Hotel sector
Data protection for
hotels and accommodation
The mandatory guest registration, OTAs as booking platforms, video surveillance and property management systems make the hotel sector one of the largest continuous processors of personal data.
RD 933/2021
Travellers' Report — mandatory
3 years
guest data retention
30 days
maximum video surveillance retention
24 h
personalised proposal
Sector challenges
General obligations for hotels and accommodation
Travellers' Report (RD 933/2021)
The registration of guests' identity data is a legal obligation. Data must be communicated to the Security Forces and Corps and retained for 3 years. Important: RD 933/2021 requires the recording of data, not the retention of a copy of the identity document.
Prohibition on photocopying national ID cards or passports
The AEPD has established, through repeated enforcement decisions, that it is strictly prohibited to photocopy, scan or retain images of guests' national ID card or passport. This practice infringes the data minimisation principle under art. 5.1.c GDPR and has led to enforcement proceedings. The check-in process must be adapted to register the data without reproducing the document.
OTAs and booking platforms
Booking.com, Expedia and Hotelbeds have their own privacy policies and generally act as independent controllers. The contractual relationship determines the processing roles.
Video surveillance in common areas
Installing cameras in a hotel requires analysing proportionality in each area, providing an information sign and complying with retention periods. It is prohibited in bedrooms, toilets and areas of privacy. Each case must be assessed individually.
Property management system (PMS)
PMS software that centralises reservations, check-in, invoicing and guest preferences may act as a data processor; it is advisable to review the provider's terms and formalise the DPA if applicable.
Credit card data
Guests' payment data are subject to the GDPR and also to PCI-DSS standards. The hotel must not store card data without complying with both sets of requirements.
Additional services
Spa, restaurant, activities and excursions generate additional processing of guest data that must be included in the establishment's RoPA (Record of Processing Activities).
The service
What the service for your hotel or accommodation includes
RoPA (Record of Processing Activities)
Tailored Record of Processing Activities: guests, employees, video surveillance, PMS, OTAs and ancillary services.
Information clauses
Texts for the check-in process, web forms and loyalty programmes.
Privacy policy and legal notice
Documentation for the hotel website.
Data Processing Agreements (DPA)
DPA for PMS, revenue management software and review management platforms.
Data breach protocol
Response procedure with notification within 72 hours.
Data subject rights management
Procedure for handling requests from guests and employees.
Document management platform
Access to a private platform with documents and electronic signature.
Ongoing support
Unlimited queries. Updates in response to regulatory changes.
External DPO (if applicable)
As a general rule, hotels and accommodation providers are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis. Separate contract.
Do you need a proposal for your hotel?
Tell us the type of establishment and the number of employees. Proposal in under 24 hours.
FAQ
Frequently asked questions about data protection in hotels
Is the guest registration form (Travellers' Report) compatible with the GDPR?
Yes. The registration of guests' identity data is a legal obligation imposed by Royal Decree 933/2021. This legal obligation constitutes the legal basis for the processing (art. 6.1.c GDPR) and takes precedence over the right of erasure during the retention period (3 years). Nevertheless, compliance with RD 933/2021 requires recording the data from the document, not retaining a photocopy or scan of it.
Can the hotel photocopy or scan a guest's national ID card or passport?
No. The AEPD has established, through repeated enforcement decisions, that it is strictly prohibited to photocopy, scan or retain images of guests' national ID card or passport. RD 933/2021 requires the registration of identity data, not the retention of a reproduction of the document. This practice infringes the data minimisation principle under art. 5.1.c GDPR and has led to numerous enforcement proceedings by the AEPD. The check-in process must be adapted to collect the data without copying the physical document.
Are Booking.com and Airbnb data processors for the hotel?
Not necessarily. Major OTAs (Booking.com, Expedia) generally act as independent data controllers: they manage the customer's data under their own policies. The hotel receives the data the OTA transmits to it for the purpose of managing the reservation. The contractual relationship with each OTA determines the roles, and the agency must review the contracts in force.
How long may a hotel retain its guests' data?
Travellers' Report data must be retained for 3 years under RD 933/2021. Invoicing data must be retained for 4 years due to fiscal obligations. Data held in the property management system (PMS) must be limited to the period necessary for the relationship with the guest. If the hotel has a loyalty programme, it may retain data for the duration of the programme with consent.
Can a hotel install video surveillance in leisure areas and outdoors?
The admissibility of video surveillance in a hotel depends on the specific area, the purpose pursued and the proportionality assessment. As a general rule, it is prohibited in spaces where people have a reasonable expectation of privacy. Each installation must be documented in the RoPA (Record of Processing Activities), include an information sign and comply with the applicable retention periods. We recommend analysing each case individually before installing any camera system.
Can the hotel's wi-fi be used to collect guests' data?
Only with the guest's informed consent. If wi-fi access requires registration with a name or email address, the hotel is collecting personal data and must inform the user of the purpose of the processing. Those data may not be used for marketing without additional and specific consent for that purpose.
Is the property management system (PMS) a data processor?
As a general rule, yes. The PMS software provider that stores guest, reservation and invoicing data for the hotel may act as a data processor. The exact legal relationship depends on each provider's terms; it is advisable to review them and, where the provider acts as a processor, to formalise the data processing agreement (DPA) and verify where the data are hosted, particularly if the PMS is cloud-based.
Sector resources
Learn more
Hotels & accommodation
Data protection in a hotel: where to start
Minimum data protection documentation for hotels and accommodation: traveller register, RoPA, information notices, processor contracts and communication to law enforcement authorities.
8 min·Read article
Hotels & accommodation
Daily good practices of hotel staff to protect data
Concrete routines for reception, housekeeping, kitchen and administration: handling the ID/passport without photocopying it, custody of reports, communications, PMS passwords, video-surveillance and time recording.
8 min·Read article
Hotels & accommodation
Your hotel PMS as processor: what to require from the provider under the GDPR
The PMS is the heart of the hotel and processes personal data on its behalf. Which art. 28 GDPR contract must be signed, which safeguards to require, access profiles, international transfers and data return upon migration.
8 min·Read article
Free tool
Data protection self-check
Check in 5 minutes your overall adaptation level in personal data protection.
No email · Anonymous · No commitment
Hotel sector
GDPR compliance
for your hotel.
An expert analyses your activity and proposes the right solution. No intermediaries.
Proposal within 24 h · info@certix.es
Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.