Privacy notice for a restaurant taking bookings
A privacy notice for a restaurant, bar or cafe with a reservation system, drafted for the business with the cookie notice and consent guidance, for a fixed fee of £595 in five working days.
Privacy notice for a restaurant taking bookings
Buy now, £595A restaurant that takes bookings holds diners' names, contact details, card details for deposits and the allergies they disclose, through a reservation platform that may use the data for its own purposes as well as the restaurant's. The privacy notice has to explain the platform's role, state the right basis for allergy information (which is health data), deal with deposits and no-show charges, separate the reminders from the marketing, and cover the review and loyalty platforms, the CCTV and the Wi-Fi. A fixed £595 covers the privacy notice, the cookie notice and guidance on the consent mechanism, drafted for the business and delivered in five working days.
Who this is for
Restaurants, bars, cafes, pubs and hospitality groups in England and Wales taking reservations online, by telephone or through a platform.
What matters in a restaurant privacy notice
The booking platform and the guest data it collects for the restaurant
The controller's duty under Article 13 of the UK GDPR is to tell diners what it collects (name, contact details, party size, the occasion, dietary and access requirements, card details for deposits, visit history and notes), and the reservation platform collecting it acts for the restaurant as a processor under Article 28 for the bookings while pursuing its own purposes (marketplace, marketing, analytics) as a controller, a split the notice should explain so that a diner booking through the platform's app knows the platform's own notice applies too; the platform's processing terms, and whether data leaves the United Kingdom under the Article 46 safeguards, are things the restaurant should know before the notice is written.
Allergies, dietary needs and the data that is special category
An allergy, an intolerance or a dietary requirement that reveals a health condition or a religion is special category data under Article 9 of the UK GDPR, and the notice should state the condition the restaurant relies on, which is usually the diner's explicit consent given when they disclose the information for the purpose of their meal, with the information used for that purpose, shared with the kitchen for the visit, and not retained beyond the visit unless the diner asks for it to be kept on their profile; the restaurant's obligations under the Food Information Regulations 2014 to provide allergen information are the reason the question is asked, and the notice should say that a diner who does not disclose takes the risk the regulations place on them.
Deposits, no-show charges and the card data held by the processor
The notice should explain that card details taken for deposits and no-show charges are held by the payment processor (tokenised, with the restaurant never seeing the full number), that the restaurant applies its cancellation and no-show policy under the booking terms to the card the processor holds, that payment records are retained for the period tax law requires, and that the processor is a controller for its own fraud and compliance purposes; a restaurant that writes card numbers on the reservation sheet has the breach the notice cannot cure.
Marketing, reminders and the messages diners receive
A booking confirmation or a reminder is a service message; a newsletter, an event promotion or a 'book again' campaign is marketing, and regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 allows electronic marketing to individuals only with consent or under the soft opt-in (which it can for a diner who booked directly and was given the chance to refuse at booking and in every message); the notice should say which the restaurant relies on, the booking platform's marketing settings should implement it, and diners who booked through the platform's marketplace should be asked rather than assumed.
Reviews, loyalty and the platforms with their own notices
Review platforms, loyalty schemes, delivery platforms and the restaurant's own app each collect data under their own notices as controllers or as the restaurant's processors, and the notice should list them and say which is which, the data shared with each (the loyalty scheme's visit and spend data, the delivery platform's order data, the review platform's invitation), the diner's choices, and the position of photographs and social media (the restaurant does not post identifiable images of diners without consent); the website's cookies and the booking widget's tracking need the consent mechanism the pack provides guidance on under regulation 6 of those Regulations.
CCTV, Wi-Fi and the data a visit generates
Cameras in the dining room, the bar and at the entrances run on legitimate interests, with signage, a stated retention, access limited to named staff and a procedure for police and subject access requests; guest Wi-Fi logging is stated; and the notice covers the rights the individual has (to access, correct, erase, restrict, port and object), the way to exercise them, the month the business has to respond, and the route to the Information Commissioner's Office; the notice should give the registration number the business holds with the Information Commissioner's Office under the Data Protection (Charges and Information) Regulations 2018; the operational note lists the platform settings the notice assumes.
What it costs
Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
Is a diner's allergy information health data?
It is, where it reveals a health condition, and dietary requirements that reveal religion are special category too. The notice states explicit consent as the basis, limits the use to the visit and the kitchen, and retains it only if the diner asks.
Can we send offers to everyone who has booked?
To diners who booked directly and could refuse at booking, under the soft opt-in with an opt-out in every message. Diners who came through the platform's marketplace should be asked. The notice states the basis.
Who is responsible for the data in our booking platform?
The restaurant, as controller for its bookings, with the platform as processor; the platform is a controller for its own marketplace and marketing. The notice explains both roles to diners.
Related guidance and services
- Data protection agreements and privacy terms, £595, the service this page describes
- Terms and conditions drafting, £995
- SaaS and technology contracts, £995
- Staff handbook for a hospitality business
- Privacy notice for a hotel or holiday let
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.