India's DPDP Act: what cafés and restaurants must do with customer data
A plain-English guide to the Digital Personal Data Protection Act and 2025 Rules for small food businesses: what counts as personal data, consent, and key dates.
· 2 min read · Tapstand team
If your café collects names, phone numbers, emails or birthdays (for a loyalty card, a waitlist, delivery orders or a feedback form), you're handling personal data. India's Digital Personal Data Protection Act, 2023 sets rules for how that data is collected and used, and the DPDP Rules, 2025 put them into practice.
Key dates
| When | What |
|---|---|
| 14 November 2025 | DPDP Rules, 2025 notified. The Data Protection Board is set up. |
| November 2026 | Consent manager framework comes into force. |
| 13 May 2027 | Core duties apply: notice and consent, security safeguards, breach reporting, retention and erasure, and data principal rights. |
There is no general exemption for small businesses for these core duties, so a café with a loyalty list should plan now.
What the law asks of you, in plain terms
- Tell people what you collect and why, in a short, clear notice, before or at the moment you collect it.
- Get clear consent through an active choice, not a pre-ticked box.
- Collect only what you need. A birthday treat needs day and month, not year of birth.
- Use it only for what you said. Loyalty emails are not a licence to sell the list.
- Keep it safe. Limit who can see it; use proper accounts, not a shared spreadsheet.
- Delete it when it's no longer needed, and when someone asks.
- Give people a way to contact you about their data, and respond.
- Report breaches to the Board and to affected people if data leaks.
What this looks like for a loyalty card
- Name and email to create and recover the card. Verified with a one-time code so nobody signs up someone else.
- Birthday as day and month, optional, used only for a birthday treat.
- No phone number unless you'll actually use it.
- A link to your privacy notice near the sign-up button.
Other places cafés collect data
- Feedback forms: make contact details optional, and use them only to reply.
- Anonymous suggestion boxes: collect no personal data at all. See digital suggestion boxes.
- Wi-Fi: if you use a login portal that collects phone numbers, that's personal data too.
- CCTV: footage of identifiable people is personal data. Signage and limited retention help.
A short checklist
- List every place you collect customer data, and why.
- Write a one-page privacy notice in plain language, and link it wherever you collect data.
- Remove fields you don't use.
- Decide how long you keep each kind of data.
- Give staff their own logins and remove them when they leave (see training staff).
- Have an email address for data requests and check it.
Sources
Screenshots show Tapstand with a sample café and demo data.



