Direct answer: Before signing with a POS, booking, or loyalty vendor, screen the vendor against each core data protection principle — lawfulness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, security, and accountability — and require documentary evidence for each, not verbal assurance. Do this during procurement, separately from any internal audit you run later on your own systems.
Why vendor screening is a distinct step
Restaurant operators often treat data protection as something to address after a system is live, through periodic internal audits of how staff use the POS, booking widget, or loyalty app. That internal audit matters, but it happens too late to influence vendor choice. Pre-purchase screening is a separate discipline: it asks what the vendor itself does with guest data — where it is stored, who can access it, how long it is kept, and what happens if the vendor is acquired or shuts down — before any data has been transferred.
The European Commission's guidance on data protection principles for businesses and organisations sets out the core obligations that apply when personal data is collected and processed. Reservation records, loyalty enrollments, and payment-linked profiles are personal data, so these principles are a reasonable starting point for structuring vendor questions, regardless of which specific law ultimately governs your business.
The Seven-Principle Vendor Screen
This framework organizes vendor evaluation around the seven principles described in the European Commission's guidance. For each principle, ask a specific question and request specific evidence — a policy document, a contract clause, or a written answer from the vendor's team — rather than accepting a general compliance claim.
| Principle | Question to ask the vendor | Evidence to request |
|---|---|---|
| Lawfulness, fairness, transparency | What is the stated legal basis for collecting guest data, and is it disclosed to guests at the point of collection? | Sample guest-facing privacy notice or booking form language |
| Purpose limitation | Is guest data used only for the purpose disclosed (e.g., reservation confirmation), or also for the vendor's own marketing or analytics? | Data processing agreement or terms describing permitted uses |
| Data minimisation | What fields does the system require versus optionally collect for a booking or loyalty signup? | Field list or data schema for the booking/loyalty form |
| Accuracy | Can guests or staff correct inaccurate records, and how quickly are corrections propagated? | Support documentation on record correction process |
| Storage limitation | How long is guest data retained after the last visit or booking, and is there an automatic deletion schedule? | Written retention policy or contract clause |
| Integrity and confidentiality (security) | How is data encrypted in transit and at rest, and who at the vendor can access raw guest records? | Security overview document or relevant certification summary |
| Accountability | Can the vendor demonstrate compliance on request, and who is responsible if a data incident occurs? | Named contact, breach notification clause, incident history disclosure |
Applying the framework during procurement
- Send the seven questions to each shortlisted vendor in writing before any sales call, so answers are documented rather than verbal.
- Score each answer as: evidence provided, partial evidence, or no evidence.
- Flag any "no evidence" response for follow-up before contract negotiation continues.
- Route the completed table to whoever handles legal or compliance review at your business, alongside the draft contract.
- Keep the completed screening record on file as part of your procurement documentation.
Limitations of this checklist
This framework is a screening aid, not a compliance certification and not legal advice. It does not determine which specific data protection law applies to your restaurant, what your obligations are as a data controller versus the vendor's obligations as a processor, or whether a given vendor's answers satisfy the law in your jurisdiction. Vendor self-reported answers are not independently verified by this checklist; they are a starting point for your own or your legal counsel's review. A vendor with strong answers on paper can still change practices after signing, which is why retention and audit rights in the contract itself matter as much as the pre-purchase answers.
Measuring vendor readiness before you sign
A simple scoring approach makes it easier to compare vendors side by side rather than relying on impression alone.
- Score each of the seven principles: 2 points for documented evidence provided, 1 point for a partial or verbal answer, 0 points for no answer.
- Maximum score: 14 points across the seven principles.
- Set a threshold before contract review begins — for example, deciding internally that any vendor scoring below a set number of points requires follow-up questions before proceeding, and any principle scoring 0 requires a direct answer before signing, regardless of the vendor's total score.
- Recheck at renewal: Vendor practices can change between initial signing and contract renewal, so re-running the same seven questions at renewal time is a reasonable checkpoint, not a one-time exercise.
This scoring method does not produce a compliance guarantee or a legal risk rating — it produces a comparable record of what each vendor was willing and able to document, which is useful input for the people who will make the final legal and business decision.
Where this fits with ChefNet
ChefNet is developing restaurant discovery and operations products, and this screening checklist reflects the kind of vendor due diligence any operator should apply when evaluating booking, POS, or loyalty technology, including tools from ChefNet itself. Because product capabilities change during active development, operators should verify directly with ChefNet which specific data handling features, retention controls, or documentation are currently available before relying on them in a procurement decision, rather than assuming any capability described in general industry guidance is already live.
Putting the checklist to use
The value of this framework comes from using it consistently across every vendor under consideration, not just the one you are inclined to choose. Send the same seven questions to competing vendors, score the answers the same way, and let gaps in documentation — not sales presentations — drive follow-up questions. Pair the completed screening record with your organization's standard contract review process, and treat it as one input alongside pricing, feature fit, and integration requirements rather than a replacement for any of them.
Edge Cases the Seven-Principle Screen Can Miss on First Pass
The core checklist assumes a single vendor holding guest data directly, but real technology stacks are rarely that simple. Before finalizing any contract, walk through these situations explicitly, since they change how the seven principles apply.
- Subprocessors and embedded third parties: A booking or loyalty vendor may route payment data, SMS confirmations, or analytics through separate companies. Ask the vendor to list every subprocessor that touches guest data, not just the primary vendor's own practices, and confirm the same seven questions apply down that chain.
- Multi-location and franchise accounts: If one vendor account serves several locations under a shared login or shared guest database, clarify whether guest records are pooled across sites by default and whether individual locations can restrict access to their own data only.
- Free trials and pilot periods: Data collected during a trial, demo, or pilot rollout is often governed by different (or absent) terms than the eventual signed contract. Confirm in writing what happens to guest data collected during a trial if you do not proceed to a full contract — whether it is deleted, retained, or migrated.
- Change of vendor ownership: Vendors can be acquired mid-contract. Ask whether the contract specifies what happens to guest data if the vendor is sold, merges, or shuts down, and whether you retain export rights in that event.
- Offline terminals and local caching: POS hardware sometimes stores guest or payment data locally before syncing to the cloud. Confirm how that locally cached data is secured and for how long it persists on the device itself, separate from cloud-side retention policies.
Embedding the Screen into an Existing Procurement Workflow
The checklist is most useful when it has a fixed place in your existing purchasing process rather than being run ad hoc by whoever happens to be evaluating a vendor.
- Assign one named person (owner, manager, or whoever handles contracts) responsibility for sending the seven questions to every shortlisted vendor before any pricing negotiation begins.
- Set a response deadline in writing, and treat a missed deadline the same as a "no evidence" score on every principle, rather than extending indefinitely.
- Attach the completed scoring table as a required document in the same file as the draft contract, so whoever signs sees both together.
- Define in advance who has authority to override a low score and proceed anyway — and require that override to be documented, not silent.
Tracking Vendor Answers Over Time
A single screening at signing has less value if it is never referenced again. Keep a simple running record, not just a one-time score:
| Checkpoint | What to compare against the original screen |
|---|---|
| Contract renewal | Whether prior answers on retention, security, and subprocessors still match current vendor documentation |
| Vendor product update announcement | Whether new features (e.g., new loyalty integrations) introduce new data collection not covered in the original answers |
| Reported vendor security incident | Whether the original accountability answer (named contact, breach clause) held up in practice |
What This Expanded Screen Still Cannot Tell You
Even with subprocessor and lifecycle questions added, this remains a documentation-gathering exercise, not verification. It cannot confirm that a vendor's written answers reflect actual internal practice, and it does not substitute for legal review of contract enforceability in your specific jurisdiction. Treat every answer collected through this expanded screen the same way as the base checklist: as an input for legal counsel or a compliance reviewer, not a final determination.
Primary sources
FAQ
Is this checklist a substitute for legal review of a vendor contract?
No. This checklist is a screening tool to organize questions and evidence requests before a legal or compliance review. Contract terms, applicable law, and jurisdiction-specific obligations still require review by qualified legal counsel.
How is vendor screening different from an internal data audit?
An internal data audit examines how your own restaurant collects, stores, and uses data across existing systems and staff practices. Vendor screening happens earlier, during procurement, and focuses on evaluating a prospective vendor's documented data handling commitments before any contract is signed.
What if a vendor cannot answer these questions clearly?
Treat unclear or evasive answers as a risk signal rather than a disqualifier by default. Ask for the specific document, policy section, or contract clause that answers the question, and escalate to legal review if the vendor cannot produce one.
Editorial disclosure: ChefNet publishes this guide and develops products for restaurant discovery and operations. General operating guidance is separated from product claims. Capabilities can change as pilots progress. Published 2026-08-11.