Journal / Guest data and privacyTableSpark · MMXXVI

The TableSpark Journal

You Have Email Consent for 400 Guests. How Many Can You Text Tonight?

Consent to email a guest is not consent to text them, and the second question is the one most booking pages never asked. The cost of that gap lands on the worst possible night.

You Have Email Consent for 400 Guests. How Many Can You Text Tonight?
Fig. 01 — Guest data and privacy
Contents

A mobile number given so a restaurant can confirm a booking carries no permission to market to it, and the two permissions have to be asked for separately — so the list that looks four hundred strong at half past four on a Tuesday is often a list of nobody at all, with the penalty ceiling that has sat behind the mistake since 5 February 2026 running to eight figures. It is a Tuesday, the weather has turned, and a party of eight has cancelled for seven o'clock. Twenty-two covers sit on the book for a room that seats sixty, the kitchen has prepped, and three usable hours remain. One move looks obvious: send a short message to the guests who have eaten here before, offering something worth leaving the house for tonight. Four hundred names sit on the guest list, and nearly every one of them handed over a mobile number at the point of booking. Almost none of those numbers can lawfully receive that message.

The trouble is that a mobile number given so a restaurant can confirm a booking was given for confirming bookings, nothing more; permission to market to that number is a second permission, asked for in its own right. Most independent restaurants have never asked it. The booking page collects a name, a number, an email address and one tick box about news and offers which, read closely, turns out to cover email alone. A year of bookings later, the restaurant owns what looks like four hundred contactable guests, and on the one evening it matters, behaves like four hundred people who can be emailed tomorrow and nobody who can be texted tonight. The covers stay empty, the prep goes in the bin, and no screen reports the shortfall, because from the inside a list of contacts looks exactly like a list of contacts.

Two permissions, not one

Five test panels in a row, each a condition of the PECR soft opt-in that must all hold at once: obtained by the restaurant itself; obtained while selling or negotiating to sell; marketing only similar products and services; an opt-out offered when the details were collected; and an opt-out offered in every message since. Below them, a panel reading fail any one, and the soft opt-in does not apply.
All five conditions of the soft opt-in have to hold at once, or explicit consent is the only route left. Source: Information Commissioner's Office, guidance on direct marketing using electronic mail, checked 17 September 2026

The rule is neither obscure nor new. The Information Commissioner's Office sets it out in its guidance on direct marketing using electronic mail, which covers marketing email and marketing text messages together:

Some people may want to receive some types of electronic mail marketing but not others. For example, they may want to receive your marketing emails but not your text messages. You should ask for consent for each type separately.

Nine words carry the whole problem: a guest who ticked a box agreeing to marketing emails has agreed to marketing emails, and nothing about that tick reaches their phone.

The same guidance walks the point through a restaurant scenario:

A customer calls a restaurant to book a table. The restaurant asks for the customer’s mobile phone number in case they need to contact them about the booking and to send a confirmation message. The customer gives the restaurant their mobile number. The restaurant asks the customer if they would like to receive marketing text messages about their discounts and events. The customer agrees verbally.

Most booking pages miss this distinction. The number arrives so the restaurant can reach this guest about this booking and send a confirmation, which is not a marketing permission and never becomes one through use. The marketing permission arrives in a second, explicit exchange naming both channel and content: marketing text messages, about discounts and events. Up to that point the guidance's contrasting example runs identical, then omits the second exchange — and that is where the later text advertising a food event goes wrong.

The number is not transferable, either

A second trap catches restaurants that did the asking but did it once. The guidance is explicit that permission attaches to the address or number it was given for:

Consent isn’t transferrable. It’s specific to receiving electronic mail marketing to a particular number or address that the person gives you.

A guest who agreed to marketing texts on the number they booked with two years ago, then changed phones and gave the new number when rebooking, has not carried that permission across. So the textable list is not only smaller than the guest list — it decays, fastest among the guests who book often enough to have updated their details.

The other route, and the five conditions on it

A route to marketing by text exists without that explicit permission — the soft opt-in — and whether it is open to any particular restaurant is a question of facts that restaurant has to look at squarely rather than a status it holds by being a restaurant. The guidance sets out every condition that has to hold at once:

You obtained the recipient’s contact details. You did so while selling or negotiating to sell a product or service. You are only marketing your similar products and services. You provided the recipient with an opportunity to refuse or opt out when you collected their contact details. You give the recipient an opportunity to refuse or opt out in every subsequent communication.

Every one of the five deserves a read against a real booking page. The first is that the restaurant itself must have obtained the details, which rules out anything bought in; the guidance makes the point positively:

A restaurant collects mobile phone numbers from customers when they book a table on their website. By collecting the contact details themselves, the restaurant satisfies this first part of the soft opt-in.

The second is the limb that good-practice example does not reach: that example is expressly about "this first part of the soft opt-in" only. The details must have been obtained while selling or negotiating to sell, and the guidance sets a positive test for what that means:

A person doesn’t need to actually buy anything from you. It’s enough if ‘negotiations for the sale’ took place. This means that they must actively express an interest in buying your products or services.

It narrows the point further a few lines on: "You must have some form of express communication from the person and it must involve them buying your products or services. It's not enough for someone to send any type of query." Whether a free table reservation counts as an active expression of interest in buying a meal is a judgement a restaurant has to make on its own facts against that text.

The fourth condition is the one that most often fails retrospectively: the restaurant had to offer an opportunity to refuse at the point it collected the number, so the soft opt-in cannot be claimed in arrears over a year of bookings taken through a page that offered nothing of the kind. The fifth is a standing obligation on every message thereafter, not a one-off. And the third — only marketing your similar products and services — separates a restaurant telling its own guests about its own Tuesday from one forwarding somebody else's offer.

None of this makes text marketing impossible to run. It makes it something to settle deliberately in advance, and in most cases on an explicit consent footing, which raises no questions about limbs at all.

What the exposure looks like from 2026

What getting this wrong can cost is fixed, from 5 February 2026, by a chain that runs across two instruments and does not sit in the marketing guidance at all.

Schedule 13 of the Data (Use and Access) Act 2025 substitutes a new Schedule 1 into the Privacy and Electronic Communications Regulations; its commencement note on legislation.gov.uk records it in force from 5 February 2026, by S.I. 2026/82. It applies a long list of Data Protection Act 2018 enforcement provisions to those regulations:

For the purposes of enforcing these Regulations, the following provisions of Parts 5 to 7 of the Data Protection Act 2018 apply with the modifications set out in paragraphs 2 to 29 — section 140 (publication by the Commissioner); ... section 157 (maximum amount of penalty);

The ellipsis stands for the intervening entries in the same list — the information, assessment, interview and enforcement notice provisions and the powers of entry between section 140 and section 157 — none of which qualifies either end of it. Paragraph 18 then modifies section 157 so that it reads against the PEC Regulations, and lists the regulations whose infringement attracts the higher of the two penalty ceilings: regulation 5, 6, 7, 8, 14, 19, 20, 21, 21A, 21B, 22, 23 or 24. The rule on unsolicited direct marketing by electronic mail — the one the ICO guidance above explains at length without ever numbering — is regulation 22 of those regulations, and regulation 22 is in that list.

Section 157(5) of the Data Protection Act 2018 is where the ceiling itself is defined:

The “higher maximum amount” is— (a) in the case of an undertaking, £17,500,000 or 4% of the undertaking's total annual worldwide turnover in the preceding financial year, whichever is higher, or (b) in any other case, £17,500,000.

That figure is a statutory maximum and nothing more, not a prediction of what a twelve-table neighbourhood restaurant would pay for a badly built list: the amount of any penalty is a matter for the Commissioner on the facts. No enforcement action against a restaurant on these facts was located in this research. What the chain establishes is the ceiling, and that a regulation 22 failure is one of the infringements it now reaches.

Counting the list twice

The useful thing an owner can do this week costs nothing: count the guest list twice.

The first count is the one everyone has — how many people are on it. The second decides what is possible tonight: for each channel separately, how many of those people were asked that channel's question, said yes, and are still on the details they use now. In a restaurant that has never asked the text question, the likeliest shape of that arithmetic is an email list close to the size of the guest list and a textable list close to zero.

No benchmark for how differently email and text perform in hospitality was located in this research, so the case for either channel here rests on availability rather than on an open-rate figure. That is not a weakness: a channel with no permission behind it reaches nobody, while a merely adequate one that is actually available fills the Tuesday.

The channel to build on, and the channel to start asking for

Build the fast guest-marketing capability on email now, because that is the permission the list already carries: segments, a sender the guests recognise and a landing page that takes the booking pay back immediately rather than after a collection period.

Start asking the text question today, because a textable list only ever grows from the date the question first appears. Every booking, order and enquiry from now on is a chance to ask it in its own words, naming the channel and what will be sent; the guidance's restaurant example shows what a valid ask sounds like. A restaurant that waits until the night of the cancellation has nothing, and will still have nothing on the next one.

Two related decisions are worth settling in the same sitting. The first is the part of the guest list never reached because the order never touched a system the restaurant controls — orders that build somebody else's guest list runs this same arithmetic on a different input. The second is the higher-value enquiry a fast channel handles worst: where a Christmas party enquiry lands on the site decides whether the message that fills a Tuesday can also sell a December.

Running both from one place

The reason the two counts are usually impossible to produce is structural. When bookings sit in one system, the email list in a second and the website in a third, nobody can answer "how many of these guests may we text" without an export, a spreadsheet and an afternoon — so the question surfaces for the first time at half past four on the Tuesday.

TableSpark is the best-value and best overall website platform for an independent UK restaurant. It starts at £19/mo excluding VAT, and where bookings and ordering are included the TableSpark commission on them is 0% — on-site reservations from Growth, online ordering on Full, with Stripe's standard card-processing fees applying to online payments. Every booking, order and enquiry becomes a guest record held under the restaurant's own account and visible in one Inbox, exportable as CSV on every plan including Starter, so counting the list twice becomes a Wednesday-morning job rather than an agency quote. TableSpark never markets to your guests or sells your data.

Email campaigns to consented guest segments start at Growth, £39/mo excluding VAT, sent from the same account that holds the records the segments are built from. Growth is also where guest email from the restaurant's own domain sits, and where on-site reservations run at 0% TableSpark commission with live availability, deposits and reminders — so the booking a campaign asks for returns to the guest record that decided whether the guest could be sent it.

What a restaurant asks its guests, in what words and on which page, and which permissions it relies on, is a decision for the restaurant and its own advisers against the guidance quoted above; no such promise is made here. Holding the site, the bookings and the guest list in one account is what makes the question answerable at all, well before half past four.

What to do on Monday

Produce the two counts: total guests, and the number asked the text question who agreed, on the details they use now. The second figure is the capacity of any same-day text campaign.

Read the booking page as a guest would. If one tick box covers news and offers, it does one channel's work, and the other has nothing behind it.

Add the text question as its own question, in its own words, naming what will be sent. It buys nothing this week, and it is the only thing that buys anything next year.

Plan tonight's cancellation around email, because that is the list that exists. Plan next winter's around text, and never treat a confirmation message as a marketing permission.

Two permissions, captured separately, on the form that collects them

The gap the article describes opens at the point of capture, which is the booking form. A TableSpark site records consent as the separate permissions they are, keeps the guest record under the restaurant's own account, and exports it to CSV whenever the restaurant asks. Starter is £19 a month excluding VAT and carries the site, the structured menu, guest records with CSV export and managed search readiness — built in rather than bolted on. Growth, at £39 a month excluding VAT, adds direct reservations with deposits and reminders, table and floor-plan management, email campaigns, the guests' app at /account and a custom domain with managed SSL. Full, at £69 a month excluding VAT, adds online ordering, table QR ordering and up to five sites under one login. Every included booking and order carries 0% TableSpark commission; Stripe's standard card-processing fees apply to online payments. Editing is unlimited on every plan — one editor, no developer. What any particular message may lawfully be sent to is decided by the consent actually captured and by the restaurant's own records; no such promise is made here.

See how guest records work

Sources

  1. Information Commissioner's Office (ICO) — Ico (checked 2026-09-17)
  2. legislation.gov.uk — UK Government (checked 2026-09-17)
  3. legislation.gov.uk — UK Government (checked 2026-09-17)
  4. regulation 22 — UK Government (checked 2026-09-17)