Restaurant management data privacy privacy act customer data

Restaurant customer data and privacy law in Australia: the honest guide

Written by Ludovic Frank Published on 12 min read
Illustration of a relaxed Australian restaurant owner behind the counter of a sunny bistro, checking a guest list on a tablet with a small glowing padlock above the screen

Every booking you take is personal information: a name, a mobile number, usually an email address, sometimes a note that says "severe peanut allergy" or "anniversary, window table". Here is the part most articles bury, or get plainly wrong: if your restaurant's annual turnover is A$3 million or less, the Privacy Act 1988 generally does not apply to you at all. That covers the vast majority of independent venues in Australia.

So why read on? Because the exemption is narrower than it looks, because several rules bind you regardless of size, and because a guest database handled carelessly costs you the thing no law can give back: trust. This guide covers what actually applies to an Australian restaurant in 2026, the reform rumours doing the rounds, and the questions to ask any online booking system before you trust it with your guest list.

The short version:

  • the Privacy Act 1988 generally does not apply to businesses with annual turnover of A$3 million or less, which includes most independent restaurants;
  • the exemption disappears if you trade in personal information, for example by selling your guest database; keeping a reservation list does not count;
  • groups, chains and venues above the threshold follow the 13 Australian Privacy Principles and the Notifiable Data Breaches scheme, enforced by the OAIC;
  • a statutory tort for serious invasions of privacy commenced on 10 June 2025 and reaches beyond the Privacy Act's coverage;
  • the Spam Act 2003 applies to every business, whatever its size: consent, identification and a working unsubscribe on every marketing email and SMS;
  • claims that small businesses "must comply from 1 July 2026" are wrong: as of September 2026, the exemption is still in place;
  • your booking system is still your biggest data decision: where the guest list lives, who owns it, and whether the platform monetises your guests.

Does the Privacy Act apply to your restaurant?

Australia's federal privacy law is the Privacy Act 1988 and its 13 Australian Privacy Principles (APPs), overseen by the Office of the Australian Information Commissioner. It has a built-in small business exemption: per the OAIC's own guidance, most businesses with an annual turnover of A$3 million or less are not covered. Turnover means all income from all sources, not profit, so a busy venue can cross the line sooner than the owner expects, but a typical independent restaurant sits well under it.

Three situations pull a restaurant back into the Act regardless of turnover:

  • You are part of something bigger. A venue related to a larger covered corporate group loses the exemption; a multi-site group over A$3 million combined should assume it is covered.
  • You trade in personal information. More on this below, because it is the exception that actually matters for hospitality.
  • You fall into a listed category, such as providing a health service or being a reporting entity under anti-money laundering law. Serving dinner is neither.

If you are setting up your first venue, our guide to opening a restaurant in Australia covers the wider regulatory picture.

The exception that matters: trading in personal information

The exemption vanishes, whatever your turnover, if your business discloses personal information for a benefit, service or advantage, or collects it in exchange for one. In plain terms: the moment you sell, rent or swap your guest database, you are trading in personal information and the full Privacy Act applies to you.

What does not count as trading: taking bookings, keeping a reservation list, emailing your own guests, running your own loyalty programme. What plainly would: selling your customer list to a marketing broker, or swapping guest emails with a neighbouring business. The line makes one decision easy: your guest list is not for sale, legally or commercially. It is worth far more as the foundation of repeat business than any one-off payment.

If you are covered: the APPs and data breaches in brief

For groups, chains and high-turnover venues, the obligations are the 13 Australian Privacy Principles. Translated for a dining room: collect only what a booking needs, tell people what you do with their details (a short privacy policy on your website), keep the data secure, use it for the purpose you collected it for, and answer guests who ask what you hold about them.

Covered entities are also bound by the Notifiable Data Breaches scheme: if personal information is lost or accessed without authorisation and serious harm is likely, you must notify the OAIC and the affected individuals. For a restaurant the realistic scenario is not a Hollywood hack; it is a phished booking-platform password or an exported spreadsheet on a stolen laptop.

One contrast is worth a sentence: a UK restaurant, however small, must comply with UK GDPR and pay a data protection fee to the ICO, a regime we cover in our guide to UK restaurant customer data. Australia took a different path. Do not import GDPR habits wholesale, and do not let anyone scare you with GDPR fine figures: they are another country's law.

The new privacy tort reaches everyone

The first tranche of privacy reform, the Privacy and Other Legislation Amendment Act 2024, delivered something that does not care about the small business exemption: a statutory tort for serious invasions of privacy, which commenced on 10 June 2025. It lets an individual sue over a serious invasion of privacy, either intrusion upon seclusion or misuse of information, where the invasion was intentional or reckless and privacy outweighs competing public interests. The OAIC notes it is broader than the Privacy Act, extending to entities that are not APP entities, which on its face includes exempt small businesses; how courts will apply it to them is still being worked out.

A restaurant is unlikely to be a defendant for taking bookings. The risk is deliberate misuse: a staff member sharing a celebrity's booking details on social media, or CCTV pointed somewhere it should never point. The tort exists now, and "we were too small for the Privacy Act" is not a defence to it.

Reform watch: no, you do not have to comply "from 1 July 2026"

You may have seen articles, many from IT companies selling compliance services, claiming the exemption is being scrapped and every cafe must comply from 1 July 2026, or from December 2026. As of September 2026, that is not what has happened. The government released the exposure draft of the tranche-2 bill, the Privacy Amendment (Personal Data Protection) Bill, at the end of August 2026, with submissions closing 18 September 2026, and the draft does not remove the small business exemption: removal remains agreed in principle only, pending an impact analysis and consultation with small business, as Ashurst Perkins Coie's analysis of the draft spells out.

The honest reading: the direction of travel is one-way, and the exemption will likely narrow in a future tranche, so habits built now will only gain value. But nobody should be panic-buying a compliance package because of a deadline that does not exist in any Act.

The Spam Act applies whatever your size

Here is the rule that catches restaurants far more often than the Privacy Act: the Spam Act 2003 has no small business exemption. Every marketing email and SMS you send is a commercial electronic message, and the ACMA's rules apply from your first newsletter:

  • Consent first. Express consent is a guest actively opting in, for example an unticked "send me news and offers" box. Consent can be inferred from an ongoing relationship where the person gave you their address directly and would reasonably expect your marketing, but the burden of proof sits with you. A booking is consent to be contacted about that booking, not a newsletter subscription.
  • Identify yourself. Every message must identify your business by its correct legal name or name plus ABN, kept accurate for at least 30 days after sending.
  • A working unsubscribe. One that works without logging in or handing over more details, honoured within five business days.

The ACMA enforces this actively, and its published penalties against well-known Australian brands run into the millions. Our guide to restaurant email marketing covers how to grow a list that is both legal and effective; a smaller list of genuine opt-ins outperforms a padded one anyway.

Why good practice pays even when the Act does not bind you

Suppose you are comfortably under A$3 million and never plan to sell a list. Why care?

Guest trust is the asset. A leaked guest list, or a diner whose allergy note circulates as a joke, becomes a one-star review and a story that travels. Nobody looks up your turnover before deciding you were careless with their details.

Allergy and dietary notes deserve special care. A note saying "coeliac" or "anaphylactic to shellfish" is information about someone's health, the category treated as most sensitive wherever privacy law does apply. Even when the Act does not bind you, handle these notes as if it did: keep them factual, visible only to staff who need them for service, and out of any marketing export.

Payment data is already regulated by contract. Card details taken for deposits or holds fall under the PCI DSS obligations in your payment processor's terms. The practical rule: never write a card number down or store one in a booking note; let the processor's tokenised system carry that risk.

Cameras have their own rules. CCTV and recording of conversations are governed by state and territory surveillance legislation, which varies across the country. Signage and sensible placement are the baseline; take state-specific advice beyond that.

Your booking system is where the guest list actually lives

Illustration of a restaurant host station where a waiter slips a handwritten allergy note into a locked drawer beside a tablet showing the evening's reservation list
The guest list lives wherever your booking system puts it

For an independent venue, the single biggest data decision is not a policy document; it is which booking system holds your guests. Moving from a paper diary to a digital reservation book concentrates every name, number and note in one place, so it is worth asking three questions before you sign:

Who owns the guest data, and can you leave with it? The Australian market has just lived through the answer's importance: TheFork left in 2024 and Quandoo is shutting down in 2026, as we detail in our comparison of restaurant booking systems in Australia. When a platform exits or is sold, the guest database is part of what moves. Get it in writing that the data is yours and exportable in a usable format.

Does the platform market to your guests? Marketplace networks build their own diner accounts and email your guests about other venues. That is their business model, not a scandal, but your regulars end up feeding an audience you do not control. Per-cover fees and commissions give a platform every incentive to sit between you and your guest.

Let us be honest about our own position: ViteUneTable is a booking system, so we are not neutral. What we can state factually is the model. With ViteUneTable, the guest data belongs to the restaurant and is exportable, there is no marketplace emailing your diners, the free version is unlimited with 0% commission and no per-booking fees, and paid features come as flat packs (Pack Standard at 29 € per month excluding VAT). Prices are in euros, since the company is European; factor the exchange rate in, as you would with any USD-billed platform.

A practical checklist for reservation data

  1. Collect the minimum. Name, mobile, party size, and email if you send confirmations. A booking form does not need a birth date or a postcode.
  2. Split marketing from booking. The opt-in for offers is a separate, unticked box, never bundled into "book a table".
  3. Set a retention habit. Delete stale exports and prune bookings from years back; they serve nobody.
  4. Guard the sensitive notes. Allergies and health-adjacent details are for service staff only, never in a marketing field.
  5. Control access. Unique logins, two-factor authentication where offered, access removed the day a staff member leaves.
  6. Plan for a breach even if unregulated. Change credentials immediately, work out who is affected, tell them straight; covered entities assess against the Notifiable Data Breaches scheme.
  7. Write the one-pager. A short privacy note on your website, what you collect and why, costs an hour and reads as professionalism, exemption or not.

Frequently asked questions

Does the Privacy Act apply to my restaurant?

Probably not, if your annual turnover is A$3 million or less and you are an independent business: the OAIC confirms most small businesses are exempt. You are covered if you are part of a larger group over the threshold, if you trade in personal information, or if you fall into a listed category such as health services.

Can I email my guests marketing offers?

Only under the Spam Act 2003, which applies to every business regardless of size. You need consent (an unticked opt-in box is the clean route), your business identification in every message, and a working unsubscribe honoured within five business days. A booking by itself is not a newsletter subscription.

Can I sell my customer list?

Treat the answer as no. Disclosing personal information for a benefit is "trading in personal information", which strips away the small business exemption and puts you under the full Privacy Act, likely in breach of it from the first sale. Commercially, the list is worth more as the engine of your repeat business.

Is it true small businesses must comply with the Privacy Act from 2026?

No. As of September 2026, the exemption is still in place, and the tranche-2 exposure draft released in August 2026 does not remove it; removal is agreed in principle only. Articles claiming a 1 July 2026 or December 2026 compliance deadline are wrong.

They are health-related information, the most sensitive kind of guest data, so handle them with care even where the Act does not bind you: keep them factual, restrict them to service staff, and never export them into marketing tools.

What should I do if my guest list is leaked?

Change passwords and revoke access immediately, work out whose data was exposed and tell them plainly. If your business is covered by the Privacy Act, assess whether serious harm is likely and notify the OAIC and affected individuals under the Notifiable Data Breaches scheme. Keep a record either way.

Also worth reading

← Back to the blog