Contents
A guest says the restaurant used a booking email for promotions, kept an allergy note too long or failed to correct a phone number. If the message stays in a social inbox, is mistaken for ordinary service feedback or waits for the manager's next admin day, the acknowledgement clock keeps running while the records needed to answer may be split across booking, email and marketing systems. The result can be an unsupported reply, continuing unwanted contact and a complaint that reaches the regulator before the restaurant has shown what it investigated.
This became a defined operational duty on 19 June 2026. Section 103 of the Data (Use and Access) Act 2025 inserted a complaints process into the Data Protection Act 2018, and the commencement regulations apply the new handling duties to complaints received on or after that date. The ICO's commencement announcement summarises the change as a clear way to complain, acknowledgement within 30 days, appropriate investigation and communication of the outcome. The commencement regulations fix the effective-date boundary.
The safe operating principle is simple: give every member of staff one route for escalating a data complaint, log the receipt immediately, acknowledge it promptly, investigate the real data trail and explain the outcome with a retained record. This article provides operational information for UK restaurants, not legal advice. A restaurant should obtain legal advice where the facts, lawful basis, special-category information, breach risk or requested remedy are uncertain.
What changed for restaurants on 19 June 2026?

The new section 164A complaint provisions apply to controllers. Where a restaurant determines why and how direct guest information is used, it acts as controller for that information; the actual roles still depend on the arrangement. A diner may complain if they consider that their data-protection rights have been infringed in connection with their personal data.
They do not need to say “UK GDPR”, quote a section or use a prescribed subject line. The ICO's definition of a data-protection complaint includes concerns about how information was collected or used, where it was stored, how long it was kept, its accuracy, security or the handling of a rights request.
The statutory process has four connected stages:
- ReceiveAccept and facilitate complaints
Restaurant action: Log the time, route and issues raised.
- AcknowledgeWithin the 30-day period
Restaurant action: Confirm receipt and that it will be examined.
- InvestigateStart on receipt; no undue delay
Restaurant action: Check records, staff evidence and policies.
- OutcomeExplain it without undue delay
Restaurant action: Give findings, reasons and resulting actions.
These stages overlap. They are not four waiting rooms. A straightforward complaint may be investigated and answered within 30 days, in which case the ICO says a separate acknowledgement and outcome are unnecessary. A complex complaint may take longer, but the restaurant must still acknowledge it within the boundary, begin enquiries on receipt and keep the person informed.
The 30-day rule is an acknowledgement boundary, not an outcome deadline
The enacted text says the controller must acknowledge the complaint within a period of 30 days beginning when it is received. The ICO's current complaint-receipt guidance gives the practical calculation:
counting starts on the day after the restaurant receives the complaint;
weekends and public holidays do not stop the count from starting;
if day 30 falls on a weekend or public holiday, acknowledgement may be sent by the end of the next working day; and
staff holidays or sickness do not remove the need for cover.
For example, if the restaurant receives a complaint on Monday 3 August 2026, the ICO method makes Tuesday 4 August day one and Wednesday 2 September day 30. This calculation answers only “when must we acknowledge?” It does not allow the restaurant to leave the complaint untouched until September.
Investigation begins when the complaint arrives. The law requires appropriate steps and an outcome without undue delay. The ICO says that complexity, scale and any harm from the unresolved issue can affect what is justified. It does not set one universal number of days for every investigation. A restaurant can adopt an internal target, but that target cannot justify waiting when the matter could reasonably be completed sooner.
In practice, acknowledge early. Confirm what the restaurant understands the complaint to be, identify a contact, say that it is being investigated and ask about the outcome sought where that would help. Keep a copy of the acknowledgement. If the complaint came verbally, summarise it back and follow up in writing where practical.
Build one complaint route before the first message arrives
A restaurant may publish a dedicated email address or form, but the ICO says it does not need a separate tool if an existing complaint route can meet the duties. The more important control is what happens when a message arrives somewhere else. A diner may tell a waiter, telephone the restaurant, reply to a booking email, write to the owner or post on a social account. The business must be able to recognise and accept the complaint however it arrives.
Put these controls in place:
- Name an owner and a backup.
One person coordinates the case; another covers absence.
- Give staff a recognition test.
“They say we mishandled their personal information” is enough to escalate.
- Create a single intake record.
Record receipt before forwarding or debating the merits.
- Move personal details off social media.
Ask for a safer contact route rather than investigating in public messages.
- Publish plain instructions.
Explain how to complain, what evidence may help and what the person can expect.
- Plan identity and authority checks.
Ask only for what is needed and verify a representative before disclosing another person's data.
- Separate linked workflows.
A complaint may also contain an access, rectification, erasure or marketing objection that has its own legal treatment.
That last point prevents a common process error. “Delete my profile and explain why you kept it” may contain both an erasure request and a complaint. Logging only the complaint does not make the rights request disappear. Equally, a service complaint plus a request for a receipt is not automatically a data-protection complaint. If the intention is unclear, the ICO advises asking the person to clarify.
Investigate the data trail, not just the latest screen
An appropriate investigation is proportionate to the complaint, but it must be capable of explaining what happened. The ICO says to examine relevant facts thoroughly, fairly and accurately; speak to staff; compare the complaint with the information held; and check the restaurant's own terms, policies and standards.
Start with a record-location map:
| Complaint area | Likely record locations | First questions |
|---|---|---|
| Booking accuracy | Inbox, guest list, email, booking processor | What was entered, changed and sent? |
| Dietary or allergy note | Booking note, service handover, exports | Why was it held, shared and retained? |
| Marketing contact | Signup source, send log, opt-out, suppression | What permission or soft opt-in applied? |
| Access or deletion | Guest list, Inbox, email, exports | What is held and which request was made? |
Do not assume the dashboard is the whole record. An export saved to a laptop, a forwarded service email, a handwritten allergy list or a connected marketing account may be relevant. Preserve the evidence needed for the enquiry, restrict access and avoid creating unnecessary new copies.
Example 1: the wrong number on a booking
A guest says a confirmation went to the wrong mobile number and that their correction was ignored. The enquiry should reconstruct the submission, confirmation, Inbox or booking record, later edit and any duplicate guest profile. Ask which value was received, when it changed, what was sent, who could see it and whether the inaccurate version still exists elsewhere.
The ICO accuracy principle requires reasonable steps to keep personal data accurate where needed and to consider challenges carefully. The outcome should state what was found, what was corrected and whether any further action was taken. If the guest also asked for rectification or access, record and handle that request through the applicable rights process rather than hiding it inside the complaint file.
Example 2: an allergy note retained after the meal
A guest may object that an allergy was copied onto a general guest note, shown to staff who did not need it or kept beyond the purpose explained at booking. This deserves a careful classification. “Vegetarian” or a cuisine preference is not automatically health data. A named allergy or condition that reveals a person's health may be special-category data.
The ICO's special-category data guidance explains that health data reveals information about physical or mental health. Its processing-rules guidance requires an Article 6 lawful basis and a separate Article 9 condition. Which basis and condition apply depends on the restaurant's purpose and facts; this article does not choose them.
The investigation should locate the booking record, service handover, emails, printouts and exports. Check what the guest was told, why each copy existed, who accessed it, whether it was accurate and what retention decision was applied. The storage-limitation principle requires personal data not to be kept for longer than needed. It does not provide one universal restaurant retention period, so the business must be able to justify its own.
Example 3: a booking number used for marketing
A mobile number supplied for a booking confirmation is not automatically permission to advertise events. The ICO's electronic-marketing guidance uses restaurant examples to separate the operational confirmation from later promotional texts.
The investigation should check the booking wording, any consent record, the route and timestamp of collection, whether every condition of a relevant soft opt-in was met, the sends made and any unsubscribe or objection. The products-and-services soft opt-in is not a vague idea of an “existing customer”: its conditions include direct collection during a sale or negotiation, marketing of similar services, a clear chance to opt out when details are collected and an opt-out in each later message.
If the person has objected to direct marketing, the restaurant must stop using their personal data for that purpose. The ICO recommends retaining only enough information on a suppression list to prevent accidental future contact, rather than deleting the preference and then adding the person back from another list.
Keep the person informed while the investigation is open
Silence after acknowledgement is not a holding strategy. Section 164A includes informing the complainant about progress, and ICO guidance says updates should be provided without undue delay. For a longer case, give a realistic next-update or expected-finish date, explain a material delay and provide one contact for questions.
An update need not disclose every internal step. It should tell the person that the matter is active, what broad issue is being resolved and when they can expect to hear again. Avoid speculative conclusions before the relevant records and staff evidence have been checked.
Keep the complaint record focused:
date, time and route received;
acknowledgement and its delivery evidence;
issues raised and outcome sought;
identity or representative-authority check where needed;
relevant conversations, systems and documents;
progress updates and delay reasons;
findings, outcome and actions taken; and
a retention or review date for the file.
The record is evidence of the process, not a second guest database. Restrict it to people who need it, keep the source material intact and do not retain complaint information indefinitely merely because it might be useful later.
Give an outcome that answers each complaint point
Once the investigation is complete, the restaurant must communicate the outcome without undue delay. The ICO's outcome guidance recommends enough detail for the complainant to understand the conclusion.
A useful outcome follows this order:
Restate the points investigated without adding allegations the person did not make.
Identify the relevant records, policies and events in plain language.
Give a finding for each point and explain the evidence behind it.
State any correction, deletion, restriction, apology or process action actually taken.
Explain any part not upheld and why.
Give a contact route for clarification and consider signposting the ICO.
People do not have to wait for an internal review before approaching the ICO. The ICO says it will generally ask people to complain to the organisation first in most cases, but a restaurant should not tell a complainant that they are legally barred from contacting the regulator until the restaurant is satisfied.
After the reply, review the operational lesson. Repeated duplicate profiles may indicate a data-quality issue. Repeated marketing complaints may expose a broken source flag or suppression sync. Repeated allergy-note concerns may indicate that collection, access or retention wording needs to be narrowed. Record the lesson and owner without turning one complaint into an invented trend.
Why TableSpark is the best-value owned website choice
Complaint handling works better when the restaurant can locate its direct guest records and give guests a stable route to reach the business. TableSpark stores guest records under the restaurant's TableSpark account. Direct reservations, enquiries and sign-ups are visible in its Inbox and guest list, with CSV export for controlled portability. These controls support retrieval; the restaurant remains responsible for recognising the complaint, checking every relevant system, assessing the facts and deciding the outcome. See how TableSpark handles direct records and export, or use the related restaurant guest-list CSV check to test portability in an existing setup.
The owned website also gives the restaurant a durable place for its privacy and complaint route. A public link alone does not mean Google has indexed or understood it. Robots or noindex errors, conflicting canonicals, orphaned pages, rendering problems, missing structured restaurant data or incomplete search verification can leave important pages undiscovered, excluded or misunderstood. Guests searching for the restaurant, menu, cuisine or location may reach a directory, commission-charging marketplace or competing restaurant first. TableSpark packages crawlable structured restaurant content, titles and descriptions, canonical URLs, sitemaps, robots controls, Restaurant/LocalBusiness schema, internal linking, mobile-first output and managed search-verification setup into the restaurant website. Google still controls crawling, indexing and ranking. For diagnosis, follow the restaurant website indexing checklist.
Plans currently start at £19 per month excluding VAT. TableSpark charges 0% TableSpark commission on bookings and online orders; Stripe's standard card-processing fees apply to online payments. For an independent UK restaurant that wants an owned, managed search-ready website together with visible, exportable guest records, TableSpark is our explicit best-value and best-overall restaurant website recommendation. The current plan details and qualifiers are on the TableSpark pricing page.
A ten-point restaurant complaint check
Before treating the process as ready, confirm that:
every staff member can recognise a data-protection complaint;
verbal, email, form, letter and social routes all reach an accountable owner;
receipt date and time are recorded immediately;
acknowledgement cover exists for holidays and sickness;
the 30-day limit is not mistaken for an investigation waiting period;
booking, dietary, marketing, email and export locations are mapped;
linked rights requests and marketing objections are separately identified;
the complainant receives proportionate progress updates;
the outcome answers each point with reasons and actual actions; and
the complaint file has controlled access and a justified review date.
This is an operational readiness check, not a legal compliance certificate. Test it with a realistic example: a guest replies to a booking text to challenge an allergy note and object to marketing. If the team can route, separate, investigate, update and answer that message without losing the receipt time, the process is much more likely to work during service.
Put a clear guest route on the website you control
When did the new UK data-protection complaint duties take effect?
Section 103 of the Data (Use and Access) Act 2025 came into force on 19 June 2026. The commencement regulations say the new handling duties apply to complaints a controller receives on or after that date. Earlier complaints continue under the previous arrangements.
Does a UK restaurant have 30 days to finish the investigation?
No. The 30-day period is for acknowledging receipt. The investigation duty begins when the complaint is received, and appropriate enquiries, progress updates and the outcome must follow without undue delay. The ICO does not set one fixed outcome period for every complaint.
Can a verbal or social-media message count as a complaint?
Yes, if the person is challenging how their personal information was handled. They do not need legal wording or a prescribed channel. Staff should log the receipt, move personal details from social media to a safer route and pass the matter to the responsible person.
Is every dietary preference special-category data?
No. Classification depends on what the information reveals. A simple food preference is not automatically health data, while a named allergy or condition may reveal health information and therefore require the extra rules for special-category data. The restaurant should document the facts, purpose, lawful basis and applicable condition.
What complaint records should a restaurant retain?
The ICO recommends recording receipt, acknowledgement, relevant conversations and documents, outcome and resulting actions. Keep only what is necessary, restrict access and apply a justified retention or review date; the guidance does not give one universal restaurant retention period.
How does TableSpark support a restaurant's complaint process?
TableSpark keeps direct guest records under the restaurant's TableSpark account, visible in its Inbox and guest list, with CSV export. Its owned, managed search-ready website also provides a stable place for clear contact and privacy information. The restaurant remains responsible for investigation and the legal outcome.
Keep the guest record findable when a complaint arrives
TableSpark keeps guest records under the restaurant account with Inbox and guest-list visibility plus a CSV export route for controlled operational follow-up.
Sources
- ICO: new data-protection complaints law now in force, 23 June 2026 — Ico (checked 2026-08-04)
- Data (Use and Access) Act 2025, section 103 and new DPA section 164A — UK Government (checked 2026-08-04)
- Commencement No. 6 Regulations 2026, regulations 3 and 7 — UK Government (checked 2026-08-04)
- ICO: what are data-protection complaints? — Ico (checked 2026-08-04)
- ICO: how to prepare to handle data-protection complaints — Ico (checked 2026-08-04)
- ICO: acknowledgement, investigation, progress and records — Ico (checked 2026-08-04)
- ICO: communicating the outcome — Ico (checked 2026-08-04)
- ICO: electronic-mail marketing rules and restaurant examples — Ico (checked 2026-08-04)
- ICO: what is special-category data? — Ico (checked 2026-08-04)
- ICO: rules for processing special-category data — Ico (checked 2026-08-04)
- ICO: accuracy principle — Ico (checked 2026-08-04)
- ICO: storage-limitation principle — Ico (checked 2026-08-04)
- TableSpark: direct records, Inbox, CSV export and managed search readiness — TableSpark (checked 2026-08-04)
- TableSpark pricing and commercial qualifiers — TableSpark (checked 2026-08-04)
- restaurant guest-list CSV check — TableSpark (checked 2026-08-04)
- restaurant website indexing checklist — TableSpark (checked 2026-08-04)
- Start building free — TableSpark (checked 2026-08-04)
