Certix

Data protection in a hotel: where to start

Certix
Certix®
· 30 May 2026 · 8 min read

Informative article. It does not replace individualised professional advice.

A hotel processes personal data long before the guest arrives: the booking comes in via the website, an OTA or by phone, is confirmed by email, completed at check-in, cross-checked against the traveller register, fed into the PMS, sent to the billing system and eventually reaches the loyalty programme. Data protection is not an add-on at the end of the project; it is part of the accommodation's day-to-day operations.

This guide summarises the minimum documentation any hotel controller should have available — to open a new accommodation, regularise an existing one or review the status of a chain — under the framework of the GDPR (Regulation EU 2016/679), the LOPDGDD (Organic Law 3/2018) and the specific sectoral hospitality regulations.

Why a hotel processes personal data

An average hotel manages four major flows of personal data on a daily basis:

  • Guests: bookings (name, contact, dates, number of persons, preferences), ID document data for the hospitality register, card data for the guarantee, communications, reviews, customer record and, where applicable, loyalty programme.
  • Employees: recruitment and payroll, time recording (using PIN, RFID card or app), training, internal communications and, where applicable, sick leave certificates or occupational accident reports.
  • Suppliers and third parties: contact persons of wineries, laundry, maintenance, accounting firm, marketing agency, channel manager, booking engine, OTAs, incident management platforms.
  • Bodies and authorities: mandatory communication of traveller register data to the State Security Forces and Bodies, through the SES.HOSPEDAJES system (Royal Decree 933/2021).

However small the accommodation, the controller is always the hotel owner (the natural or legal person). That figure decides which data are collected and for what purpose, and therefore assumes the obligations of the GDPR.

The traveller register and communication to law enforcement authorities

The obligation to register travellers and to communicate them to the competent authorities is one of the structural particularities of the sector. The reference rule is Royal Decree 933/2021, of 26 October, which regulates the obligations of documentary registration and reporting of natural or legal persons engaged in accommodation activities and motor vehicle rental.

  • Legal basis: art. 6.1.c GDPR — compliance with a legal obligation — under RD 933/2021 itself.
  • Data collected: those listed by the sectoral rule itself (guest identification data, ID document, stay data, payment data on the terms provided). Only those necessary to comply with the legal obligation.
  • Electronic channels: communication is carried out via the electronic channels enabled by the Secretariat of State for Security, mainly the SES.HOSPEDAJES system.
  • Retention period: traveller register information must be retained for three years from the date the contracted service or provision ends, in accordance with RD 933/2021.
  • How the ID document is handled: the hotel records in the system the essential data required by the rule. It never photocopies, scans or stores an image of the guest's ID or passport: the AEPD enforcement criterion and the minimisation principle (art. 5.1.c GDPR) rule it out.

Regional tourism regulations (establishment registers, registration forms, regional traveller registers) may add further formal requirements in each Autonomous Community; it is mandatory to check the regional tourism regulations applicable to the accommodation.

The minimum documentation of the controller

These are the documents that, as a minimum, a hotel should have ready before the first check-in. Some are mandatory; others are good practices that save trouble when a complaint, an inspection or a change of supplier arrives.

Document Legal basis Purpose
Record of Processing Activities (RoPA) Art. 30 GDPR Internal inventory of what is processed, for what purpose, for how long and with what measures.
Information notice for guests Art. 13 GDPR Information provided at booking, on the website, at the booking engine and at check-in.
Information notice for employees Art. 13 GDPR Information delivered with the employment contract and with the digital tools of the role.
Website privacy policy Arts. 13 and 14 GDPR Public and complete version of the information the controller provides to the user.
Website legal notice Art. 10 LSSICE Identification of the site owner: name, tax ID, address, email, commercial registry.
Cookies policy and banner Art. 22.2 LSSICE Information layer and consent mechanism for cookies that are not strictly necessary.
Processor contracts Art. 28 GDPR Agreement signed with every supplier processing data on behalf of the hotel (PMS, booking engine, channel manager, accounting firm, marketing, laundry with guest data).
Security policy Art. 32 GDPR Technical and organisational measures: passwords, role-based access, backups, retention periods.
Breach protocol Arts. 33–34 GDPR Procedure to detect, assess and, where appropriate, notify the AEPD and the data subjects.
Procedure for data subject rights Arts. 15–22 GDPR Channel to handle access, rectification, erasure, objection, portability and restriction.

RoPA (Record of Processing Activities) in a hotel

Art. 30 GDPR requires keeping an internal record of processing activities. The exception in paragraph 5 for entities with fewer than 250 workers ceases to apply if the processing is not occasional or may affect rights and freedoms. In a hotel — video-surveillance, loyalty, mandatory traveller register, staff management with shifts — virtually no processing is "occasional", so the recommended practice is to keep a RoPA in all cases.

A realistic RoPA for an average hotel includes, as a minimum, these activities:

  • Bookings and guest care. Basis art. 6.1.b GDPR (performance of contract): contact, confirmations, online pre-registration, check-in, check-out, billing to the guest.
  • Traveller register and communication to law enforcement authorities. Basis art. 6.1.c GDPR — legal obligation — under Royal Decree 933/2021. Three-year retention period.
  • Billing and tax obligations. Basis art. 6.1.c GDPR: General Tax Law, accounting regulations.
  • Personnel management (recruitment, payroll, training). Basis art. 6.1.b + art. 6.1.c.
  • Time recording. Basis art. 6.1.c (art. 34.9 ET) + art. 6.1.b. Through systems such as PIN, RFID card, mobile app or NFC.
  • Video-surveillance of accesses, general corridors, car park and common areas. Basis art. 6.1.f (legitimate interest) on the terms of art. 22 LOPDGDD. Areas excluded by legal mandate: rooms, bathrooms, changing rooms and staff rest areas (art. 89.1 LOPDGDD).
  • Marketing and loyalty (newsletter, guest programme). Basis art. 6.1.a (consent) or art. 6.1.f (legitimate interest in existing customers regarding similar products, art. 21.2 LSSICE).
  • Supplier management. Basis art. 6.1.b or art. 6.1.f.
  • Handling of data subject rights. Basis art. 6.1.c.

Each RoPA entry must identify: purpose, legal basis, categories of data and data subjects, recipients and, where applicable, international transfers, retention periods and security measures. Regional regulations on tourism, consumer protection and security may extend or qualify formal requirements.

Information notice: check-in, website, booking form and booking engine

The duty to inform under art. 13 GDPR is mandatory even when the legal basis is not consent. It is a common mistake to think that, because the booking is based on the performance of the contract and the communication to law enforcement authorities on a legal obligation, nothing needs to be provided. It does. The information notice must be available at all the usual collection points:

  • At the booking engine on the website and on the contact form (visible and accessible link before submission).
  • In the booking confirmation by email.
  • On the check-in card (paper or digital), ideally with a summarised first-layer version and a complete, accessible version.
  • As an annex to the employment contract and in the staff welcome handbook.
  • On the video-surveillance signage (information notice in a visible area, in accordance with art. 22.4 LOPDGDD).
  • On the loyalty or newsletter form.

The guest must know, before handing over the data, who processes it, for what purpose, on what basis, to whom it is communicated (including the mandatory communication to law enforcement authorities), how long it is retained and how to exercise their rights. The same requirement applies to the employee on day one.

Common processors in a hotel (art. 28 GDPR)

The hotel decides what to do with the data; but in practice it stores and processes them through suppliers. Each of those suppliers, if processing data on behalf of the controller, is a processor and requires a contract signed on the terms of art. 28 GDPR.

Supplier Data processed Key document
PMS (Property Management System) Guest records, bookings, billing, loyalty Art. 28 GDPR contract + role-based access profiles
Booking engine Guest contact data, payment data, preferences Art. 28 GDPR contract + server location
Channel manager Bookings from OTAs and synchronised availability Art. 28 GDPR contract + list of sub-processors
OTAs (when acting as processors) Guest data handled through the platform Case-by-case analysis: they may act as independent controllers in the acquisition phase and as processors when transmitting to the hotel
Accounting firm / labour advisor Personnel data, payroll, contracts Art. 28 GDPR contract
Marketing agency Newsletter databases, advertising audiences Art. 28 GDPR contract + verification of acquisition databases
Cleaning / laundry company Access to rooms, occupancy lists Art. 28 GDPR contract + reinforced confidentiality clause
Video-surveillance company Images of accesses, general corridors, car park Art. 28 GDPR contract + 30-day period (art. 22.3 LOPDGDD)

A recurring note: at the end of the contract, the processor must return or export the data to the controller, and only then erase them (art. 28.3.g GDPR). That allows the hotel to continue meeting its statutory retention periods — tax, employment, traveller register — without depending on the outgoing supplier.

Loyalty marketing and commercial communications

The guest programme and the sending of newsletters are common pieces of the hotel. It is worth being clear about the legal bases:

  • Consent (art. 6.1.a GDPR): general rule for acquiring new newsletter subscribers or members of the guest club. Specific, granular tick box, unticked by default and independent from acceptance of the general policy.
  • Legitimate interest or existing customers regarding similar products (art. 6.1.f GDPR + art. 21.2 LSSICE): allows commercial communications to customers who have already stayed at the hotel about products or services similar to those they already enjoyed, provided they were given the option to object at the initial collection and in each communication.
  • Accessible opt-out in every commercial communication (visible link, without artificial obstacles).

If the hotel profiles the guest's preferences (room type, intolerances, usual dates, average spend) to personalise offers, it must document this in the RoPA and reflect it in the information notice. If health data (allergies, reduced mobility) is added to that record on a permanent basis, explicit specific consent under art. 9.2.a GDPR must be applied, with an independent tick box unticked by default.

Good practices to get started on day one

  • Who is who: identify the controller (the hotel owner) and the team member who coordinates rights requests and incidents.
  • Supplier inventory: list PMS, booking engine, channel manager, OTAs, accounting firm, marketing, cleaning, laundry, video-surveillance. Check that an art. 28 GDPR contract is in place with each one.
  • One single source of truth: avoid duplicating the guest database in personal spreadsheets, staff mobiles or paper diaries without control.
  • Ready and delivered notices: short versions for guests and employees, accessible at reception and on the website/booking engine.
  • Well-signposted video-surveillance configured to retain images for 30 days maximum (art. 22.3 LOPDGDD). Zero cameras in rooms, bathrooms, changing rooms and staff rest areas (art. 89.1 LOPDGDD).
  • Individual accounts in the PMS (one user per person, never shared).
  • Action plan for incidents: who to notify if a USB drive is lost, if the PMS goes down or if an erasure request arrives.

The aim is not to generate folders: it is that, on the day a complaint, an access request or a supplier change arrives, the hotel has a clear view of where each piece of data is and who manages it.

"En un hotel, la protección de datos empieza en recepción: con un check-in que registra lo justo, devuelve el documento al huésped y guarda con orden lo que la ley pide guardar. No hace falta más, y tampoco menos."

Mario P. Talamillo · Managing Partner, Certix®

If you manage a hotel, hostel or accommodation chain and want to review your data protection documentation, at Certix we work specifically with hotels and accommodation providers. No salespeople: from the first contact, you will speak to a specialist.


This content is merely indicative and informative; it does not in any case constitute specialised legal advice. Regional sectoral regulations may extend or modify the periods and requirements of the national rule. The application of the regulations to each specific case requires individualised analysis.

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →