News and resources on
data protection
Page 5 of 7
Data protection in a rural guest house: where to start
Minimum data protection documentation for rural guest houses: traveller register, RoPA, information notices, processor contracts and communication to law enforcement authorities.
Daily good practices of the rural guest house owner to protect data
Concrete routines to manage guest data in a small tourist accommodation: recording the ID without photocopying it, custody of registers, personal mobiles, destruction of contracts.
Booking platforms (Booking, Airbnb) in a rural guest house: what to bear in mind under the GDPR
Booking, Airbnb and other portals: when they act as independent controllers and when as processors. What to require from the channel, what data you can keep and how to coordinate with the platform.
Data protection in a hotel: where to start
Minimum data protection documentation for hotels and accommodation: traveller register, RoPA, information notices, processor contracts and communication to law enforcement authorities.
Daily good practices of hotel staff to protect data
Concrete routines for reception, housekeeping, kitchen and administration: handling the ID/passport without photocopying it, custody of reports, communications, PMS passwords, video-surveillance and time recording.
Your hotel PMS as processor: what to require from the provider under the GDPR
The PMS is the heart of the hotel and processes personal data on its behalf. Which art. 28 GDPR contract must be signed, which safeguards to require, access profiles, international transfers and data return upon migration.
Data protection in a restaurant: where to start
Minimum data protection documentation to open or regularise a restaurant: RAT, legal notice, privacy policy, information clause, processor contracts. No scaremongering, step by step.
Daily good practices for a restaurant team to protect data
Concrete routines for the front-of-house, kitchen and admin teams: TPV password management, role-based access, allergy data, WhatsApp communications, control of paper copies and CCTV.
Booking software and TPV in a restaurant: the supplier's obligations under the RGPD
Your TPV and booking system process personal data on behalf of the restaurant. What processor contract (art. 28 RGPD) you must sign, what guarantees to require and what happens at the end of the service.
AI Act: complete guide to the European Artificial Intelligence Regulation
Complete guide to the AI Act (Regulation EU 2024/1689): structure, risk-based approach, prohibited practices, high-risk systems, general-purpose AI models (GPAI), transparency, governance (AESIA and AI Office), penalties and 2025–2027 application timeline.
Data Protection Compliance: what it is and how to implement it
Data protection compliance integrates GDPR requirements as a continuous system in your organisation. What it includes, how it differs from an audit, and how to implement it.
AEPD and DPO: complete guide to the Data Protection Officer
Complete guide to the relationship between the AEPD and the Data Protection Officer. Functions, registration, sanctions and how Certix can help.
Do you need direct expert advice?
At Certix you will be attended by a data protection expert, with no sales teams involved.