Guest data & GDPR: keeping your reservation system compliant
Name, phone number, allergies: every reservation means processing personal data. This guide explains the essentials โ understandable, without legalese, with a checklist for choosing a system.
Start your free 30-day trial View pricingThe GDPR does not only apply from corporation size upwards: even the reservation book with names and mobile numbers is data processing. No reason to panic โ for reservations the legal situation is pleasantly clear once a few ground rules are in place. And it demands nothing impossible: if you know which data you collect and what for, the biggest part is already done.
This guide answers the most common questions: Which data is collected? On what basis may you process it? How long may you keep it? And how do you recognise whether your reservation system does its part properly? At the end you will find a checklist with five points you can verify with any provider in a few minutes.
Which data is collected with reservations?
A table reservation regularly involves personal data: name, e-mail address or phone number, date, time and party size โ often complemented by occasion, special requests or notes on allergies. Internal notes and guest profiles with visit history count as well. With events, participant lists and payment information may be added depending on the offer.
The principle of data minimisation applies: collect what you need for the reservation โ and mark optional fields as optional. A mandatory phone number plus mandatory address plus date of birth for a table for two would be hard to justify. A pleasant side effect: shorter forms get completed more often โ data minimisation and conversion are, for once, allies here.
Legal basis: contract performance under Art. 6(1)(b) GDPR
You do not need separate consent to process reservation data: the legal basis is contract performance (Art. 6(1)(b) GDPR) โ the data is required to carry out the reservation. This also covers confirmation and reminder messages for the specific reservation.
The line runs along the purpose: everything that serves carrying out the reservation is covered. Everything beyond that โ advertising, for instance โ needs its own legal basis. An example: the reminder for tomorrow's table is contract performance, the invitation to next week's themed evening is advertising. More on that in a moment.
Retention and deletion: do not keep data forever
Reservation data may be stored as long as it is required for the purpose โ after that it is deleted or anonymised. A deletion concept defines which data automatically drops off after which period, instead of relying on "tidying up at some point". How long the periods are is your own documented decision โ what matters is that they exist and are respected.
Think of special cases too: exports made for a system switch are deleted after the import, and inactive guest profiles should be thinned out regularly. What a clean data move looks like is shown, by way of example, in our switching checklist.
Marketing only with its own legal basis
A reservation is not a licence for advertising: newsletters and marketing e-mails need their own legal basis โ as a rule the guest's consent, properly documented and ideally confirmed via double opt-in. That applies regardless of how the address entered the system โ even regulars never gave blanket consent to advertising.
In practice that means: a separate, unticked checkbox in the booking process, a confirmation link by e-mail and an unsubscribe option in every message. Reservation confirmations and reminders remain unaffected โ they belong to contract performance.
DPA and responsibility explained simply
If you use a reservation system, its provider processes guest data on your behalf โ which requires a data processing agreement (DPA, German: AVV). You as the business remain the controller of the data; the system provider is your processor and may only use the data on your instructions. Among other things, the DPA governs security measures, sub-processors and what happens to the data when the contract ends.
Be careful with platforms that also use guest data for their own purposes โ say, for their own marketing to "their" users. That quickly creates joint controllership with additional obligations. With a pure system provider that processes data exclusively for you, things stay simple.
Checklist: how to recognise a GDPR-clean reservation system
- Server location Germany or EU โ clearly named, not "somewhere in the cloud"
- DPA (data processing agreement) is actively offered
- Data export possible at any time โ your guest data stays yours
- Deletion concept in place: old data is deleted instead of stored forever
- Encrypted transmission (TLS/HTTPS) on all pages and forms
GDPR as a locational advantage
Data protection is also a selling point: "Your data is stored on servers in Germany" answers a question more and more guests are asking. VidiReserve is built exactly that way โ servers in Germany, DPA, double opt-in for marketing and data export included.
Here too: this guide is no substitute for legal advice. For specific questions about your business, a data protection officer or a specialised law firm can help. The basics from this guide are enough, though, to ask the right questions โ of your system and of every provider.
Guest data in good hands
Try VidiReserve free for 30 days โ German servers, DPA and data export included. No credit card needed.
Start your free 30-day trial View pricing