Zomato Is About to Hand You Customer Data. Congratulations, You're Now a Data Fiduciary.
When aggregators start sharing customer phone numbers, restaurants inherit legal duties under the DPDP Act. A plain language guide to what changes, the deadlines, and how to stay safe.

There is a detail buried in the Zomato and NRAI data sharing arrangement that almost nobody in the restaurant industry is talking about, and it is the most consequential part of the whole deal.
The moment a customer's phone number lands in your possession for your own marketing, you stop being a bystander to India's data protection law and become a participant in it. Under the Digital Personal Data Protection Act, an entity that decides why and how personal data gets used is a data fiduciary. That is not a label reserved for tech companies. It attaches to a three table restaurant in Kozhikode exactly as it attaches to Zomato itself.
And the law now has teeth on a schedule. The DPDP Rules were notified on November 13, 2025. The Data Protection Board is already operational. Enforcement powers and the penalty framework switch on from November 2026. Full compliance with consent, notice, security, and data principal rights is required by May 13, 2027. Critically, there is no small business revenue threshold for the core obligations. The extra tier of duties applies only to significant data fiduciaries, but the foundation applies to everyone who holds personal data.
The penalties are not symbolic. Up to ₹250 crore for failing to maintain reasonable security safeguards. Up to ₹200 crore for failing to notify a breach. Up to ₹50 crore for general non compliance. Penalties are imposed per violation and can stack, so one bad incident can trigger several categories at once.
Nobody is suggesting the Data Protection Board's first target will be a family restaurant. But the industry is about to move millions of phone numbers from two heavily lawyered platforms into hundreds of thousands of small businesses with no compliance function at all. That migration is exactly the kind of thing regulators watch.
What you actually have to get right
Strip away the legal language and the core duties are five.
One, use the data only for what was consented. The Zomato prompt asks customers to share their number for marketing and promotional updates from the restaurant. That is the boundary. Selling the list, sharing it with a sister brand, or using it for anything beyond that purpose breaks the consent it arrived with.
Two, offer a way out. Customers must be able to withdraw consent as easily as they gave it. Reports on the Zomato pilot have already flagged that the platform's system may not allow revocation after a number is shared, which means the withdrawal mechanism becomes your problem. Every message you send should carry a working opt out, and opt outs must actually be honored, immediately and permanently.
Three, keep it secure. Reasonable security safeguards is the obligation carrying the ₹250 crore ceiling. For a restaurant this means the customer list does not live in a WhatsApp group of former staff, an unprotected Excel sheet on the cashier's laptop, or a marketing agency's drive with no agreement behind it. It lives in one system, access controlled, with a clear answer to the question of who can see it.
Four, report breaches. If the list leaks, the framework requires notifying the Data Protection Board and informing affected customers within 72 hours, in plain language, with what leaked and what they should do. Failing to notify is its own penalty category, separate from the breach itself.
Five, delete what you no longer need. Data principals have erasure rights, and retention is not forever by default. A customer who has not ordered in years and never responded is not an asset. Under this framework, they are a liability you are storing voluntarily.
The uncomfortable question about inherited data
Here is the subtlety the industry will wrestle with. A number that arrives via an aggregator's consent prompt carries a consent you did not design, scoped by words you did not write, revocable through a mechanism you do not control. If a dispute arises about what the customer actually agreed to, you are holding secondhand consent.
Compare that with data you collect yourself. When a customer orders directly from your own website or app, or messages you on WhatsApp to order, the relationship is first party from the first interaction. You wrote the notice. You logged the consent. You control the opt out. The data trail is clean because you built it.
This is the quiet compliance argument for direct ordering that nobody frames as a compliance argument. Platforms like Menuthere give restaurants exactly this: a branded ordering channel where every customer contact is collected first party, with consent captured at the moment of the order, synced with your Petpooja POS, and owned by you in every sense, legally as well as commercially. Inherited numbers are a windfall with strings attached. First party customers are yours cleanly.
The practical checklist
Before the shared numbers start arriving, an afternoon of setup covers most of the risk. Decide the single system where customer data lives. Limit who can access it. Write the two line consent notice for your own collection points. Put a working opt out in every campaign. Set a retention habit, reviewing and pruning the list twice a year. And if an agency runs your marketing, get the data handling terms on paper, because the fiduciary responsibility stays with you regardless of who processes the data.
The unmasking deal gives restaurants something they fought a decade for. The DPDP framework decides whether it becomes an asset or an exposure. The distance between the two is about a day of honest setup, and the restaurants that do it now, before the May 2027 deadline concentrates everyone's minds, will be the ones for whom the phone numbers are purely good news.
Menuthere helps restaurants build first party customer relationships through their own commission free ordering channel. menuthere.com
