Certix

Tourism & travel

Data protection for
travel agencies

Travel agencies manage passports, identity data and, on occasion, health data for their customers, and transmit them to airlines, hotels and operators around the world. International data transfers and the correct documentation of relationships with third-party providers are their principal regulatory challenges.

Art. 46

GDPR — international transfer safeguards

Art. 9

GDPR — special diets and health data

3 years

travel file retention

24 h

personalised proposal

Sector challenges

General obligations for travel agencies

Passports and identity data

Passport data are sensitive identity information that the agency manages for visa formalities, boarding and reservations. Their storage must be secure and time-limited.

International transfers

The transmission of travellers' data to airlines, hotels and operators outside the EEA requires adequate safeguards. For US-based providers that have joined the Data Privacy Framework (DPF), that is the applicable mechanism. For other destinations, Standard Contractual Clauses or other mechanisms under art. 46 GDPR apply; their validity should be verified in each case.

Processor chain

GDS (Amadeus, Galileo), hotel extranets and airline APIs form a chain of systems that process travellers' data, each under its own terms.

Health data for special travel needs

Requests for special assistance (wheelchair, medical diet, assistance due to illness) involve the processing of health data with enhanced protection (art. 9 GDPR).

Minor children's data in family bookings

The management of minor children's data in family bookings has specific implications. The information clause in the contract must adequately cover the processing of minors' data.

Travel documentation

Tickets, vouchers, travel insurance and consular documentation contain personal data that the agency manages and must retain for the period during which claims may be brought.

The service

What the service for your travel agency includes

RoPA (Record of Processing Activities)

Tailored Record of Processing Activities: travellers, employees, GDS, operators and international transfers.

Information clauses

Texts for the travel contract, web forms and the collection of special health data.

Privacy policy and legal notice

Documentation for the agency website.

Data Processing Agreements (DPA)

DPA for management software and booking platforms acting as processors.

Data breach protocol

Response procedure with notification within 72 hours.

Data subject rights management

Documented procedure for handling requests from travellers and employees.

Document management platform

Access to a private platform with documents and electronic signature.

Ongoing support

Unlimited queries. Updates in response to regulatory changes.

External DPO (if applicable)

As a general rule, travel agencies are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis. Separate contract.

Do you need a proposal for your travel agency?

Tell us the type of travel and your customer volume. Proposal in under 24 hours.

Request a proposal

FAQ

Frequently asked questions about data protection in travel agencies

Must travel agencies inform customers of international data transfers?

Yes. When the agency transmits a traveller's data to airlines, hotels or tour operators outside the European Economic Area (EEA), an international transfer of data takes place. This transfer must be communicated to the customer in the privacy policy or information clause, stating the applicable mechanism: for US providers that have joined the Data Privacy Framework (DPF), that is the currently applicable mechanism; for other destinations, Standard Contractual Clauses or other mechanisms under art. 46 GDPR are required, whose validity should be verified periodically.

Is a passport number a specially protected data item?

A passport number is an identity data item that enables the unambiguous identification of the traveller. It is not a special category under art. 9 GDPR, but its sensitivity is high: improper use can facilitate identity fraud or theft. The agency must apply appropriate security measures, restrict internal access and not retain it for longer than necessary.

Can data relating to minors in a family booking be processed without their consent?

The management of minor children's data in family bookings has specific implications regarding consent and legal representation. The agency must adequately inform parties about the processing of minors' data in the information clause of the contract and ensure that the corresponding legal representation is in place.

Are special diets and assistance needs health data?

Yes. Information about medically required diets (diabetes, severe food allergies, coeliac disease) or requests for special assistance at the airport (wheelchair, medical assistance) are health data (special category, art. 9 GDPR). Their processing requires the traveller's explicit consent for that specific purpose.

How long must a travel agency retain the travel file?

The travel documentation must be retained for the period during which consumer claims may be brought (3 years for contractual liability under the Civil Code) and for the fiscal period (4 years). Passport data and identity documentation must be deleted once they are no longer needed for travel formalities.

Are global distribution systems (GDS) such as Amadeus data processors?

GDS and airline and hotel reservation systems manage travellers' data under their own terms. Depending on the contractual model, they may act as processors for the agency or as independent controllers. The agency must review its contractual terms and reflect these relationships appropriately in its RoPA (Record of Processing Activities).

Free tool

Data protection self-check

Check in 5 minutes your overall adaptation level in personal data protection.

No email · Anonymous · No commitment

Start the test

Tourism & travel

GDPR compliance
for your travel agency.

An expert analyses your activity and proposes the right solution. No intermediaries.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →

Proposal within 24 h · info@certix.es

Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.