Certix

Daily good practices of the rural guest house owner to protect data

Certix
Certix®
· 1 Jun 2026 · 7 min read

Informative article. It does not replace individualised professional advice.

In a rural guest house, almost everything is decided and managed by the same person: the owner opens the door, welcomes the guest, records the ID details, sends the confirmation, issues the invoice and keeps custody of the contracts. That closeness is one of the sector's virtues, but it is also where data protection is at stake: on the entry table, on the owner's mobile phone, in the cupboard where the registers are kept, and in the bin where — far too often — the contracts end up at the close of the season.

This guide gathers concrete routines for the day-to-day running of a small tourist accommodation. It is not a legal course: it is a set of habits that organise operations and, along the way, comply with the GDPR, the LOPDGDD and Royal Decree 933/2021.

The golden rule: record data, not documents

The first operational principle of check-in in a rural guest house is straightforward: the data required by hospitality regulations are recorded, not the image of the document. In practical terms, this means:

  • The guest presents their ID card, NIE or passport.
  • The owner reads and records the essential data required to comply with Royal Decree 933/2021 (identification data, document number, stay data) and for billing.
  • The document is returned immediately to the guest.
  • It is not photocopied, not scanned, not photographed with the mobile, and no copy is kept — neither on paper nor in a digital file.

The reason is twofold: art. 5.1.c GDPR imposes the minimisation principle (only the data strictly necessary for the purpose) and the consolidated enforcement criterion of the AEPD considers it disproportionate to retain the full image of the ID document for this purpose. Recording the data covers the legal obligation; the photocopy does not add anything, but it does add risk.

Do not use the personal mobile to store copies of guest documents

This is probably the most widespread bad practice in the sector and, also, the easiest to correct. From the owner's point of view it is very tempting: "I'll just take a photo of the ID with my mobile so I can write it down later in peace". The problem is that the photo:

  • Is automatically uploaded to the personal cloud of the mobile (Google Photos, iCloud) and mixed with family photos.
  • May end up in domestic backups without professional encryption.
  • Is visible to anyone with access to the mobile: family members, technicians during a repair, shared devices.
  • Cannot be erased with any guarantees once the guest leaves, nor does it comply with the periods set in RD 933/2021.
  • Mixes the owner's personal sphere with the professional one, which hinders any subsequent audit and the handling of data subject rights.

The rule is clear: the owner's personal mobile is not a professional processing system. Guest data — including ID document data — must only enter the accommodation's management software or, where applicable, the physical register kept under lock and key. If the owner needs an operational messaging channel with guests, a specific business number or corporate tool is preferable, kept separate from the family sphere.

Communication to law enforcement authorities (SES.HOSPEDAJES)

Royal Decree 933/2021 requires the accommodation to communicate the traveller register data to the competent authorities through the established electronic channels, mainly the SES.HOSPEDAJES system, managed by the Secretariat of State for Security. In practical terms:

  • Legal basis: art. 6.1.c GDPR (compliance with a legal obligation).
  • What is transmitted: guest identification data, document data, stay data and payment data on the terms set out by the rule itself. Only what is provided for.
  • Communication deadline: the one set by RD 933/2021 from the moment of check-in.
  • Internal retention period: three years from the date the contracted service or provision ends.

Regional tourism regulations may add further formal requirements (establishment registers, own books, registration forms). It is advisable to check the applicable regional rule.

Secure custody of physical registers and holiday rental contracts

Although more and more accommodations are digitising check-in, it is still common to keep physical registers and holiday rental contracts on paper. The practical rule is simple but strict:

  • Cabinet or drawer with a key, not on an open table at the entrance or on a visible shelf.
  • Location reserved for the rural guest house owner: not in areas accessible to guests or to external cleaning staff.
  • Chronological order that allows the period of each register to be identified (three years from the end of the service for the traveller register; applicable tax periods for the associated invoice).
  • Minimum inventory of what is kept, so that a piece of data can be located quickly if a guest request or an inspection arrives.

Secure destruction when retention periods are met

Meeting the RD 933/2021 period also means securely destroying what should no longer be retained. Throwing registers or contracts into the general waste is not erasure: it is exposure. The reasonable options are:

  • Cross-cut paper shredder, sufficient for a small accommodation.
  • Specialised confidential destruction service with certificate, if the volume justifies it.
  • Logical deletion in the management software with confirmation to the owner, for digital registers.

And an important reminder: if the rural guest house uses external booking software, that supplier is a processor (art. 28 GDPR). When the contract with it ends, the correct approach is to first export the full database to the owner in a useful format (CSV, Excel) in order to keep the historical records the accommodation still needs for its statutory periods — tax, traveller register — and only then request erasure from the outgoing supplier's systems (art. 28.3.g GDPR).

WhatsApp with guests: use it well, without overusing it

WhatsApp is a legitimate tool for operational communication with the guest (confirmation of timings, arrival instructions, location). The practical rules are:

  • Minimum essential data: no copies of ID documents, no payment data, no sensitive information.
  • No broadcast lists that expose the numbers of some guests to others. Individual conversations only.
  • The booking record channel remains the professional system or email, not the mobile chat.
  • Periodic deletion of old conversations once their purpose has been served.
  • Separation from the personal sphere: ideally a specific number for the accommodation, not the owner's private WhatsApp.

Perimeter video-surveillance: sign, perimeter and retention period

Rural guest houses often have security cameras at accesses, gardens and car parks, especially in isolated settings. The operational rules are clear:

  • Information sign visible at the entrance area (art. 22.4 LOPDGDD), with the controller and how to exercise rights.
  • Maximum retention period of 30 days (art. 22.3 LOPDGDD), save for retention to report offences or for proceedings.
  • Coverage limited to the property itself: without invading the public thoroughfare beyond what is essential for access, or neighbours' land.
  • Never inside the accommodation: the interior of the rural guest house is the guest's private space during their stay. Video-surveillance stays outside. Applying the spirit of art. 89.1 LOPDGDD (which prohibits cameras in rest areas, changing rooms and toilets), the interior of the guest's accommodation falls outside any capture system.
  • No microphones associated with the cameras: sound recording is an additional intrusion that is very difficult to justify.

"En una casa rural casi todo se decide en el primer minuto de la llegada del huésped. Si en ese minuto se anotan los datos, se devuelve el documento y no se le hace una foto al DNI con el móvil, casi todo lo que viene después va bien."

Mario P. Talamillo · Managing Partner, Certix®

If you manage a rural guest house or small tourist accommodation and want to review your data protection documentation, at Certix we work specifically with rural guest houses. No salespeople: from the first contact, you will speak to a specialist.


This content is merely indicative and informative; it does not in any case constitute specialised legal advice. Regional sectoral regulations may extend or modify the periods and requirements of the national rule. The application of the regulations to each specific case requires individualised analysis.

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →