Restaurant management PDPA customer data Singapore

PDPA for restaurants in Singapore: guest data, marketing messages and the Do Not Call Registry

Written by Ludovic Frank Published on 13 min read
Illustration of a Singaporean restaurant manager at a shophouse host stand checking the evening's guest list on a laptop, a small glowing padlock above the screen

Every reservation you take is personal data: a name, a mobile number, usually an email address, sometimes a note that says "shellfish allergy" or "anniversary, quiet table". In Singapore, all of it sits under the Personal Data Protection Act (PDPA), enforced by the Personal Data Protection Commission (PDPC), and unlike some countries there is no small business exemption: the Act applies to a two-man kopitiam stall company and a hotel group alike, from the first booking.

That sounds heavier than it is. The PDPA is, at heart, a set of common-sense rules about collecting only what you need, saying what you do with it, keeping it safe and not spamming people. This guide translates those rules for an F&B business: what they mean at the host stand, how the Do Not Call Registry changes your SMS and WhatsApp marketing, what to do if your guest list leaks, and the questions to ask a booking system that treats your guest list as yours before you trust it with your diners.

The short version:

  • the PDPA applies to every private-sector organisation in Singapore, whatever its size, with the PDPC as regulator;
  • since 1 October 2022, a breach of the data protection obligations can cost up to S$1 million, or 10% of your annual Singapore turnover if that turnover exceeds S$10 million;
  • a reservation confirmation or reminder is a service message about a booking the guest made; a promotional SMS is a marketing message, and for those the Do Not Call Registry rules apply;
  • allergy and dietary notes are health-related information, the kind the PDPC treats as higher-risk: handle them with extra care;
  • if guest data is breached, there is a 30-day clock to assess and a 3-day clock to notify the PDPC once the breach is assessed as notifiable;
  • your biggest practical data decision is your booking platform: who holds the guest list, who markets to it, and whether you can leave with it.

What personal data a restaurant actually holds

Before the obligations, take stock of what a typical Singapore restaurant collects without ever thinking of itself as a "data business":

  • Bookings and waitlists: names, mobile numbers, emails, party sizes, dates and times, table preferences.
  • Service notes: allergies, dietary and religious requirements, birthdays, anniversaries, "VIP, knows the owner".
  • Payment traces: card details taken for deposits or card holds, usually tokenised by a payment processor rather than stored by you (keep it that way; never write a card number in a booking note).
  • Marketing lists: newsletter sign-ups, loyalty members, past guests exported into a mailing tool.
  • CCTV footage of the dining room and, often, staff records.

All of that is personal data under the PDPA. The PDPC's overview of the data protection obligations lists the full set; below is what each one means when your organisation is a dining room rather than a bank.

The PDPA obligations, translated for a dining room

Consent and notification. Collect personal data with consent, for purposes a reasonable guest would expect, and tell them what those purposes are. A booking form asking for a name and mobile number to manage the reservation needs no legal theatre: the purpose is obvious. The line is crossed when data collected for a booking quietly becomes a marketing list. Keep the marketing opt-in a separate, deliberate choice, never bundled into "book a table".

Purpose limitation. Use the data for the purpose you collected it for. The mobile number given for tonight's table is for tonight's table; it becomes a promotional channel only if the guest agreed to that.

Accuracy, access and correction. Keep guest records reasonably accurate, and answer a guest who asks what you hold about them or wants it corrected. In practice this is rare and painless if your records live in one tidy system instead of five spreadsheets.

Protection. Take reasonable security arrangements: unique staff logins on the booking system, two-factor authentication where offered, access revoked the day someone leaves, no guest exports sitting on a personal laptop. This is the obligation restaurants actually get caught on, as the Marina Bay Sands case below shows.

Retention limitation. Keep personal data only as long as you need it for a legal or business purpose, then dispose of it. Prune stale exports and years-old waitlist entries; they serve nobody and enlarge every breach.

Transfer limitation and accountability. If data leaves Singapore, whoever receives it must protect it to a comparable standard (relevant when your booking platform's servers are overseas: ask). And someone in the business, formally a data protection officer, must own these questions; in an independent restaurant that is usually the owner, and appointing yourself is allowed and normal.

A note on NRIC numbers. The PDPC's advisory guidelines on NRIC numbers, in force since September 2019, restrict collecting them to situations where the law requires it or where verifying identity to a high degree is necessary. A dinner reservation is neither: do not collect NRIC numbers for bookings, and push back on any form or template that asks for them.

What the penalties look like

Since 1 October 2022, the PDPC can impose a financial penalty of up to 10% of an organisation's annual Singapore turnover where that turnover exceeds S$10 million, and up to S$1 million in any other case, per its Guide on Active Enforcement.

The hospitality sector has already produced the headline case. In October 2025, the PDPC fined Marina Bay Sands S$315,000 for a breach of the protection obligation after the personal data of 665,495 patrons of its lifestyle rewards programme was exfiltrated in October 2023 and later offered for sale on the dark web. The cause was not an exotic hack: a security control was left off during a software migration. The lesson scales down to any restaurant: most breaches are a phished password, a misconfigured page or an exported spreadsheet, not a cinema plot.

For an independent restaurant, the realistic exposure is smaller but real: the PDPC also issues directions, warnings and smaller penalties, and a published decision with your restaurant's name on it is its own punishment in a market where diners read everything.

The Do Not Call Registry: the rule that catches F&B marketing

Here is the part that trips up more restaurants than any other: Singapore's Do Not Call (DNC) Registry. Singapore telephone numbers can be listed on three registers, one each for voice calls, text messages and faxes, and the DNC provisions prohibit sending marketing messages to a listed number.

For a restaurant that means: before you blast "20% off set lunches this week" by SMS to your guest list, every Singapore number on that list must either be screened against the DNC Registry or covered by the guest's clear and unambiguous consent to receive marketing messages from you, given in a form you can evidence (a ticked opt-in box with a timestamp, not a verbal maybe). An existing customer relationship alone is not enough for a number listed on the register. Marketing messages must also identify your business and give the guest a way to opt out, and the same discipline is the safe assumption for messages sent to a Singapore number through apps such as WhatsApp: the PDPC's advisory guidelines on the DNC provisions treat marketing by message to a telephone number as the regulated act, not the particular app that carries it.

Transactional messages are not marketing messages

The DNC regime covers "specified messages": messages whose purpose is to advertise or promote goods, services or suppliers. A message whose only content is servicing a booking the guest made, "your table for 4 at 7.30pm on Friday is confirmed", "reminder: your reservation is tomorrow, reply to cancel", is not promoting anything, and this is why booking confirmations and reminders operate under a different logic from marketing blasts.

The trap is the hybrid message. The moment your reminder adds "and try our new omakase menu!", it acquires a promotional purpose and should be treated as a marketing message, DNC rules included. Keep the two streams separate: confirmations and reminders do their quiet no-show-fighting job for everyone, marketing goes only to guests who opted in. Your email marketing should follow the same split, and a clean opt-in list outperforms a padded one anyway.

Illustration of a guest tapping a separate marketing opt-in toggle on a tablet booking form held by a waitress at a Singapore restaurant host stand
The marketing opt-in is its own box, never bundled into the booking

Allergy notes deserve the most care

A booking note saying "coeliac" or "anaphylactic to peanuts" is information about someone's health. In its data breach guidance, the PDPC treats health-related records among the categories of personal data whose exposure is more likely to cause significant harm. Even though a service note is humbler than a medical file, adopt the same posture: keep allergy and dietary notes factual, visible to service and kitchen staff who need them, and out of every marketing export. A leaked mailing list is embarrassing; a guest's health information circulating is a betrayal, and diners treat it as one.

Booking platforms: who actually holds your guest list

For most restaurants, the PDPA question with the biggest commercial consequence is not a policy document. It is which booking system holds the guest list, and on whose terms.

Singapore has just lived through a vivid reminder that platforms are not forever. Chope, the homegrown reservation platform half the island booked through, is now part of Grab, and its diner accounts and loyalty currency are being folded into the super-app's ecosystem. Quandoo is shutting down worldwide and its Singapore platform goes offline at the end of 2026. In both cases the practical question for a restaurant is the same: which guest records can you take with you, in what format, and who else has been marketing to your regulars in the meantime?

When you evaluate any platform, in our comparison of reservation systems in Singapore or anywhere else, put three questions in writing:

  1. Who owns the guest data, and is it exportable in a usable format, at any time, without begging?
  2. Does the platform market to your guests? A marketplace that emails your diners about other restaurants is not evil, it is a business model, but your regulars become an audience you do not control.
  3. Where is the data processed, and what happens to it if the platform is acquired or shuts down?

Let us be honest about our own position: ViteUneTable is a booking system, so we are not neutral. What we can state factually is the model. With ViteUneTable the guest data belongs to the restaurant and is exportable, there is no marketplace emailing your diners, and the free version is unlimited with 0% commission and no per-booking fees. Automatic email confirmations and reminders come with the Pack Standard at 29 € per month excluding VAT (prices are in euros, since the company is European; factor the exchange rate in as you would with any USD-billed platform). Your guest list stays a loyalty asset you own, not inventory in someone else's network.

If guest data leaks: the 30-day and 3-day clocks

Since the data breach notification obligation came into force, a Singapore organisation that suspects a breach must move on a schedule. Per the PDPC's guide on managing and notifying data breaches:

  • Assess quickly. Once you have credible grounds to believe a breach occurred, assess whether it is notifiable, as a rule of thumb within 30 calendar days.
  • A breach is notifiable if it is likely to result in significant harm to the individuals (health records, financial data and identification numbers are among the higher-risk categories) or if it affects 500 or more individuals.
  • Notify the PDPC within 3 calendar days of assessing the breach as notifiable, and notify the affected guests where significant harm is likely.

For a restaurant the playbook is simple: change the passwords and revoke access the hour you learn of it, work out whose data was exposed, write down what you did and when, and tell affected guests plainly rather than hoping nobody notices. A restaurant that says "here is what happened and here is what we did" keeps more trust than one that gets outed by a screenshot.

A PDPA checklist for your restaurant

  1. Collect the minimum. Name, mobile number, party size, email for confirmations. No NRIC numbers, no birth dates unless you genuinely run a birthday programme the guest joined.
  2. Split marketing from booking. The marketing opt-in is a separate, unticked box, with its own timestamped record.
  3. Screen before you blast. Any promotional SMS or call to numbers without clear opt-in consent gets checked against the DNC Registry first.
  4. Keep reminders purely transactional. No promotional lines inside confirmations and reminders.
  5. Guard the sensitive notes. Allergies and health-adjacent details are for service staff only, never in a marketing field or export.
  6. Control access. Unique logins, two-factor authentication where offered, access removed the day a staff member leaves.
  7. Set a retention habit. Delete stale exports; prune data you no longer need.
  8. Name a data protection officer. In an independent restaurant, that is usually you; write it down.
  9. Know your platform's answers. Data ownership, exportability, and who markets to your guests, in writing.
  10. Have the one-page breach plan. Who changes passwords, who assesses, who calls the PDPC if it comes to that.

Frequently asked questions

Does the PDPA apply to a small restaurant?

Yes. Singapore's PDPA applies to private-sector organisations regardless of size, from a single hawker stall company to a hotel group. There is no turnover threshold or small business exemption, so the obligations, and the penalties, apply from your first booking.

Can I send SMS promotions to past guests?

Only if each Singapore number is either covered by the guest's clear and unambiguous opt-in consent to marketing messages, in a form you can evidence, or has been screened against the Do Not Call Registry and is not listed. The message must identify your business and offer an opt-out. A past booking by itself is not marketing consent.

Are reservation reminders covered by the Do Not Call Registry?

A message that only services the guest's own booking, a confirmation or a reminder with no promotional content, is not a marketing message under the DNC regime. Add a promotional line and it becomes one. Keep reminders strictly transactional and run marketing as a separate, opt-in stream.

What are the penalties for breaching the PDPA?

Since 1 October 2022, the PDPC can impose up to S$1 million, or up to 10% of annual Singapore turnover for organisations whose Singapore turnover exceeds S$10 million. In October 2025 it fined Marina Bay Sands S$315,000 over a breach affecting 665,495 patrons. Smaller organisations more commonly receive directions, warnings or smaller penalties, all published.

Do I have to report a data breach?

You must assess a suspected breach promptly, as a rule of thumb within 30 days. If it is likely to cause significant harm or affects 500 or more people, you must notify the PDPC within 3 calendar days of that assessment, and notify affected guests where significant harm is likely.

Can I collect NRIC numbers for reservations?

No. PDPC guidelines in force since September 2019 restrict NRIC collection to cases where the law requires it or where identity must be verified to a high degree. A restaurant booking is neither, so a name and mobile number are all you should ask for.

Also worth reading

← Back to the blog