Use cases
RGPD in a restaurant: the 9 documents you need
General information about the law. It’s no substitute for a lawyer’s advice or a look at your specific case.
A bar or restaurant in Spain needs, as a minimum, 9 data protection documents: a record of processing activities, the information clause for customers, the sign and the information about the cameras, the contract with the suppliers that touch your data (the TPV card terminal, online bookings, the gestoría that keeps your books), two documents for each employee, the information about the working time record, the marketing consent and the retention policy. They can be completed in about 15 minutes by answering questions about your own business. Here are all 9, one by one, with the official sources (AEPD, BOE, EUR-Lex) and no technical jargon.
Last reviewed: 16 July 2026. Author: Tranquilia by GRAC SA.
Contents
- Why does a small restaurant need this paperwork?
- Document 1 — The record of what you do with the data (RAT)
- Document 2 — The information for your customers
- Document 3 — The camera sign (if you have cameras)
- Document 4 — The contract with your TPV, your booking software or your gestoría
- Documents 5 and 6 — What every employee signs
- Document 7 — The working time record: is it data protection too?
- Document 8 — The permission to send offers by WhatsApp or email
- Document 9 — How long you keep each piece of data
- The 9 documents at a glance
- What happens if you don't have them?
- Frequently asked questions
Why does a small restaurant need this paperwork?
A restaurant handles more personal data than it looks: its customers' data (bookings, invoices, sometimes allergies or preferences), its employees' data (payslips, working hours, sometimes camera footage) and its suppliers' data. The RGPD does not exempt small businesses. It applies to a neighbourhood bar just as it does to a chain.
You do not need a legal department. You need 9 specific documents, most of them one page long, written with your business's real data.
Hospitality is not a minor sector for the authority that polices this in Spain, the AEPD (Agencia Española de Protección de Datos, Spain's data protection authority). According to its own 2025 activity report, the Agency closed 326 proceedings with a fine that year (compared with 281 in 2024), for a total amount of 48,108,765 €. Two out of every three euros in penalties were concentrated in three types of infringement: internet services, retail and hospitality, and security breaches. You will see this further down with a real, sourced case, without dramatising it: the aim of this article is for you to have your paperwork in order, not for you to be afraid.
Document 1 — The record of what you do with the data (RAT)
This is the base document. In technical language it is called the Registro de Actividades de Tratamiento (the record of processing activities), but it is, quite simply, your list of the data you handle and what for (art. 30 RGPD). A restaurant usually has at least 3-4 lines on that list: customers, employees, suppliers and, if it has cameras, video surveillance.
For each line you write down: what data you process, what for, on what legal basis, how long you keep it and who you pass it on to (for example, your gestoría or the booking platform). It is the first document because the others rest on it.
Document 2 — The information for your customers
Every time you ask a customer for data (a booking by phone or on the web, an invoice with a NIF, a loyalty card record) you have to tell them, briefly, what you do with that data (art. 13 RGPD). This is called a cláusula informativa (an information clause) and it usually has two layers:
- A short sentence on the form or the invoice itself: who you are, what you use the data for and where to find fuller information.
- A more complete text, linked or available on the premises, with all the details.
If you have a website with a booking form, a newsletter or a WhatsApp button, each of those entry points needs its own clause, adapted to what you actually do there.
Document 3 — The camera sign (if you have cameras)
If you record images of customers or employees — the camera at the entrance, the one at the till, the one in the dining room — you have two obligations that go together:
- A visible sign in the recorded area, using the AEPD's official template (the existence of the video-monitored area, who the controller is and where to exercise your rights).
- Noting the camera down in your register (document 1) and having the fuller information available for anyone who asks for it.
Here it is worth being careful about the framing. A real case: in 2022, the AEPD fined a restaurant 20,000 € for recording sound and images in the employees' rest area — a space where the camera is not justified as a security measure for the business — (source: FACUA, see the sources at the end). The AEPD's general rule is simple: the camera watches over the business (entrances, till, storeroom); it does not spy on the people who work or eat in it.
Document 4 — The contract with your TPV, your booking software or your gestoría
Any outside company that handles data on your behalf is what the law calls an encargado del tratamiento (a data processor): your gestoría when it runs the payroll, your TPV (point-of-sale) provider, the online booking platform, the company that runs your delivery page. With each of them you need a contrato de encargado del tratamiento (art. 28 RGPD) setting out what it may do with that data and what it may not.
You do not have to negotiate it from scratch: most of these suppliers already have their own model contract available to sign or accept online. Your job is to identify everyone who touches your business's data and to have the contract signed with each of them.
Documents 5 and 6 — What every employee signs
Every person who works with you signs two short documents when they join:
- The employment information clause: what data of theirs you process (payslip, working hours, sometimes their image) and what for. It goes as an annex to the employment contract (art. 13 RGPD).
- The confidentiality undertaking: the agreement not to tell anyone what they see at work — customer data, recipes, the business's figures — (duty of confidentiality, art. 5 LOPDGDD).
If the employee appears in photos for social media, you need a third, separate piece of paper: their image consent, separate and voluntary, which they can withdraw whenever they want.
Document 7 — The working time record: is it data protection too?
Yes, even if it does not look like it. Since 2019 every company, whatever its size, has been obliged to record the start and finish time of each worker (art. 34.9 of the Estatuto de los Trabajadores, Spain's Workers' Statute, introduced by Real Decreto-ley 8/2019). That record holds personal data, so it also goes on your list in document 1.
A practical warning: the AEPD has published a specific guide on clocking in with a fingerprint or other biometric data. It considers them sensitive data and requires the business to show that there is no other reasonable way of recording working time before using them. If you can clock in with a card, a PIN or an app, that is the option with the least paperwork and the least risk.
Document 8 — The permission to send offers by WhatsApp or email
If you want to tell your customers about a promotion, an event or the dish of the day by WhatsApp, SMS or email, you need their explicit and specific permission for that: a box the customer ticks themselves, never pre-ticked, and which they can untick whenever they want. This consent is different from the one you use to handle a booking or an invoice: one does not replace the other.
Keep a record of when and how they gave it (the date, the form, the exact wording they accepted). It is your proof if anyone ever asks you for it.
Document 9 — How long you keep each piece of data
The last document is your retention policy: how long you keep each type of data before deleting it. In Spain there are legal periods that already set the minimum: invoices, for example, are kept because of tax and commercial law obligations (check with your gestoría the exact periods that apply to your case, as they vary depending on the type of document). The data of a customer who never comes back, or of a CV you did not hire, is not kept "just in case": it is deleted when it is no longer needed.
The 9 documents at a glance
| # | Document | What for? |
|---|---|---|
| 1 | Record of processing activities (RAT) | Your list of what data you handle and what for |
| 2 | Information for customers | Clause on bookings, invoices and website |
| 3 | Sign + cameras on the record | If you record images inside the premises |
| 4 | Contract with suppliers (TPV, bookings, gestoría) | Sets what they can do with your data |
| 5 | Employment information clause | Annex to each employee's contract |
| 6 | Confidentiality undertaking | Signed by each employee |
| 7 | Information about the working time record | Clock in with a card, PIN or app, not biometrics unless justified |
| 8 | Marketing consent | Specific box for WhatsApp, SMS or email |
| 9 | Retention policy | How long you keep each piece of data |
What happens if you don't have them?
The reality, without dramatising: the AEPD is the body that polices this in Spain and it can ask for explanations, order changes or impose a fine. The case of the restaurant fined 20,000 € that you saw in document 3 is not some rare exception: the AEPD's 2025 report places "retail and hospitality" among the three types of infringement that account for two thirds of the amount fined that year.
In practice, most proceedings against small businesses start with a complaint from a customer or an employee, not with a random inspection. Having these 9 documents in order is not just complying with the law: it is having a clear answer to hand if anyone ever asks.
Frequently asked questions
Does a bar with a single employee need all 9 documents just the same? Yes, although some of them are shorter. If you have no cameras, you skip document 3. If you do no marketing by WhatsApp or email, you skip document 8. The rest apply from the first employee onwards.
Is it enough to copy a template from the internet? A generic template does not mention your NIF, your actual suppliers or your specific cameras, so it is no good as it stands. It works as a starting point if you adapt it with your business's data.
Who can help me fill this in? Your gestoría, if it does your accounts, is the best placed: it already knows your tax and employment data. You can also generate them yourself by answering a guided questionnaire about your business.
Does this also apply to a food truck or a catering business with no fixed premises? Yes. What determines which documents you need is not the premises but what data you process: if you have customers, employees and suppliers, the same 9 documents apply, adapted to the way you work.
Do you want to generate these 9 documents with your restaurant's real data? Tranquilia has a guided questionnaire designed for hospitality: simple questions, no jargon, ready in about 15 minutes. You can see it in the use case for restaurants.
Report produced for information purposes. It does not constitute individual legal advice: for your specific case, consult your gestoría or a specialist lawyer.
Review: Written with AI assistance from official sources (AEPD, BOE, EUR-Lex), checked article by article before publication. See the editorial policy. Translation of the Spanish original, which prevails in case of divergence.
Get your clients GDPR-compliant in 15 minutes.
No card, no sales calls. Two companies free, for as long as you like.