Food & Drink · Cork

GDPR Compliance for Breweries / Distilleries in Cork

Policies, checklists, and monitoring to keep your Cork business on the right side of the DPC. Start in under 2 minutes.

Join 2,000+ Irish businesses already protected

Why This Matters for Breweries / Distilleries in Cork

Every year, the Data Protection Commission opens investigations into Irish businesses that mishandle personal data. Breweries / Distilleries in Cork are not immune — especially when it comes to collecting visitor data during distillery tours and tastings without providing a privacy notice.

Cork is Ireland's second-largest economic centre, with a powerful pharmaceutical and life sciences cluster including Pfizer, Eli Lilly, and Johnson & Johnson. The tech sector thrives with Apple's European headquarters and a growing startup scene. The county's food heritage is nationally renowned, with Ballymaloe and the English Market underpinning a vibrant artisan food economy. With around 32,000 SMEs across Cork, many breweries / distilleries near Cork City and throughout the county process customer names, email addresses, and phone numbers and delivery and billing addresses for online sales on a daily basis. Under the GDPR and the Data Protection Act 2018, all of this data must be collected, stored, and managed lawfully.

This guide gives you a clear, actionable path to full GDPR compliance — built specifically for breweries / distilleries in Cork.

Do breweries / distilleries in Cork need GDPR compliance?

Yes — it's a legal requirement. Any brewery / distillery in Cork processing personal data must meet GDPR standards. This covers everything from customer names and emails to CCTV footage and HR files. The DPC enforces compliance across all Irish businesses regardless of size, with fines of up to €20 million.

RISK ASSESSMENT

Key GDPR Risks for Breweries / Distilleries

Collecting visitor data during distillery tours and tastings without providing a privacy notice

Operating loyalty or bottle clubs that build detailed customer preference profiles without data minimisation

Age verification processes that collect and retain identity document data unnecessarily

Using event attendee data for ongoing marketing without separate consent

CCTV in taprooms and production areas capturing visitor and employee footage without proper policies

DATA INVENTORY

Personal Data Your Brewery / Distillery Processes

Customer names, email addresses, and phone numbers
Delivery and billing addresses for online sales
Age verification data and dates of birth
Payment card information
Tour and tasting booking details
Loyalty or bottle club membership records and preferences
CCTV footage from taproom and visitor areas

FREE ASSESSMENT

Find out your GDPR score in 2 minutes

See exactly where your Brewery / Distillery in Cork stands on GDPR compliance — no signup required.

REQUIRED DOCUMENTS

Required GDPR Policies & Documents

Every Brewery / Distillery in Ireland needs these documents to demonstrate GDPR compliance. ComplianceKit generates all 8 policy types with a living compliance score that tracks your progress.

Customer privacy notice covering sales, tours, and events
CCTV policy with appropriate signage in taproom and visitor areas
Age verification data handling procedure
Cookie policy for e-commerce website
Data processing agreements with booking platforms, payment processors, and delivery services
Data retention schedule for customer, tour, and event records

STEP BY STEP

GDPR Compliance Steps for Breweries / Distilleries

01

Create a comprehensive privacy notice that covers all your customer touchpoints: online shop, taproom, tours, events, and loyalty club.

02

Implement an age verification process that collects the minimum data necessary — typically a date of birth or age confirmation rather than copies of identity documents.

03

Ensure your taproom CCTV complies with DPC guidance including signage, a documented lawful basis, a maximum 30-day retention period, and restricted access.

04

Put data processing agreements in place with your booking system, e-commerce platform, payment processor, and any delivery or distribution partners.

05

Obtain separate, specific consent for marketing when customers book a tour or attend a tasting — do not assume booking consent extends to marketing.

06

Review your loyalty club or bottle club database regularly and contact inactive members to confirm whether they wish to remain on your records.

07

Ensure your website has a compliant cookie banner that allows visitors to refuse non-essential analytics and marketing cookies.

COMMON PITFALLS

Common GDPR Mistakes Breweries / Distilleries Make

Adding every tour visitor's email to the marketing newsletter without asking for separate consent.

Keeping copies of identity documents used for age verification instead of simply recording that verification was completed.

Operating taproom CCTV without signage, a written policy, or a defined retention period.

Assuming that a customer's purchase of a product constitutes consent to receive ongoing promotional emails.

FAQ

Frequently asked questions

Everything you need to know about GDPR compliance for your business.

Contact us

Don't wait for the DPC to come knocking

Every day your Brewery / Distillery in Cork operates without proper GDPR compliance is a risk. The DPC is increasing enforcement across Ireland — get ahead of it today.

Join 2,000+ Irish businesses. No credit card required.