In a travel agency, data protection plays out more in the small daily gestures than in the formal documentation. The file may be perfectly drafted, but if the agent photographs the passport with their personal mobile, shares the GDS user with the intern, sends the tickets without verifying the recipient or leaves the bookings screen facing the client coming in behind, everything else stops working.
This guide brings together operational routines for the day-to-day of a travel agency — leisure, corporate or mixed. It is not a legal course: they are habits that organise the team's work and, in passing, comply with the GDPR, the LOPDGDD and sector-specific regulations.
The golden rule: record data, not documents
The first operational principle at the counter and in the back office is straightforward: what is recorded in the system is the data required for each booking, not the image of the identity document. In practice:
- The client provides their ID card or passport in person or by email.
- The agent records in the GDS and in the CRM the data strictly necessary for the booking (name, exact surnames as on the document, number, expiry date, nationality).
- The document is not scanned by default to be filed "just in case".
- If at some moment the airline, the embassy or the authority of the destination country requires a copy of the document, that copy is sent at the specific moment, through an encrypted channel, and removed from the agent's sending environment once the procedure is completed.
The reason is twofold: art. 5.1.c GDPR imposes the principle of minimisation (only the data strictly necessary for the purpose) and the AEPD's consolidated enforcement criterion considers it disproportionate to retain the full image of the identity document when it is enough to record it. Recording covers the operation; systematic copying of the passport adds no value and does add risk.
Secure sending of tickets, vouchers and confirmations by email
Sending travel documents by email is one of the most frequent breaches in the sector and, at the same time, the easiest to correct with three routines:
- Verification of the recipient before sending: double-check the full email address, especially when it is auto-completed from the email client's address book. A one-character error sends tickets with passport data to the wrong recipient.
- Encryption of the PDF when it carries sensitive data: if the ticket, voucher or travel insurance contains a passport number, a partial card number or medical information about the client, the attachment is encrypted with a password and the password is communicated through another channel (text message to the client's mobile, phone call). Not through the same email.
- No mass sends in the open: never send operational communications with several clients in the "To" or "CC" field. If there is a legitimate multiple send, use "BCC" or, better, transactional email tools that send an individual email to each recipient.
Individual accesses to the GDS and the tourism CRM
The booking systems (Amadeus, Sabre, Travelport) and the tourism CRMs are the heart of the file. Their operational security rests on a clear rule: one account per agent, never shared.
- Individual user per agent with a personal password and, where the provider allows it, a second authentication factor.
- Differentiated profiles: not every agent needs to see every file or modify every booking. Roles must match the actual function of each person.
- Sign-out at the end of the day and automatic screen lock after inactivity.
- Immediate revocation when someone leaves the agency: on the day they leave, their user is deactivated in the GDS, CRM, corporate email and any auxiliary tool. The account is not reused for the replacement; a new one is created.
- Periodic review of the list of active users: once a quarter, check that there are no zombie accounts of people who are no longer there.
The traceability of accesses — knowing who entered, when and which file — is a measure under art. 32 GDPR and forms part of the agency's security policy. Sharing credentials destroys that traceability.
Custody of physical files
Although more and more agencies digitise the file, it is still common to keep printed copies of tickets, passport pages brought to the counter, signed package travel contracts or group lists. The practical rule is simple but strict:
- Cabinet or drawer with a lock, not on an open counter desk or on a visible shelf.
- Clean desk: "clean desk" policy at the end of the day. Anything not in use goes back to the cabinet.
- Location reserved to the team: not in areas accessible to clients or to external cleaning staff without a confidentiality agreement.
- Secure destruction upon expiry of the period: cross-cut paper shredder for small volumes; specialised service with certificate for larger volumes. Throwing tickets and booking sheets into the general bin is not erasure.
Counter service: discretion and screens not visible
The counter of a physical agency is an exposed space where several people may coincide. The operational routines are obvious but worth formalising:
- Agent's screen oriented so that it is not visible to the client waiting behind or to the one at the adjacent desk. Privacy filters if the layout of the premises does not allow it.
- Do not verbalise a client's data in front of another: full names, card numbers, destinations. Conversations involving sensitive data are moved to a private area or to a written channel.
- Screen lock when stepping away, even for a moment.
- Quote sheets and receipts printed for a client are either handed over or destroyed at the end of the day; they do not remain in trays accessible to other clients.
WhatsApp with clients: what for, and what not for
WhatsApp is an everyday tool in the relationship with travel clients. The practical rules are:
- Operational messages yes: time confirmation, departure reminder, boarding instructions, meeting point, location. Strictly minimum data.
- Travel documents, no: tickets, vouchers, insurance copies, contracts. Those documents travel by email (encrypted if they carry sensitive data) or through the client's private area.
- No broadcast lists that expose some clients' numbers to others. Individual conversations.
- Separation from the personal sphere: ideally, a specific number for the agency, not the agent's private WhatsApp. And in any case, the agent's mobile must not be used as the historical archive of the file.
Minors' data in group lists
When the agency manages group trips (school groups, family groups, organisations), it often handles lists with minors' data. The routine is:
- Only the strictly necessary data of the minor (name, date of birth, passport number if the destination requires it). No excess data.
- Boarding and check-in lists: when a list is printed for operational use (handed to the guide, the destination handler, the group leader) it is delivered only to the person who needs it, recovered at the end of the trip and destroyed.
- Distribution through secure channels: never a PDF with minors' data sent to an open WhatsApp group or to a generic address.
- Differentiated custody: minors' travel files are kept under the same rules of minimisation and retention as the rest, but with enhanced sensitivity.
Breaches at airlines, hotels or the GDS: what to do
Security breaches at large sector providers (airlines, hotel chains, GDS, payment platforms) are a realistic scenario. When one of those providers notifies that it has suffered a breach that may affect the agency's clients, the routines are:
- Activate the agency's internal breach protocol and record the incident in the breach register (art. 33.5 GDPR), with description, affected data, time of detection and measures taken.
- Assess the role of each party: if the data are under the provider's control in its role as independent controller (typically the airline or the hotel), the main obligation to notify the AEPD lies with that provider. If the affected data are under the agency's control (its CRM, its file), the obligation lies with the agency.
- Communication to the affected client under art. 34 GDPR where appropriate: when the breach entails a high risk to the rights and freedoms of the data subject.
- Do not forward the provider's email containing the personal data of those affected to unauthorised recipients. Breach handling is internal and, where appropriate, before the AEPD.
Time-tracking of the agency's staff, finally, can be arranged through systems such as individual PIN codes, proximity cards or a corporate mobile app.
"En una agencia de viajes, casi todo el riesgo de protección de datos cabe en tres frases: no fotografíes pasaportes con el móvil, no compartas el usuario del GDS y verifica el destinatario antes de enviar el billete. Lo demás suele ordenarse solo."
Mario P. Talamillo · Managing Partner, Certix®
If you run a travel agency and want to review your data protection documentation, at Certix we work specifically with travel agencies. No sales reps: from the first contact, you will speak to a specialist.
Data protection guide for travel agencies
This content is merely indicative and informative; it does not in any case constitute specialist legal advice. Regional sector regulations may extend or modify the periods and requirements set by state law. The application of the regulations to each specific case requires an individualised analysis.