A phone number and a note about a peanut allergy are "personal data"
Every restaurant collects it without thinking twice: a name, a phone number, an email, a note that the guest at table 12 doesn't eat shellfish, a record of what they ordered last time. None of that feels like "data" in the way a bank's records do. Legally, in most of the markets restaurants in Asia actually operate in, it is exactly that — personal data, covered by a real law, with real obligations attached to collecting, storing and using it.
This isn't a legal opinion — we're not a law firm, and if you need advice for your specific business, talk to local counsel. But it's worth knowing, in plain language, what's actually on the books in the markets where restaurants book guests through Bistrochat, and how that shapes the way we handle guest data on your behalf.
What "guest data" actually covers
It's more than a booking. A typical guest profile includes contact details, visit history, table and seating preferences, allergies and dietary notes, special requests, and — where POS is connected — itemised spend per visit. None of it is exotic. All of it is personal data under most privacy laws, and allergy or dietary information in particular is often treated as a more sensitive category that deserves extra care.
Personal data protection laws, market by market
Rules differ in the details, but the shape is similar almost everywhere: tell guests why you're collecting their data, get a lawful basis (usually consent) for using it, keep it reasonably secure, and let guests exercise rights over it — usually access, correction and deletion.
| Market | Law | Regulator | What it actually means for a restaurant |
|---|---|---|---|
| Singapore | Personal Data Protection Act (PDPA) | PDPC | Consent for collection/use, mandatory breach notification for notifiable breaches, opt-in rules for marketing messages |
| Thailand | Personal Data Protection Act B.E. 2562 | PDPC (Thailand) | Consent, breach notification, restrictions on sending data outside Thailand without safeguards |
| Hong Kong | Personal Data (Privacy) Ordinance (PDPO) | PCPD | Six Data Protection Principles; strict opt-in consent specifically for using guest data in direct marketing |
| Philippines | Data Privacy Act of 2012 | NPC | Registration of data processing activities, 72-hour breach notification, defined data subject rights |
| Vietnam | Personal Data Protection Decree 13/2023 | Ministry of Public Security | Consent, breach notification, extra steps for transferring data outside Vietnam |
| Taiwan | Personal Data Protection Act | Sector regulators / PDPC | Purpose limitation — data collected for a booking shouldn't be reused for unrelated purposes without consent |
| Macau | Personal Data Protection Act (Law 8/2005) | GPDP | Notification obligations for certain processing, consent, security requirements |
| Indonesia | Personal Data Protection Law (UU PDP) | Kominfo (dedicated authority pending) | Consent, breach notification, controller/processor obligations |
| Malaysia | Personal Data Protection Act 2010 (amended 2024) | JPDP | Consent; the 2024 amendment added mandatory data breach notification for the first time |
| Mexico | Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) | Federal oversight body | A privacy notice ("aviso de privacidad") at collection, and guest rights to access, correct, cancel or object (ARCO) |
| European Union | General Data Protection Regulation (GDPR) | National DPAs | Lawful basis for processing, 72-hour breach notice, and it applies to any EU guest's data regardless of where your restaurant is |
| United States | No single federal law — California's CCPA/CPRA is the closest equivalent, with other states following | CPPA (California) | Rights to know, delete and opt out of data "sale," triggered by the guest's residency, not the restaurant's location |
| China | Personal Information Protection Law (PIPL) | Cyberspace Administration of China (CAC) | Separate, explicit consent for sensitive data, and strict rules on moving data outside China |
The common thread: if you have guests from a market with a privacy law and you hold their data, that law can apply to you even if your restaurant isn't physically there — GDPR and PIPL are both written to reach outside their home borders.
What these laws actually ask of a restaurant, day to day
Underneath the different names, most of them come down to a handful of practical habits: collect only what you need for the booking and service, tell guests in plain terms why you're keeping it, don't repurpose it for something they didn't agree to (like adding them to a marketing list without consent), keep it reasonably secure, and be able to act when a guest asks what you hold or asks you to delete it.
Where Bistrochat guest data is stored, and who can access it
Guest data lives inside your Bistrochat account, not in a spreadsheet passed between staff phones. Access is controlled per venue — a host at one location doesn't see another venue's guest list unless your group is set up to share it, and for multi-venue restaurant groups, cross-venue guest recognition is a deliberate feature you control, not a side effect of loose access.
Payment data doesn't sit in the guest profile as a card number
When a guest pays a deposit, the payment is handled through the payment processor's secure channel — WeChat Pay, Alipay, PromptPay, PayNow, GrabPay, Apple Pay, Google Pay, VISA and Mastercard — rather than a raw card number sitting in the guest's notes.
Guest data is yours — and that includes if you ever leave
The guest relationships your restaurant has built don't belong to a booking marketplace, and they're not held hostage inside Bistrochat either. If a restaurant group ever moves on, its guest data goes with it.
What happens when a guest asks to be forgotten
Most of the laws above give guests some version of the right to ask what data you hold on them, correct it, or have it deleted. In practice, that means a restaurant needs to be able to find a specific guest's record and act on it — not send a support ticket into a void. That's a lookup and a deletion, not a data-recovery project.
FAQ: guest data privacy for restaurants
Is my guest data sold to anyone? No. It's used to run your reservations, guest recognition and marketing for your restaurant — not resold as a data product.
Does this apply to me if I only have one small restaurant? Usually yes. Most of these laws apply based on the size and sensitivity of the data you hold, not the size of your business, though some have thresholds for the strictest obligations.
What if my guests are mostly tourists from another country? Several of these laws — GDPR and PIPL especially — are written to follow the guest, not stop at a border. A Hong Kong restaurant with EU or mainland Chinese guests can still have that guest's home-market law apply to their data.
Do I need a separate privacy policy for my restaurant? That's a question for local counsel given your specific setup, but most of these laws expect guests to be told, in some form, why their data is being collected — which usually means some kind of notice, even a simple one.
Can a guest ask me to delete everything I have on them? In most of these markets, guests have some form of that right, and a restaurant should be able to locate and act on that request.
Good data practices aren't a compliance checkbox bolted onto your reservation system — they're what makes guests comfortable handing you their number, their allergy, and their trust in the first place. Get in touch to see how Bistrochat handles guest data across every market you operate in.