Skip to content

GDPR for Restaurants: The Essentials Explained Simply

By the gastronomx editorial teamUpdated in June 2026Reading time approx. 7 min

The GDPR (in German: DSGVO) applies across the EU and affects every restaurant, café and snack bar as soon as personal guest data is processed – for example with reservations, online orders or a newsletter. This article explains clearly which data typically arises in hospitality, which core principles apply and which first steps put you on the safe side. It offers general orientation and is not legal advice.

Which guest data a restaurant typically processes

Personal data is any information relating to an identifiable person – a name, phone number, email address or even an IP address. In hospitality, such data comes together in many places, often without anyone consciously noticing. Even a phone reservation with a name noted down counts as processing under the GDPR.

  • Reservations with name, phone number, party size and sometimes special requests or allergy notes.
  • Online orders with delivery or pickup address, contact details and payment information.
  • Newsletter sign-ups with an email address and possibly a first name for personal address.
  • Guest Wi-Fi access, where depending on the solution device or login data may be recorded.
  • Contact forms on the website as well as enquiries via messenger or social networks.
  • Video surveillance (CCTV) in the dining area or at the entrance, plus job applications from staff.

The more digital channels you use, the more data sources arise. A sensible first step is therefore to get an overview: which data do we collect, where is it stored and who has access to it? This inventory forms the basis for everything else.

The core GDPR principles at a glance

The GDPR is built on a few clear principles. You do not need to memorise them, but their logic helps you act correctly in everyday life. At its heart it is about collecting only the data you really need and handling it transparently. Anyone who internalises this logic usually makes the right call when in doubt.

The most important principles

  • Lawful basis: every processing needs a permitted reason, such as consent, a contract (e.g. an order) or a legitimate interest.
  • Purpose limitation: data may only be used for the purpose it was collected for – reservation data not for advertising without asking.
  • Data minimisation: collect only what is truly necessary and avoid mandatory fields that serve no purpose.
  • Transparency: guests must understand in plain terms which data you process and how – this is what the privacy policy is for.
  • Storage limitation: data may not be kept longer than the purpose or statutory periods require.
  • Security: personal data must be protected against loss and unauthorised access with appropriate technical and organisational measures.

These principles apply across the EU because the GDPR is a European regulation. In Germany it is supplemented in places by the Federal Data Protection Act (BDSG). Which lawful basis fits in a given case cannot be answered in a blanket way – when in doubt, clarify it with the competent supervisory authority or qualified legal counsel.

Privacy policy and data-processing agreements (AVV)

As soon as you process personal data, you need a privacy policy – usually on your website, easy to find and in understandable language. Among other things, it explains which data you collect for which purpose, how long you store it and which rights guests have. If you use external service providers that process data on your behalf for specific tasks, a data-processing agreement (in German: Auftragsverarbeitungsvertrag, AVV) is added.

  1. Get an overview of all tools and providers that process guest data on your behalf – such as reservation, ordering, newsletter or hosting providers.
  2. Check for each of these services whether a data-processing agreement (AVV) is in place; reputable providers offer one and conclude it with you.
  3. Create or update a privacy policy that truthfully reflects all the services and data types you use.
  4. Document which processing activities take place in your business – this belongs in your record of processing activities.
  5. Review the details regularly and adjust them as soon as you introduce new tools or change procedures.

An AVV governs the provider's obligations and ensures that data is processed only on your instructions. Responsibility for complying with the GDPR remains with you as the business – even when the data sits technically with a third party. A legally sound privacy policy should therefore be tailored individually to your business, with qualified support when in doubt.

Data-subject rights and first practical steps

The GDPR gives guests a range of rights you should be prepared for. If someone makes a request – for access or deletion, for example – you generally have to respond within one month. It helps to have a clear internal process so such requests do not get lost in day-to-day operations.

  • Right of access: guests may learn whether and which data you have stored about them.
  • Right to rectification: incorrect or outdated data must be corrected on request.
  • Right to erasure: if data is no longer needed or the basis is missing, it must be deleted, unless a retention obligation prevents it.
  • Right to restriction and to data portability, as well as the right to object to certain processing.
  • Withdrawal of consent: a granted consent, for instance for the newsletter, must be easy to withdraw at any time.

Recommended first steps are: an inventory of all data sources, an up-to-date privacy policy, AVV with all providers, sparing data collection and a regulated way of handling requests. Also briefly train your team on how to deal with guest data. This way a solid level of data protection emerges step by step, without everything having to be perfect at once.

How gastronomx supports handling guest data

A practical part of data protection is order: the more clearly your guest data is organised, the easier responsible handling becomes. gastronomx brings reservations and online orders together in one place, so you no longer have to switch between scattered lists, notes and inboxes. This central overview makes it easier to keep track and respond to requests in an orderly way.

Order creates the foundation

Within the product, reservation and order data is processed in a structured way instead of being spread uncontrolled across many places. That does not relieve you of legal responsibility – the GDPR duties remain with you as the business – but a tidy data basis is a good starting point for clean data protection. Dedicated topics on the privacy policy and on data security go deeper into the individual aspects.

What remains important: gastronomx is a tool, not a substitute for an individual data-protection review. Which lawful bases, periods and wordings apply to your business should, when in doubt, be clarified with the competent supervisory authority or qualified legal counsel. This article offers general orientation and is not legal advice.

Frequently asked questions

Does the GDPR also apply to my small restaurant?
Yes. The GDPR applies across the EU and regardless of business size as soon as personal data is processed – and that is already the case with a reservation that includes a name. Small businesses should therefore also have a privacy policy and observe the core principles.
What is a data-processing agreement (AVV)?
An AVV is a contract with a service provider that processes personal data on your behalf, such as a reservation or newsletter provider. It ensures the data is processed only on your instructions and securely. Reputable providers offer such a contract; responsibility for data protection remains with you.
How long may I store guest data?
Only as long as the respective purpose or a statutory retention obligation requires. Reservation data with no further purpose should be deleted promptly, whereas invoice-relevant data, for example, is subject to statutory periods. Which period applies concretely depends on the individual case and should be checked when in doubt.
Do I need consent for the newsletter?
As a rule, yes: for promotional newsletters you need demonstrable consent that is given freely and can be withdrawn at any time. The common method is double opt-in, where the sign-up is confirmed by email. You should secure the exact arrangement for your case.

Related Reading

Guest data in one place – clear and orderly

With gastronomx you manage reservations and online orders centrally and keep the overview. That creates a clean basis for handling guest data responsibly.

Discover gastronomx