Cookie settings

Choose what we may store on your device. You can change your choice at any time with the link at the bottom of every page.

Questions about your data? Contact us

Running a restaurant

CCTV, guest lists and marketing texts: the privacy rules for Icelandic restaurants

What the Icelandic rules say about security cameras, how long you can keep footage, what to keep from bookings, and when you can send marketing emails and SMS.

By Resto team Published Updated 8 min read

In this guide
  1. 01The rules that apply
  2. 02Cameras
  3. 03Bookings and guest data
  4. 04Marketing emails and SMS
  5. 05A checklist for this week

Most restaurants in Iceland collect personal data every day without thinking of it that way. A camera over the counter records guests and staff. A booking holds a name, a phone number and sometimes a note about an allergy. A list of regulars gets a text about the new brunch menu.

All of this is allowed, within some clear rules. This guide describes the rules as of October 2026.

The rules that apply

The main law is the Data Protection Act, lög nr. 90/2018. It makes the GDPR (EU Regulation 2016/679) part of Icelandic law, and the full GDPR text is published with the act.1 Persónuvernd, the Data Protection Authority, supervises it.

Cameras have their own article in the act, 14. gr., and their own rules from Persónuvernd: rules no. 50/2023 on electronic monitoring (rafræn vöktun).12 Marketing by email and SMS is covered by a different law, the Electronic Communications Act, lög nr. 70/2022.7

Cameras

According to Persónuvernd, the privacy law does not ban security cameras, but it sets clear limits.4 A camera that records people who can be identified processes personal data, so the normal privacy rules apply to the footage.4

Have a clear purpose

Monitoring must always have a clearly stated, lawful and legitimate purpose, for example safety or the protection of property.2 Before you put up a camera, the rules ask you to check whether a milder, realistic measure can do the same job.2 Persónuvernd also asks you to think about the area that the camera sees, and whether it reaches into places where people expect more privacy.4

In a restaurant, a camera over the POS and the cash drawer, or on the back door, usually has an easy purpose to explain. A camera in a staff changing area, a staff toilet or a break room is very hard to justify.

No hidden cameras

Hidden monitoring is not allowed, unless a special legal authority or a court order supports it.2

A sign at the door, and information for staff

When you monitor a workplace or a public place, you must say so clearly with a sign or in another visible way, and say who is responsible.1 The rules add detail. The sign must be visible before people come into the monitored area. It must name the controller (your company) and tell people where they can get more information, or give a link to it.2

Staff need more than the sign. You must give the people who are regularly in the area, such as your employees, the full information about the monitoring, in a way that you can prove.2 A short written note that each employee signs, or a section in the staff handbook that they confirm, does this well.

Cameras are for safety, not for checking work

The rules treat monitoring of how employees do their work (vöktun með vinnuskilum) as a separate case. It needs a special need, for example when there is no other way to supervise the work, or when pay depends on measured output. You must also do a data protection impact assessment (DPIA) before it starts.2

For most restaurants, the rule is simple: the security camera is for security. Do not use it to check who is on their phone or how fast someone wipes the tables.

How long to keep footage

You may keep footage only while it is necessary for the purpose of the monitoring. You must delete it when there is no longer a legitimate reason to keep it.2 The rules set an upper limit, with some exceptions, for example when footage is needed for a legal claim.2

That upper limit changed. Rules no. 1329/2025 changed it from 30 days to 90 days. They were published on 10 December 2025 and took effect at once.3 Many websites still say 30 days. The 90 days are a maximum and not a target. If your system records over itself after 14 days and that is enough for your purpose, 14 days is a good setting.

When footage shows an accident or a suspected crime, the rules allow you to give it to the competent authority, for example the police. You must then delete all other copies.32

Two real cases

Persónuvernd has fined restaurants and food shops for camera use. These two decisions show where the line is. Read the full decisions before you draw conclusions for your own case.

  • Subway (Stjarnan ehf.), 20 March 2024. A store manager looked at the restaurant’s cameras, took screenshots of an employee and wrote on them what the employee was doing. Persónuvernd found that this was monitoring of the employee’s work, outside the stated purpose of the cameras. The signs and the information for staff were also not good enough. The fine was 1.500.000 kr.5 Persónuvernd also said that it had no objection to the cameras themselves for safety and the protection of property.5
  • Huppuís ehf., 29 June 2021. In one of five ice cream shops, a camera covered the staff area where employees, many of them under 18, changed into their uniforms. There was no sign at the entrance, and staff had not been told about the monitoring. The fine was 5.000.000 kr. The fact that the staff were children counted against the company.6

Bookings and guest data

A booking needs very little: a name, a way to reach the guest, the date, the time and the number of people. The GDPR asks you to collect only the data that you need for the purpose, and to keep it in a form that identifies people no longer than you need it.1

Some practical points:

  • Notes about allergies and health. The GDPR gives health data stronger protection.1 A note such as “Anna, nut allergy” is information about a named person’s health. Use it for the dinner that it was written for. Do not copy it into a marketing list or a long-term guest profile without a clear reason.
  • Notes about guests. Write notes that you would be comfortable showing to the guest. Guests have the right to see the data that you hold about them.1
  • Old bookings. Decide how long you keep booking details after the visit, and delete or anonymise them after that. Base the period on a real reason, for example questions about a booking or a no-show.
  • Receipts are a separate matter. The Bookkeeping Act requires you to keep accounting records for seven years from the end of the financial year.8 That rule covers your sales records and receipts. It does not give you a reason to keep guest profiles or booking notes for seven years.

Who on the team can see guest data also matters. Resto has staff roles and an audit log, so you can limit who does what on the POS. See security.

Marketing emails and SMS

The basic rule is in the Electronic Communications Act, 94. gr. You may use email and other electronic messages for direct marketing only when the person has given informed consent in advance.7 SMS counts as an electronic message.

There is one exception, and it is for email only. You may use a customer’s email address to market your own products or services, if the customer could say no for free when you collected the address, and can say no for free in every message.7 This is often called the soft opt-in. It does not apply to SMS. For texts, you need consent first.

Each marketing email must also show clearly who sent it, with a name and an address.7 Fjarskiptastofa enforces these rules.7

When you rely on consent, the GDPR adds three points. You must be able to show that the person consented. The request must be clear and separate from other terms. And it must be as easy to withdraw consent as it was to give it.1

A simple way to do this in a restaurant: put an unticked box on the booking form or the online order that says “Send me news and offers by SMS”. Keep a record of when the guest ticked it. Put a working unsubscribe link or a “reply STOP” option in every message.

A checklist for this week

  1. Walk through the restaurant and list every camera, with what it sees and why.
  2. Turn away or remove any camera that sees a changing area, a toilet or a break room.
  3. Put a sign at each entrance to a monitored area, with your company name and where to read more.
  4. Give each employee a short written note about the cameras, and keep their signed copy.
  5. Set the recording system to delete footage automatically, at 90 days or less.
  6. Decide who may look at footage, and in which situations. Write it down.
  7. Check your booking notes, and remove health notes after the visit.
  8. Check that every SMS contact on your marketing list gave consent, and that every message has a way to unsubscribe.

Sources

  1. Lög um persónuvernd og vinnslu persónuupplýsinga nr. 90/2018 (with the GDPR, Regulation (EU) 2016/679, in Icelandic) Alþingi · Accessed
  2. Reglur um rafræna vöktun nr. 50/2023 Persónuvernd, Stjórnartíðindi · Accessed
  3. Reglur um breytingu á reglum nr. 50/2023 um rafræna vöktun, nr. 1329/2025 Persónuvernd, Stjórnartíðindi · Accessed
  4. Eftirlitsmyndavélar og vöktun Persónuvernd · Accessed
  5. Vöktun með vinnuskilum starfsmanns á veitingastaðnum Subway (case 2021051091, 20 March 2024) Persónuvernd · Accessed
  6. Huppuís ehf. sektað vegna vöktunar með eftirlitsmyndavélum í starfsmannarými (case 2020010545, 29 June 2021) Persónuvernd · Accessed
  7. Lög um fjarskipti nr. 70/2022 Alþingi · Accessed
  8. Lög um bókhald nr. 145/1994 Alþingi · Accessed

More guides

Book a demo of Resto

We show you the system at a time that suits you. The demo does not commit you to anything.

We read every request and get back to you ourselves. We also answer in the evening and at the weekend.

hello@resto.is

We use these details only to contact you about Resto.