PII (Personally Identifiable Information)
PII, or personally identifiable information, is any data that identifies a specific guest: name, phone number, email address, birthday, and the notes attached to them. Privacy law governs how a restaurant collects, stores and uses it. Consent is one lawful basis among several, required for marketing texts and not for keeping a reservation record.
PII is a legal and security term rather than a hospitality one, and it covers any business holding records about people. A restaurant becomes a holder of it the moment it takes a reservation. What is specific to hospitality is where the data ends up: a reservation platform, a point-of-sale system, a review site, an email tool, spreadsheets and staff phones. A restaurant CRM concentrates those copies into one guest record.
What counts as PII in a restaurant’s guest data?
The obvious identifiers are name, phone number, email address and postal address. Less obvious guestbook items carry the same status.
- Reservation notes. “Difficult on the phone, comped last time” is personal data about an identified person, and where a right of access applies the guest can ask to see it.
- Dietary and allergy information. In several jurisdictions this is health data and sits in a more sensitive category than a phone number.
- Occasion fields. A birthday, an anniversary or a proposal date identifies a person and a relationship.
- Payment references. A card’s last four digits and a processor’s token usually sit with the payment processor rather than with the restaurant, and that division is worth confirming.
The test is whether a record traces back to one guest, on its own or combined with something else the business holds. A table number and a time are not PII alone, and both become PII the moment they sit next to a name.
Do you need a guest’s consent to hold their data?
No, not as a blanket rule, and this is the most common misreading of privacy law in hospitality. Consent is one lawful basis for processing personal data among several, and it is not the one a reservation runs on. A restaurant records a booking, keeps a service note and retains a check because doing so is necessary to provide the service the guest asked for.
Where consent does the work is marketing, and the standard rises with the channel. Marketing texts require the guest’s express consent, recorded and honored when withdrawn. Email is governed less strictly in most jurisdictions and still requires a working unsubscribe on every send. So consent is tracked per channel rather than as one yes or no on the profile.
Where does a restaurant’s guest PII actually live?
Guest PII lives in more systems than most operators would list from memory, and that inventory is what matters when a deletion request arrives. The reservation platform holds contact detail and notes. The POS may hold a name and email with the check. Review platforms hold names the restaurant never collected. Every list exported to a spreadsheet is another copy, and those copies honor nothing.
Consolidating profiles into one system makes the inventory knowable without making the other copies disappear. A guest asking to be forgotten has to be removed from each place the record was written, including the reservation platform and any export sitting in a shared drive.
Last updated