# What Are the Australian Privacy Rules for Restaurants in 2026?

nolemon.io · September 27, 2026

> What Australian restaurant privacy compliance actually requires Australian restaurants must comply with the Privacy Act 1988 and the Australian Privacy...

## What Australian restaurant privacy compliance actually requires

Australian restaurants must comply with the Privacy Act 1988 and the Australian Privacy Principles when they collect, use, store, disclose or deal with personal information as part of a business. The rules apply to customer bookings, delivery and account records, staff information, CCTV footage, payment-related data, marketing preferences, complaints and customer photographs. Restaurant privacy compliance is not limited to maintaining a privacy policy: operators need a lawful and reasonably foreseeable basis for handling information, restrict access, retain records only as needed, provide breach notice where required, and explain how data practices work. As at 28 September 2026, most incorporated Australian businesses with an annual turnover of at least $3 million are covered organisations under the federal Privacy Act. The $3 million threshold was unchanged even though reforms proposed a higher turnover threshold; businesses should check their current status rather than assuming the proposal is law. A smaller restaurant can still have privacy obligations under state or territory laws, contracts, employment requirements, and the Spam Act 2003.

**Also worth reading:** [How Should Australian Restaurants Control and Use Customer Data in 2026?](https://nolemon.io/knowledge/how_should_australian_restaurants_control_and_use_customer_data_in_2026.php) · [How Does Local Food Merchant Discovery SaaS Help Restaurants and Food Operators?](https://nolemon.io/knowledge/how_does_local_food_merchant_discovery_saas_help_restaurants_and_food_operators.php) · [How Should Restaurants Measure Restaurant Software ROI Metrics in 2026?](https://nolemon.io/knowledge/how_should_restaurants_measure_restaurant_software_roi_metrics_in_2026.php)

The federal rules are technology-neutral. A handwritten reservation book, paper loyalty card, POS system, booking platform, delivery app or cloud-based CRM can all be relevant. Privacy compliance is also not the same as cybersecurity: the Privacy Act regulates what an organisation does with personal information, while security controls determine how practically it protects that information. A restaurant can have a privacy policy but still mishandle data through unrestricted POS access, an exposed cloud account, excessive camera retention or a third-party marketing integration.

## When the Privacy Act applies to a restaurant

Under the Privacy Act, a restaurant is generally an “APP entity” if it operates as an Australian incorporated entity and has a turnover of at least $3 million in a financial year, or is part of a trading entity whose combined turnover is at least $3 million and has more than $50 million in turnover overall. Turnover calculations need to account for the structure in which the restaurant business operates, not merely the operator’s intuition about annual sales. Incorporated service companies, trading entities and organisations that exceed the threshold only during a year should obtain specific advice rather than waiting for the next annual report. The Office of the Australian Information Commissioner is the regulator, and privacy complaints, investigations and enforceable undertakings remain realistic risks.

Exemption from the federal Act does not mean a restaurant has no privacy responsibilities. The Australian Capital Territory, New South Wales, Queensland, South Australia, Tasmania, Victoria and Western Australia each regulate private-sector information through legislation that shares many principles with the Australian Privacy Principles. Some state laws contain turnover thresholds, exceptions or registration mechanisms, so the correct analysis depends on location, legal structure and revenue. Even where no general privacy statute applies, contract law, employment law, surveillance law, industry rules and platform policies may restrict collection or disclosure of information. Restaurants should treat excluded or below-threshold businesses as needing documented governance rather than assuming there are no rules.

The practical trigger is collection or dealing with personal information, not the introduction of a particular system. A customer gives a name, phone number, dietary note or email address when making a booking; a staff applicant supplies employment information; or a security camera records people entering the dining room. These acts can engage applicable privacy law. The organisation should identify the purposes at that point, explain them clearly and avoid collecting information merely because a form or vendor makes it technically possible.

## How restaurants must collect and use customer information

The Australian Privacy Principles require APP organisations to collect personal information only for a permitted purpose, through a reasonably lawful and fair means, and when it is directly related to that purpose. They must also collect only what is reasonably necessary, tell the person what the organisation will do with the information, and use and disclose it consistently with the stated purpose, subject to permitted exceptions. For a restaurant, a booking purpose normally supports taking a diner’s name, contact details, time, party size and reasonable seating or accessibility information. Marketing is a different purpose and should not be added to a reservation without a valid choice.

A privacy policy should identify the entity responsible for the information and explain the kinds of personal information handled, the purposes, how the information is collected, the authorised recipients, whether information is stored overseas, the relevant retention approach, and the individual’s rights. It should also give the name and contact details of the privacy contact. A generic policy copied without checking a restaurant’s systems, CRM, booking tools and apps is not adequate documentation. If the restaurant uses vendors, the policy should describe them accurately, while a service-privacy policy cannot excuse the restaurant from its own transparency obligations.

Consent is relevant but should not be described as the only legal basis used by APP entities. APP 1.4 recognises reasonably necessary compliance, establishment or exercise of a right or obligation, and certain other permitted situations. Consent is still important for direct electronic marketing under the Spam Act and for other activities where consent is expressly required. A customer can understand that their booking details will be processed to provide the booking, but that does not automatically mean they consented to being added to an advertising list.

## Practical compliance measures for a restaurant

A restaurant can establish a workable control system in four stages: identify its information flows, set rules for collection and retention, configure access and vendors, and assign responsibility for testing and incident response. For bookings, a booking form should collect only fields needed to provide the service. An optional marketing field should be separate and unticked by default, while dietary information should be recorded only when necessary and accessed only by staff who need it. Employee and contractor records require a separate retention process from customer records. Loyalty cards should contain a real deletion or cancellation route rather than an email-only dead end.

CCTV requires deliberate governance. Cameras should serve a defined and lawful operational purpose, and footage should be viewed or released only by authorised personnel. A restaurant should consider whether sound recording is necessary, place appropriate notices where people can see them, apply role-based access, and delete footage on a fixed schedule. A sign saying “CCTV in use” is not a complete privacy control. A restaurant must also manage health, accessibility and payment information: access to special-occasion meal notes should be limited, card details should generally pass through PCI DSS-compliant payment systems rather than being stored in restaurant software, and systems supporting health information require a more specific assessment.

Vendors should be documented before data is connected to their platform. This includes POS providers, booking platforms, delivery platforms, payroll firms, cloud storage, email providers, advertising tools, accountants and IT contractors. Contracts and settings should address permitted use, security, subcontractors, breach cooperation, location of storage, return or deletion at termination, and any onward disclosure. The restaurant should know whether vendor credentials can create an export of customer or employee records, and deactivate accounts promptly when a person leaves the business. Quarterly access reviews and immediate removal of former users are inexpensive controls compared with responding to an avoidable disclosure.

## Privacy, records, technology and security

The Privacy Act does not prescribe one universal retention period for every category of restaurant information. APP 11 requires APP entities to take reasonable steps to prevent and correct unauthorised disclosure, and APP 5 requires a document setting out how the entity meets the principles. Retention periods should reflect legal, contractual, tax, employment, evidentiary and operational needs. A booking confirmation may be operationally useful for several months, while a CCTV recording could be destroyed within days or weeks unless it is needed for a specific incident. Keeping years of footage or customer data merely because storage is cheap creates unnecessary exposure and increases breach impact.

Restaurants should use unique accounts, multi-factor authentication where supported, supported software, encrypted connections, controlled administrative privileges, logging and tested backups. Default passwords must be changed, and all staff should receive basic handling guidance. Payment card data should be kept to the minimum needed and handled through systems certified to the Payment Card Industry Data Security Standard. CVV and card security-code data should not be retained after authorisation, and full card details should not be copied into reservation notes, emails or spreadsheets.

Australia does not have one general federal data-protection rule requiring every business to obtain certified security certification. That does not mean security is optional. APP 8 and APP 11 create obligations to protect against interference, misuse, loss and unauthorised access in relevant circumstances. The Australian Signals Directorate’s Cyber Security Baseline, which contains the Essential Eight, is a practical reference for prioritising controls, particularly for small and midsize operators. Technology providers may also offer their own product security commitments, but those commitments do not replace restaurant oversight.

Operational records should include an information inventory, privacy policy, APP accountability statement where appropriate, vendor register, access list, retention schedule, CCTV procedure, marketing preferences, deletion process and incident plan. The person responsible need not be a lawyer, but responsibility should be assigned to a named manager with access to external legal or cyber advisers. Evidence is more useful than assurance alone: a dated access review, training record or vendor test demonstrates that the process is being operated rather than merely written.

## Common restaurant privacy mistakes and expensive misunderstandings

One common error is assuming the federal $3 million turnover threshold is the only test. Legal structure, state law, contracts and the type of information may create responsibilities even below that figure. Another is treating a booking confirmation as marketing consent. If a diner receives a text advertising tonight’s specials after every reservation, the restaurant should assess the Spam Act, identify a valid consent basis and provide a simple opt-out. Repeated or misdirected messages can lead to complaints, reputational damage and enforcement action.

A second error is using the “internal use” exception too broadly. Permitted internal use is not a general permission to move personal information to every service provider or allow unrelated employees to inspect it. A marketing agency, booking platform or analytics vendor may be an authorised recipient, but a restaurant should document the relationship and make sure its use remains consistent with collection purposes. Contract wording cannot override privacy obligations toward the individual.

The third error is assuming cloud storage fixes privacy. Storing a database with the vendor’s name in a Dropbox, Google Drive or Microsoft account does not establish an appropriate retention policy or access control. Shared links can remain public after staff assume they were removed, and staff can accidentally expose photographs, bookings or employee records. The fourth error is collecting sensitive information without an operational reason. Health-related notes, religious requirements and accessibility details should be collected only where needed, transferred securely to staff who need them and not published in general customer channels.

Breach response is also often misunderstood. An organisation does not need certainty that harm occurred before it must take appropriate steps after an actual or suspected compromise. Under the Notifiable Data Breaches scheme, an APP entity must investigate a suspected serious breach and notify affected individuals and the OAIC when the breach is likely to cause serious harm. Eligible breaches must be assessed quickly, and the regulator must be notified within 72 hours after the organisation becomes aware that the circumstances meet the relevant threshold. A restaurant that waits for a lawyer to confirm the facts can lose valuable response time.

## Restaurants, platforms, consent and marketing compared

| Feature | Restaurant-controlled operation | SaaS or marketplace option | Practical assessment |
| --- | --- | --- | --- |
| First-party booking data | POS, website and in-house reservation records, subject to documented controls | Booking engine, CRM or merchant platform can centralise records, but requires vendor and access review | Keep source ownership clear and know every export before migration |
| Marketing | Operator sends campaigns only through a defensible basis and easy opt-out | CRM, delivery or social platform may automate targeting and sharing | Automation does not remove responsibility for consent, disclosure and suppression |
| CCTV | On-site cameras with local retention and authorised viewing | Cloud or managed-video vendor may improve access logs and deletion controls | Use the option only after checking purpose, notice, retention and overseas storage |
| Payment | Direct payment terminals or provider-hosted checkout | Hosted checkout, stored tokenisation or platform payment can reduce card-data exposure | The restaurant should not keep CVV data or use unapproved spreadsheets |
| Data access | Staff permissions can be simple if the operation is small | SaaS may provide roles, logs and review tools, at recurring cost | A small system with disciplined administration can be safer than an unmanaged enterprise tool |
| Vendor exit | Records may be harder to recover and delete from systems without an export plan | Contracted SaaS should support export, return or deletion | Test the exit process before committing operational data |

SaaS is useful when it supplies ticketing, reservations, staff scheduling, bookkeeping or a controlled loyalty program, provided the restaurant verifies the vendor’s practices and contract. A merchant-recommendation or local-discovery platform should tell users what information it collects, how businesses receive it, how it prevents inappropriate use and how someone can correct or delete their information. It should not quietly expose a restaurant’s customer list, take unrestricted payment data, or imply that a customer has endorsed marketing simply because they searched for dining options.
Cost depends on the restaurant’s size and existing systems. As at 28 September 2026, a small independent venue may budget from roughly $30 to $500 Australian dollars per month for a compliant cloud CRM or booking tool, but pricing varies by users, bookings, features and transaction volume. A focused privacy review, policy and operational setup may cost approximately $2,500 to $15,000, while a broader legal audit involving contracts, CCTV, state-law issues and a complex POS environment can range from $10,000 to $50,000 or more. Staff training may be delivered inexpensively internally or through a short external engagement. These are planning ranges rather than legal or regulatory fees, and prices should be confirmed by quotations.

A SaaS provider’s low subscription price can still create a high compliance cost if staff must manually correct data, reconcile multiple exports or remove an individual from several systems. Evaluate total operating cost, migration effort, data portability, support response times, security features, Australian support and deletion commitments. The cheapest option is not necessarily the one with the lowest monthly invoice.

## When an Australian restaurant should act and keep checking compliance

An operator should prioritise action when it first collects identifiable booking, staff, loyalty or CCTV data; when it migrates from paper to a digital system; or when it starts sending promotions, accepting online orders or connecting a delivery app. Growth, a new branch, a franchise arrangement or a change in corporate ownership also changes the information flows and may affect which entity is responsible. A venue approaching the federal turnover threshold should obtain a current analysis before the financial year closes because the method and the legal structure matter.

A practical timetable is to complete a data inventory in the first 30 days, assign a responsible manager within 60 days, and review major vendors, retention settings and user access within 90 days. Policies should be reviewed at least annually and whenever a new system, camera, overseas provider or marketing channel is introduced. Staff need short training at onboarding and a refresher when the rules change. The restaurant should test how it would delete a customer’s record, revoke a former staff member’s access and respond to a misdirected email or lost device.

There is no universal “compliance certificate” that proves an Australian restaurant follows the Privacy Act. Claims of certification should therefore be treated cautiously unless the provider identifies the exact framework, scope and auditing body. A useful assurance statement describes the controls actually in place, such as multi-factor authentication, role-based access, breach-notification commitments, data location, retention limits and independent testing. For a local-discovery SaaS vendor, these are also the questions a restaurant should ask before allowing access to customer or merchant information.

If a complaint, loss, data breach or regulator inquiry occurs, the restaurant should preserve relevant evidence, stop unnecessary processing, involve responsible staff and obtain qualified advice. It should not destroy records merely to reduce disclosure, and it should not promise a particular regulatory outcome before the facts are assessed. Legal advice becomes particularly valuable where the restaurant is close to a turnover threshold, handles health information, operates across states, records extensively, uses overseas processors or faces a serious breach.

Compliance is a continuing operating discipline rather than a one-time website change. A well-run restaurant can meet its obligations with a small number of documented controls, but complexity rises quickly with loyalty programmes, automated marketing, multiple locations and third-party platforms. As at 28 September 2026, the safest approach is to keep personal information to what the dining operation genuinely needs, make the relevant rules understandable to staff, and maintain a clear record of who can access each system and why.

## Quick answers

### Does a small restaurant with turnover below $3 million have no privacy obligations?

Not necessarily. The federal turnover test depends on incorporation and trading-entity structure, and state or territory private-sector privacy laws may apply below the federal threshold. Contracts, employment duties, surveillance requirements and the Spam Act 2003 can also create obligations.

### Can an Australian restaurant collect customers’ dietary information?

Yes, when the information is reasonably necessary and appropriately protected for a legitimate dining or safety purpose. It should not be copied into general marketing records, exposed to unrelated staff or retained longer than needed. Health information requires particular care and a clearer assessment of access, security and applicable privacy rules.

### Is CCTV allowed in an Australian restaurant?

CCTV can be used where the purpose and means are reasonable, lawful and consistently disclosed, and access and retention are controlled. A notice, authorised viewing process and automatic deletion schedule are stronger controls than simply purchasing a camera. Audio recording, private areas and disclosure of footage need additional scrutiny.

### Does a restaurant need consent before adding diners to email marketing?

For commercial electronic marketing, the Spam Act 2003 generally requires consent, with a limited exception for messages sent in response to an inquiry or in relation to an existing commercial arrangement when the sender is identified and provides an easy unsubscribe. A privacy notice or booking is not automatically marketing consent.

### What should a restaurant do after a suspected data breach?

It should contain the incident where possible, preserve evidence, investigate the affected information and notify the OAIC and affected individuals when the applicable threshold is met. Under the Notifiable Data Breaches scheme, qualifying breaches must be assessed promptly, and regulator notification is required within 72 hours after the organisation becomes aware of the circumstances.

Canonical: https://nolemon.io/knowledge/what_are_the_australian_privacy_rules_for_restaurants_in_2026.php
Markdown: https://nolemon.io/knowledge/what_are_the_australian_privacy_rules_for_restaurants_in_2026.php/index.md
