Finance & Strategy

The First 72 Hours After a Restaurant Data Breach

Your reservation system, your POS and your loyalty card all hold guest data. The clock starts the moment you find out something went wrong.

In this article
  1. Where your guests' data actually lives
  2. The 72-hour clock, window by window
  3. What cyber insurance actually covers — and what it doesn't
  4. What insurers check before they'll even quote you
  5. The clock runs either way — the question is whether you already knew that

A restaurant data breach isn't an IT problem — it's a legal clock that starts running the moment you find out about it. The instant you know, or reasonably should know, that guest data has been stolen, deleted or exposed to the wrong hands, GDPR gives you 72 hours to notify the supervisory authority. Not 72 hours to fix it — 72 hours to report it.

It rarely starts with an alarm going off. More often it's a guest calling because their card was charged twice, your reservation platform emailing about "unusual activity", or a member of staff finding the till screen full of strange text on a Tuesday morning. At that point the question stops being "how bad is this technically" and becomes "what do I actually do right now" — and most owners don't know the answer, because nobody ever wrote it down.

The exposure is real, and it isn't reserved for big chains. Point-of-sale systems are consistently among the most targeted equipment in hospitality and retail worldwide, precisely because they process card data and often keep running unpatched for years. A small restaurant has no IT department to absorb the hit — which is exactly why cyber insurance, and a written plan for the first 72 hours, matters more here than at a business with its own security team.

This guide walks through exactly that: where your guests' data actually lives, what has to happen in each of the four windows of the 72-hour clock, what a cyber insurance policy typically does and doesn't cover, and — with a calculator built on your own numbers — what a breach could realistically cost your restaurant.

Where your guests' data actually lives

A data breach is any incident where guests' personal data is accidentally or unlawfully lost, altered, or accessed by someone without the right to it — which is far broader than "getting hacked". A laptop left in a car, a booking confirmation emailed to the wrong address, or a POS backup left accidentally public all count just as much as a targeted attack.

Most owners underestimate how many systems they're actually running. Add it up: the POS system holding card data from every transaction, the reservation and CRM system with every guest's name, phone number and sometimes allergies, the loyalty programme with email addresses and order history, guest WiFi with a login portal that often asks for an email, the delivery-platform integration passing along addresses, and the gift-card ledger with codes that are literally worth money. Six systems, six places a leak can start — and in most venues, nobody has ever listed them side by side.

Our guide to guest data and GDPR covers how to collect and use that data legally; our guide to restaurant cybersecurity covers the nine steps that prevent an attack in the first place. This guide covers the moment after: it has already gone wrong — now what?

The 72-hour clock, window by window

GDPR Article 33 requires you to notify the data protection authority within 72 hours of becoming aware of a breach, unless it's unlikely to result in a risk to your guests' rights and freedoms. That clock doesn't start once you understand everything — it starts the moment you reasonably know something has happened. Here's what those 72 hours actually look like.

The 72-Hour Clock

Four windows, walked through once — pin this order up next to your emergency plan

Hour 0–1

  • Disconnect the affected device from the network
  • Don't wipe or restart anything — evidence stays put
  • Change every admin password
  • Write down the exact time of discovery

Hour 1–24

  • Call your IT provider or a specialist
  • Involve your insurer's breach hotline
  • What data — names, cards, allergies?
  • How many guests could be affected?

Hour 24–72

  • Assess the risk with an adviser or insurer
  • File the notification with the authority
  • Notify even if the risk is uncertain
  • Document the decision and its reasoning

After 72 hours

  • Notify guests only if the risk is high
  • Write the message in plain, clear language
  • Restore only from a clean backup
  • Report the final scope to your insurer

Only the last column is conditional — the first three apply to almost every breach.

Hour 0 to 1: discover and contain

Disconnect the affected device from the network — pull the cable or switch off the WiFi — but don't turn anything off or wipe anything. Every trace you erase now is a trace your IT provider or insurer won't be able to use later to work out what actually happened.

Change the password on every admin account with access to the POS, the reservation system and your email, immediately. Write down the exact time you discovered it — that timestamp is the start of your 72 hours, and you'll need it on every form that follows.

Hour 1 to 24: assess and document

Call your IT provider, or a specialist service if you don't have one — and call your insurer at the same time if you have a policy: most cyber policies have a breach hotline you can involve from day one, and waiting often costs you exactly the cover you need.

Write down what data may have been involved: just names and email addresses, or also card data and allergy notes? How many guests are in that file? Those two questions — what and how many — decide almost everything that happens over the next 48 hours, so write it down as soon as you know, even if the answer is still incomplete.

Hour 24 to 72: notify the authority

Assess with your insurer, IT provider or legal adviser whether the breach is "likely to result in a risk" to your guests. If the answer is yes, notifying the data protection authority is mandatory — not optional, and not something to wait on until you're certain.

File the notification before the 72 hours are up, with what you know at that point: the nature of the breach, an estimate of how many guests are affected, the likely consequences and the measures already taken. Incomplete information can be added later — missing the 72-hour window can't, and a late notification has to be explicitly justified.

After 72 hours: notify guests and recover

Notify affected guests directly only if the risk to them is high — stolen card data or passwords, for instance. At a lower risk level, notifying the authority is enough. Write that message in plain language: what happened, what you're doing about it, and what the guest can do themselves (block a card, change a password).

Only restore from a clean backup once you're certain the breach is actually closed — otherwise you restore the exact same problem. And give your insurer the final scope of the incident: that figure, not your first estimate, is what determines the payout.

What cyber insurance actually covers — and what it doesn't

Most owners assume their existing insurance already covers this. It almost never does: a standard fire, business-interruption or public-liability policy typically excludes data breaches and cyber incidents outright, precisely because it's a separate risk with its own price tag. Our guide to restaurant insurance covers the full picture of what an average venue needs; the section below is specifically about the cyber policy.

A cyber policy usually covers the cost of fixing the problem and notifying your guests. It rarely covers the cost of the trust you lose, or a risk you didn't disclose when you took out the policy.

Usually Covered, Usually Not

Read your policy's exclusions before you need them, not after

Usually Covered

  • Forensic investigation and IT recovery
  • Legal counsel and advice
  • Cost of notifying guests (post, email, call centre)
  • Business interruption from the downtime itself
  • Ransom payments, where permitted
  • Crisis communication and PR support

Often Excluded

  • Fines resulting from your own prior negligence
  • Loss of trust or future custom
  • Upgrading to better security than you had
  • Anything, if you declared MFA you didn't actually have
  • Unencrypted data on a lost device (often)
  • Social-engineering fraud without a separate rider

Enter your own numbers and see roughly where you stand. The estimator works from how many guests are in your files, your revenue per service day, and the two questions insurers ask first themselves.

Exposure Estimator

What would a breach roughly cost you? Slide in your own numbers

Estimated cost of this breach An indication based on your own numbers — not an insurer's quote.
Red flags that could reduce or endanger your payout

Compare that figure to the price of a policy, and to what it costs to fix the two red flags above today — usually the second is by far the cheaper option. To check your wider cover, use our guide to restaurant insurance.

What insurers check before they'll even quote you

This isn't a month-long project. Three half-hour tasks take you from "no idea" to a file an insurer takes seriously:

Today — the free fix:

  • Turn on MFA for the POS, email and reservation system — often the single line that decides whether you get quoted at all
  • Ask your POS provider whether card data is tokenised or stored locally
  • Save your IT provider's or insurer's emergency number in your phone, not in a drawer

This week — check your cover:

  • Ask your broker explicitly whether cyber is included or needs a separate policy
  • Get two to three quotes and compare what's covered, not just the premium
  • Write down, on one page, who you call first if something looks wrong

This month — finish the file:

  • Set up encrypted, tested backups of your guest and reservation data
  • Read your policy's exclusions before you need them
  • Pin the emergency plan next to your fire escape plan — same seriousness, same place

The clock runs either way — the question is whether you already knew that

You'll never prevent a data breach with total certainty — even large businesses with their own IT teams get hit. What you do control is whether the first 72 hours are chaos or a checklist. A team that knows which device to disconnect first, an insurer you already have on the line from hour one, and a notification filed on time: that's the difference between an unpleasant incident and a second crisis stacked on top of the first.

And the venues that get this right rarely do it purely for the premium. They do it because a guest's trust — that their data is safe with you — is as much a part of the brand as the kitchen. At HappyChef we build the reservation system with exactly that in mind: your data sits with one party, not scattered across five systems nobody has ever audited. See what it costs and take the first, free step today: turn on MFA.

Frequently asked questions

What exactly counts as a 'data breach' for a restaurant?

Any incident where guest personal data is accidentally or unlawfully lost, altered, or made accessible to someone without the right to it. That's not just hacking — a forgotten laptop, a booking email sent to the wrong address, or a misconfigured POS backup all count just as much.

Do I have to notify my guests if my restaurant is breached?

Only if the risk to them is likely to be high — stolen card data or passwords, for example. Notifying the data protection authority within 72 hours is almost always required regardless, unless the breach is unlikely to result in any risk at all.

Does my normal business insurance cover a data breach?

Usually not. A standard fire, business-interruption or liability policy typically excludes cyber incidents and data breaches outright. Ask your broker explicitly — a separate cyber policy or an extension is usually needed.

What does cyber insurance typically not cover?

Fines resulting from your own prior negligence, reputational or lost-trust damage, and usually anything tied to a security measure you declared on the application but didn't actually have, like MFA. Read the exclusions before you need them.

How much does cyber insurance cost for a small restaurant?

It varies a lot depending on how much guest data you hold, whether your POS stores card data locally, and what security you already have. Get two to three quotes — the spread is wide enough to make it worth comparing.

What's the very first thing to do if I suspect a breach?

Disconnect the affected device from the network without wiping anything, change every admin password, and write down the exact time of discovery — that's the start of your 72 hours. Only then call your IT provider or insurer.