Bookings, menus, online ordering, search. Written by the people building the product, between services.
A fingerprint clocking-in terminal turns payroll admin into special category data. Consent can make it lawful — but only where refusing costs a member of staff nothing.
A regulator can now disable a restaurant's website and impose a penalty without a court case, while the diner's own right sits on a saving with a condition, not a date.
The posting duty on a hygiene notice stops at the door; whether it reaches the ordering page behind it is untested, and getting it wrong risks a second offence.
Repackaging draught beer for takeaway leaves an unpaid duty difference and a forfeiture risk an ordinary pint at the bar never triggers — and the rate has moved twice since 2023.
A DNS record left pointing at a cancelled supplier is, on how shared platforms generally work, claimable by a stranger — and the security risk stays with the restaurant.
A loyalty form's date-of-birth field is the easy part — sending the birthday message afterwards is where restaurants risk a live PECR breach.
A vendor's ransomware notice can start the restaurant's own 72-hour clock and its own liability risk — being hacked by proxy is not, on its own, a defence.
Too small for a staff accident book doesn't mean too small to report a guest's injury — and the record it creates is its own compliance risk.
A copied menu listing raises two different property-right tests and a separate, unsettled liability question — confusing them leaves the exposure with you.
A plate that counts as exempt packaging in England has no exemption in Wales, where it carries a penalty — and a straw needs a declared health reason, not a simple request.
A business sale does not move the alcohol licence, a death or insolvency starts a 28-day clock, and a stale “fully licensed” claim now risks a fine.
Existing directors get a grace period tied to their next filing — but one already overdue on 18 November 2025 forfeited it on 2 December, at real legal exposure.