上次更新时间:2026年3月24日 11:18
Toast is committed to ensuring that individuals that provide personal information(referred to as “personal data” for the purposes of this GDPR guidance note) to Toast and our customers trust that their information is being adequately protected and managed in line with their expectations and in accordance with the applicable data privacy legislation. Part of this commitment means that our customers have the appropriate information and tools on hand to understand their obligations and how Toast can support certain aspects of these obligations.
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that applies to the personal data of individuals located in the European Union (EU) or European Economic Area (EEA). The GDPR applies a single data protection law that is binding throughout each EU member state.
The GDPR uses a very broad definition of personal data. It means any information that directly or indirectly relates to an individual. This can be a name, a phone number, an email address, or a unique identifier like a transaction ID. When in doubt, if the information identifies or can identify an individual, it is likely to be considered personal data under the GDPR.
Does the GDPR affect my business?
There are two different roles that can apply to businesses under the GDPR and affect the way that they manage their operations with respect to data protection: being a Data Controller or being a Data Processor (as such terms are defined under the GDPR).
Customers are most likely considered to be a Data Controller for the personal data they collect from restaurant guests through Toast devices and services to use for their own purposes. Data Controllers have specific, defined obligations under the GDPR, including notice requirements and responding to individual rights requests. In certain cases, Toast will help customers provide notice within their restaurants regarding the use of Toast’s products and services, and Toast may assist customers in responding to individual rights requests.
The GDPR provides a number of individual rights that your customers or employees may be able to exercise depending on the applicability of the GDPR to your business. The most common rights requests that you may receive while using Toast products and services include:
This is a high-level summary of the individual rights under the GDPR. There are additional requirements in relation to each right as well as many exceptions where these rights may not be able to be invoked depending on the specific circumstances.
Please consult with your independent legal counsel to determine the applicability of the GDPR to your business and the applicability of the above rights to determine if you need to comply with an individual’s request.
Below are some considerations when you receive an individual rights request from one of your customers or employees:
In certain cases, Toast may be able to support our customers with individual rights fulfillment. Toast has prepared additional guidance outlining where Toast is able to assist during this process. Check out our article for more information.