Restaurant customer data privacy in the US: what actually applies to you in 2026
Every restaurant that takes reservations handles personal data: a name, a phone number, usually an email, sometimes a note about a peanut allergy. In Europe, one big regulation (the GDPR) covers all of it. In the United States, there is no federal equivalent, and the honest answer to "which privacy law applies to my restaurant?" is: it depends on your state, your size, and what you do with the data.
That nuance gets lost in most articles on the subject, which either wave the CCPA around as if it applied to every taco truck in America, or conclude that small businesses can ignore privacy entirely. Both are wrong. This guide walks through what actually applies to a US restaurant: the California law and its thresholds, the growing list of state laws, the federal rules that do reach you (CAN-SPAM for email, the TCPA for texting), breach notification duties that exist in all 50 states, and the practical hygiene that keeps you out of trouble regardless of any threshold.
The short version:
- there is no comprehensive federal privacy law; the FTC polices unfair and deceptive practices as a baseline;
- the CCPA has size thresholds ($25 million revenue, or data on 100,000+ Californians) that most independent restaurants do not meet;
- other states (Virginia, Colorado, Texas and more) have their own laws, each with its own thresholds and carve-outs;
- CAN-SPAM applies to every marketing email you send, whatever your size, with penalties up to $53,088 per email;
- texting guests marketing messages without written consent is a TCPA lawsuit magnet: $500 to $1,500 per text;
- all 50 states require you to notify people if their personal information is breached;
- collecting less, securing what you keep, and honoring unsubscribes is cheap insurance and good business.
Is there a federal privacy law for restaurants?
No. Unlike the EU's GDPR, the United States has no single comprehensive privacy law covering ordinary consumer data. What exists instead is a patchwork: sector-specific federal laws (health records, financial data, children's data online), channel-specific federal laws (email, phone, fax), and a growing set of state privacy laws.
The closest thing to a federal baseline is Section 5 of the FTC Act, which bars unfair and deceptive business practices. The FTC brings enforcement actions against companies that break the privacy promises they make to consumers or fail to maintain reasonable security for sensitive information. The practical lesson for a restaurant is simple: whatever your privacy policy says, do it. Promising "we never share your information" and then handing your guest list to a marketing partner is exactly the kind of deceptive practice Section 5 covers, at any business size.
The tool holding your guest data matters here too. A reservation system that collects only what a booking needs, sends the confirmation automatically and keeps the guest list yours makes most of this guide easier to follow. That is the approach of ViteUneTable, a reservation system where your guest data stays yours: the free plan takes unlimited bookings with 0% commission, and your guest list is never used to promote other restaurants.
Does the CCPA apply to your restaurant?
The California Consumer Privacy Act (CCPA, expanded by the CPRA) is the law everyone has heard of, so let's start with the question that matters: does it apply to you?
According to the California Attorney General, the CCPA applies to for-profit businesses doing business in California that meet any one of these criteria:
| Threshold | What it means for a restaurant |
|---|---|
| Gross annual revenue over $25 million | A large group or chain, not an independent |
| Buy, sell, or share personal information of 100,000+ California residents or households per year | A very large marketing database, not a reservation book |
| Derive 50%+ of annual revenue from selling Californians' personal information | You would be a data broker, not a restaurant |
Be honest with yourself, but the arithmetic is clear: a typical independent restaurant, even a busy one in Los Angeles, sits below every one of these thresholds. If that is you, the CCPA's formal obligations (privacy notices, "Do Not Sell or Share" links, consumer request workflows) do not legally bind you.
Two caveats before you close the tab:
- Thresholds change and groups add up. Revenue is counted at the business level, so a restaurant group with multiple locations can cross the line as a whole even if each venue seems small.
- The rights are becoming customer expectations. California residents have the right to know what data a covered business holds, to delete it, to correct it, and to opt out of its sale or sharing. Even where the law does not compel you, being able to answer "what do you have on me?" and "delete my info" gracefully is increasingly what guests expect from any business they trust.
The growing patchwork of state privacy laws
California opened the door, and a steady stream of states has followed with comprehensive privacy laws of their own. Each has different thresholds, and the details matter. Three examples worth knowing:
Virginia
The Virginia Consumer Data Protection Act applies to businesses that control or process personal data of at least 100,000 Virginia consumers in a year, or at least 25,000 consumers while deriving over 50% of gross revenue from selling personal data (Va. Code § 59.1-576). Same conclusion as California: an independent restaurant is almost certainly out of scope.
Colorado
The Colorado Privacy Act applies to entities that process personal data of more than 100,000 individuals per year, or that derive revenue (or discounts) from selling personal data of 25,000+ individuals, per the Colorado Attorney General. Notably, Colorado's law also covers nonprofits, but the volume thresholds still put small restaurants outside it.
Texas
Texas took a different approach. The Texas Data Privacy and Security Act has no numeric threshold: instead, it exempts small businesses as defined by the US Small Business Administration, with one exception spelled out by the Texas Attorney General: even an exempt small business may not sell sensitive data (health information, precise geolocation, data on children under 13) without the consumer's consent. Selling a guest list that includes allergy notes would cross that line. Violations after the cure period run up to $7,500 each.
The takeaway: most independent restaurants are exempt from most state privacy laws today, but "exempt" is not the same as "unregulated" (Texas proves it), the list of states keeps growing, and the trend only points one way. Building clean habits now costs little; retrofitting them under enforcement pressure costs a lot.
CAN-SPAM: the email law that applies to everyone
Here is where the size exemptions end. The CAN-SPAM Act covers every commercial email, from a national chain's blast to the twelve-table bistro announcing its new fall menu. There is no small-business carve-out, and the FTC's compliance guide puts the penalty at up to $53,088 per non-compliant email.
The good news: unlike Europe's consent-first model, CAN-SPAM does not require opt-in consent before you email your guests. You may email people whose addresses you collected through reservations. What the law does require in every marketing email:
- Truthful header and subject line: your "From" name and subject must not mislead;
- Identification as an ad: disclose clearly that the message is promotional;
- Your physical postal address: your restaurant's street address works fine;
- A clear opt-out mechanism: a working unsubscribe link, no login required, no fee;
- Honor opt-outs within 10 business days, and keep the mechanism working for at least 30 days after sending.
One nuance restaurateurs get wrong: transactional messages are exempt from most of these rules. A reservation confirmation or a reminder about tomorrow's booking is a transactional message, not an ad, so it needs no unsubscribe link (it must still have truthful routing information). But the moment the "confirmation" leads with a promotion for your wine dinner, its primary purpose becomes commercial and the full rules apply. Keep confirmations clean and put marketing in clearly labeled marketing emails; our guide to booking confirmation and reminder emails covers what belongs in each.
Done right, email is still the best-value channel a restaurant owns: your list, your guests, no platform in between. The mechanics of turning reservation data into repeat visits are covered in our guide to building restaurant customer loyalty.
Texting guests: the TCPA is not a technicality
If email regulation is forgiving, text messaging is the opposite. The Telephone Consumer Protection Act (TCPA) and the FCC's implementing rules require prior express written consent before sending marketing texts or autodialed/prerecorded marketing calls (47 CFR § 64.1200). A phone number typed into a reservation form so you can call about the table is not consent to receive promotions by text.
What makes the TCPA uniquely dangerous for a small business is its private right of action: any recipient can sue, without a regulator involved, for $500 per violating text, tripled to $1,500 for willful violations. Class actions over marketing texts are an industry of their own. A 300-guest promotional text campaign sent without proper consent is a theoretical exposure of $150,000 or more.
If you do run an SMS program, the FCC's rules also require you to honor revocations sent by any reasonable means (a guest replying "STOP", "unsubscribe" or plain "please stop texting me" all count) within at most ten business days, and you may not require any special exclusive procedure to opt out.
The safe posture for most independents: use texting for what the guest actually asked for (their reservation), get separate written consent with clear terms before any promotional texting, and keep marketing on email where the rules are manageable. For the record, ViteUneTable's reminders run on email, not SMS.
Data breaches: the duty that exists in all 50 states
There may be no federal privacy law, but breach notification is one area with wall-to-wall coverage: as the FTC's data breach response guide notes, all states, the District of Columbia, Puerto Rico and the Virgin Islands have laws requiring notification of security breaches involving personal information.
For a restaurant, the realistic breach scenarios are unglamorous: a laptop with an exported guest list stolen from the office, a compromised email account, a POS or reservation vendor incident, a spreadsheet emailed to the wrong person. If personal information is exposed, you will need to determine which state laws apply (they follow the residence of the affected people, not your location), notify affected individuals, and in some states notify the attorney general.
Two consequences worth internalizing before anything ever goes wrong:
- The data you never collected cannot leak. Every field you do not ask for, every stale export you delete, shrinks your breach surface and your notification duty.
- Your vendors are part of your risk. Ask your reservation and POS providers where data is stored, who can access it, and how they would notify you of an incident. You remain the one your guests trusted with their information.
Good data hygiene: what to do regardless of thresholds
Legal thresholds tell you what you can be fined for. They say nothing about what your guests deserve, and guest trust is the actual asset here. The FTC's own small-business guidance, Protecting Personal Information, boils sound practice down to five principles: take stock, scale down, lock it, pitch it, plan ahead. Translated into restaurant terms:

- Take stock. Where does guest data live today? Reservation system, POS, email inbox, paper book, that Excel export from last year? You cannot protect what you have not located.
- Scale down. A reservation needs a name, a phone number, an email, date, time and party size. It does not need a birth date, a home address or an occupation. Collect the minimum; it is also faster for the guest.
- Lock it. Unique passwords, two-factor authentication where offered, access limited to staff who need it. The stray unprotected spreadsheet on three laptops is a bigger real-world risk than any hacker in a hoodie.
- Pitch it. Delete stale exports, shred old paper reservation sheets, purge marketing contacts who have not interacted in years. A digital reservation book makes this manageable: one central guest file you can search, correct and delete, instead of years of paper you can neither find nor erase.
- Plan ahead. Know today who you would call and what you would do if a laptop disappeared. The FTC's breach guide linked above is a fine starting template.
Allergy notes deserve extra care, even without a law telling you so
US privacy laws mostly will not force you to treat a guest's "severe shellfish allergy" note differently from their phone number. Ethically, you should anyway: it is health information a guest shared so you could serve them safely, not a marketing attribute. Use it in the kitchen for that visit, never for advertising segments, and do not let allergy notes pile up in exports. Texas already treats health data as "sensitive data" that even exempt small businesses may not sell without consent, and other states define it similarly; treating it with care now is both decent and future-proof. (Your duty to inform guests about allergens in your dishes is a separate, very real topic: see our guide to US restaurant allergen rules.)
Who actually owns your guest list?
One last question that no threshold analysis answers: when your reservations live on a third-party platform, who gets to use that guest data?
With marketplace platforms, the diner who books often becomes the platform's user too, and the platform's marketing can recommend other restaurants to them, including your competitors. That is not a scandal, it is the marketplace business model: the platform sells its audience. But it means the "customer file" you think you are building may be working for someone else.
Whoever your provider is, ask three questions: Can I export my complete guest list, free, anytime, in a usable format? Who may use this data for marketing, me alone or also the platform? What happens to the data if I cancel?
At ViteUneTable, the answers are: yes, you alone, and it stays your data. The service is built in France and runs under the GDPR, the world's strictest privacy regime, so European-grade rules (data minimization, deletion rights, no repurposing of your guest list) apply by design, not because a US statute forced them. Let's be honest about the limits: no software makes you "compliant", and following CAN-SPAM or the TCPA in your own campaigns remains your responsibility. A good tool just makes the clean way the easy way.
Frequently asked questions
Does the CCPA apply to a small independent restaurant?
Almost never. The CCPA applies to for-profit businesses that meet at least one threshold: over $25 million in gross annual revenue, buying/selling/sharing personal information of 100,000+ California residents or households a year, or earning 50%+ of revenue from selling personal data. A typical independent restaurant meets none of them. Restaurant groups should count revenue and data across all locations, though.
Can I email my guests marketing offers without their consent in the US?
Yes, under CAN-SPAM you do not need prior opt-in consent to email people, including guests whose addresses came from reservations. Every marketing email must, however, use truthful headers, identify itself as an ad, include your physical postal address and a working unsubscribe link, and you must honor opt-outs within 10 business days. Penalties reach $53,088 per non-compliant email.
Can I text my guests promotions?
Not without prior express written consent. The TCPA and FCC rules require signed, informed written consent before marketing texts, and any recipient can sue for $500 to $1,500 per text. A phone number collected for a reservation is not consent to receive promotions. If you text at all, honor "STOP" replies immediately and keep marketing on email unless you have a proper consent process.
What do I have to do if my guest data is breached?
Every US state (plus DC, Puerto Rico and the Virgin Islands) has a breach notification law. If personal information is exposed (a stolen laptop with a guest list export, a hacked account, a vendor incident), you generally must notify the affected individuals, and in some states the state attorney general. Which law applies depends on where the affected guests live, not where your restaurant is.
Are guest allergy notes legally sensitive data?
It depends on the state, but treat them as sensitive regardless. Texas, for example, defines health information as "sensitive data" and forbids even exempt small businesses from selling it without consent. Best practice: let guests volunteer allergy notes, use them only to serve the meal safely, never build marketing segments from them, and do not keep them longer than needed.
Do I need a privacy policy on my restaurant website?
If none of the state laws reach you, a policy is often not strictly mandatory, but you should have a short honest one anyway: it is what guests and partners expect, and some laws (like California's) can require one from covered businesses. The one hard rule applies to everyone: whatever your policy promises, keep the promise. Breaking your own stated privacy practices is a deceptive practice the FTC can act on under Section 5 of the FTC Act, at any business size.
Also worth reading
Walk-ins vs reservations: finding the right mix for your restaurant
All reservations, walk-in only, or a deliberate mix of both? Each model wins in a different restaurant. Here is how to choose yours, how many tables to hold back, and why overbooking is a trap for restaurants even though it works for airlines.
VAT on restaurant food in the UK: rates, takeaway rules and worked examples
Eat-in at 20%, cold takeaway at 0%, and a dozen traps in between. A plain-English guide to VAT for UK restaurants, with worked examples in pounds.
Valentine's Day restaurant reservations: the playbook for your biggest nights of the year
February 14 does not get a do-over: demand lands on a single night. Here is the complete method for peak dates, from the set menu to the D-30 run sheet, including protection against the year's worst no-shows.