industry-guides8 min read7 June 2026

PDPA for F&B and Restaurants: Customer Data Compliance in Singapore

Learn how Singapore F&B businesses and restaurants can comply with PDPA requirements for customer data — from reservations to loyalty programmes.

ComplyHQ Team

PDPA for F&B and Restaurants: Customer Data Compliance in Singapore

PDPA for F&B and Restaurants: Customer Data Compliance in Singapore

A cafe owner I work with launched a birthday rewards programme last year. Customers filled out a card with their name, phone number, date of birth, and — because why not — their favourite dish and any food allergies. That allergy information? It's health data under the PDPA. Nobody in the cafe knew that. Nobody had set up consent for collecting it. And the cards were sitting in an unlocked drawer behind the counter where any staff member could rifle through them.

This is the reality for most F&B businesses in Singapore. You're collecting more personal data than you think, and the PDPA applies to every bit of it. Non-compliance can mean financial penalties of up to S$1 million, or 10% of your turnover — whichever is higher.

TL;DR — Key Takeaways for F&B Businesses

  • You need valid consent before collecting customer data for reservations, loyalty programmes, or marketing.
  • Your business must appoint a Data Protection Officer (DPO), even if it's the owner themselves.
  • Retention periods must be defined — don't keep customer data forever.
  • Third-party platforms (delivery apps, POS providers, marketing tools) don't absorb your responsibility.
  • A data breach involving 500+ individuals must be reported to the PDPC within 3 calendar days.

For a full compliance walkthrough, see our PDPA Compliance Checklist for Singapore SMEs.


You're Collecting More Data Than You Realise

Under the PDPA, "personal data" means any data that can identify an individual — on its own or combined with other information you hold. Walk through a typical day at your restaurant and count the touchpoints:

  • Reservations: Names, mobile numbers, email addresses, party size, special requests (dietary restrictions or allergies are potentially sensitive health data)
  • Loyalty programmes: Birth dates, spending history, visit frequency — and NRIC/FIN numbers, which are now heavily restricted
  • Online ordering and delivery: Home or office addresses, payment card details, order history
  • Wi-Fi login: Device addresses, phone numbers, email addresses
  • CCTV footage: Facial images, timestamps of customer visits
  • Marketing: Email addresses, SMS numbers, customer preferences

Each one carries specific PDPA obligations. The critical first step? Actually knowing what you collect and why.


The PDPA Obligations That Hit F&B Hardest

When a customer calls to book a table and gives their phone number, they've consented to being contacted about that reservation. That typically qualifies as deemed consent under Section 15. But — and this is the part that catches people — they have not consented to receiving your weekly promotional SMS blasts.

I've seen this exact violation lead to PDPC fines. A restaurant using reservation numbers for marketing. The owner genuinely thought it was fine. It wasn't.

For loyalty programmes, your sign-up form needs to clearly state what data you're collecting and why. A pre-ticked consent box doesn't count as valid consent under the PDPA. And if you require a phone number for guest Wi-Fi, you need to tell customers why and not collect more data than necessary.

Purpose Limitation (Section 18): Stick to What You Said

You can only collect and use personal data for purposes that a reasonable person would consider appropriate. A restaurant collecting NRIC numbers for a basic loyalty programme? The PDPC would likely consider that excessive. Since 1 September 2019, NRIC collection has been heavily restricted — use alternatives like phone numbers or membership IDs.

Retention Limitation (Section 25): Stop Hoarding Data

Many F&B businesses keep customer records indefinitely in their POS or CRM systems. "We might need it someday." That's not how the PDPA works. You need defined retention periods:

Reservation records — 3 to 6 months after the visit Loyalty programme data — 1 to 2 years after last activity CCTV footage — 30 days (industry standard) Delivery addresses — Duration of active account Marketing contact lists — Until consent is withdrawn

Document these in your data protection policy and actually enforce them through regular purges.

Protection (Section 24): Lock It Down

This covers both digital and physical security:

  • POS systems: Password-protected, encryption for payment data. Check with your POS vendor on PCI DSS compliance.
  • Reservation books: If you're still using a physical book, don't leave it visible at the host stand. Store it securely.
  • Staff access: Your kitchen team generally doesn't need access to customer contact details. Limit who sees what.
  • Cloud systems: If you use cloud-based reservation or CRM platforms, verify your provider stores data securely — ideally with a provider meeting ISO 27001 standards.

The Four Biggest Mistakes I See in F&B

Mistake 1: Using Reservation Data for Marketing

I've already mentioned this, but it bears repeating because it's the most common violation I encounter in F&B. Separate your marketing consent from your reservation process. Different purpose, different consent.

Mistake 2: Sharing Customer Data Without Safeguards

You work with food delivery platforms, marketing agencies, event booking tools, and payment processors. Under the Transfer Limitation Obligation (Section 26), you must ensure any third party receiving your customer data provides comparable protection. Put data processing agreements in place with every vendor that handles personal data on your behalf.

If your business uses multiple digital tools stitched together, consider working with a provider like Adaptels to build an integrated system with proper data handling controls instead of patching disconnected platforms together.

Mistake 3: No Data Breach Response Plan

A hacked POS system leaking payment data. A stolen laptop with customer records. A misconfigured online ordering system exposing delivery addresses. These aren't hypothetical — they happen to F&B businesses. Under mandatory breach notification, if a breach affects 500+ individuals or is likely to result in significant harm, you must notify the PDPC within 3 calendar days and affected individuals as soon as practicable.

Every F&B business — regardless of size — should have a documented data breach response plan.

Mistake 4: No DPO Appointed

Under Section 11(3), every organisation must designate at least one individual as a Data Protection Officer. For a small restaurant, this can be the owner or manager — no dedicated hire needed. But the appointment must be made, and the DPO's contact details should be publicly available on your website or at the counter. Many small F&B operators simply don't know this requirement exists.


CCTV in Your Restaurant: What the PDPA Requires

CCTV is standard in most F&B establishments, and under the PDPA, that footage is personal data because it can identify individuals. Your obligations:

  • Signage: Display clear notices informing customers and staff that CCTV is in operation. State the purpose (e.g., "for security purposes") and who to contact for enquiries.
  • Retention: Don't keep footage longer than necessary. 30 days is the industry standard. Up to 90 days for incident investigation is generally acceptable if documented.
  • Access: Restrict who can view CCTV footage. Don't share it on social media or with unauthorised third parties (yes, I've seen this happen).
  • Access requests: Individuals have the right to request access to footage of themselves under Section 21. You must respond within 30 days.

For more on monitoring obligations, see our guide on employee monitoring and the PDPA.


A Practical Compliance Checklist for Your F&B Business

  1. Appoint a DPO — Designate someone responsible for data protection. This can be the business owner.
  2. Map your data — Identify every touchpoint where you collect personal data (reservations, loyalty, CCTV, Wi-Fi, deliveries).
  3. Review consent mechanisms — Make sure you have valid, informed consent for each purpose. Separate marketing consent from service-related consent.
  4. Draft a privacy policy — Publish a clear, accessible policy. Put it on your website and make it available in-store.
  5. Set retention schedules — Define and enforce how long you keep each type of data.
  6. Secure your systems — Password-protect POS terminals, encrypt customer databases, restrict staff access.
  7. Vet your vendors — Ensure third-party providers (delivery platforms, CRM tools, payment processors) have adequate data protection measures.
  8. Prepare a breach response plan — Document what to do if a breach occurs, including PDPC notification procedures.
  9. Train your staff — Front-of-house and management need to understand basic data protection: what to collect, what not to share, and how to handle access requests.

For most F&B businesses, working through this manually is time-consuming and easy to get wrong. Tools like ComplyHQ offer AI-powered compliance that handles your PDPA obligations in minutes — especially useful for restaurant owners who'd rather spend their time on service and food, not regulatory paperwork.


What a PDPA Violation Actually Costs

The PDPC has actively enforced the PDPA across F&B and hospitality. Here's what you're looking at:

  • Financial penalties of up to S$1 million or 10% of annual turnover (whichever is higher) for organisations with turnover exceeding S$10 million.
  • Directions to stop collecting or using data, destroy improperly collected data, or implement specific remediation.
  • Reputational damage — PDPC enforcement decisions are published publicly. For a restaurant that depends on trust and word-of-mouth, that can be worse than the fine.

Even for smaller F&B businesses, fines of S$10,000 to S$50,000 have been issued for relatively straightforward violations — inadequate protection of customer data, failure to implement reasonable security. See real cases in our PDPC enforcement cases analysis.


The Bottom Line

Running a compliant F&B business in Singapore doesn't require a legal department or a massive budget. It requires knowing what data you collect, having sensible policies around it, and making sure your team follows them. The PDPA is designed to be practical — for most restaurants and food businesses, compliance boils down to: collect only what you need, tell customers why, keep it safe, and delete it when you no longer need it.

Start with a data audit. Put your policies in writing. Train your team. And if you want to shortcut the process, ComplyHQ can walk your business through each step with AI-guided compliance tailored to your industry.


Sources

  1. Personal Data Protection Act 2012 — Full Text
  2. PDPC Advisory Guidelines on Key Concepts in the PDPA
  3. PDPC Guide on Managing and Notifying Data Breaches
  4. PDPC Advisory Guidelines on the NRIC and Other National Identification Numbers
  5. PDPC Enforcement Decisions

Simplify Your Compliance

ComplyHQ's AI can assess your PDPA compliance gaps in under 15 minutes and generate the policies you need.

Try Free Assessment

Frequently Asked Questions

Do I need consent to collect customer phone numbers for restaurant reservations?
Yes. Under the PDPA, you must obtain consent before collecting personal data such as phone numbers for reservations. However, you may rely on the deemed consent provision (Section 15) if the customer voluntarily provides their number for the purpose of making a reservation. You must still inform them of the purpose of collection and not use the data for unrelated purposes like marketing without separate consent.
How long can my restaurant keep customer data from loyalty programmes?
The PDPA does not specify a fixed retention period. Under the Retention Limitation Obligation (Section 25), you must stop retaining personal data once the business purpose is no longer served. For loyalty programmes, a reasonable retention period is typically 1–2 years after the customer's last activity. You should document your retention policy and purge inactive records regularly.
Can I share customer data with a third-party food delivery platform?
You may share customer data with a third-party platform only if the customer has consented to such disclosure, or if a valid exception applies. Under Section 20 of the PDPA, consent must cover the specific purpose of sharing. You must also ensure the third party provides a comparable standard of data protection, and you should formalise this through a data processing agreement.
Tags:PDPASingapore complianceF&Bdata protectionPDPCrestauranthospitality

Ready to get PDPA compliant?

Stop guessing about compliance. ComplyHQ uses AI to assess your gaps, generate policies, and guide you through every PDPA obligation.

Gap AssessmentPolicy GeneratorAI Compliance Chat
15 July 20267 min read

PDPA for Law Firms: Client Privilege and Data Protection

A practical guide to PDPA compliance in Singapore for law firms — reconciling legal professional privilege with data protection duties, breach rules, and PDPC penalties.

Read more
12 July 20267 min read

PDPA for Accounting Firms: Client Financial Data

PDPA compliance Singapore guide for accounting firms handling client financial data. Learn PDPC obligations, penalties, and practical steps to protect sensitive records.

Read more
9 July 20267 min read

PDPA for Event Companies: Attendee Data Rules

PDPA compliance for Singapore event companies: how to collect, use, and protect attendee data under the PDPA — consent, retention, breach rules, and penalties.

Read more