Hospitality & restaurants
Data protection for
hospitality and restaurants
From video surveillance on the premises to reservation data, loyalty programmes and delivery platforms, the hospitality sector handles more personal data than it might appear. The GDPR applies from the very first customer.
30 days
maximum video surveillance retention
Art. 21
LSSI — commercial communications
4 years
invoicing data retention
24 h
personalised proposal
Sector challenges
General obligations for hospitality and restaurants
Video surveillance on the premises
Installing cameras in a hospitality venue requires analysing the proportionality in each area, providing an information sign, and documenting the system in the RoPA (Record of Processing Activities). Each case must be assessed individually.
Reservation data
The name, telephone number and email of the customer making a reservation are personal data. The booking platform (TheFork, El Tenedor) may act as a data processor.
Loyalty programmes
A points card or customer club requires a clear legal basis and separate consent for sending commercial communications.
Delivery platforms
Home delivery apps (Glovo, Just Eat, Uber Eats) may act as data processors or as independent controllers. The relationship must be documented.
Special diets and health data
Managing allergies and food intolerances in reservations involves the processing of health data with enhanced protection.
Employee data
Payroll, contracts, schedules and occupational health data for hospitality staff require the same level of compliance as in any other sector.
The service
What the service for your hospitality business includes
RoPA (Record of Processing Activities)
Tailored Record of Processing Activities: customers, employees, video surveillance and delivery platforms.
Information clauses
Texts for reservation forms, loyalty programmes and on-site data collection.
Privacy policy and legal notice
Documentation for the business website or social media.
Data Processing Agreements (DPA)
DPA for booking platforms, delivery services and venue management software.
Data breach protocol
Response procedure with notification within 72 hours.
Data subject rights management
Procedure for handling requests from customers and employees.
Document management platform
Access to a private platform with documents and electronic signature.
Ongoing support
Unlimited queries. Updates in response to regulatory changes.
External DPO (if applicable)
As a general rule, hospitality businesses are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis. Separate contract.
Do you need a proposal for your business?
Tell us the type of venue and the number of employees. Proposal in under 24 hours.
FAQ
Frequently asked questions about data protection in hospitality
Can a restaurant install video surveillance cameras?
Video surveillance in a hospitality establishment may be justified in certain circumstances, but its installation requires a prior proportionality assessment, a clearly visible information sign, documentation in the RoPA (Record of Processing Activities) and compliance with retention periods. As a general rule, it is prohibited in spaces where people have a reasonable expectation of privacy. Each case must be assessed individually.
How long may reservation data be retained?
Reservation data (name, telephone, email) must be retained for as long as necessary to manage the reservation and address possible claims. A maximum of 1 year is recommended, unless the customer is part of a loyalty programme with their consent. Invoicing data must be retained for 4 years due to fiscal obligations.
Are platforms such as Glovo or Just Eat data processors for the restaurant?
It depends on the model. When the platform acts as an intermediary and transmits the order to the restaurant, it may be a joint controller or an independent controller of the customer's data. The restaurant must review the contractual terms of each platform to determine the legal relationship and ensure it is properly documented.
Does a points programme or loyalty card require consent?
The loyalty programme may be based on the contract with the customer (performance of the subscription contract for the programme), but the sending of associated commercial communications requires separate consent from the data subject. The customer must be able to participate in the programme without being obliged to receive advertising.
Does offering free wi-fi involve collecting customers' data?
Only if prior registration is required. If access to wi-fi requires the entry of a name, email or other data, the establishment is collecting personal data and must inform the user of the purpose of the processing, retention period and rights. That information may not be used for purposes other than network access without additional consent.
Do customer reviews on Google or TripAdvisor contain personal data?
Yes. Reviews bearing an identifiable username are personal data belonging to the person who wrote the review. The restaurant may respond to reviews, but must not include additional customer data in its response (such as their address or the specific reservation) without their consent.
Sector resources
Learn more
Hospitality
Data protection in a restaurant: where to start
Minimum data protection documentation to open or regularise a restaurant: RAT, legal notice, privacy policy, information clause, processor contracts. No scaremongering, step by step.
7 min·Read article
Hospitality
Daily good practices for a restaurant team to protect data
Concrete routines for the front-of-house, kitchen and admin teams: TPV password management, role-based access, allergy data, WhatsApp communications, control of paper copies and CCTV.
8 min·Read article
Hospitality
Booking software and TPV in a restaurant: the supplier's obligations under the RGPD
Your TPV and booking system process personal data on behalf of the restaurant. What processor contract (art. 28 RGPD) you must sign, what guarantees to require and what happens at the end of the service.
8 min·Read article
Free tool
Data protection self-check
Check in 5 minutes your overall adaptation level in personal data protection.
No email · Anonymous · No commitment
Hospitality & restaurants
GDPR compliance
for your business.
An expert analyses your activity and proposes the right solution. No intermediaries.
Proposal within 24 h · info@certix.es
Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.