Skip to main content

Food Allergies and GDPR: The Compliance Nightmares That Could Close You Down

Navigate the compliance minefield without hiring expensive consultants. Simple systems that keep you legal and let you focus on running your pub.

12 December 2025 · 10 min read · Peter Pitcher

Quick answer

Build one master allergen matrix covering every dish and all 14 allergens, put it in writing where guests can see it, and train the team to say 'let me check' rather than guess. For data, collect consent properly, store contact details securely, and answer access or deletion requests within one calendar month.

Compliance is not exciting, but it is the part of the job that can end the business rather than just dent the takings. An allergen mistake can put someone in hospital. A careless mailing list can put you in front of the regulator. Neither happens because a licensee is careless by nature. They happen because there was no system.

Both problems are solved by the same thing: writing down what you do, once, and making it easy for a busy team to follow at seven on a Friday. That is an afternoon with a spreadsheet, not a consultant's fee.

I run The Anchor in Stanwell Moor as a Greene King tenant, so this is written from the same side of the bar as you: practical, not legal advice. Rules change, so check the current Food Standards Agency and ICO guidance before you finalise anything. The same discipline that keeps a health and safety routine tight is what makes this work.

Part 1: Allergen safety system

Know which rules apply to which food

Pubs get caught out because three different sets of rules apply on the same premises.

Food type Example in a pub What you must do
Non-prepacked, made to order Almost all your menu Provide accurate allergen information for the 14 allergens, and follow FSA best practice by having it in writing as well as talking it through
Prepacked for direct sale (PPDS) Sandwiches wrapped before ordering, boxed cake on the counter, salads in a chilled cabinet Full ingredients list on the pack with the 14 allergens emphasised, under Natasha's Law (in force since October 2021)
Prepacked by someone else Crisps, bottled soft drinks, packaged desserts The manufacturer's label does the job, but keep the packaging until the stock is gone

The PPDS category is where most pubs slip. If you wrap it before the guest chooses it, it needs a label. If you make it after they order, it does not, though the allergen information still has to be right.

Build the master matrix

One spreadsheet. Rows are dishes, columns are the 14 allergens. Allow only three answers in each cell: contains, does not contain, or cannot be guaranteed because of cross-contact. Vague entries are worse than none, because the team will interpret them differently under pressure.

Put a version number and a date in the header, name one person as the owner, and print it fresh whenever it changes. Two copies: one in the kitchen, one behind the bar. Old printed copies go in the bin the same day, not in a drawer.

Maintain an ingredient file

Keep supplier specification sheets and a photograph of the actual packaging label for every line, in one folder, dated. Recipes and supplier formulations change without warning, and the label on the box is the only thing that proves what you were told.

The mistake that causes real harm: the mid-service substitution. Someone runs out of one oil and uses another, or swaps a brand of stock, and nobody updates the matrix. Write the rule down and enforce it: no substitution goes into a dish until the matrix has been checked and, if needed, changed.

Create a clear service protocol

Train one script: "Let me check." Nobody guesses, ever, including you.

Then run one flow every time, in this order. Guest declares the allergy. It goes on the ticket or as an allergen flag in the EPOS, not in someone's head. The person taking the order checks the matrix. The kitchen confirms verbally. The plate is carried separately and handed over with the dish name and the allergen said out loud: "This is the chicken, prepared without gluten-containing ingredients."

Do this week: time the flow during a real service. If it adds more than a minute, the matrix is not accessible enough or the answers are not clear enough.

Control cross-contact

Separate colour-coded boards, dedicated utensils, and allergen-free prep done first in the day on a cleaned surface. Be honest about the fryer: if the same oil cooks battered fish, you cannot describe anything from it as gluten free, and saying so plainly builds far more trust than fudging it. This is exactly what an inspector examines when setting your food hygiene rating.

Make the information visible

Put allergen information on the menu itself, or put a clear line on the menu telling guests where to find it. Since March 2025 the FSA has recommended that written allergen information is available as standard, rather than only handed over when someone asks.

Train it and record it

Every new starter before their first shift, everyone refreshed at least quarterly, and a signed and dated sheet in the folder. If you are ever asked to demonstrate your system, that sheet is the evidence.

The £5,000 cap on magistrates' court fines was removed in 2015, so a breach of the food information rules carries an unlimited fine, and where an allergen failure has led to a death, operators have faced gross negligence manslaughter charges. Your pub insurance cover is far more likely to respond cleanly when you can show a documented system that was actually followed.

Part 2: GDPR basics for pubs

Know what you actually hold

A typical pub holds booking names, phone numbers and emails, a marketing list, wifi sign-up data, CCTV footage, staff records and supplier contacts. That is plenty to bring you inside the rules.

Note that an allergy recorded against a booking is information about someone's health, which UK data protection law treats as a special category needing extra care. Keep it to what you need to serve that guest safely, and never let it drift into your marketing list.

Pay the fee and pick your lawful basis

Most pubs need to pay the ICO data protection fee: £52 a year at tier one (£47 by direct debit), rising to £78 at tier two. It takes ten minutes online.

For bookings, your lawful basis is normally the contract with the guest. For marketing emails and texts the rules are stricter and come from PECR, not just GDPR. You need consent, unless the soft opt-in applies: you collected the details during a sale or negotiations for a sale, you are marketing your own similar products or services, and you offered an opt-out at the point of collection and in every message since.

No pre-ticked boxes, no adding the business card from the raffle jar. A simple form that says what you will send and how often, with a record of when and how the person opted in. That record is the whole defence if anyone ever asks. If you are building a list to run email marketing that keeps regulars coming back, get this right at the start rather than cleaning it up later.

Held properly, that data pays for itself. Using the contact details guests give at the point of booking to confirm and remind is how we cut booking no-shows by 89% at The Anchor.

Store it securely

The list lives in one password-protected system, not on a manager's personal phone and not in a spreadsheet emailed between devices. Turn on two-factor authentication for the booking system and the mailbox. Remove a leaver's access on their last day, not the following month.

Respond to requests properly

If someone asks for a copy of their data, or asks to be deleted, you have one calendar month to respond, extendable by up to two further months if the request is genuinely complex. Since February 2026 you can pause the clock while you wait for proof of identity or for clarification of what they want, and your search only has to be reasonable and proportionate rather than exhaustive. Do not use either point as a delaying tactic.

Set a retention rule and stick to it

Write down how long you keep each type of record, then actually delete. Something like: booking contact details for 12 months after the visit, marketing contacts who have not opened anything for 24 months, CCTV for 30 days. A shorter list of engaged people outperforms a long list of strangers anyway.

The statutory maximum under UK GDPR is £17.5m or 4% of global annual turnover, and PECR breaches (the marketing message rules) are capped at £500,000. A small pub is far more likely to get guidance or a reprimand for a first, fixable mistake. What causes real trouble is ignoring opt-outs after being told.

What to do when something goes wrong

An allergic reaction. Call 999 immediately if the reaction is severe, and say the word anaphylaxis if that is what you are seeing. Do not clear the table. Keep the plate, the ticket and the packaging. Write down what was ordered, what was said, who checked the matrix and what version they used, while it is fresh. Then notify your insurer and your local authority environmental health team.

A data breach. If personal data is lost, exposed or stolen and there is a risk to the people involved, you have 72 hours to report it to the ICO. Record what happened, what data was affected, how many people, and what you did about it, even if you conclude it does not need reporting.

Both situations are survivable. What is not survivable is having nothing written down when someone asks what your system was.

Common mistakes

  • Outdated allergen lists. A matrix that does not match the current recipe is worse than no matrix, because staff trust it.
  • Staff guessing. Usually well-meant, always dangerous. "Let me check" must be normal from everyone, including you.
  • Treating "ask a member of staff" as the whole system. It is a signpost, not the information.
  • Collecting emails without consent. Raffle entries, wifi logins and business cards are not permission to market.
  • Lists on personal devices. Once a leaver walks out with your customer database on their phone, you have both a data problem and a competitor problem.
  • Never deleting anything. Every extra record is extra risk with no upside.

Quick checklist

  • Allergen matrix updated, versioned, dated and printed for kitchen and bar.
  • PPDS items identified and labelled with full ingredients and emphasised allergens.
  • Written allergen information available to guests without them having to ask.
  • Ingredient file with supplier specs and label photos, and a no-substitution rule.
  • Team trained on "let me check", with a signed training record.
  • ICO fee paid and lawful basis decided for bookings and for marketing.
  • Consent records kept, storage secured, two-factor turned on.
  • Retention rule written down and a deletion date in the diary each quarter.

Mini FAQ

Do I need a lawyer? Not usually. The FSA and ICO both publish free guidance aimed at small businesses. Get professional advice if you are facing an actual incident, an enforcement notice, or a claim.

How often should I update allergen information? Every time a recipe, a supplier or a product changes, and a full review at least quarterly whether or not you think anything has moved.

Can I keep a note that a regular is coeliac so we get it right next time? Yes, if you keep it to what you need to serve them safely, tell them you are doing it, store it securely, and use it for nothing else.

questions people ask.

What are the 14 allergens pubs must declare?
Celery, cereals containing gluten, crustaceans, eggs, fish, lupin, milk, molluscs, mustard, nuts, peanuts, sesame, soya, and sulphur dioxide. Every dish must be checked against all 14, and staff must know how to direct guests to the information.
Do I need written consent to collect customer email addresses?
Yes. Under GDPR you need clear, affirmative consent before adding anyone to a mailing list. Use a simple sign-up form that explains what you will send and how often. Never add emails without permission, even if someone left a business card.
What happens if a customer has an allergic reaction in my pub?
Call emergency services immediately if severe. Record everything: what was ordered, what was served, and the allergen information provided. Contact your insurer and local authority. Prevention is key: train every team member to say 'let me check' rather than guessing.
Do pubs have to provide allergen information in writing?
For non-prepacked food you must provide allergen information, and since March 2025 the Food Standards Agency's best practice guidance says it should be available in writing as well as through a conversation with the guest. A sign saying 'ask a member of staff' is no longer considered enough on its own. Put the information on the menu, on an allergen matrix at the bar, or on a clearly signposted separate sheet.
Does Natasha's Law apply to a pub kitchen?
It applies to anything you package before the guest orders it and then sell from the same premises, such as sandwiches wrapped in advance, boxed cakes on the counter or salads in a chilled cabinet. Those items need a full ingredients list with the 14 allergens emphasised. Food made to order after the guest chooses it is not covered by those labelling rules, but you still have to give accurate allergen information.
Do I need to register with the ICO to run a pub?
Most pubs that hold customer bookings, a marketing list, CCTV or staff records need to pay the ICO data protection fee. Tier one is £52 a year (£47 by direct debit) for organisations with no more than ten staff or turnover under £632,000, and tier two is £78. Check your status on the ICO's self-assessment tool rather than assuming you are exempt.
Taggedallergen managementGDPR compliancefood safetypub regulationscompliance systems

not sure this is your actual problem?

That's the more common situation, and it's what the first conversation is for. An hour, free, going through what's happening in your business before anybody suggests a fix.