2026-03-10

When a US restaurant actually has GDPR exposure from calls

Most American restaurants owe nothing under GDPR, and a handful genuinely do. How to tell which you are before a voice vendor sells you a policy you don't need.

Most restaurants in the United States have no GDPR exposure at all, and a fair number of vendors will happily imply otherwise. Before you buy a compliance posture, work out whether the regulation reaches you.

The test in the regulation is territorial and it is narrower than the marketing around it suggests. GDPR reaches you if you have an establishment in the EU, if you offer goods or services to people located in the EU, or if you monitor the behavior of people located there. That's the whole gate. A taqueria in Tucson that takes a call from a French tourist staying at the hotel down the street has not offered goods or services to someone in the EU. The tourist was in Tucson.

The three situations where it genuinely bites

The first is obvious: you operate a location in the EU or the UK. A US-headquartered group with a site in Dublin or Berlin is inside the regulation for that entity, and often for the shared systems behind it, including a phone platform that pools call data across all stores.

The second is deliberate targeting. This is the one operators get wrong in both directions. Accepting a euro-denominated payment once does not target the EU. Running a catering business that solicits contracts from EU-based companies, publishing a menu in German with prices in euros, or advertising to a European audience does. The question regulators ask is whether you envisaged serving customers in those countries, not whether one showed up.

The third is the quiet one: your vendor chain. If your voice platform stores audio in an EU region, or subcontracts transcription to a provider that does, you may find contractual GDPR obligations flowing to you through the vendor's own paperwork even where the regulation itself doesn't reach your restaurant. That's a contract question rather than a regulatory one, and it still lands on your desk. The data processing agreement with a voice vendor is where it shows up.

If none of those three describe you, GDPR is not your problem. Your actual obligations sit in state law, which brings us to the more useful point.

The rules that probably do apply to you

For a US restaurant, the phone regulations that bite are state call-recording consent statutes and, in a growing set of states, consumer privacy law. Recording consent is the immediate one: whether you need one party's consent or all parties' consent depends on the state, and on where the caller is, not just where you are. That's covered in call recording consent laws for restaurants.

Consumer privacy statutes come next. California's rules treat voice recordings as personal information and give residents access and deletion rights, and several other states have followed with similar frameworks. The practical work looks a lot like GDPR work at a smaller scale, which is why a vendor built for one is usually usable for the other. See CCPA and voice data for restaurants.

Spend your effort there first. A restaurant with a solid answer on state recording consent and a real retention policy is in better shape than one with a GDPR binder and no idea how long its call audio is kept.

What counts as personal data on a phone call

If GDPR does reach you, assume everything on the call is in scope. The audio recording is personal data. The transcript is personal data. The name, callback number, delivery address, card token reference and any allergy the caller mentioned are all personal data, and the allergy is health data, which sits in a stricter category.

The voice itself is the part people misunderstand. A recording of someone talking is ordinary personal data. It becomes biometric data in the special-category sense only when it is processed for the purpose of uniquely identifying a person, such as matching a voiceprint to recognize a returning caller. Ask your vendor whether any speaker-identification feature is running. Most restaurant agents transcribe and understand speech without ever attempting to identify who is speaking, and that distinction is worth confirming in writing rather than assuming.

Where the obligations actually land

Four things, in the order they cause problems.

None of that is exotic. It is roughly the same list a serious enterprise buyer works through in a voice AI security questionnaire, which is why the questions are worth asking even when the regulation doesn't apply.

The multi-country group problem

Groups with locations on both sides of the Atlantic hit a specific trap. Phone platforms tend to centralize: one account, one call archive, one analytics view across every store. That's operationally sensible and it means the EU location's call data is now sitting in the same system as everything else, potentially in a US region, without a transfer mechanism in place.

If that's you, the fix is usually regional isolation rather than a legal document. Ask whether the platform can pin storage and processing for specific locations to an EU region, and whether call data can be segmented by store rather than pooled. Some can, some cannot, and finding out after rollout is expensive. How granular a platform's per-location settings are, right down to menus and hours, is a decent proxy for whether its data handling is granular too.

What to do this week

Write down two sentences: where your callers physically are when they call you, and whether you have ever solicited business from someone in Europe. For the overwhelming majority of US restaurants, those two sentences end the GDPR conversation.

Then take the questions GDPR would have forced you to ask and ask them anyway. How long is call audio kept, who else touches it, can you export it, and can you delete one customer's records on request without a vendor ticket. Those answers matter whether or not a European regulator ever cares, because they determine what happens to your customer data if you switch platforms or if your vendor has a breach. Data ownership and privacy in voice AI and getting your data out when you leave are the pieces to read next.

If a vendor's answer to any of them is a marketing page rather than a paragraph, that is your finding.

More on compliance & legal

All compliance & legal articles

Frequently asked questions

Hear it answer a real call.

Call the demo line and order like a customer would, or book time and we'll walk your team through it.