In this article
A restaurant data breach isn't an IT problem — it's a legal clock that starts running the moment you find out about it. The instant you know, or reasonably should know, that guest data has been stolen, deleted or exposed to the wrong hands, GDPR gives you 72 hours to notify the supervisory authority. Not 72 hours to fix it — 72 hours to report it.
It rarely starts with an alarm going off. More often it's a guest calling because their card was charged twice, your reservation platform emailing about "unusual activity", or a member of staff finding the till screen full of strange text on a Tuesday morning. At that point the question stops being "how bad is this technically" and becomes "what do I actually do right now" — and most owners don't know the answer, because nobody ever wrote it down.
The exposure is real, and it isn't reserved for big chains. Point-of-sale systems are consistently among the most targeted equipment in hospitality and retail worldwide, precisely because they process card data and often keep running unpatched for years. A small restaurant has no IT department to absorb the hit — which is exactly why cyber insurance, and a written plan for the first 72 hours, matters more here than at a business with its own security team.
This guide walks through exactly that: where your guests' data actually lives, what has to happen in each of the four windows of the 72-hour clock, what a cyber insurance policy typically does and doesn't cover, and — with a calculator built on your own numbers — what a breach could realistically cost your restaurant.
Where your guests' data actually lives
A data breach is any incident where guests' personal data is accidentally or unlawfully lost, altered, or accessed by someone without the right to it — which is far broader than "getting hacked". A laptop left in a car, a booking confirmation emailed to the wrong address, or a POS backup left accidentally public all count just as much as a targeted attack.
Most owners underestimate how many systems they're actually running. Add it up: the POS system holding card data from every transaction, the reservation and CRM system with every guest's name, phone number and sometimes allergies, the loyalty programme with email addresses and order history, guest WiFi with a login portal that often asks for an email, the delivery-platform integration passing along addresses, and the gift-card ledger with codes that are literally worth money. Six systems, six places a leak can start — and in most venues, nobody has ever listed them side by side.
Our guide to guest data and GDPR covers how to collect and use that data legally; our guide to restaurant cybersecurity covers the nine steps that prevent an attack in the first place. This guide covers the moment after: it has already gone wrong — now what?
The 72-hour clock, window by window
GDPR Article 33 requires you to notify the data protection authority within 72 hours of becoming aware of a breach, unless it's unlikely to result in a risk to your guests' rights and freedoms. That clock doesn't start once you understand everything — it starts the moment you reasonably know something has happened. Here's what those 72 hours actually look like.
The 72-Hour Clock
Four windows, walked through once — pin this order up next to your emergency plan
Hour 0–1
- Disconnect the affected device from the network
- Don't wipe or restart anything — evidence stays put
- Change every admin password
- Write down the exact time of discovery
Hour 1–24
- Call your IT provider or a specialist
- Involve your insurer's breach hotline
- What data — names, cards, allergies?
- How many guests could be affected?
Hour 24–72
- Assess the risk with an adviser or insurer
- File the notification with the authority
- Notify even if the risk is uncertain
- Document the decision and its reasoning
After 72 hours
- Notify guests only if the risk is high
- Write the message in plain, clear language
- Restore only from a clean backup
- Report the final scope to your insurer
Only the last column is conditional — the first three apply to almost every breach.
Hour 0 to 1: discover and contain
Disconnect the affected device from the network — pull the cable or switch off the WiFi — but don't turn anything off or wipe anything. Every trace you erase now is a trace your IT provider or insurer won't be able to use later to work out what actually happened.
Change the password on every admin account with access to the POS, the reservation system and your email, immediately. Write down the exact time you discovered it — that timestamp is the start of your 72 hours, and you'll need it on every form that follows.
Hour 1 to 24: assess and document
Call your IT provider, or a specialist service if you don't have one — and call your insurer at the same time if you have a policy: most cyber policies have a breach hotline you can involve from day one, and waiting often costs you exactly the cover you need.
Write down what data may have been involved: just names and email addresses, or also card data and allergy notes? How many guests are in that file? Those two questions — what and how many — decide almost everything that happens over the next 48 hours, so write it down as soon as you know, even if the answer is still incomplete.
Hour 24 to 72: notify the authority
Assess with your insurer, IT provider or legal adviser whether the breach is "likely to result in a risk" to your guests. If the answer is yes, notifying the data protection authority is mandatory — not optional, and not something to wait on until you're certain.
File the notification before the 72 hours are up, with what you know at that point: the nature of the breach, an estimate of how many guests are affected, the likely consequences and the measures already taken. Incomplete information can be added later — missing the 72-hour window can't, and a late notification has to be explicitly justified.
After 72 hours: notify guests and recover
Notify affected guests directly only if the risk to them is high — stolen card data or passwords, for instance. At a lower risk level, notifying the authority is enough. Write that message in plain language: what happened, what you're doing about it, and what the guest can do themselves (block a card, change a password).
Only restore from a clean backup once you're certain the breach is actually closed — otherwise you restore the exact same problem. And give your insurer the final scope of the incident: that figure, not your first estimate, is what determines the payout.
What cyber insurance actually covers — and what it doesn't
Most owners assume their existing insurance already covers this. It almost never does: a standard fire, business-interruption or public-liability policy typically excludes data breaches and cyber incidents outright, precisely because it's a separate risk with its own price tag. Our guide to restaurant insurance covers the full picture of what an average venue needs; the section below is specifically about the cyber policy.
A cyber policy usually covers the cost of fixing the problem and notifying your guests. It rarely covers the cost of the trust you lose, or a risk you didn't disclose when you took out the policy.
Usually Covered, Usually Not
Read your policy's exclusions before you need them, not after
Usually Covered
- Forensic investigation and IT recovery
- Legal counsel and advice
- Cost of notifying guests (post, email, call centre)
- Business interruption from the downtime itself
- Ransom payments, where permitted
- Crisis communication and PR support
Often Excluded
- Fines resulting from your own prior negligence
- Loss of trust or future custom
- Upgrading to better security than you had
- Anything, if you declared MFA you didn't actually have
- Unencrypted data on a lost device (often)
- Social-engineering fraud without a separate rider
Enter your own numbers and see roughly where you stand. The estimator works from how many guests are in your files, your revenue per service day, and the two questions insurers ask first themselves.
Exposure Estimator
What would a breach roughly cost you? Slide in your own numbers
Compare that figure to the price of a policy, and to what it costs to fix the two red flags above today — usually the second is by far the cheaper option. To check your wider cover, use our guide to restaurant insurance.
What insurers check before they'll even quote you
This isn't a month-long project. Three half-hour tasks take you from "no idea" to a file an insurer takes seriously:
Today — the free fix:
- Turn on MFA for the POS, email and reservation system — often the single line that decides whether you get quoted at all
- Ask your POS provider whether card data is tokenised or stored locally
- Save your IT provider's or insurer's emergency number in your phone, not in a drawer
This week — check your cover:
- Ask your broker explicitly whether cyber is included or needs a separate policy
- Get two to three quotes and compare what's covered, not just the premium
- Write down, on one page, who you call first if something looks wrong
This month — finish the file:
- Set up encrypted, tested backups of your guest and reservation data
- Read your policy's exclusions before you need them
- Pin the emergency plan next to your fire escape plan — same seriousness, same place
The clock runs either way — the question is whether you already knew that
You'll never prevent a data breach with total certainty — even large businesses with their own IT teams get hit. What you do control is whether the first 72 hours are chaos or a checklist. A team that knows which device to disconnect first, an insurer you already have on the line from hour one, and a notification filed on time: that's the difference between an unpleasant incident and a second crisis stacked on top of the first.
And the venues that get this right rarely do it purely for the premium. They do it because a guest's trust — that their data is safe with you — is as much a part of the brand as the kitchen. At HappyChef we build the reservation system with exactly that in mind: your data sits with one party, not scattered across five systems nobody has ever audited. See what it costs and take the first, free step today: turn on MFA.