What you hold on a guest, how long you keep it and who may ask for it.
Six months after the chef left, the shared password still works, and the register that would say who else holds it is missing.
A departed booking supplier can still hold the whole guest list, and the restaurant that never instructed deletion carries the risk when a guest complains.
Two thousand addresses came off the wifi splash screen, and the Christmas send is booked. A network login is not negotiations for the sale, and the risk sits with the restaurant.
The servers are in London, so the owner stopped worrying. The transfer test is where the supplier is registered, and the wrong answer leaves the restaurant exposed.
A guest asks for the terrace footage after a fall. The recorder overwrites fortnightly, other diners are in frame, and the retention setting can remove the evidence mid-dispute.
A booking from two years ago still holds a name, a phone number and an allergy note. Data kept longer than it is needed is exposure the restaurant chose to keep.
A message on Instagram asks for everything you hold on her. Nobody on the floor recognises it as a request, and days of the statutory month are already lost.
An exposed guest record can leave a restaurant unsure what happened, who is affected and whether the ICO reporting threshold is met.
A restaurant can add one booking embed or advertising pixel and start non-essential tracking before a guest has chosen, leaving banner and behaviour out of step.
A booking email can confirm a table without authorising promotions. Mix the two, and a routine guest record can become a PECR compliance risk.
Booking, dietary and marketing complaints can expose scattered guest records and missed deadlines before a restaurant establishes what went wrong.
A booking form that collects too much or explains privacy too late can leave restaurants with uncontrolled guest records, confused customers and complaints.