Restaurant marketing

Customer data and privacy law: what Canadian restaurants need to know

By Pete RossAugust 3, 20269 min read
A restaurant host stand with a reservation book and warm lighting, representing guest data and privacy

Your reservation system holds names, phone numbers, emails, allergy notes, and visit histories. Your card-on-file setup stores Stripe tokens linked to guest profiles. Your email list has 600 addresses you collected from comment cards and wifi logins over the past three years.

All of that is personal information under Canadian law. And the rules around how you collect, store, and eventually delete it are tighter than most operators realize.

The good news: compliance for a 30-seat independent isn't as complicated as the consulting firms selling $5,000 audits want you to believe. But ignoring it isn't an option either.

Which law actually applies to your restaurant?

Canada's privacy framework is layered, and the answer depends on where you operate.

PIPEDA (the Personal Information Protection and Electronic Documents Act) is the federal baseline. It covers every private-sector business engaged in commercial activity, with no size exemption. A single-location bistro collecting reservation emails is subject to the same law as a national chain.

Three provinces have their own private-sector privacy laws that replace PIPEDA for in-province activity:

Province Law Key difference from PIPEDA
Quebec Law 25 (fully in force since Sep 2024) Mandatory privacy impact assessments, data portability rights, administrative fines up to $10M or 2% of worldwide turnover
British Columbia PIPA Covers employee information too; provincial commissioner can issue binding orders
Alberta PIPA Same scope as BC; binding orders from provincial commissioner

If you're in Ontario, Manitoba, Saskatchewan, or the Atlantic provinces, PIPEDA applies directly.

For cross-provincial data flows (say, a POS system with servers in another province), PIPEDA still governs the cross-border piece. In practice, if your restaurant is in one location and your data stays in Canada, the provincial law (where applicable) is the one that shapes your day-to-day obligations.

Better guest experience. Bigger nights. $299. Once.

What data does your restaurant actually hold?

Most operators underestimate how much personal information they accumulate. Here's what counts:

Data type Examples Where it lives
Reservation data Name, phone, email, party size, date/time Reservation software, paper book
Guest profiles Visit history, preferences, allergy notes, "birthday March 12" tags, VIP flags CRM, reservation system
Card-on-file Last 4 digits, card brand, Stripe customer/payment method IDs Reservation system via Stripe
Marketing lists Email addresses, phone numbers, communication preferences Mailchimp, SMS platform
Employee records SIN, bank info, schedules, performance notes Payroll system, HR files
Wifi logins Email or phone collected for guest wifi access Router/captive portal system
Security footage Camera recordings of identifiable people NVR, cloud storage

Each row is personal information under PIPEDA. Allergy and dietary notes are considered sensitive personal information under Quebec's Law 25, which triggers heightened consent and security requirements.

A guest's name linked to their phone number and shellfish allergy? Personal information. The last four digits of their Visa tied to their guest profile? Also personal information.

Five obligations that actually matter for a restaurant

Privacy law has dozens of provisions, but for an independent restaurant, five are the ones you'll interact with.

1. Designate someone responsible

Under PIPEDA, your business must have a designated privacy contact. In a restaurant, that's almost always the owner. You don't need to hire a privacy officer or create a new role. You need to know where the data is, who has access, and what to do if something goes wrong.

Quebec's Law 25 makes this explicit: the person with the highest authority in the organization is the default privacy officer. You can delegate to a manager, but the buck still stops with you. Publish the contact on your website.

2. Only collect what you need

The principle of data minimization runs through every Canadian privacy law. Collect the information necessary for the stated purpose. Nothing more.

For a reservation: name, phone, email, party size, date, time. That's it. You don't need a mailing address. You don't need their birthday unless they volunteered it.

For card-on-file: you need enough to charge a no-show fee if your policy requires it. Stripe handles the tokenization, so you store IDs and last-4, never the full card number (that's PCI DSS, separate from privacy law but equally non-negotiable).

For wifi: if your captive portal collects an email address, that email is personal information. Using it for marketing without separate consent violates both PIPEDA and CASL (more on that below).

Consent under Canadian privacy law must be meaningful: clear, specific, and freely given. Pre-checked boxes don't count.

Reservations fall under the necessity exception. You're collecting the name and phone number because you need it to confirm and manage the booking. No checkbox required.

But that doesn't extend to marketing. "By booking, you agree to receive our promotions" is not valid consent because it's neither distinct nor free. The guest isn't choosing to receive promotions. They're trying to book a table.

Card-on-file requires clear disclosure. The guest needs to understand why you're saving their card, what you might charge (no-show fee amount), and how long you'll keep it. A plain-language message at booking time covers this. No legal boilerplate needed.

Email/SMS marketing requires separate, explicit opt-in consent under CASL. One important detail: CASL recognizes implied consent through an existing business relationship. If a guest dined at your restaurant, you have implied consent to send them marketing emails for two years from the last purchase. Each new visit resets that clock. But you still need express opt-in for anyone who hasn't dined with you, and you need separate consent for each channel (email consent doesn't cover SMS).

4. Delete data when you're done with it

This is the rule most restaurants ignore. When the purpose for which you collected data is fulfilled, you must destroy it securely.

A guest booked once three years ago, never returned, never opted into your mailing list. Why do you still have their phone number, email, and allergy notes sitting in your reservation system?

Set a retention schedule. Common practice for restaurants:

Data type Reasonable retention period
Reservation records 2-3 years (supports guest history, CASL implied consent window)
Guest profiles (active) As long as the guest relationship is active
Guest profiles (inactive) Delete after 2 years of no activity
Card-on-file data Clear after the reservation is complete and any no-show window has passed
Marketing consent records Keep as long as you're sending messages (CASL requires proof of consent)
Employee records Follow provincial employment standards (varies by province)
Security footage 30-90 days unless needed for an investigation

Quebec's Law 25 gives guests the right to request deletion and, as of 2024, data portability (you have 30 days to provide their data in a usable format).

5. Report breaches

Under PIPEDA, you must report any breach that creates a "real risk of significant harm" to the Office of the Privacy Commissioner as soon as feasible. You must also notify the affected individuals directly and maintain a breach log for 24 months covering every breach, whether or not it met the reporting threshold.

What counts as a breach in a restaurant? A laptop stolen from the back office that had a reservation spreadsheet with names, phones, and card data. An employee forwarding the guest email list to a personal account. A booking confirmation sent to the wrong email address.

In Quebec, Law 25 requires parallel notification to the Commission d'accès à l'information (CAI), with its own forms and deadlines.

Failing to report, notify, or keep breach records is a criminal offence under PIPEDA, with penalties up to CA$100,000 per violation.

The penalty picture is changing

PIPEDA's current maximum is $100,000 per violation for failing to report breaches or obstructing investigations. The OPC doesn't issue fines directly. It investigates, publishes findings, and refers serious cases to the Attorney General.

Quebec is a different story. The CAI can now impose administrative fines up to $10 million or 2% of worldwide turnover, and penal fines up to $25 million or 4% of turnover. No administrative monetary penalties have been issued yet as of early 2026, but the CAI published new breach-prevention guidelines in January 2026 and investigations are increasing.

CASL carries its own penalties: up to $10 million per violation for businesses that send commercial messages without proper consent.

And if Bill C-27 (the proposed CPPA) ever passes federally, maximum penalties would jump to $25 million or 5% of global revenue.

Jurisdiction Maximum penalty Who enforces
Federal (PIPEDA) $100,000/violation OPC recommends, AG prosecutes
Quebec (Law 25) $10M or 2% turnover (admin); $25M or 4% (penal) CAI
CASL $10M/violation CRTC
Federal (CPPA, if enacted) $25M or 5% revenue Proposed

For a 40-seat independent, the realistic risk isn't a $10-million fine. It's a complaint to the OPC or CAI that triggers an investigation, mandatory remediation, and published findings that damage your reputation. And an email marketing violation under CASL can compound fast if you're sending to a list without proper consent records.

What to do this week

You don't need a law firm. You need an afternoon.

Post a privacy policy on your website. One page. What data you collect, why, how long you keep it, how guests can request access or deletion, and who to contact. Quebec requires this by law. Every other province should have one anyway. Your reservation software likely has a template, but customize it.

Audit your consent flows. Is your email opt-in a separate, unchecked box? Are guests informed about card-on-file before they enter their card details? Do you have separate consent for SMS?

Set up a data retention schedule. Look at the table above. Pick reasonable timelines and set calendar reminders to purge old data. Most reservation systems let you export and delete inactive guest profiles.

Keep a consent log. Record when, how, and to what each guest consented. CASL requires this, and it's your best defence if someone files a complaint.

Start a breach log. A simple spreadsheet: date, what happened, what data was involved, who was notified, actions taken. Keep it for 24 months.

Brief your team. Anyone who handles guest data needs 15 minutes of context: what's personal information, who can access it, what to do if something looks wrong. One conversation per year is enough.

None of this requires new software or consultants. It requires attention.

Sources: Office of the Privacy Commissioner: PIPEDA, Quebec CAI: Law 25, CRTC: CASL, BLG: Quebec compliance guide.


Frequently Asked Questions

Does PIPEDA apply to small, independent restaurants in Canada?

Yes. PIPEDA covers every private-sector business engaged in commercial activity, with no revenue threshold or employee-count exemption. A single-location restaurant collecting reservation emails or guest phone numbers is fully subject to the law.

What customer data counts as personal information in a restaurant?

Any information about an identifiable individual: reservation details (name, phone, email), guest profiles with visit history and preferences, allergy notes, card-on-file records, email and SMS marketing lists, wifi login data, and security camera footage of identifiable people.

Can I use reservation emails to send marketing without asking?

Not without consent. Reservation data collected for booking purposes can't be repurposed for marketing. CASL allows implied consent through an existing business relationship for two years from last purchase, but promotional content requires separate opt-in.

What happens if my restaurant has a data breach?

Under PIPEDA, you must report breaches posing a real risk of significant harm to the OPC, notify affected individuals directly, and maintain a 24-month breach log. In Quebec, parallel notification to the CAI is required. Failing to report is a criminal offence with fines up to $100,000 per violation.

How long should a restaurant keep customer data?

Only as long as necessary for the stated purpose. Practical guidelines: 2-3 years for reservation records, clear card-on-file data after the booking window closes, delete inactive guest profiles after 2 years, and keep security footage for 30-90 days unless needed for an investigation.

Tags
privacyPIPEDAcustomer datarestaurant complianceCanadaLoi 25CASLdata protection
Back to blog

Continue reading

SMS marketing notification on a phone at an independent restaurant host stand
Restaurant marketing

SMS Marketing for Restaurants: A Canadian Guide

SMS has a 98% open rate and costs less than most restaurant marketing channels. This guide covers how Canadian independents can build a compliant text list, what to send, when to send it, and which platforms actually work in Canada. CASL compliance included.

June 22, 2026

A restaurant table set with a folded napkin and a handwritten note beside a plate
Restaurant marketing

Email Marketing for Restaurants: Build the List First

Your email list is the only marketing channel you actually own. This guide walks Canadian independent restaurants through building a list from scratch, staying CASL compliant, choosing the right tool, and sending emails that bring guests back. Most restaurants already have the data. They just haven't connected it yet.

June 12, 2026

Fresh herbs growing beside a handwritten restaurant menu board
Operations & Costs

Green Claims on Your Menu: What Canadian Law Actually Requires

Canada's updated Competition Act imposes penalties up to $10 million for unsubstantiated environmental claims. Restaurants using terms like "eco-friendly," "sustainable," or "zero waste" on menus, websites, and social media now need evidence to back those words up. Here's what the law requires, what's safe, and what crosses the line.

August 1, 2026

Clean restaurant kitchen counter with temperature log ready for health inspection
Opening a Restaurant

Health Inspections for Restaurants in Canada: How to Prepare

Health inspectors in Canada can arrive unannounced at any restaurant. They check temperature control, food storage, handwashing, cross-contamination prevention, pest control, and staff certification. Penalties range from $250 tickets to $200,000 corporate fines depending on the province, and every jurisdiction publishes results online. This guide covers what inspectors look for, how penalties differ by province, and a daily checklist so the inspection is a non-event.

July 24, 2026

A restaurant kitchen counter with a single order ticket, warm evening light
Online Ordering & Delivery

Who Owns Your Customers: Delivery Apps vs You

Every order through DoorDash, Uber Eats, or SkipTheDishes generates a customer profile the restaurant never sees. For a busy independent doing 25 delivery orders a day, that's 9,000 customer records a year owned by someone else. This article breaks down what platforms keep, what it costs in lost repeat business, and four practical steps Canadian restaurants can take to reclaim their customer relationships.

July 20, 2026

50 spots only

Restaurants across Canada are joining

Everything you need. $299. Once.

Perks, add-ons, no-show gift cards, card-on-file, and automated reminders. Everything for a better guest experience and bigger nights. One payment. No subscription. First 50 restaurants only.

Start with Trudy