Certix

Data protection in a travel agency: where to start

Certix
Certix®
· 1 Jun 2026 · 8 min read

Informative article. It does not replace individualised professional advice.

A travel agency processes personal data from the very first minute: the client requests a quote, shares the exact name and surnames as they appear in the passport, the dates of fellow travellers, a dietary preference, a possible need for reduced mobility and, when minors are involved, the name and date of birth of the son, daughter or grandchild who is travelling. Bookings then follow with airlines, hotels, insurers and, where the destination requires it, authorities of the country of arrival. Data protection is not an add-on at the end of the file: it forms part of the package travel file itself.

This guide summarises the minimum documentation any travel agency should have available — to open a new agency, regularise an existing one or review its position after a change of advisor or GDS — under the framework of the GDPR (EU Regulation 2016/679), the LOPDGDD (Organic Act 3/2018) and the sector-specific tourism regulations.

Why a travel agency processes personal data intensively

The typical file of a package trip brings together data of several categories and several data subjects simultaneously. It is worth identifying them from the outset:

  • Contracting clients: name and surnames, ID card or passport, date of birth, contact details, billing data and payment data.
  • Adult fellow travellers: the same basic identifying data, in their capacity as travellers on the file.
  • Minors who travel: name, date of birth, passport details if the trip requires them and, where applicable, authorisation from the holder of parental responsibility.
  • Declared special needs: food allergies, intolerances, reduced mobility, medical assistance, specific menus. These are health data (art. 9 GDPR) and require enhanced processing.
  • Suppliers and partners: contact persons at airlines, hotel chains, destination handlers, travel insurers, advisors and the payment platform.
  • Authorities of the destination country: on certain trips, traveller data are communicated to the immigration or health authorities of the destination, as required by the law of that country.

The controller is the travel agency itself (legal entity or self-employed holder), which decides what data are collected, for what purpose and by what means. That role is independent of the role of each airline, hotel or insurer with which the agency contracts: each one acts as an independent controller for the part of the processing that it carries out within the trip.

The controller's minimum documentation

These are the documents that, as a minimum, a travel agency should have ready before the first file. Some are mandatory; others are good practices that save trouble when a complaint, a consumer inspection or a change of provider arrives.

Document Legal basis Purpose
Record of Processing Activities (RoPA) Art. 30 GDPR Internal inventory of what is processed, for what purpose, for how long and with what measures.
Information clause for clients Art. 13 GDPR Information delivered when contracting the trip and when collecting data of fellow travellers and minors.
Website privacy policy Arts. 13 and 14 GDPR Public, full version of the information that the agency provides to the website user.
Website legal notice Art. 10 LSSICE Identification of the site owner, name, tax ID, address, travel agency registration number.
Cookie policy and banner Art. 22.2 LSSICE Information layer and consent mechanism for cookies that are not strictly necessary.
Processor contracts Art. 28 GDPR Agreement signed with each provider that processes data on behalf of the agency (GDS, tourism CRM, advisor, payment platform).
Security policy Art. 32 GDPR Technical and organisational measures: individual accesses to the GDS, passwords, backups, custody of paper.
Breach protocol Arts. 33–34 GDPR Procedure to detect, assess and, where appropriate, notify the AEPD and the data subjects.
Data subjects' rights procedure Arts. 15–22 GDPR Channel to handle access, rectification, erasure, objection, portability and restriction.

Package travel files: content, retention and documentary trail

The package travel file has a twofold reading. From the commercial and consumer perspective, the General Act for the Defence of Consumers and Users (consolidated text approved by RD Legislativo 1/2007, amended by RD-Ley 23/2018 as regards package travel and linked travel arrangements) requires documenting the contract, the conditions of the trip, the pre-contractual information, amendments and, where applicable, incidents and complaints. From the GDPR perspective, that same file contains personal data which are retained for as long as the purpose lasts and the associated statutory periods apply.

  • Retention for contractual and consumer obligations: as a prudent and general criterion, an approximate horizon of five years is usually applied, derived from the general limitation periods for personal actions under the Spanish Civil Code (art. 1964 CC after the 2015 reform) and from consumer law obligations. For commercial obligations, the Commercial Code provides for periods of up to six years for commercial documentation (art. 30 CCom).
  • Retention for tax obligations: documentation with tax effects is retained in accordance with the periods laid down in the General Tax Act and its implementing regulations (in general terms, the tax limitation periods).
  • Minimisation within the file: what is retained is what is needed to evidence the provision of the service and handle complaints; it is not necessary to keep full copies of the passport nor detailed health data beyond the period for which they were useful.

The regional regulations of the tourism sector (registers of agencies, complaint forms, formal requirements for the documentation handed to the client) may add additional requirements in each Autonomous Community. It is mandatory to check the regional regulations applicable to the establishment.

Information clause for the client (art. 13 GDPR)

The duty to inform under art. 13 GDPR is mandatory even where the legal basis of the processing is the performance of the contract. This is one of the most frequent mistakes in the sector: assuming that, because the trip is contracted, nothing needs to be handed over. It does. The agency's information clause must respond, in simple but complete terms, to the following:

  • Who processes the data: identification of the agency, registration number as a travel agency, address and contact channel for data protection matters.
  • What data are processed: identifying data of the client and fellow travellers, passport or ID card details, date of birth (particularly relevant for minors), payment data, declared special needs (allergies, reduced mobility, medical assistance).
  • Purposes: management of the travel file, contracting with suppliers (airline, hotel, destination handler, insurer), invoicing, customer service and complaints, compliance with legal obligations of the destination country where applicable.
  • Legal basis: performance of the contract (art. 6.1.b) as the general basis; legal obligation (art. 6.1.c) for processing required by law; consent (art. 6.1.a) for the agency's own marketing if any; and, for declared medical needs and allergies, dual basis: art. 6.1.b + art. 9.2.a (explicit consent).
  • Recipients: airline, hotel chain, destination handler, travel insurer, payment platform, Tax Administration, advisor and, where the destination requires it, authorities of the country of arrival.
  • International transfers: where the trip involves destinations outside the EU, express mention of the communication of data to the airline, the hotel or the authority of the destination country, identifying the enabling basis (art. 49.1.b GDPR for communications necessary for the performance of the contract with the data subject).
  • Retention period: the duration of the trip and the subsequent retention periods (consumer, commercial, tax) applicable to the file.
  • How to exercise rights: access, rectification, erasure, objection, restriction, portability and lodging a complaint with the AEPD.

The clause must be available at the usual collection points: website form, quote sheet, package travel contract, special needs form and, if the agency sends a newsletter, on the subscription form.

Special data in the file: allergies, reduced mobility, medical assistance

When a client declares a food allergy, an intolerance, a reduced mobility or a need for medical assistance, that information is health data (art. 9 GDPR). The agency needs it to ensure the service (special in-flight menu, airport assistance, adapted room, accessible transport at destination), but its processing requires a dual legal basis:

  • Art. 6.1.b GDPR: performance of the contract. Without that information, the agency cannot provide the service safely.
  • Art. 9.2.a GDPR: the client's explicit consent for that specific information to be communicated to the airline, the hotel, the destination handler and the insurer.

In operational terms, the information clause must explain that these data are transmitted exclusively to the suppliers that need to adapt the service, for the time strictly necessary for the provision of the trip, and that they are not added to the agency's commercial or marketing databases. If the client does not wish to communicate that information, the agency must assess whether it can provide the service without that adaptation; but it cannot require it for other purposes.

Minors' data in family bookings

In family bookings, it is common to include one or more minors. Two key rules of the GDPR and the LOPDGDD come into play here:

  • Art. 7 of the LOPDGDD sets the consent threshold for minors in Spain at 14 years. Below that age, consent corresponds to the holder of parental authority or guardianship.
  • In family travel bookings, we are not really in a consent scenario but in one of performance of the contract signed by the parents or guardians (art. 6.1.b). The agency processes the minor's data so that they can travel under the booking made by their parents.
  • As an operational rule: only the strictly necessary data of the minor are collected (name, date of birth, passport number if the destination requires it). Additional unnecessary data are not requested. If the minor has food allergies, the dual basis described above applies and the information is transmitted to the airline and the hotel to ensure food safety.
  • The travel authorisations for minors that some destinations require (when the minor travels with only one parent or with a third party) are documents whose purpose is to evidence the consent of the holder of parental authority. They are kept in the travel file, not in commercial databases.

Usual processors (art. 28 GDPR)

An agency's file depends on several providers that process personal data on behalf of the agency. Each one is a processor and requires a contract signed under the terms of art. 28 GDPR.

Provider Data processed Key document
GDS (Amadeus, Sabre, Travelport) Traveller data for flight, hotel and related service bookings Art. 28 GDPR contract + international transfer analysis
Tourism CRM / back office Client records, travel history, document management Art. 28 GDPR contract + server location
Advisor / tax adviser Invoicing, accounting data, personnel Art. 28 GDPR contract
Payment platform (virtual POS) Client payment data Art. 28 GDPR contract + PCI-DSS compliance
Airlines, hotels, insurers, destination handlers Traveller data to provide the contracted service Usually independent controllers; case-by-case analysis

A recurring note: at the end of the contract, the processor must return or export the data to the controller, and only then delete them (art. 28.3.g GDPR). This allows the agency to keep the historical record of files during the legal periods — consumer, commercial, tax — without depending on the outgoing provider. The detail of the regime applicable to the GDS and the CRM is developed in the third article of this guide.

International transfers in the travel sector

A travel agency makes, almost by definition, communications of data outside the European Economic Area. It is important to distinguish two different scenarios that are often mixed up:

  • Communication necessary for the performance of the contract with the data subject (art. 49.1.b GDPR): when the client's data are sent to the airline of the destination country, to the hotel where they are staying, to the insurer covering the trip or to the immigration authority of the country of arrival, that transfer is covered by the very nature of the travel contract. It does not require an adequacy decision or standard contractual clauses: it forms part of the provision of the service that the client has contracted.
  • Regulated international transfer with CCT, DPF or adequacy decision: when the agency contracts a provider outside the EU to process data on its behalf (a GDS with servers in the US, a CRM hosted in a non-EU region, a hosting or technical support service outside the EU), we are dealing with an ordinary international transfer that does require safeguards. In the US, the usual safeguard is the provider's adherence to the Data Privacy Framework (DPF); in other destinations, the Standard Contractual Clauses (CCT) approved by the Commission or, where it exists, the adequacy decision.

The information clause given to the client must mention both scenarios in understandable terms: that on their trip data will be communicated to providers and authorities of the destination country (art. 49.1.b) and that the agency's technology providers may process data on servers outside the EU under the applicable safeguards.

"En una agencia de viajes la protección de datos se juega en el expediente. Si está claro qué datos se piden, para qué, durante cuánto tiempo, con quién se comparten y bajo qué base jurídica, todo lo demás —contratos con proveedores, deber de información, transferencias internacionales— encaja casi solo."

Mario P. Talamillo · Managing Partner, Certix®

If you run a travel agency and want to review your data protection documentation, at Certix we work specifically with travel agencies. No sales reps: from the first contact, you will speak to a specialist.


This content is merely indicative and informative; it does not in any case constitute specialist legal advice. Regional sector regulations may extend or modify the periods and requirements set by state law. The application of the regulations to each specific case requires an individualised analysis.

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →