be assessed individually.

How long may reservation data be retained?

Reservation data (name, telephone, email) must be retained for as long as necessary to manage the reservation and address possible claims. A maximum of 1 year is recommended, unless the customer is part of a loyalty programme with their consent. Invoicing data must be retained for 4 years due to fiscal obligations.

Are platforms such as Glovo or Just Eat data processors for the restaurant?

It depends on the model. When the platform acts as an intermediary and transmits the order to the restaurant, it may be a joint controller or an independent controller of the customer's data. The restaurant must review the contractual terms of each platform to determine the legal relationship and ensure it is properly documented.

Does a points programme or loyalty card require consent?

The loyalty programme may be based on the contract with the customer (performance of the subscription contract for the programme), but the sending of associated commercial communications requires separate consent from the data subject. The customer must be able to participate in the programme without being obliged to receive advertising.

Does offering free wi-fi involve collecting customers' data?

Only if prior registration is required. If access to wi-fi requires the entry of a name, email or other data, the establishment is collecting personal data and must inform the user of the purpose of the processing, retention period and rights. That information may not be used for purposes other than network access without additional consent.

Do customer reviews on Google or TripAdvisor contain personal data?

Yes. Reviews bearing an identifiable username are personal data belonging to the person who wrote the review. The restaurant may respond to reviews, but must not include additional customer data in its response (such as their address or the specific reservation) without their consent.

Free tool

Data protection self-check

Check in 5 minutes your overall adaptation level in personal data protection.

No email · Anonymous · No commitment

Start the test

Hospitality & restaurants

GDPR compliance
for your business.

An expert analyses your activity and proposes the right solution. No intermediaries.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →

Proposal within 24 h · info@certix.es

Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.