Restaurant customer data privacy in Canada: PIPEDA, Law 25 and CASL in plain English
Every reservation you take is personal information: a name, a phone number, usually an email address, sometimes a note that says "severe peanut allergy" or "anniversary, window table". In the United States, whether privacy law reaches your restaurant depends on your state and your size. In Canada, the answer is simpler and stricter: privacy law applies to you, whatever your size. There is no small-business exemption in PIPEDA, none in Alberta or BC's provincial laws, and emphatically none in Quebec's Law 25.
The good news is that the obligations are reasonable once you see them laid out, and most of them boil down to habits a well-run restaurant has anyway: collect only what you need, tell people what you do with it, keep it safe, and stop emailing people who ask you to stop. This guide walks through what actually applies to a Canadian restaurant in 2026: PIPEDA and its 10 principles, the three provinces with their own laws, the CASL rules that govern every marketing email you send, breach duties, and the questions to ask any reservation platform before you trust it with your guest list.
The short version:
- PIPEDA applies to commercial activity across Canada; Alberta, BC and Quebec have "substantially similar" laws that apply instead for business inside those provinces;
- there is no size threshold: a 30-seat bistro is covered just like a national chain;
- allergy and dietary notes can be health information, the most sensitive data you hold;
- CASL governs marketing emails and texts, with penalties up to $10 million for a business, and its consent rules are stricter than the American CAN-SPAM regime;
- Quebec's Law 25 adds its own layer (a designated privacy officer, a published privacy policy, incident registers) with the toughest penalties in the country;
- reform is coming federally (Bill C-36 would replace PIPEDA) but nothing has changed yet: PIPEDA still applies;
- your reservation platform is your biggest privacy decision: where the data lives, who owns it, and what happens when the platform is sold.
Which law applies to your restaurant
Canada's federal private-sector privacy law is the Personal Information Protection and Electronic Documents Act, PIPEDA, enforced by the Office of the Privacy Commissioner of Canada. It covers personal information handled in the course of commercial activity, and taking reservations, running a loyalty program or sending a newsletter is commercial activity.
Three provinces have their own private-sector laws deemed "substantially similar", which apply instead of PIPEDA for activity inside the province:
- Alberta: the Personal Information Protection Act (PIPA), overseen by the Office of the Information and Privacy Commissioner of Alberta;
- British Columbia: its own PIPA, overseen by the Office of the Information and Privacy Commissioner for BC;
- Quebec: the Act respecting the protection of personal information in the private sector, heavily reinforced by Law 25, overseen by the Commission d'accès à l'information (CAI).
In practice the direction of travel is the same everywhere: identify why you collect data, get consent, protect it, and answer people who ask what you hold on them. If your restaurant operates in Ontario, the Prairies (outside Alberta), Atlantic Canada or the territories, PIPEDA is your law. And whenever personal information crosses a provincial or national border, for instance because your reservation platform stores it on servers in the United States, PIPEDA applies to that flow regardless of where you are.
One thing you will not find anywhere in this landscape is a revenue or headcount threshold. American articles about the CCPA's $25-million cutoff simply do not translate; if that is the market you operate in, the picture is different, and we cover it in our guide to US restaurant customer data privacy.
PIPEDA's 10 principles, translated for a dining room
PIPEDA is built on 10 fair information principles. Here is what each one looks like when the "data subject" is a guest with a 7:30 booking:
- Accountability: someone in your business is responsible for privacy. In a small restaurant, that is the owner, and it helps to say so.
- Identifying purposes: know why you collect each field. Name and phone number to hold the table; email to confirm; allergy notes to keep someone safe. If you cannot name the purpose, drop the field.
- Consent: get it for each purpose. Booking a table implies consent to being contacted about that booking; it does not imply consent to weekly promotions (more on that under CASL below).
- Limiting collection: collect only what the purpose requires. A reservation form does not need a birth date or a postal code.
- Limiting use, disclosure and retention: use data for the stated purpose, do not sell or share it beyond that, and do not keep it forever. Old no-show notes about a guest from 2019 serve nobody.
- Accuracy: keep records correct, which for a restaurant mostly means updating contact details when a regular tells you they changed.
- Safeguards: protect the data with measures matching its sensitivity. A paper reservation book left open by the door fails this test as surely as a shared password taped to the POS.
- Openness: make your practices easy to learn about, typically through a short privacy policy on your website.
- Individual access: when a guest asks what you hold about them, answer, and correct it if it is wrong.
- Challenging compliance: give people a way to complain to the accountable person, before they complain to a regulator.
A word on allergy and dietary notes: a record that says "coeliac" or "anaphylactic to shellfish" is information about someone's health. Health information is treated as sensitive under Canadian privacy law, which means stronger safeguards and more care in who can see it. Keep those notes factual, visible only to staff who need them for service, and never in a field that gets exported to a marketing tool.
CASL: the rules for every marketing email and text
Canada's Anti-Spam Legislation is where Canadian law diverges most sharply from what American guides teach. CAN-SPAM in the US is an opt-out regime; CASL is opt-in. Before you send a commercial electronic message, an email or text promoting your restaurant, you need consent, and the CRTC can impose administrative monetary penalties of up to $1 million per violation for an individual and $10 million for a business.
CASL recognizes two kinds of consent:
- Express consent: the guest actively agreed, for example by ticking an unchecked box that says "send me news and offers". It never expires until withdrawn. This is the gold standard, and the only durable foundation for a newsletter list.
- Implied consent: an existing business relationship creates temporary permission. A guest who dined with you has given implied consent for roughly two years from the transaction; someone who merely made an inquiry, six months. After that, without express consent, you must stop.
Every message must also identify your business, include your contact details, and carry a working unsubscribe mechanism that you honour promptly. If you use your reservation system's guest emails for marketing, make sure the marketing checkbox is separate from the booking itself: bundling "book a table" with "receive our offers" is exactly the pattern regulators dislike. Our guide to restaurant email marketing covers how to grow a list properly; the short answer is that a smaller list of people who actually opted in outperforms a big scraped one anyway.
Quebec: Law 25 raises the bar
If you operate in Quebec, or hold data about guests in Quebec, Law 25 adds obligations on top of the familiar principles, and it applies to businesses of every size:
- designate a person in charge of the protection of personal information; by default it is the person with the highest authority, in other words the owner, and their title and contact information must be published, typically on your website;
- publish a privacy policy in clear language;
- obtain valid consent for each purpose, and assess privacy impacts before sending personal information outside Quebec;
- keep a register of confidentiality incidents and notify the CAI and affected people when an incident presents a risk of serious injury.
The penalty ceiling is the highest in the country: administrative monetary penalties of up to $10 million or 2% of worldwide turnover, and penal fines of up to $25 million or 4%, per the Commission d'accès à l'information. Nobody is fining a bistro $25 million, but the CAI has made clear that small businesses are expected to comply with the basics. Quebec is also the province where reservation practices themselves are regulated, including the $10 no-show fee cap we detail in our guide to no-shows in Canada.
Breaches: what happens when data leaks
Since 2018, PIPEDA has required organizations to report breaches of security safeguards that create a real risk of significant harm to the Privacy Commissioner, to notify the affected individuals, and to keep records of every breach, reportable or not, for 24 months. Alberta's PIPA has its own mandatory reporting; Quebec's incident register goes further still.
For a restaurant, the realistic scenarios are unglamorous: a phishing email that captures your reservation-platform password, a laptop with an exported guest list left on the train, a former employee who kept access. The defences are equally unglamorous: unique passwords, two-factor authentication where offered, access removed the day someone leaves, and no CSV exports floating around in inboxes.
Your reservation platform is a privacy decision
Here is the part most privacy guides skip: for an independent restaurant, the single biggest data-protection decision is which reservation system you use, because that is where the guest list actually lives.
Three questions to ask any provider:
Where is the data hosted, and who answers for it? Under PIPEDA's accountability principle, transferring data to a processor, including one in another country, does not transfer your responsibility. The Privacy Commissioner's guidelines on cross-border processing expect you to use contractual means to ensure comparable protection, and to be transparent with guests that their information may be stored abroad and be subject to that country's laws. Most large reservation networks are US-owned and US-hosted; that is not forbidden, but it is something your privacy policy should say plainly.
Who owns the guest data, and can you leave with it? The consolidation wave of the last year makes this concrete: OpenTable acquired Montreal's Libro in April 2026, and Amex is folding Tock into Resy. When a platform changes hands, the guest database is part of what is being bought. Before you sign anywhere, confirm in writing that the guest data is yours and exportable in a usable format. Our comparison of reservation software in Canada weighs the options through exactly this lens.
Does the platform market to your guests? Marketplace networks build their own diner accounts and email your guests about other restaurants. That is their business model, not a scandal, but it means your guest's data feeds an audience you do not control.
Let us be honest about our own position here: ViteUneTable is a reservation system, so we are not neutral. What we can state factually is the model: with ViteUneTable, the guest data belongs to the restaurant, there is no marketplace emailing your guests, the free version is unlimited, and there is 0% commission on reservations; paid features come as flat-rate packs (Pack Standard at 29 € per month excluding VAT), priced in euros since the company is European, which Canadian owners should factor in alongside the exchange rate.
What about reform: Bill C-36
Canada's federal framework is due for modernization. The previous attempt, Bill C-27, died when Parliament was prorogued in January 2025. Its successor, Bill C-36, the Protecting Privacy and Consumer Data Act, was tabled on June 15, 2026 and had only completed first reading when Parliament rose for the summer. If passed, it would replace PIPEDA's privacy part with a new law, create a new regulator and sharply increase penalties.
None of that is in force. As of September 2026, PIPEDA still applies, and everything above remains the rulebook. The practical takeaway for a restaurant is that the direction is one-way: obligations will get stricter, so habits built now, minimal collection, real consent, a clean opt-in list, will only become more valuable.
A 30-minute privacy tune-up for your restaurant
- Write down, in one page, what data you collect and why. That page is 80% of a privacy policy.
- Put the policy on your website with a contact for privacy questions (in Quebec, name the person in charge).
- Split the marketing opt-in from the booking flow, and make it an unchecked box.
- Restrict allergy and preference notes to service staff.
- Turn on two-factor authentication on your reservation platform and POS, and remove departed staff the same day.
- Delete what you no longer need, including that ancient exported spreadsheet.
- Ask your reservation provider the three questions above, and keep the answers.
Guests notice care. The same discipline that keeps a loyal regular's preferences at your fingertips, without ever making them feel surveilled, is what the law asks of you anyway.
Frequently asked questions
Does PIPEDA really apply to a small independent restaurant?
Yes. PIPEDA covers personal information handled in commercial activity with no minimum size, revenue or headcount. In Alberta, BC and Quebec, the provincial law applies instead, and none of those has a small-business exemption either.
Can I email past guests about events and offers?
Under CASL, a past dining transaction gives you implied consent for about two years, and every message needs your identification and a working unsubscribe. For a durable list, collect express consent with a separate, unchecked opt-in box; express consent does not expire.
Are allergy notes in my reservation system a legal risk?
They are health-related information, so treat them as sensitive: keep them factual, limit who can view them, and never export them into marketing tools. Handled that way, recording allergies is both lawful and the responsible thing to do for guest safety.
What do I do if my guest list is leaked or my account is hacked?
Assess whether the breach creates a real risk of significant harm. If so, PIPEDA requires reporting it to the Privacy Commissioner and notifying affected guests; Alberta and Quebec have their own mandatory reporting. Keep a record of the incident either way, and rotate credentials immediately.
Is it legal to use a US-based reservation platform?
Yes. Canadian law does not prohibit storing personal information abroad, but you remain accountable for it, you should ensure comparable protection contractually, and your privacy policy should tell guests their data may be processed in another country and be subject to its laws.
Does Quebec's Law 25 affect me if my restaurant is in Ontario?
It can, if you handle personal information about people in Quebec, for example guests booking from Montreal. The safest posture for a multi-province operation is to meet the strictest applicable standard, which today is Law 25.
Also worth reading
Restaurant reservation systems in Singapore: the honest 2026 comparison
Chope has been absorbed into Grab, Quandoo is shutting down, and almost every system sells by quote. Here is the honest Singapore comparison, fees and fine print included.
No-show fees for NZ restaurants: what you can legally charge
A no-show fee is legal in New Zealand, but only if it is disclosed at booking and reflects your real loss. Here is what Kiwi restaurants actually charge, and how to write a policy that holds up.
Restaurant no-show deposits in Singapore: what is fair, what is legal
No Singapore statute caps restaurant deposits or cancellation fees: it all comes down to what you disclosed at booking. Here is what local venues charge, what the law actually says, and how to write a policy that protects your margin without ending up on Mothership.