Restaurant management privacy customer data New Zealand

Privacy Act 2020 for restaurants: the NZ guide to guest data in 2026

Written by Ludovic Frank Published on 13 min read
New Zealand restaurant owner reviewing guest booking records on a laptop behind the counter of her cafe, with a locked filing cabinet beside her

Every booking your restaurant takes creates personal information: a name, a mobile number, an email address, sometimes an allergy or a note like "anniversary, window table". Multiply that by a few thousand covers a year and your reservation diary is one of the largest databases of personal information you will ever be responsible for.

In New Zealand, that responsibility has a name: the Privacy Act 2020. And here is the fact that surprises hospo owners who read Australian or American advice online: the Privacy Act applies to every New Zealand business, with no small-business exemption. A six-table BYO in New Plymouth has the same core obligations as a national chain.

The good news is that for a restaurant, compliance is mostly a handful of sensible habits. This guide translates the law into floor-level practice: what you can collect at booking, how to handle allergy notes, what your booking software vendor must let you do, and exactly what happens if guest data leaks. If you run your bookings through a free reservation system that lets you export your guest data at any time, most of the technical side is already handled; the habits are still yours to build.

Yes, the Privacy Act 2020 applies to your restaurant

The Privacy Act 2020, in force since 1 December 2020, covers every "agency", which is the Act's word for any organisation or business that collects or holds personal information about identifiable people. There is no turnover threshold, no headcount threshold and no carve-out for hospitality: the Office of the Privacy Commissioner (OPC) is explicit that the privacy principles govern how organisations and businesses of any size handle personal information.

This is a genuine difference from Australia, where the Privacy Act 1988 generally does not apply to businesses with an annual turnover of A$3 million or less. A lot of the "small cafes are exempt" content that ranks in search results is written for Australians. In New Zealand it is simply wrong: if you take bookings, you are covered.

"Personal information" is any information about an identifiable person. For a restaurant that includes, at minimum:

  • names, phone numbers and email addresses collected at booking
  • dietary requirements and allergy notes
  • visit history and preferences ("regular, always the deck", "no-show on 14 Feb")
  • marketing lists and loyalty records
  • CCTV footage of your dining room
  • payment-related details such as the last digits of a card used to guarantee a booking

The 13 privacy principles, translated for a restaurant

The Act is built on 13 information privacy principles (IPPs). You do not need to memorise them; you need to recognise what they look like on a Tuesday night service.

Collecting guest information (IPPs 1 to 4)

Collect only what you need for a lawful purpose connected to your business, collect it from the guest directly where practicable, and be upfront about why. For bookings, that is easy to satisfy: a name and a contact number are clearly needed to hold a table and to send a confirmation or reminder. Where owners get into trouble is over-collection: requiring a date of birth to book dinner, or quietly harvesting details for purposes the guest was never told about. A short privacy note on your booking page ("we use your details to manage your booking and, if you opt in, to send occasional news") covers the transparency requirement in one sentence.

One specific rule worth knowing: IPP13 restricts collecting unique identifiers. You have no reason to ask for a passport, driver licence or IRD number to take a dinner booking, so never do.

Storing it securely (IPP5)

You must protect personal information with security safeguards that are reasonable in the circumstances. In a restaurant that means: the booking system is protected by individual logins rather than one shared password taped to the POS, the paper diary (if you still run one) does not sit open on the host stand where any guest can read the previous pages, old function sheets with guest phone numbers go through a shredder rather than the recycling bin, and laptops or tablets that hold guest exports are password-protected. The more sensitive the information, the higher the standard: allergy notes deserve more care than first names.

Using and sharing it (IPPs 8 to 12)

Use guest information for the purpose you collected it for. Booking details can be used to run the booking: confirmations, reminders, a call when the kitchen floods. They do not automatically become a marketing list; more on that below. Disclosure to third parties is limited too: reading a guest's visit history to a caller who claims to be their partner, or passing your database to the promoter running an event at your venue, are both disclosures you would need authorisation for. IPP12 adds a modern twist: if your booking platform stores data overseas, you are responsible for checking the recipient country or company offers comparable safeguards, which in practice means reading your vendor's data-processing terms once and keeping a copy.

Access and correction (IPPs 6 and 7)

Any guest can ask what personal information you hold about them, and ask you to correct it. You must respond as soon as reasonably practicable and no later than 20 working days. For a restaurant the request is usually trivial (a booking history and a preference note), but the deadline is real, so make sure whoever reads the info@ inbox knows these requests exist. This is also a strong argument for keeping guest notes professional: assume the guest will one day read what your team wrote about them, because they have the legal right to.

Allergy and dietary notes deserve special care

An allergy note is health-related information, and sensitivity is one of the factors the OPC weighs when assessing how serious a breach is. That does not mean you should stop recording allergies; capturing them at booking and pushing them to the kitchen is exactly what good service and food safety require. It means three habits:

  1. Record facts, not commentary. "Coeliac, confirmed at booking" is fine. Jokes or scepticism ("claims gluten-free, watch her order the brioche") are not, and remember the guest's right of access.
  2. Limit visibility to who needs it. Kitchen and floor need the allergy flag during service; the marketing list does not.
  3. Do not repurpose it. An allergy note collected for service is not a segmentation field for promotional emails about your new gluten-free menu unless the guest opted in to marketing.

Marketing lists: bookings are not automatic opt-ins

A guest who booked a table gave you their email address to manage that booking. Using it for a monthly newsletter is a different purpose, and New Zealand has a second law that applies here: the Unsolicited Electronic Messages Act 2007 requires consent before sending commercial electronic messages, plus a working unsubscribe link and accurate sender details in every message.

The clean pattern is a genuine opt-in tick box at booking (unticked by default), a visible unsubscribe in every send, and a list that lives in your own hands rather than inside a platform you might leave. Done properly, email marketing is one of the highest-return channels a restaurant has, precisely because everyone on the list chose to be there. The same logic underpins any loyalty programme: reward visits you can see in your own booking data, with the guest's knowledge.

Transactional messages are different: a booking confirmation or a reminder about tomorrow's table is part of delivering the service the guest asked for, not marketing. Keep them factual and they stay that way; add a promotional paragraph and you have converted them into something that needed consent.

CCTV: point it at the till, tell people it exists

Most venues run cameras, and the OPC publishes specific CCTV guidance. The restaurant version: have a clear purpose (security, not curiosity), tell people with visible signage that says who operates the cameras and how to contact them, position cameras over entries and the till rather than spaces where guests reasonably expect privacy, restrict who can view footage, and delete it on a short cycle unless an incident requires keeping a copy. Footage of an identifiable person is personal information, so the access right applies to it too.

Your booking platform holds your guest data. Ask it these questions

For most restaurants, the single biggest privacy decision is which reservation system holds the guest database. The Privacy Act does not stop being your problem because a vendor stores the data; you remain the agency responsible for it. Before you sign, get answers in writing to four questions:

  1. Can I export my complete guest database at any time, in a usable format?
  2. Where is the data stored, and under whose law? (That is your IPP12 homework done.)
  3. What happens to my data if I leave, and how quickly is it deleted?
  4. Does the platform use my guests for its own marketing? A marketplace that emails your guests about other venues is using data collected through your restaurant for its own purposes; make sure you and your guests are comfortable with that.

New Zealand just watched the cautionary tale play out: Quandoo, which operated here, is shutting down worldwide, with bookings ending 30 September 2026 and the platform going offline on 31 December 2026. Every venue that treated Quandoo as the home of its guest list has spent 2026 scrambling to export before the lights go out. Our guide to moving off Quandoo covers the migration; the privacy lesson is simpler: your guest database should never have a single point of failure you do not control.

This is a deliberate design choice at ViteUneTable: your guest data belongs to you, you can export it whenever you like, and the free version with 0% commission does not pay for itself by marketing to your guests. When you compare providers for the New Zealand market, put data ownership next to price on the checklist; our comparison of restaurant booking systems in NZ does exactly that.

When something goes wrong: the breach playbook

Restaurant team working through a privacy breach checklist together on a tablet at the kitchen pass
Four steps: contain, assess, notify, fix

A lost phone with the booking app logged in, a stolen laptop with last year's function sheets, an email to the whole marketing list with everyone in CC, a break-in that takes the office computer: these are privacy breaches, and the Act sets out what happens next.

  1. Contain it. Revoke the logged-in session, change the passwords, recall the email if you can.
  2. Assess the harm. The legal test is whether the breach has caused, or is likely to cause, serious harm to the people affected. Sensitivity of the information, who has it now and what they could do with it all feed the assessment; the OPC provides a self-assessment tool to work through it.
  3. Notify if it is serious. A notifiable breach must be reported to the Privacy Commissioner via the online NotifyUs tool, ideally within 72 hours of becoming aware of it, and affected guests must be told as soon as possible so they can protect themselves. Failing to notify is an offence with a fine of up to NZ$10,000.
  4. Fix the cause. The OPC cares far more about honest notification and a corrected process than about punishing a cafe that owned its mistake.

Beyond fines, guests can complain to the OPC, and cases that reach the Human Rights Review Tribunal have produced damages awards from a few thousand dollars up to six figures in the most serious cases. For a small venue, though, the realistic cost of sloppy data handling is reputational: manaakitanga is the standard Kiwi hospitality holds itself to, and looking after guests includes looking after what they told you.

The one-page privacy setup for a busy venue

You can put all of the above into place in an afternoon:

  • a two-line privacy note on your booking page and website
  • individual logins for the booking system; shared passwords retired
  • an unticked marketing opt-in at booking, and an unsubscribe link in every campaign
  • allergy notes: factual wording, service-only visibility
  • CCTV signage at the door, footage on a short auto-delete cycle
  • a written answer from your booking vendor on export, storage location and deletion
  • one nominated person who handles access requests and would run the breach playbook
  • a calendar note to purge data you no longer need: old function sheets, stale exports, the CV pile from last summer's hiring

None of this slows down service. Most of it makes service better, because clean, well-organised guest data is also what powers good hospitality: remembering the regulars, catching the allergies, filling the room on a wet Wednesday.

Frequently asked questions

Does my small restaurant really need to comply with the Privacy Act 2020?

Yes. The Act covers every New Zealand business that handles personal information, regardless of size or turnover. There is no small-business exemption like Australia's A$3 million threshold, so advice written for Australian cafes does not apply here.

Do I need a written privacy policy?

The Act does not prescribe a document, but IPP3 requires you to tell people why you collect their information and what you do with it. A short, plain-English note on your booking page and website is the practical way to meet that, and it doubles as staff guidance.

Can a guest demand to see what I have recorded about them?

Yes. Under IPP6 anyone can request the personal information you hold about them, and you must respond within 20 working days at most. That includes booking history, preference notes and CCTV footage they appear in, so keep every note professional.

Absolutely, and you should keep them: they are essential for safe service. Because they are health-related and more sensitive than a name or phone number, store them factually, show them only to staff who need them during service, and never reuse them for marketing without consent.

When do I have to report a data breach?

When it has caused, or is likely to cause, serious harm to the people affected. Report it to the Privacy Commissioner through the NotifyUs tool, ideally within 72 hours, and tell the affected guests. Not notifying a notifiable breach is an offence with a fine of up to NZ$10,000.

Who owns the guest data inside my booking platform?

Legally you remain responsible for it, so contractually it should be yours: full export at any time, a clear storage location, deletion when you leave. Quandoo's shutdown in New Zealand showed what happens when a guest database lives inside someone else's business decisions.

Also worth reading

← Back to the blog