PDPA for restaurants in Malaysia: what the law really asks of your guest list
Every booking your restaurant takes is personal data: a name, a mobile number, a party size, often a note that says "peanut allergy" or "no beef for the table". In Malaysia all of it falls under the Personal Data Protection Act 2010 (PDPA), which applies to anyone processing personal data in respect of commercial transactions. There is no small business exemption: a two-table kedai makan that takes bookings is covered the same way a hotel group is, from the first name it writes down.
For years that was mostly theoretical. It is not any more. The Personal Data Protection (Amendment) Act 2024 came into force in stages through 2025 and raised the ceiling to RM1,000,000 in fines or three years' imprisonment, added a mandatory 72-hour breach notification, and put data protection on the agenda of every business that holds a customer list. This guide translates what that means for an F&B outlet: which duties actually apply to an independent restaurant and which do not, how marketing messages differ from booking confirmations, why allergy notes are legally special, and what to ask a reservation system that leaves the guest list in your hands before you trust it with your diners.
The short version:
- the PDPA applies to every business processing personal data in commercial transactions, whatever its size; the regulator is the Personal Data Protection Commissioner (JPDP);
- since 1 April 2025, breaching any of the seven data protection principles can cost up to RM1 million, three years' imprisonment, or both;
- since 1 June 2025, a breach likely to cause significant harm must be notified to the Commissioner within 72 hours; failing to notify carries a fine of up to RM250,000;
- a data protection officer is only mandatory above thresholds most independent restaurants never reach, and an ordinary restaurant is generally not in a class that must register with the Commissioner;
- Malaysia has no Do Not Call registry: marketing by SMS or WhatsApp runs on consent, plus the guest's section 43 right to stop direct marketing by written notice;
- allergy and dietary notes touch health and religious beliefs, which the Act treats as sensitive personal data requiring explicit consent;
- your biggest practical decision remains the same as everywhere: who holds your guest list, who markets to it, and whether you can leave with it.
What personal data a Malaysian restaurant actually holds
Most owners never think of their outlet as a data business. Take stock of what a typical restaurant collects anyway:
- Bookings and waitlists: names, mobile numbers, emails, pax, dates, table preferences.
- WhatsApp threads: in Malaysia the reservation book often lives in a chat app on someone's personal phone, a problem with its own article on WhatsApp bookings and guest data.
- Service notes: allergies, halal or vegetarian requirements, birthdays, "regular, knows the boss".
- Deposit traces: payment-link records and card details for festive-season deposits, ideally tokenised by a payment provider rather than stored by you (never write a card number in a booking note).
- Marketing lists: loyalty sign-ups, past guests exported into a mailing tool.
- CCTV footage and staff records.
All of it is personal data processed in a commercial transaction, which is exactly the scope of the Personal Data Protection Act 2010. Since the 2024 amendments, the law calls you a "data controller" rather than a "data user"; the duties sit with you either way.
The 2024 amendments: three dates that raised the stakes
The Amendment Act arrived in three phases, summarised by law firm Tay & Partners:
- 1 January 2025: terminology changes, including "data user" becoming "data controller".
- 1 April 2025: the penalty for breaching the seven data protection principles rose to RM1,000,000, imprisonment up to three years, or both; biometric data joined the sensitive category.
- 1 June 2025: mandatory data breach notification and the data protection officer requirement came into force, and data processors became directly subject to the security principle.
None of this changed the basic truth that the PDPA already applied to your restaurant. What changed is the price of ignoring it.
The seven principles, translated for a dining room
General principle: consent. Process personal data with consent, for a lawful purpose directly related to your activity. A guest giving a name and number to book a table is consenting to exactly that: managing the booking. Using the same number for promotions is a different purpose and needs its own consent.
Notice and choice. Tell guests why you collect their data, who it may be disclosed to, and their right to access and correct it. Malaysian specificity worth knowing: under section 7(3) of the Act, the written notice must be provided in both the national language and English. A short bilingual privacy note on your booking page or at the counter covers what a reasonable restaurant needs.
Disclosure. No passing guest data to third parties for purposes the guest never agreed to. Selling or "sharing" your list with a promoter is the obvious breach.
Security. Take practical steps to protect the data: unique staff logins on the booking system, two-factor authentication where offered, access removed the day someone leaves, no guest exports sitting in a personal Google Drive. This is the principle small businesses most commonly trip on.
Retention. Keep data only as long as the purpose requires, then destroy it. Prune years-old waitlist exports; they serve nobody and enlarge every leak.
Data integrity. Keep records reasonably accurate and up to date.
Access. Answer a guest who asks what you hold about them or wants it corrected. Painless if your records live in one tidy system instead of five spreadsheets and three phones.
Do you have to register with the Commissioner?
Here is a nuance that generic PDPA articles get wrong. Malaysia has a registration regime: certain classes of businesses must register with the Personal Data Protection Commissioner and display a certificate. But the classes are set by the Personal Data Protection (Class of Data Users) Order 2013, and its hospitality class targets licensees under the Tourism Industry Act 1992, which means hotels and similar licensed operators, per DLA Piper's Malaysia registration guide.
An ordinary restaurant is generally not in a registrable class. So do not pay a consultant to register you "just in case" without checking the Order against your actual licences; and conversely, if your business also runs a licensed hotel or travel operation, check carefully. Registration or not, the seven principles above apply to everyone.
Do you need a data protection officer?
Probably not. Under the guidelines in force since 1 June 2025, summarised by DLA Piper, a DPO is mandatory only where processing involves personal data of more than 20,000 data subjects, sensitive personal data (including financial information) of more than 10,000 data subjects, or activities involving regular and systematic monitoring of personal data.
A neighbourhood restaurant with a few thousand guests a year in its booking history is nowhere near those thresholds. A large chain, a group with a loyalty programme, or an outlet sitting on a decade of exported guest data could be. Even below the thresholds, it costs nothing to write down that the owner is the person responsible for data questions: the breach notification duty below applies to you regardless of any DPO.
Marketing messages: no Do Not Call registry, but consent still rules
Restaurateurs who read about Singapore's Do Not Call Registry sometimes assume Malaysia has one. It does not. There is no DNC registry and no dedicated e-marketing law in Malaysia; direct marketing runs on the PDPA's consent rules, as law firm Donovan & Ho explains.
That is not a free pass. It means two things:
- Consent first. A number collected to manage a booking is not a marketing channel. Before you blast "weekend set menu, 20% off" by SMS or WhatsApp, the guest must have opted in to marketing from you, in a form you can evidence: a ticked box with a timestamp, not a verbal maybe. Keep the marketing opt-in a separate, deliberate choice, never bundled into "book a table".
- The stop right is absolute. Under section 43 of the PDPA, a guest can require you by written notice to stop processing their data for direct marketing. You must comply within a reasonable period, and a guest you ignore can complain to the Commissioner. Honour every "stop" and "unsubscribe" the day it arrives, whatever the channel.
Booking confirmations are not marketing
A message that only services the guest's own booking, "your table for 4 pax at 8pm on Friday is confirmed", "reminder: your reservation is tomorrow", is a transactional message about a transaction the guest initiated, not direct marketing. This is why booking confirmations and reminders operate on a different logic from promotional blasts, and why they are the one message stream you can and should send to everyone: they are also your quietest no-show deterrent.
The trap is the hybrid. The moment your reminder adds "and try our new nasi lemak brunch!", it acquires a marketing purpose. Keep the two streams separate: confirmations and reminders purely transactional for all guests, promotions only to the opted-in list.
Allergy and dietary notes are sensitive personal data
Under section 4 of the PDPA, information about a person's physical or mental health and their religious beliefs is "sensitive personal data", and section 40 requires explicit consent to process it. Think about what sits in a Malaysian booking book: "anaphylactic to shellfish" is health data; "halal only" or "no beef, Hindu family" touches religious belief.
In practice the guest volunteering the note at booking is the explicit consent you need for using it to serve them safely. The legal posture to adopt is about discipline, not paperwork: record the note factually, show it to the service and kitchen staff who need it, and keep it out of every marketing export and every analytics spreadsheet. A leaked mailing list is embarrassing; a guest's health or religious information circulating is a betrayal, and since the 2024 amendments it is also the category of data where a breach is most likely to be judged as causing significant harm.

If your guest list leaks: the 72-hour clock
Since 1 June 2025, a data controller that suffers a breach must notify the Commissioner within 72 hours where the breach is likely to cause significant harm, under the Guideline on Data Breach Notification analysed by Donovan & Ho. Failing to notify is itself an offence carrying a fine of up to RM250,000, two years' imprisonment, or both. Where significant harm is likely, affected guests must be informed too.
For a restaurant the realistic breach is not a cinema plot. It is a phished email password, a lost phone full of WhatsApp booking threads, a departed manager who still has the login, or an exported spreadsheet shared to the wrong group chat. The playbook fits on one page: change passwords and revoke access the hour you learn of it, work out whose data was exposed and whether health or payment details were in it, write down what you did and when, notify if the harm test is met, and tell affected guests plainly rather than hoping nobody screenshots it first.
Has a restaurant actually been fined?
Honesty requires saying it: we found no published PDPA enforcement case against a restaurant in Malaysia. Enforcement is real but has historically concentrated elsewhere; the Commissioner compounds offences and has prosecuted data controllers in other sectors, and activity has picked up since the amendments, as the enforcement overview by Christopher & Lee Ong shows.
Do not read that as a pass. The pre-2025 era had low ceilings and no breach duty; the new regime has RM1 million fines, a 72-hour clock and a public appetite for data stories. The first Malaysian restaurant in a PDPA headline will pay in reputation long before it pays the compound.
Booking platforms: who actually holds your guest list
For most restaurants, the PDPA question with the biggest commercial consequence is not a notice template. It is which booking system holds the guest list, and on whose terms. If a platform's servers, terms and marketing engine sit between you and your regulars, then your compliance, your exports and your relationship with those guests all run through someone else's product decisions.
Malaysia makes the question concrete: both consumer booking marketplaces, TABLEAPP and Eatigo, belong to the same Taiwanese group, FunNow, and a marketplace's model is to market its whole network to its diner base. That is not evil, it is a business model; but your regulars become an audience you do not control. When you evaluate any system, in our comparison of reservation systems in Malaysia or anywhere else, put three questions in writing:
- Who owns the guest data, and is it exportable in a usable format, at any time, without begging?
- Does the platform market to your guests about other restaurants?
- Where is the data processed, and what happens to it if the platform is acquired or shuts down?
Let's be honest about our own position: ViteUneTable is a booking system, so we are not neutral. What we can state factually is the model. With ViteUneTable the guest data belongs to the restaurant and is exportable, there is no marketplace emailing your diners, and the free version is unlimited with 0% commission and no per-booking fees. Automatic email confirmations and reminders come with the Pack Standard at 29 € per month excluding tax, about RM134 at early-October 2026 rates. Your guest list stays an asset you own, not inventory in someone else's network.
A PDPA checklist for your restaurant
- Collect the minimum. Name, mobile number, pax, email for confirmations. No IC numbers for a dinner booking.
- Put up a short bilingual notice. What you collect, why, and how to reach you, in Bahasa Malaysia and English, on the booking page and at the counter.
- Split marketing from booking. The marketing opt-in is a separate, unticked box with its own timestamped record.
- Keep reminders purely transactional. No promotional lines inside confirmations and reminders.
- Honour every stop request immediately. Section 43 makes it a right, not a favour.
- Guard the sensitive notes. Allergy, health and religious-dietary details are for service staff only, never in a marketing field or export.
- Control access. Unique logins, two-factor authentication where offered, access removed the day a staff member leaves, bookings out of personal phones.
- Set a retention habit. Delete stale exports and years-old guest data you no longer need.
- Know your platform's answers. Data ownership, exportability, and who markets to your guests, in writing.
- Have the one-page breach plan. Who changes passwords, who assesses harm, who notifies the Commissioner within 72 hours if it comes to that.
Frequently asked questions
Does the PDPA apply to a small restaurant in Malaysia?
Yes. The PDPA 2010 applies to anyone processing personal data in respect of commercial transactions, with no turnover threshold or small business exemption. A single-outlet restaurant taking bookings is covered from its first guest record, and since 1 April 2025 the maximum penalty for breaching the data protection principles is RM1 million, three years' imprisonment, or both.
Does my restaurant need to register with the Personal Data Protection Commissioner?
Generally no. Registration only applies to classes listed in the Class of Data Users Order 2013, and its hospitality class targets Tourism Industry Act 1992 licensees such as hotels. An ordinary restaurant is usually outside every registrable class, but check the Order against your actual licences before deciding either way. The seven data protection principles apply whether or not you register.
Do I need a data protection officer?
Only if your processing involves personal data of more than 20,000 data subjects, sensitive personal data of more than 10,000 data subjects, or regular and systematic monitoring. Most independent restaurants never reach those thresholds. The 72-hour breach notification duty applies to every data controller regardless.
Can I send WhatsApp or SMS promotions to past guests?
Only with the guest's marketing consent, evidenced in a form you can show, such as a timestamped opt-in. Malaysia has no Do Not Call registry, so consent is the whole game, and under section 43 of the PDPA a guest can require you by written notice to stop direct marketing, which you must honour. A past booking by itself is not marketing consent. Booking confirmations and reminders about the guest's own reservation are transactional messages, not marketing.
Are allergy notes really "sensitive personal data"?
Information about physical or mental health is sensitive personal data under section 4 of the PDPA, and religious-dietary requirements touch religious beliefs, another sensitive category. Section 40 requires explicit consent to process it, which the guest gives by volunteering the note for their booking. Keep such notes for service use only and out of marketing lists and exports.
What do I do if my guest data is breached?
Revoke access and change passwords immediately, establish whose data was exposed and whether sensitive or financial details were included, and document everything. If the breach is likely to cause significant harm, notify the Commissioner within 72 hours and inform affected guests. Failing to notify is an offence punishable by a fine of up to RM250,000, two years' imprisonment, or both.
Also worth reading
Zomato and Swiggy dining commissions: what a table booking really costs your restaurant
Everyone debates delivery commissions. Almost nobody has priced the dining side: the commission, the funded discount and the GST on top. Here is the full cost stack of an aggregator table booking, with a worked INR example.
WhatsApp table bookings in India: the honest operator guide
WhatsApp is the front door of Indian restaurant bookings, from neighbourhood CDRs to tasting-menu rooms. Here is how to run it well, where it breaks, and the hybrid setup that fixes it.
WhatsApp restaurant bookings in Malaysia: from chat chaos to a real system
In Malaysia the reservation book is often a WhatsApp thread on one phone. Here is how to keep the channel guests love, fix the failure modes and put a real system underneath.