GDPR for Restaurants and Salons: What You Actually Have to Do With Guest Data
A booking name, a phone number, an allergy note, a card on file. Every venue in Europe collects personal data, and most owners have no idea which parts of it need consent and which do not.
Guestavo
9 min read
Open your booking book. There is a name, a mobile number, a party size, and probably a scribble that says "nut allergy" or "hates the window table." That last one is a note about a human being, stored by your business, and under European law it is personal data with rules attached.
Most restaurant and salon owners hear "GDPR" and picture a cookie banner. The cookie banner is the least of it. The rules that actually bite in a venue are about the guest list, the marketing list, and how long you keep both. The good news is that the practical minimum for a small independent venue is short and mostly free. The bad news is that the single most common mistake, treating a reservation as permission to market, is also the one supervisory authorities receive complaints about.
This article explains the shape of the thing in plain language. It is not legal advice, and hospitality-specific interpretations vary between countries. Where it matters, check with your national data protection authority or a data protection officer before you commit to anything.
Reservation data and marketing data are two different animals
This is the distinction that everything else hangs off, so it is worth getting straight before anything else.
When somebody books a table for Friday at eight, you need their name and a way to reach them. You do not need to ask permission for that. Under GDPR, processing that data is generally justified because it is necessary to perform the service the guest asked for, or because you have a legitimate interest in running the booking properly. Nobody has to tick a box to reserve a table. Any system that makes them do so is misreading the law and adding friction for nothing.
Marketing is a separate purpose with a separate justification. Sending that same guest a newsletter about your spring menu, or a birthday offer, or a "we miss you" message three months later, is not part of delivering the Friday booking. It needs its own lawful basis, and in practice, for electronic messages to consumers, that usually means consent under the ePrivacy rules that sit alongside GDPR.
There is a narrow exception in many countries, often called soft opt-in, that lets a business email existing customers about similar products if they were given a clear chance to refuse at the point of collection and in every message afterwards. How narrow it is depends on where you are, and SMS and WhatsApp are frequently treated more strictly than email. This is exactly the kind of detail worth one email to your local authority rather than one guess.
Booking data keeps the booking running: confirmations, reminders, a message when the kitchen is running late, a cancellation link. Marketing data sells them something later. Same person, same phone number, two entirely different permissions.
What consent has to look like when you need it
If you are relying on consent, GDPR is specific about what counts, and most of the ways venues collect it fall short.
Consent has to be freely given, which means the guest can refuse and still get their table. A checkbox that blocks the booking button until it is ticked is not consent. It has to be specific, so "I agree to the terms" bundled together with marketing permission does not work. It has to be informed, meaning the guest knows who is contacting them, about what, and on which channel. And it has to be an active choice, so pre-ticked boxes are out and have been for years.
You also have to be able to show that you got it. That means a record: what the guest agreed to, when, and how it was worded at the time. A verbal "sure, add me to the list" at the host stand is legally possible but practically indefensible six months later when somebody complains. Capture it where it leaves a trace.
Withdrawal has to be as easy as giving it. If somebody signed up in two taps on their phone, they should be able to leave in roughly two taps. Every marketing message needs a working unsubscribe, and for SMS or messaging channels that means an opt-out instruction that a human being will actually see and honour.
Retention: the part everyone skips
There is no GDPR article that says "keep reservation records for eighteen months." The rule is that you keep personal data no longer than you need it for the purpose you collected it for, and that you decide what that period is and stick to it.
For a small venue, a defensible policy might look like this. Reservation records that serve no ongoing purpose get deleted or anonymised after a set period. Guest profiles for people who have actively opted into marketing stay while the relationship is live, with a rule for what happens after long silence. Financial records follow whatever your national tax law requires, and that requirement usually runs for several years and overrides your preference for tidiness. CCTV, if you have it, is typically expected to be kept for days rather than months in most European guidance.
Notice that the numbers are deliberately absent. Retention periods are one of the areas where national practice differs most, and picking a figure off a blog is how you end up defending a number you cannot justify. Decide your periods, write them down in one paragraph, and confirm the tax and CCTV ones with your accountant and your local authority.
The thing that makes this manageable is automation. A retention policy that depends on somebody remembering to purge old bookings every quarter is a policy that will be honoured for two quarters. If your booking system can delete or anonymise on a schedule, that decision gets made once.
Subject access requests, and the others
A guest can ask what data you hold on them. They can ask for it to be corrected, deleted, or sent to them in a portable format, and they can object to marketing at any time. You generally have one month to respond, extendable in genuinely complex cases, and you cannot charge for it in normal circumstances.
For a restaurant or salon this is far less dramatic than it sounds. The honest answer to most requests is a short list: a name, a contact detail, a booking history, some notes, and marketing preferences. The hard part is being able to find all of it at once. If your guest data lives across a booking system, a spreadsheet, an email list, and a WhatsApp thread on somebody's personal phone, a single request turns into an afternoon of archaeology.
Two things make this painless. First, keep guest data in one place, so a request is a lookup instead of a hunt. Second, decide in advance who handles these. In a small venue that is usually the owner or the manager, and the only real risk is a request landing in a shared inbox and sitting there unread for five weeks.
Deletion has limits worth knowing. If you are required to keep an invoice for tax purposes, a deletion request does not override that. You delete what you can, keep what the law requires, and tell the person clearly which is which.
Guestavo keeps bookings, contact records, notes, and marketing preferences on a single guest profile, so answering "what do you hold on me" means opening one record rather than searching four systems.
The practical minimum for a small venue
You do not need a compliance department. For an independent restaurant or salon, the realistic baseline is short.
Write a privacy notice and put it where guests will meet it: on the booking page, linked from your website footer, printed on request in the venue, and included wherever you collect an email address. It should say who you are, what you collect, why, how long you keep it, who else sees it, and how to contact you about it. Plain language beats legal boilerplate, and regulators have said so repeatedly.
Separate your marketing consent from your booking flow, with its own unticked box and its own clear wording, and store the record of it. Write down your retention periods and, where you can, automate them. Keep a short list of every place guest data lives, including the tools you forget about: the booking system, the till, the email platform, the reviews widget, the WhatsApp number. That list is the backbone of both your privacy notice and any request you get.
Check what your suppliers are doing. When a booking platform or messaging provider processes data on your behalf, you generally need a processor agreement with them and you should know where the data is stored. Any serious vendor has this ready and published, and if you have to chase them for it, that itself tells you something.
Finally, tell your team the two things that matter most in practice: guest notes go in the system rather than on a personal phone, and nobody gets added to the marketing list because they seemed friendly.
Where to verify
Everything above is the general shape. The specifics that vary by country include retention periods, whether soft opt-in applies to your situation, the rules for SMS and messaging apps, CCTV expectations, and whether your venue needs a designated data protection officer. Most small venues do not need a DPO, but "most" is not "all."
Your national supervisory authority publishes guidance, usually in your own language and often with sector-specific pages, and many of them answer straightforward questions from small businesses at no cost. For anything involving special category data, and health or allergy information can fall into that territory depending on how it is recorded and used, get proper advice rather than working from an article.
The underlying principle is easier to remember than any of the rules. Collect what you need to serve the guest, use it for what you told them, keep it while it is useful, and make it easy to leave. Venues that do that tend to find the compliance paperwork mostly describes what they were already doing.
If you are rewriting your booking terms anyway, our reservation policy generator gives you a clean starting point for the guest-facing side, which pairs neatly with a privacy notice written the same week.
Keep reading
- Compliance
The 14 EU Allergens: What Restaurants Actually Have to Do
EU law requires allergen information on every dish you serve. Here is what the rule says, what counts as compliant, and where kitchens usually get caught out.
- Marketing
The Guests You Already Have Are Cheaper Than the Ones You Don't
Winning back a guest who came twice and drifted costs a fraction of finding a new one. Most venues never try, because nobody is watching who stopped coming.
- Operations
The First 90 Days: What a New Venue Should Actually Set Up (And What Can Wait)
The builders are gone, the kitchen passed inspection, and you open in three weeks. Here is what genuinely matters in the first three months, and the long list of things that can safely wait until month four.