A rural guest house is a small business with a close relationship to its guests, but from a legal standpoint it processes personal data with the same seriousness as a hundred-room hotel: it receives bookings via its website or through platforms such as Booking and Airbnb, records identification details at check-in, communicates the traveller register to the Ministry of the Interior, issues invoices, keeps holiday rental contracts and, in many cases, installs perimeter security cameras. Data protection in this context is not an extra piece of paperwork; it is part of the accommodation's day-to-day operations.
This guide summarises the minimum documentation any owner of a rural guest house should have available — to open a new accommodation, regularise an existing one or review the status after changing accounting firm or booking software — under the framework of the GDPR (Regulation EU 2016/679), the LOPDGDD (Organic Law 3/2018) and the specific sectoral hospitality regulations.
Why a rural guest house also processes personal data
Although the operation is simple and, in many cases, managed directly by the owner, a rural guest house manages several flows of personal data on a regular basis:
- Guests: bookings (name, contact, dates, number of persons), ID document data for the hospitality register, payment data, communications before and after the stay and, where applicable, customer reviews.
- Owners and proprietors: if the accommodation operates under a company structure or if there are co-owners, their personal data are also managed (administrative, tax, banking).
- Suppliers and third parties: contact persons of accounting firm, cleaning company, maintenance, utilities, booking platforms, management software and, occasionally, catering or activity providers.
- Bodies and authorities: mandatory communication of traveller register data to the State Security Forces and Bodies through the SES.HOSPEDAJES system (Royal Decree 933/2021).
The controller is always the owner of the rural guest house (natural person or company), even if daily operations are run by a single individual. That figure decides which data are collected and for what purpose, and therefore assumes the obligations of the GDPR.
The traveller register and communication to law enforcement authorities
The obligation to register travellers and to communicate them to the competent authorities also reaches small tourist accommodations. The reference rule is Royal Decree 933/2021, of 26 October, which regulates the obligations of documentary registration and reporting of natural or legal persons engaged in accommodation activities and motor vehicle rental.
- Legal basis: art. 6.1.c GDPR — compliance with a legal obligation — under RD 933/2021 itself.
- Data collected: those listed by the sectoral rule itself (guest identification data, ID document, stay data, payment data on the terms provided). Only those necessary to comply with the legal obligation.
- Electronic channels: communication is carried out via the electronic channels enabled by the Secretariat of State for Security, mainly the SES.HOSPEDAJES system.
- Retention period: traveller register information must be retained for three years from the date the contracted service or provision ends, in accordance with RD 933/2021.
- How the ID document is handled: the owner records the essential data required by the rule. They never photocopy, scan or store an image of the guest's ID or passport: the AEPD enforcement criterion and the minimisation principle (art. 5.1.c GDPR) rule it out.
Regional tourism regulations (establishment registers, registration forms, regional traveller registers) may add further formal requirements in each Autonomous Community; it is mandatory to check the regional tourism regulations applicable to the rural guest house.
The minimum documentation of the controller
These are the documents that, as a minimum, a rural guest house should have ready before the first check-in. Some are mandatory; others are good practices that save trouble when a complaint, an inspection or a change of supplier arrives.
| Document | Legal basis | Purpose |
|---|---|---|
| Record of Processing Activities (RoPA) | Art. 30 GDPR | Internal inventory of what is processed, for what purpose, for how long and with what measures. |
| Information notice for guests | Art. 13 GDPR | Information provided in the booking confirmation and at check-in. |
| Website privacy policy | Arts. 13 and 14 GDPR | Public and complete version of the information the controller provides to the user. |
| Website legal notice | Art. 10 LSSICE | Identification of the site owner: name, tax ID, address, email. |
| Cookies policy and banner | Art. 22.2 LSSICE | Information layer and consent mechanism for cookies that are not strictly necessary. |
| Processor contracts | Art. 28 GDPR | Agreement signed with every supplier processing data on behalf of the accommodation (booking software, accounting firm, cleaning company with access to data). |
| Security policy | Art. 32 GDPR | Technical and organisational measures: passwords, backups, paper custody. |
| Breach protocol | Arts. 33–34 GDPR | Procedure to detect, assess and, where appropriate, notify the AEPD and the data subjects. |
| Procedure for data subject rights | Arts. 15–22 GDPR | Channel to handle access, rectification, erasure, objection, portability and restriction. |
| Video-surveillance information sign | Art. 22.4 LOPDGDD | Visible information device in the perimeter area where security cameras are installed. |
Information notice for the guest (art. 13 GDPR)
The duty to inform under art. 13 GDPR is mandatory even when the legal basis is not consent. It is a common mistake to think that, because the booking is based on the performance of the contract and the communication to law enforcement authorities on a legal obligation, nothing needs to be provided. It does. The rural guest house's information notice must answer, in simple but complete terms:
- Who processes the data: identification of the accommodation owner, address and contact channel on data protection matters.
- What data are processed: the booking data, the ID document data for the traveller register and the billing data.
- For what purposes: management of the booking, provision of the accommodation service, compliance with RD 933/2021, billing, handling of complaints and, where applicable, commercial communications if the guest accepts them.
- On what legal basis: performance of the contract (art. 6.1.b), legal obligation for the communication to the Ministry of the Interior (art. 6.1.c), legitimate interest or consent, depending on the specific processing.
- To whom they are communicated: State Security Forces and Bodies (mandatory communication), Tax Administration, accounting firm and, where applicable, booking platform or software provider.
- How long they are retained: three years for the traveller register (RD 933/2021), the applicable tax and accounting periods for billing, and the general GDPR periods for the rest.
- How to exercise rights: access, rectification, erasure, objection, restriction, portability and complaint before the AEPD.
The notice must be available at the usual collection points: website form, booking confirmation by email, check-in card (paper or digital) and, if the rural guest house sends a newsletter, on the subscription form.
Common processors in a rural guest house (art. 28 GDPR)
However small the operation, almost any rural guest house relies on suppliers that process personal data on behalf of the owner. Each of those suppliers is a processor and requires a contract signed on the terms of art. 28 GDPR.
| Supplier | Data processed | Key document |
|---|---|---|
| Small booking software | Guest records, calendars, billing | Art. 28 GDPR contract + server location |
| Accounting firm / tax advisor | Billing, accounting data, where applicable personnel data | Art. 28 GDPR contract |
| Booking platforms (Booking, Airbnb) | Guest data handled through the platform | Case-by-case analysis: they usually act as independent controllers (see article 9.3) |
| External cleaning company | Occupancy lists, access to the accommodation | Art. 28 GDPR contract + confidentiality clause |
| Video-surveillance company (if any) | Images of perimeter accesses | Art. 28 GDPR contract + 30-day period (art. 22.3 LOPDGDD) |
A recurring note: at the end of the contract, the processor must return or export the data to the controller, and only then erase them (art. 28.3.g GDPR). That allows the rural guest house to continue meeting its statutory retention periods — tax, traveller register — without depending on the outgoing supplier. The specific role of platforms such as Booking or Airbnb is dealt with in detail in the third article of this guide.
Perimeter video-surveillance: security cameras outside the accommodation
Many rural guest houses are located in isolated areas or have large surroundings (gardens, accesses, car parks), and it is common to install perimeter security cameras. Video-surveillance is permitted for the purpose of securing the property, provided the following rules are respected:
- Legal basis: art. 6.1.f GDPR (legitimate interest) on the terms of art. 22 LOPDGDD.
- Retention period: images must be erased within a maximum of 30 days from their capture, save for retention to report offences or for proceedings (art. 22.3 LOPDGDD).
- Information sign visible at the access area, in accordance with art. 22.4 LOPDGDD, indicating the controller and how to exercise rights.
- Coverage limited to the property itself: the camera must not capture the public thoroughfare beyond what is essential to monitor the access, nor neighbouring properties.
- Prohibited spaces: art. 89.1 LOPDGDD strictly prohibits the installation of video-surveillance or sound recording systems in areas intended for rest, changing rooms, toilets and similar spaces. Applied to tourist accommodation, this reinforces the obvious rule: never cameras inside the accommodation, nor in the bathrooms or bedrooms intended for the guest. Video-surveillance is strictly limited to the outdoor perimeter.
If there are cameras, the activity must appear in the RoPA, with the signage required by art. 22.4 LOPDGDD and, where the system is operated by an external company, an art. 28 GDPR contract must be signed with that company.
"En una casa rural, la protección de datos cabe en una carpeta de diez documentos bien hechos. No hace falta más, y tampoco menos. Lo que marca la diferencia es la coherencia entre lo que dice el papel y lo que se hace cada vez que llega un huésped a la puerta."
Mario P. Talamillo · Managing Partner, Certix®
If you manage a rural guest house or small tourist accommodation and want to review your data protection documentation, at Certix we work specifically with rural guest houses. No salespeople: from the first contact, you will speak to a specialist.
Data protection guide for rural guest houses
This content is merely indicative and informative; it does not in any case constitute specialised legal advice. Regional sectoral regulations may extend or modify the periods and requirements of the national rule. The application of the regulations to each specific case requires individualised analysis.