Data protection in a hotel is not played out in the documents in the cupboard, it is played out at reception, at the shift handover, in the corridor and in the staff dining room. A PMS PIN shared with a temp, a screen visible to the customer waiting for the key, a photo of the passport taken "just in case", or a WhatsApp group where the name of the guest in room 304 is discussed: each daily gesture defines what the hotel really does with the information it safeguards.
This guide brings together concrete routines for reception, housekeeping, kitchen and administration. It is not a legal course: these are habits that organise operations and, along the way, comply with the GDPR, the LOPDGDD, the Ley Orgánica 4/2015 on Citizen Security, Real Decreto 933/2021 (SES.HOSPEDAJES) and the applicable labour regulations.
The golden rule: record data, not documents
The first operational principle of the hotel check-in is straightforward and non-negotiable: only the alphanumeric data legally required are recorded — never the image of the document.
Hotels MUST NOT photocopy, photograph or scan guests' ID cards or passports. According to the AEPD's settled doctrine and the data minimisation principle (art. 5.1.c GDPR), making full copies of identity documents is disproportionate and unlawful. Hotels are only allowed to capture — manually or via automated digital systems — the alphanumeric data legally required by the traveller registration system (Ley Orgánica 4/2015 on Citizen Security and its implementing regulation, Real Decreto 933/2021, SES.HOSPEDAJES). Retaining images of the physical document containing signatures, photographs or national security features is expressly forbidden.
In practical terms this means:
- The guest presents their ID card, NIE or passport at reception.
- Reception reads the document and types into the PMS only the alphanumeric data required by Real Decreto 933/2021 (identification data, document number, stay data) and the data necessary for billing. The image of the document is never captured.
- Reception returns the document immediately to the guest. It is not kept in the drawer, not moved to the back of the counter, not left on the bar.
- The hotel never photocopies, photographs, scans or stores an image of the ID card or the passport — neither on paper, nor as a PDF, nor as a photo on any device.
The basis is twofold. On the one hand, the minimisation principle of art. 5.1.c GDPR: only data adequate, relevant and limited to what is necessary for the purpose may be processed. On the other, the consolidated enforcement criterion of the AEPD: storing the full image of the document is disproportionate when the sectoral rule only requires the alphanumeric data. The legal obligation of Ley Orgánica 4/2015 and Real Decreto 933/2021 is met by transmitting the required data through the enabled SES.HOSPEDAJES electronic channel, not by archiving a copy of the guest's document.
Communication to law enforcement authorities (SES.HOSPEDAJES)
The Ley Orgánica 4/2015 on Citizen Security and its implementing regulation, Real Decreto 933/2021, require accommodation establishments to record and communicate to the competent authorities certain alphanumeric data about guests. That communication is made through the SES.HOSPEDAJES system, managed by the Secretariat of State for Security. The legal basis is art. 6.1.c GDPR (compliance with a legal obligation). The obligation is fulfilled by transmitting only the alphanumeric data required by the rule — never by sending or archiving an image of the document.
- What is transmitted: the data required by the sectoral rule (guest identification, document, stay data and other fields provided for in RD 933/2021).
- When it is transmitted: within the deadlines set by the rule itself for communication to the authorities.
- Retention period: the traveller register information is retained for three years from the end of the service (RD 933/2021).
- How it is transmitted: through the enabled electronic system; not by ordinary mail or informal channels.
Regional tourism regulations may add further formal requirements (regional traveller registers, sectoral registers). It is advisable to check the regional regulations applicable to the accommodation.
Reception and front desk: individual passwords, non-visible screens, discretion
Reception is the nerve centre for data processing in a hotel. It concentrates the PMS, the booking engine, card data for the guarantee, calls and check-in forms. Any access must be identified and any conversation must be discreet.
- One user per person in the PMS (never shared between receptionists, not even between shifts). Joiners and leavers are managed on the same day of joining or departure.
- Lock the session when leaving the counter (even to accompany the guest to the lift: the PMS with an open session is an open door).
- Screens oriented so that they are not visible from the customer's side. If the layout does not allow it, use a privacy filter.
- Do not say names or room numbers aloud when handing over the key card: the envelope with the room number is shown to the guest, it is not announced out loud.
- Do not discuss guest data between receptionists while there are customers at the counter. Confidential matters are dealt with in the back office.
- Role-based permissions: reception does not need access to staff payroll; management does not need to see laundry supplier lists; each profile sees only what is necessary.
The basic rule: if an operation in the PMS is logged with Lucía's user, Lucía must have performed it. That traceability protects everyone — the guest, the team and the controller.
Custody of the entry form and the traveller register
Although much of the traveller register is digitised and connected to the SES.HOSPEDAJES system, in many hotels it coexists with physical format (printout, guest's signature). That documentation contains identification data and must be kept in an orderly manner:
- Do not leave it in view on the counter. File it at the end of the shift.
- Locked cabinet or closed drawer in an area not accessible to the public.
- Restricted access: only reception and administration, according to role.
- Retention during the statutory period (three years from the end of the service, RD 933/2021).
- Secure destruction upon expiry of the period: in-house shredder or contract with a specialist confidential destruction company. Never an ordinary bin.
Housekeeping and cleaning: discretion and protocol with personal belongings
The housekeeping team accesses rooms with guests' personal belongings on a daily basis. Practice must be governed by discretion and minimum intervention:
- Do not photograph personal belongings, forgotten documents or any content of the room with the personal mobile. The camera on the personal mobile is not a work tool.
- Lost property protocol: custody in a controlled "lost property" cupboard, with a note of room, date and generic description. The description does not include personal data beyond what is essential to return the item.
- Forgotten documentation (ID, passport, cards): specific custody protocol and communication to the guest through PMS channels. It is never photocopied, photographed, scanned or shared in internal groups, and it is not left in view. The same prohibition that applies at check-in applies to any document found in the room.
- Schedules and occupancy lists: visible only to the staff who need them. Not displayed in common staff areas accessible to third parties (suppliers, external technicians).
- Staff mobiles: responsible use; guests, rooms or documentation are not photographed.
Guest's medical information: allergies, assistance and specific needs
If the hotel has a restaurant, cafeteria or room service, it will receive information about allergies and intolerances of the guest. The operational rule is the same as in the hospitality sector:
- Ephemeral processing during the service: the allergy is a vital note for the kitchen for as long as the service lasts. Once the service is over, the data is deleted from the order and the sheet is destroyed. It does not require a specific checkbox but it must be informed in the privacy notice indicating its temporary nature (art. 13 GDPR).
- Permanent processing in the CRM or VIP record of the PMS (retaining the allergy for future stays): requires explicit specific consent from the guest themselves (art. 9.2.a GDPR). It is implemented with an independent tick box unticked by default in the booking engine, or with a specific signature on the physical record. A generic "I accept the terms" is never enough.
- Other health needs communicated at booking (reduced mobility, requested medical assistance, specific requirements): same principle. If used only for that stay, it is treated as ephemeral data; if it is to be kept in the guest's profile, it requires explicit consent.
- Discretion in transmitting that information within the team: through corporate channels, not through the staff's personal messaging groups.
Team communications: corporate channel, not staff WhatsApp
The hotel staff's WhatsApp group is a convenient and quick channel, but it is also a personal channel of the worker, outside the controller's control and with copies on mobiles that do not belong to the company. It is not the place to transmit guest data or sensitive HR matters.
- Do not transmit via staff WhatsApp guest names, room numbers, customer incidents, health data or payment data.
- Do not transmit via staff WhatsApp sick leave certificates, medical data of colleagues, payslips or disciplinary matters.
- Controlled corporate channel for internal operational messaging: individual accounts, ability to revoke upon leaving, storage under the controller's control.
- Hotel telephone line (not the receptionist's personal mobile) for calls to guests from the team.
- Schedules and internal communications through the corporate platform, not by broadcast on a personal messaging group.
Video-surveillance in the hotel: permitted areas, prohibited areas, retention period
Video-surveillance is a legitimate security and prevention tool, but it is subject to strict limits. The reference rule in Spain is art. 22 LOPDGDD, complemented, for the employment context, by art. 89 LOPDGDD.
| Area | Camera? | Basis / limit |
|---|---|---|
| Reception and general accesses | Yes | Art. 6.1.f GDPR + art. 22 LOPDGDD. Signage under art. 22.4 LOPDGDD. |
| General corridors and common areas | Yes | Security and access control. |
| Car park | Yes | Asset security. |
| Rooms | NO | Guest's privacy: absolute prohibited area. |
| Communal bathrooms and changing rooms | NO | Art. 89.1 LOPDGDD: strict prohibition. |
| Staff dining room and rest areas | NO | Art. 89.1 LOPDGDD: strict prohibition. |
| Kitchen (employment monitoring) | Subject to limits | Art. 89 LOPDGDD: express information to staff; defined purpose; no audio as a general rule. |
Additional operational rules:
- Maximum retention period: one month from the capture (art. 22.3 LOPDGDD), except for retention required by judicial or police order or to evidence acts against persons or property.
- Visible signage in an accessible area with the essential information of art. 13 GDPR and a system to access the complete information (art. 22.4 LOPDGDD).
- Do not record audio as a general rule.
- Access to recordings restricted to authorised staff, with a log of who accesses and why.
Regional regulations and sectoral collective bargaining may modulate the scope of employment monitoring.
Staff time recording: safe alternatives
Working-time recording is mandatory (art. 34.9 ET) and must be retained for four years. In a hotel — with shifts, temps, peak seasons and rotation — the clock-in system must be agile.
The lawful and safe alternatives the hotel should implement are:
- Individual PIN at the clock-in terminal.
- RFID proximity card or clock-in key.
- Corporate mobile app with authentication.
- NFC clock-in with workplace devices.
The time record is retained for four years (art. 34.9 ET and art. 20 bis ET), accessible to the worker, to the legal representation and to the Labour Inspectorate. Regional regulations and the applicable collective bargaining agreement may add detailed requirements.
Employee data and duty to inform on day one
- Art. 13 GDPR information notice delivered upon signing the contract and filed with acknowledgement of receipt.
- Access to tools: individual user in the PMS and other systems; never a shared password.
- Sick leave, certificates and medical data: direct channel with the person in charge. Never through the staff group.
- Welcome training: every new joiner receives a brief internal good practices guide (ID rule, session closing, communications, mobiles).
- Staff departures: upon leaving, immediate revocation of access to the PMS, internal systems and corporate channels.
"En un hotel, el día que un huésped reclama no se mira la carpeta de políticas: se mira si recepción devolvió el documento, si el PMS tenía un usuario por persona y si nadie habló del cliente en voz alta. Ahí se gana o se pierde la confianza."
Mario P. Talamillo · Managing Partner, Certix®
If you manage a hotel, hostel or accommodation chain and want to review your data protection documentation, at Certix we work specifically with hotels and accommodation providers. No salespeople: from the first contact, you will speak to a specialist.
Data protection guide for hotels
This content is merely indicative and informative; it does not in any case constitute specialised legal advice. Regional sectoral regulations may extend or modify the periods and requirements of the national rule. The application of the regulations to each specific case requires individualised analysis.