Customer data and privacy law: what Canadian restaurants need to know

Your reservation system holds names, phone numbers, emails, allergy notes, and visit histories. Your card-on-file setup stores Stripe tokens linked to guest profiles. Your email list has 600 addresses you collected from comment cards and wifi logins over the past three years.
All of that is personal information under Canadian law. And the rules around how you collect, store, and eventually delete it are tighter than most operators realize.
The good news: compliance for a 30-seat independent isn't as complicated as the consulting firms selling $5,000 audits want you to believe. But ignoring it isn't an option either.
Which law actually applies to your restaurant?
Canada's privacy framework is layered, and the answer depends on where you operate.
PIPEDA (the Personal Information Protection and Electronic Documents Act) is the federal baseline. It covers every private-sector business engaged in commercial activity, with no size exemption. A single-location bistro collecting reservation emails is subject to the same law as a national chain.
Three provinces have their own private-sector privacy laws that replace PIPEDA for in-province activity:
| Province | Law | Key difference from PIPEDA |
|---|---|---|
| Quebec | Law 25 (fully in force since Sep 2024) | Mandatory privacy impact assessments, data portability rights, administrative fines up to $10M or 2% of worldwide turnover |
| British Columbia | PIPA | Covers employee information too; provincial commissioner can issue binding orders |
| Alberta | PIPA | Same scope as BC; binding orders from provincial commissioner |
If you're in Ontario, Manitoba, Saskatchewan, or the Atlantic provinces, PIPEDA applies directly.
For cross-provincial data flows (say, a POS system with servers in another province), PIPEDA still governs the cross-border piece. In practice, if your restaurant is in one location and your data stays in Canada, the provincial law (where applicable) is the one that shapes your day-to-day obligations.
Better guest experience. Bigger nights. $299. Once.
What data does your restaurant actually hold?
Most operators underestimate how much personal information they accumulate. Here's what counts:
| Data type | Examples | Where it lives |
|---|---|---|
| Reservation data | Name, phone, email, party size, date/time | Reservation software, paper book |
| Guest profiles | Visit history, preferences, allergy notes, "birthday March 12" tags, VIP flags | CRM, reservation system |
| Card-on-file | Last 4 digits, card brand, Stripe customer/payment method IDs | Reservation system via Stripe |
| Marketing lists | Email addresses, phone numbers, communication preferences | Mailchimp, SMS platform |
| Employee records | SIN, bank info, schedules, performance notes | Payroll system, HR files |
| Wifi logins | Email or phone collected for guest wifi access | Router/captive portal system |
| Security footage | Camera recordings of identifiable people | NVR, cloud storage |
Each row is personal information under PIPEDA. Allergy and dietary notes are considered sensitive personal information under Quebec's Law 25, which triggers heightened consent and security requirements.
A guest's name linked to their phone number and shellfish allergy? Personal information. The last four digits of their Visa tied to their guest profile? Also personal information.
Five obligations that actually matter for a restaurant
Privacy law has dozens of provisions, but for an independent restaurant, five are the ones you'll interact with.
1. Designate someone responsible
Under PIPEDA, your business must have a designated privacy contact. In a restaurant, that's almost always the owner. You don't need to hire a privacy officer or create a new role. You need to know where the data is, who has access, and what to do if something goes wrong.
Quebec's Law 25 makes this explicit: the person with the highest authority in the organization is the default privacy officer. You can delegate to a manager, but the buck still stops with you. Publish the contact on your website.
2. Only collect what you need
The principle of data minimization runs through every Canadian privacy law. Collect the information necessary for the stated purpose. Nothing more.
For a reservation: name, phone, email, party size, date, time. That's it. You don't need a mailing address. You don't need their birthday unless they volunteered it.
For card-on-file: you need enough to charge a no-show fee if your policy requires it. Stripe handles the tokenization, so you store IDs and last-4, never the full card number (that's PCI DSS, separate from privacy law but equally non-negotiable).
For wifi: if your captive portal collects an email address, that email is personal information. Using it for marketing without separate consent violates both PIPEDA and CASL (more on that below).
3. Get consent right
Consent under Canadian privacy law must be meaningful: clear, specific, and freely given. Pre-checked boxes don't count.
Reservations fall under the necessity exception. You're collecting the name and phone number because you need it to confirm and manage the booking. No checkbox required.
But that doesn't extend to marketing. "By booking, you agree to receive our promotions" is not valid consent because it's neither distinct nor free. The guest isn't choosing to receive promotions. They're trying to book a table.
Card-on-file requires clear disclosure. The guest needs to understand why you're saving their card, what you might charge (no-show fee amount), and how long you'll keep it. A plain-language message at booking time covers this. No legal boilerplate needed.
Email/SMS marketing requires separate, explicit opt-in consent under CASL. One important detail: CASL recognizes implied consent through an existing business relationship. If a guest dined at your restaurant, you have implied consent to send them marketing emails for two years from the last purchase. Each new visit resets that clock. But you still need express opt-in for anyone who hasn't dined with you, and you need separate consent for each channel (email consent doesn't cover SMS).
4. Delete data when you're done with it
This is the rule most restaurants ignore. When the purpose for which you collected data is fulfilled, you must destroy it securely.
A guest booked once three years ago, never returned, never opted into your mailing list. Why do you still have their phone number, email, and allergy notes sitting in your reservation system?
Set a retention schedule. Common practice for restaurants:
| Data type | Reasonable retention period |
|---|---|
| Reservation records | 2-3 years (supports guest history, CASL implied consent window) |
| Guest profiles (active) | As long as the guest relationship is active |
| Guest profiles (inactive) | Delete after 2 years of no activity |
| Card-on-file data | Clear after the reservation is complete and any no-show window has passed |
| Marketing consent records | Keep as long as you're sending messages (CASL requires proof of consent) |
| Employee records | Follow provincial employment standards (varies by province) |
| Security footage | 30-90 days unless needed for an investigation |
Quebec's Law 25 gives guests the right to request deletion and, as of 2024, data portability (you have 30 days to provide their data in a usable format).
5. Report breaches
Under PIPEDA, you must report any breach that creates a "real risk of significant harm" to the Office of the Privacy Commissioner as soon as feasible. You must also notify the affected individuals directly and maintain a breach log for 24 months covering every breach, whether or not it met the reporting threshold.
What counts as a breach in a restaurant? A laptop stolen from the back office that had a reservation spreadsheet with names, phones, and card data. An employee forwarding the guest email list to a personal account. A booking confirmation sent to the wrong email address.
In Quebec, Law 25 requires parallel notification to the Commission d'accès à l'information (CAI), with its own forms and deadlines.
Failing to report, notify, or keep breach records is a criminal offence under PIPEDA, with penalties up to CA$100,000 per violation.
The penalty picture is changing
PIPEDA's current maximum is $100,000 per violation for failing to report breaches or obstructing investigations. The OPC doesn't issue fines directly. It investigates, publishes findings, and refers serious cases to the Attorney General.
Quebec is a different story. The CAI can now impose administrative fines up to $10 million or 2% of worldwide turnover, and penal fines up to $25 million or 4% of turnover. No administrative monetary penalties have been issued yet as of early 2026, but the CAI published new breach-prevention guidelines in January 2026 and investigations are increasing.
CASL carries its own penalties: up to $10 million per violation for businesses that send commercial messages without proper consent.
And if Bill C-27 (the proposed CPPA) ever passes federally, maximum penalties would jump to $25 million or 5% of global revenue.
| Jurisdiction | Maximum penalty | Who enforces |
|---|---|---|
| Federal (PIPEDA) | $100,000/violation | OPC recommends, AG prosecutes |
| Quebec (Law 25) | $10M or 2% turnover (admin); $25M or 4% (penal) | CAI |
| CASL | $10M/violation | CRTC |
| Federal (CPPA, if enacted) | $25M or 5% revenue | Proposed |
For a 40-seat independent, the realistic risk isn't a $10-million fine. It's a complaint to the OPC or CAI that triggers an investigation, mandatory remediation, and published findings that damage your reputation. And an email marketing violation under CASL can compound fast if you're sending to a list without proper consent records.
What to do this week
You don't need a law firm. You need an afternoon.
Post a privacy policy on your website. One page. What data you collect, why, how long you keep it, how guests can request access or deletion, and who to contact. Quebec requires this by law. Every other province should have one anyway. Your reservation software likely has a template, but customize it.
Audit your consent flows. Is your email opt-in a separate, unchecked box? Are guests informed about card-on-file before they enter their card details? Do you have separate consent for SMS?
Set up a data retention schedule. Look at the table above. Pick reasonable timelines and set calendar reminders to purge old data. Most reservation systems let you export and delete inactive guest profiles.
Keep a consent log. Record when, how, and to what each guest consented. CASL requires this, and it's your best defence if someone files a complaint.
Start a breach log. A simple spreadsheet: date, what happened, what data was involved, who was notified, actions taken. Keep it for 24 months.
Brief your team. Anyone who handles guest data needs 15 minutes of context: what's personal information, who can access it, what to do if something looks wrong. One conversation per year is enough.
None of this requires new software or consultants. It requires attention.
Sources: Office of the Privacy Commissioner: PIPEDA, Quebec CAI: Law 25, CRTC: CASL, BLG: Quebec compliance guide.
Frequently Asked Questions
Does PIPEDA apply to small, independent restaurants in Canada?
Yes. PIPEDA covers every private-sector business engaged in commercial activity, with no revenue threshold or employee-count exemption. A single-location restaurant collecting reservation emails or guest phone numbers is fully subject to the law.
What customer data counts as personal information in a restaurant?
Any information about an identifiable individual: reservation details (name, phone, email), guest profiles with visit history and preferences, allergy notes, card-on-file records, email and SMS marketing lists, wifi login data, and security camera footage of identifiable people.
Can I use reservation emails to send marketing without asking?
Not without consent. Reservation data collected for booking purposes can't be repurposed for marketing. CASL allows implied consent through an existing business relationship for two years from last purchase, but promotional content requires separate opt-in.
What happens if my restaurant has a data breach?
Under PIPEDA, you must report breaches posing a real risk of significant harm to the OPC, notify affected individuals directly, and maintain a 24-month breach log. In Quebec, parallel notification to the CAI is required. Failing to report is a criminal offence with fines up to $100,000 per violation.
How long should a restaurant keep customer data?
Only as long as necessary for the stated purpose. Practical guidelines: 2-3 years for reservation records, clear card-on-file data after the booking window closes, delete inactive guest profiles after 2 years, and keep security footage for 30-90 days unless needed for an investigation.




