Ireland
The data rules, in plain terms.
Not legal advice, but the handful of things that most restaurants get wrong and that carry real consequences.
In short
Restaurants need a lawful basis to process customer data and, for electronic marketing to consumers in Ireland, prior consent with a free opt-out in every message. Consent must be specific and recorded, marketing opt-in must be separate from the order itself, and opt-outs must be honoured promptly. This is a summary rather than legal advice.
Updated 28 August 2026
Order data and marketing data are different
Taking a name, address and phone number to deliver an order is processing you need for the contract. Using those details later to send an offer is marketing, and it needs its own basis. The single most common mistake is treating an order as permission to market, which it is not.
Consent has to be a real choice
A separate, unticked box, with plain wording, at the point of collection. Not buried in terms, not pre-ticked, not bundled with accepting the order. Record what they consented to, when, and from where, because if you are ever asked to demonstrate consent, an assertion is not evidence.
- Separate from the order confirmation
- Unticked by default
- Plainly worded, saying what you will send
- Logged with a timestamp and a source
Every message needs a working opt-out
Irish electronic communications regulations require a free and simple way to opt out in every marketing message, and this is enforced with real penalties. Test yours periodically, because a broken unsubscribe link is both a compliance failure and the fastest way to generate complaints.
Keep what you use, delete what you do not
Do not hold data indefinitely because a system allows it. Decide a retention period, apply it, and be able to delete a customer's data on request. Also be able to export it, because access requests are a right and a system that cannot produce a customer's data on demand is a problem waiting to happen.
The one that catches restaurants out
Wifi sign-ins and competition entries. Collecting an email in exchange for wifi access does not give you marketing consent unless you asked for it separately and clearly. A lot of restaurant lists are built this way and are not lawfully usable for marketing.
Questions, answered straight.
Not covered here? Just ask us.
Do I need a privacy policy?
Yes, and it needs to say what you collect, why, how long you keep it and who you share it with. It should be linked from any form that collects data.
Can I email customers who ordered by phone?
Only with marketing consent. Taking a number to arrange a delivery is not consent to market to it.
How long can I keep customer data?
As long as you have a reason. Set a retention period, document it, and apply it. Indefinite retention with no justification is not defensible.
Is this different in the UK?
The framework is similar in substance, with UK GDPR and PECR in place of the Irish equivalents. The practical requirements around consent and opt-outs are broadly the same.
Is this legal advice?
No. It is a summary of the areas restaurants most often get wrong. For anything specific to your business, take proper advice.
See it run your restaurant.
Twenty minutes on your menu and your numbers. We'll show you what actually changes in the first month and exactly what it costs. If it's not right for your restaurant, we'll tell you that instead.
- Live in days, not months
- We build your menu and train your staff
- No contract, and thirty days to change your mind
Rather just ring us? +353 87 438 8032
Tell us about your restaurant
We reply the same day, usually inside a couple of hours.