Restaurant customer database and UK GDPR: the practical guide 2026
Data protection has a bad reputation among restaurateurs: fines, solicitors, forms nobody understands. The reality is far simpler. UK GDPR and the Data Protection Act 2018 do not forbid you from keeping a customer database. They ask three common-sense things of you: collect only what you actually need, do not keep it forever, and respect a few basic rights your guests have over their own information.
A restaurant that takes bookings inevitably handles personal data: a name, a phone number, often an email address, sometimes an allergy. This guide covers what you can collect and keep, what the ICO actually expects from a small business, whether you owe the data protection fee, and one question too few restaurateurs ask: who really controls your guest database when it lives on someone else's platform?
In short:
- you are allowed to keep a customer database; taking a booking rests on the "contract" lawful basis, no consent box needed;
- UK GDPR sets no fixed retention periods, but you must define and justify your own, then actually delete;
- an allergy note is health data, a special category with extra protection: let the guest volunteer it and never use it for marketing;
- most restaurants must pay the ICO data protection fee, £52 or £78 a year for nearly all independents;
- you can email your existing customers about your own similar services under the PECR soft opt-in, with an unsubscribe link in every message;
- if your guest database lives on a booking platform, check whether you can export it fully and who is allowed to market to it.
What guest data can you collect for a booking?
The founding principle of UK GDPR is data minimisation: collect what is necessary for the purpose, nothing more. For a table booking, the list is short and nobody will challenge it:
- name: to greet the guest and find the booking;
- phone number: to reach each other if something changes;
- email address: for the booking confirmation and any reminder;
- date, time, party size: that is the booking itself;
- special requests: high chair, terrace, birthday.
By contrast, demanding a date of birth, a postal address or an occupation to book a table is not necessary for the service, and that is exactly the kind of excessive collection the minimisation principle rules out.
A well-designed booking system applies minimisation by construction: the form asks only for the essentials, the confirmation goes out automatically, and your guest database builds itself cleanly service after service. That is the approach of ViteUneTable, a reservation system where your guest data stays yours: every booking enriches your database, not an intermediary's.
Allergy notes are health data, treat them accordingly
Allergies deserve their own paragraph. UK GDPR gives extra protection to special category data, which includes "data concerning health", defined broadly by the ICO. A food allergy disclosed with a booking reveals something about the guest's health, so it falls in that category.
No need to panic, the practice stays simple if you follow three rules:
- The guest volunteers it, you never demand it by default. A free-text "special requests" field where the guest writes what they wish is very different from a mandatory "list your medical conditions" box. A guest who mentions their allergy so the kitchen can serve them safely is asking you to use it for exactly that.
- The note serves the meal, not your marketing. Use it in the kitchen on the day. Do not build a "gluten-free guests" promotional segment: using health data that way requires explicit consent, and a restaurant database simply does not need it.
- Do not store it forever. An allergy note attached to a long-past booking has no reason to sit in your records for years. Purge those fields or let guests restate them at each booking.
A useful reminder that has nothing to do with data protection: telling customers about the 14 allergens in your dishes remains mandatory under UK food law, however you manage your bookings.
What is your lawful basis for holding guest data?
UK GDPR requires every use of personal data to rest on a lawful basis. That sounds scarier than it is: for a restaurant, two situations cover almost everything.
The booking itself: contract. When a guest books a table, you need their name and contact details to deliver the service they asked for. The ICO's guidance on the contract lawful basis covers precisely this case: processing that is necessary to deliver a contractual service, or to do something the person asked for before a contract. No tick box, no consent form: the booking is the contract.
Marketing and staying in touch: legitimate interests or consent. Contacting past guests (announcing your new menu, inviting regulars back) is a separate purpose with its own basis, typically your legitimate interest in maintaining your clientele, or consent. In practice the question is mostly settled by the specific email marketing rules in PECR, covered in the next section.
Special category data: explicit consent. Any use of health data beyond serving the meal needs explicit consent. When in doubt, abstain: your customer database does not need sensitive data to be valuable.
Emailing your guests: how the PECR soft opt-in works
Many restaurateurs stopped emailing their customers altogether, convinced it became illegal. It did not. Alongside UK GDPR, the Privacy and Electronic Communications Regulations (PECR) govern marketing emails, and the ICO's electronic mail marketing guidance spells out an exception built for businesses like yours, known as the soft opt-in. You may email an individual without specific consent when all of the following hold:
- they are an existing customer: they bought, or negotiated to buy, from you;
- your message concerns your own similar products or services: your menus, your events, your offers, not a partner's;
- you gave them a clear chance to opt out when you collected their details, and again in every message you send.
A guest who has dined with you can therefore receive your seasonal menu or an invitation to your wine evening, provided each email carries a working unsubscribe link. Two boundaries to respect: the soft opt-in does not cover prospects who never became customers (someone who dropped a business card in a bowl needs real consent), and it never covers bought-in lists.
Used properly, this rule turns your booking history into a revenue lever: reactivating lapsed regulars, filling quiet weeks, promoting events, all with the guest list you built yourself.
How long should you keep guest data?
Here is the honest answer most guides dodge: UK GDPR sets no fixed retention periods. The ICO's guidance on the storage limitation principle says you must not keep personal data longer than you need it, you must be able to justify how long that is, and you should set standard retention periods in a policy, then review and actually erase.
For a restaurant, a defensible and practical policy looks like this:
| Type of data | Suggested retention | Why |
|---|---|---|
| Guest contact details and booking history | While the guest remains active, then 2 to 3 years after the last visit or interaction | Long enough to win back a lapsed regular, short enough to justify |
| Allergy and dietary notes | The booking they relate to | Health data, keep the minimum |
| Marketing consent and opt-out records | As long as you email the person, plus proof of any opt-out | You must honour and evidence objections |
| Accounting and billing records | 6 years from the end of the financial year | Companies must keep records 6 years for HMRC |
Two habits make the policy real rather than theoretical: the clock restarts at every visit, so a regular who returns monthly never drops out of your database; and once a year, purge contacts with no interaction for your chosen period. Accounting records are archived separately and never used for marketing.
Do you need to register with the ICO and pay the fee?
Under the Data Protection (Charges and Information) Regulations 2018, organisations that process personal data must pay an annual data protection fee to the ICO unless exempt. The ICO's guide to the data protection fee sets three tiers:
| Tier | Who | Annual fee |
|---|---|---|
| Tier 1, micro organisations | Turnover up to £632,000 or no more than 10 staff | £52 |
| Tier 2, small and medium | Turnover up to £36 million or no more than 250 staff | £78 |
| Tier 3, large | Everyone else | £3,763 |
Almost every independent restaurant lands in tier 1 or 2, and paying by direct debit knocks £5 off automatically. There are exemptions for organisations that only process data for core purposes such as staff administration, accounts and their own marketing, but in practice many restaurants fall outside them, CCTV being the classic reason. Do not guess: the ICO's registration self-assessment takes five minutes and gives you a definitive answer. Skipping a fee you owe can lead to a penalty on top of the fee itself, an expensive way to save £52.
Subject access requests: what to do when a guest asks
Your guests hold rights over their data: to know what you hold (access), to correct it (rectification), to have it deleted (erasure), and to object to marketing. When someone asks what you hold about them, that is a subject access request, and the ICO's guidance is clear on the deadline: you must respond without undue delay and at the latest within one month of receiving the request, free of charge in almost all cases.
In the real life of a restaurant these requests are rare and take minutes, if your tool cooperates:
- "Delete me from your records": you delete the guest profile; only invoices stay archived, accounting law obliges;
- "What do you hold about me?": you open the profile and send its contents, contact details and booking history;
- "Stop emailing me": the unsubscribe link should already have handled it without anyone writing to you.
The deciding factor is the tool. If your bookings live in a paper diary, finding and erasing every trace of one guest across years of pages is archaeology, and UK GDPR does apply to organised paper filing systems. It is one more argument for switching to a digital reservation book: one centralised guest profile you can open, correct or delete in a click.
Who controls your guest database when it lives on a platform?
Here is the question this kind of guide usually forgets. Every obligation above assumes you can actually consult, export, purge and delete your guest data. Whether you can depends entirely on where it lives.
With a booking system acting as your processor, the provider hosts and processes guest data on your instructions, under a data processing agreement. The database remains yours to export and use.
With a marketplace, the dynamic differs by design: the diner who books through the platform creates an account there and becomes the platform's user too, and the platform markets to its diner base, including recommending other restaurants. That is not a scandal, it is the business model of a marketplace: it sells its audience. But it means the regular you won can receive suggestions for competing tables, and if you ever leave, what you can take with you varies widely. We break down what guest data you can and cannot export from one major platform in our alternative to Quandoo comparison.

Three questions to put to any provider, whatever its size or reputation:
- Can I export my complete guest database (names, contact details, history) in a reusable format, at any time, at no charge?
- Who may use this data for marketing: only me, or the platform for its own ends?
- What happens to the data if I cancel?
At ViteUneTable the answer is simple and deliberate: the guest database belongs to the restaurant, the free version charges 0% commission with no time limit, and your guests' data is never used to promote other establishments. ViteUneTable is built in France and designed under GDPR from day one, the same regulation UK GDPR is derived from, so data protection is the default, not an add-on. Let's be honest about the rest: no software makes you "GDPR compliant" by itself. Compliance is your responsibility as the controller; a good tool just makes it far easier to keep up day to day.
Your UK GDPR afternoon checklist
To finish, the minimum checklist of a restaurant calmly in order:
- Take inventory: where does guest data live today? Booking system, paper diary, spreadsheet, inbox, till, CCTV?
- Kill the dangerous duplicates: spreadsheet exports sleeping on three laptops are your biggest breach risk.
- Check the ICO fee: run the self-assessment on ico.org.uk, pay your tier if due, diarise the renewal.
- Write your retention policy: one page stating what you keep, why and for how long, then schedule the yearly purge.
- Add a privacy notice to your booking form and website: who processes the data, why, for how long, and how to exercise rights.
- Question your provider: data processing agreement, full export possible, no marketing of your guests for anyone else's benefit.
Nothing on this list requires a full-time solicitor. And if your current booking tool makes any of these points impossible, the problem is probably the tool, not the law.
Frequently asked questions
Does UK GDPR ban restaurants from keeping a customer database?
No, quite the opposite: UK GDPR regulates customer databases, it does not prohibit them. Taking a booking rests on the contract lawful basis and needs no consent box. Your main duties are collecting only what is necessary, limiting how long you keep it, and honouring guests' rights of access, rectification and erasure.
How long can a UK restaurant keep a guest's contact details?
UK GDPR sets no fixed period: the ICO's storage limitation principle requires you to define and justify your own retention and then actually delete. A defensible policy for a restaurant is to keep guest details while the person remains a customer, then 2 to 3 years after their last visit, with each new booking restarting the clock. Accounting records follow their own rule: 6 years for HMRC.
Can I email my customers without their consent in the UK?
Yes, under the PECR soft opt-in. You may email existing customers about your own similar products and services, provided you offered a chance to opt out when you collected their details and include a simple unsubscribe route in every message. People who never actually became customers, and any bought-in list, still require specific consent.
Is a guest's allergy note special category data?
Yes. An allergy disclosed by a guest reveals information about their health, which UK GDPR treats as special category data with extra protection. In practice: let the guest volunteer it, use it only to serve their meal safely, do not keep it beyond the booking it relates to, and never use it for marketing segmentation.
How much is the ICO data protection fee for a restaurant?
Most independent restaurants pay tier 1 (£52 a year, for organisations with turnover up to £632,000 or no more than 10 staff) or tier 2 (£78, up to £36 million or 250 staff), with a £5 discount for paying by direct debit. Some businesses are exempt, but CCTV commonly makes the fee payable, so run the ICO's online self-assessment rather than assume.
Does a paper reservation diary fall under UK GDPR?
Yes, once the paper records are organised so you can find a specific person's information, they form a filing system within the law's scope. Paper mostly makes your obligations harder to meet: finding and erasing every trace of one guest across old diaries is impractical, whereas a digital guest profile can be corrected or deleted in seconds.
Also worth reading
Walk-ins vs reservations: finding the right mix for your restaurant
All reservations, walk-in only, or a deliberate mix of both? Each model wins in a different restaurant. Here is how to choose yours, how many tables to hold back, and why overbooking is a trap for restaurants even though it works for airlines.
VAT on restaurant food in the UK: rates, takeaway rules and worked examples
Eat-in at 20%, cold takeaway at 0%, and a dozen traps in between. A plain-English guide to VAT for UK restaurants, with worked examples in pounds.
Valentine's Day restaurant reservations: the playbook for your biggest nights of the year
February 14 does not get a do-over: demand lands on a single night. Here is the complete method for peak dates, from the set menu to the D-30 run sheet, including protection against the year's worst no-shows.