A good part of the bookings of any rural guest house today come through Booking, Airbnb or portals more specialised in rural accommodation. For the owner, those channels are an essential commercial tool. For data protection, they are an intermediate layer between the guest and the accommodation that deserves specific analysis: who is responsible for what? What document is appropriate to sign with them? What happens with the guest data that comes in through them? And what about when the relationship with the platform ends?
This guide reviews the GDPR regime applied to the relationship between a rural guest house and booking portals: the key distinction between independent controller and processor, the actual flow of guest data, the duty to inform under art. 13 GDPR and the management of breaches, retention and channel terminations.
How booking platforms work from the GDPR's point of view
The GDPR distinguishes two main roles for any organisation that processes personal data:
- Controller (art. 4.7 GDPR): the party that decides the purposes and means of the processing.
- Processor (art. 4.8 GDPR): the party that processes personal data on behalf of the controller, following its instructions, without deciding the purposes.
Added to these two roles is that of joint controllers (art. 26 GDPR), which arises when two organisations jointly determine the purposes and means. Classifying a booking portal as an independent controller, a processor or a joint controller depends on the actual data flow and on who takes each decision.
Key distinction: independent controller or processor?
The answer is not uniform: it depends on the specific portal and on the moment of the flow. As a general criterion, in the case of the large consumer-facing portals (Booking, Airbnb, Expedia or equivalents), the most widely held and conservative reading is that they usually act as independent controllers of the guest's data, not as processors of the accommodation. The operational reasons are consistent with that reading:
- The portal captures the guest's data on its own account (user registration on the portal, customer profile, searches and bookings), before the accommodation is involved.
- It maintains its own database of the guest, separate from the accommodation's, and uses it for the portal's own purposes (recommendations, loyalty, commercial communications, profiling).
- When it transmits the booking to the accommodation, it does not do so on the accommodation's instructions, but applying its own terms and conditions.
- The guest receives the portal's own privacy policy and exercises their rights against the portal directly.
In the case of more specialised B2B channels (channel managers, niche portals that only distribute availability and communicate bookings following the accommodation's instructions) the reading may be different: there it is more likely that the portal acts as a processor of the accommodation, which triggers the art. 28 GDPR contract.
A categorical and universal statement about the role of Booking, Airbnb or any other platform would be imprudent: the specific role depends on the portal's business model and on the actual data flow. The practical rule is: analyse case by case, read the portal's clauses on data processing and, in case of doubt, refer the matter to a specialist.
When the platform acts as an independent controller
In this scenario — the most common with Booking and Airbnb — both parties are joint controllers of the guest's data, each one for its own part of the processing:
- The portal is responsible for acquisition, the user profile, the portal's marketing, its own historical database and the handling of the guest's rights against that part.
- The rural guest house is, in turn, responsible for the data it receives to manage the stay: booking confirmation, provision of the accommodation service, compliance with Royal Decree 933/2021, billing, handling of complaints and, where appropriate and on its own basis, commercial communications or its own loyalty programme.
Each party answers to the guest for its own share of processing. The accommodation is not released from the GDPR by virtue of the booking having come in through a platform: it remains the controller of the processing it carries out with the data received.
When the platform acts as a processor
This is less common with the large consumer-facing portals, but it does happen with channel managers, integrated booking engines and certain specialised B2B channels: the portal processes the guest's data on behalf of the accommodation, following its instructions, without significant purposes of its own. In that case:
- It is appropriate to sign a processor contract under art. 28 GDPR, with the minimum content of art. 28.3 (subject matter, duration, nature and purpose of the processing, type of data, obligations and rights of the controller, etc.).
- The processor must work under documented instructions from the accommodation, commit to the confidentiality of its staff, apply appropriate technical and organisational measures and notify breaches to the controller.
- At the end of the contract, art. 28.3.g GDPR applies: the processor must return or erase the data at the controller's choice. In practice, first export the database to the accommodation in a useful format and only then proceed to erase it in the processor's systems.
What guest data the accommodation receives from the platform and how to handle them
When a booking arrives through a portal, the accommodation normally receives a limited set of data: name of the main guest, contact, dates, number of persons, amount and, in some cases, partial payment data. The practical rule is:
- Process those data only for the purposes of the booking: provision of the service, compliance with RD 933/2021, billing and, where applicable, operational communications with the guest.
- Complete only what is essential at check-in (ID document data for the traveller register), applying the golden rule of the guide: record data, do not photocopy the document.
- Do not use the data for own marketing without a legitimate basis of one's own (consent of the guest given to the rural guest house, or legitimate interest in existing customers regarding similar products on the terms of art. 21.2 LSSICE).
- Document in the RoPA the flow: origin of the data (platform), purposes, legal basis and periods.
Coordinating the duty to inform (art. 13 GDPR) with the platform
The duty to inform under art. 13 GDPR is triggered whenever the accommodation collects personal data, regardless of the channel. The platform's privacy policy only covers the portal's part of the processing. In practice:
- The guest receives the portal's own privacy policy when registering and booking on the platform.
- When they come into direct contact with the rural guest house — accommodation's confirmation email, pre-check-in message, registration card on arrival — they must also receive the accommodation's own information notice.
- The accommodation's notice must mention the platform as the source of the data (where applicable) and the State Security Forces and Bodies as the recipient of the mandatory communication (RD 933/2021).
This dual information is not redundant: each party informs about its own share of processing.
Security breaches on the platform
A breach in the systems of a large portal is a realistic scenario. The allocation of responsibilities depends on the role of each party with respect to the data affected:
- If the breach affects data under the portal's control in its role as an independent controller, the obligation to notify the AEPD and, where appropriate, the data subjects, falls primarily on the platform (arts. 33 and 34 GDPR).
- If the breach affects data that the accommodation already holds under its control — records in its software, physical registers, contracts — the notification obligation falls on the accommodation as controller.
- If the platform acts as a processor and suffers a breach, it must notify it to the accommodation (controller) without undue delay (art. 33.2 GDPR), and the accommodation assesses notification to the authority and to the data subjects.
That is why it is important to have an internal breach protocol that triggers the assessment whenever any communication from a portal in this regard is received.
When the relationship with the platform ends
Exiting the channel is a moment when it is worth being clear about the rules:
- If the platform was acting as a processor, art. 28.3.g GDPR applies: the right to receive the full return of the data in a useful format (CSV, Excel) before erasure in the processor's systems. The correct procedure is to export first, verify afterwards and request erasure in writing at the end.
- If the platform was acting as an independent controller, art. 28.3.g does not apply — it was not a processor. Each party manages the retention of its own database in accordance with its periods and legal obligations. The accommodation keeps intact the data it collected itself (traveller register, billing, own records) for the corresponding period.
Hence an essential practical recommendation: do not rely exclusively on the portal to retain guest information. The data essential for compliance with RD 933/2021, billing and the handling of complaints must be held in the accommodation's own system (or in physical format kept under lock and key), not only in the portal's interface.
"Booking y Airbnb no eximen a la casa rural de cumplir el RGPD. Cuando entran como canal, lo más habitual es que sean responsables independientes sobre su parte, y el alojamiento sigue siendo responsable sobre la suya. Saber dónde acaba uno y dónde empieza el otro es la mitad del trabajo."
Mario P. Talamillo · Managing Partner, Certix®
If you manage a rural guest house or small tourist accommodation and want to review your data protection documentation, at Certix we work specifically with rural guest houses. No salespeople: from the first contact, you will speak to a specialist.
Data protection guide for rural guest houses
This content is merely indicative and informative; it does not in any case constitute specialised legal advice. Regional sectoral regulations may extend or modify the periods and requirements of the national rule. The application of the regulations to each specific case requires individualised analysis.