Certix

Hotel sector

Data protection for
hotels and accommodation

The mandatory guest registration, OTAs as booking platforms, video surveillance and property management systems make the hotel sector one of the largest continuous processors of personal data.

RD 933/2021

Travellers' Report — mandatory

3 years

guest data retention

30 days

maximum video surveillance retention

24 h

personalised proposal

Sector challenges

General obligations for hotels and accommodation

Travellers' Report (RD 933/2021)

The registration of guests' identity data is a legal obligation. Data must be communicated to the Security Forces and Corps and retained for 3 years. Important: RD 933/2021 requires the recording of data, not the retention of a copy of the identity document.

Prohibition on photocopying national ID cards or passports

The AEPD has established, through repeated enforcement decisions, that it is strictly prohibited to photocopy, scan or retain images of guests' national ID card or passport. This practice infringes the data minimisation principle under art. 5.1.c GDPR and has led to enforcement proceedings. The check-in process must be adapted to register the data without reproducing the document.

OTAs and booking platforms

Booking.com, Expedia and Hotelbeds have their own privacy policies and generally act as independent controllers. The contractual relationship determines the processing roles.

Video surveillance in common areas

Installing cameras in a hotel requires analysing proportionality in each area, providing an information sign and complying with retention periods. It is prohibited in bedrooms, toilets and areas of privacy. Each case must be assessed individually.

Property management system (PMS)

PMS software that centralises reservations, check-in, invoicing and guest preferences may act as a data processor; it is advisable to review the provider's terms and formalise the DPA if applicable.

Credit card data

Guests' payment data are subject to the GDPR and also to PCI-DSS standards. The hotel must not store card data without complying with both sets of requirements.

Additional services

Spa, restaurant, activities and excursions generate additional processing of guest data that must be included in the establishment's RoPA (Record of Processing Activities).

The service

What the service for your hotel or accommodation includes

RoPA (Record of Processing Activities)

Tailored Record of Processing Activities: guests, employees, video surveillance, PMS, OTAs and ancillary services.

Information clauses

Texts for the check-in process, web forms and loyalty programmes.

Privacy policy and legal notice

Documentation for the hotel website.

Data Processing Agreements (DPA)

DPA for PMS, revenue management software and review management platforms.

Data breach protocol

Response procedure with notification within 72 hours.

Data subject rights management

Procedure for handling requests from guests and employees.

Document management platform

Access to a private platform with documents and electronic signature.

Ongoing support

Unlimited queries. Updates in response to regulatory changes.

External DPO (if applicable)

As a general rule, hotels and accommodation providers are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis. Separate contract.

Do you need a proposal for your hotel?

Tell us the type of establishment and the number of employees. Proposal in under 24 hours.

Request a proposal

FAQ

Frequently asked questions about data protection in hotels

Is the guest registration form (Travellers' Report) compatible with the GDPR?

Yes. The registration of guests' identity data is a legal obligation imposed by Royal Decree 933/2021. This legal obligation constitutes the legal basis for the processing (art. 6.1.c GDPR) and takes precedence over the right of erasure during the retention period (3 years). Nevertheless, compliance with RD 933/2021 requires recording the data from the document, not retaining a photocopy or scan of it.

Can the hotel photocopy or scan a guest's national ID card or passport?

No. The AEPD has established, through repeated enforcement decisions, that it is strictly prohibited to photocopy, scan or retain images of guests' national ID card or passport. RD 933/2021 requires the registration of identity data, not the retention of a reproduction of the document. This practice infringes the data minimisation principle under art. 5.1.c GDPR and has led to numerous enforcement proceedings by the AEPD. The check-in process must be adapted to collect the data without copying the physical document.

Are Booking.com and Airbnb data processors for the hotel?

Not necessarily. Major OTAs (Booking.com, Expedia) generally act as independent data controllers: they manage the customer's data under their own policies. The hotel receives the data the OTA transmits to it for the purpose of managing the reservation. The contractual relationship with each OTA determines the roles, and the agency must review the contracts in force.

How long may a hotel retain its guests' data?

Travellers' Report data must be retained for 3 years under RD 933/2021. Invoicing data must be retained for 4 years due to fiscal obligations. Data held in the property management system (PMS) must be limited to the period necessary for the relationship with the guest. If the hotel has a loyalty programme, it may retain data for the duration of the programme with consent.

Can a hotel install video surveillance in leisure areas and outdoors?

The admissibility of video surveillance in a hotel depends on the specific area, the purpose pursued and the proportionality assessment. As a general rule, it is prohibited in spaces where people have a reasonable expectation of privacy. Each installation must be documented in the RoPA (Record of Processing Activities), include an information sign and comply with the applicable retention periods. We recommend analysing each case individually before installing any camera system.

Can the hotel's wi-fi be used to collect guests' data?

Only with the guest's informed consent. If wi-fi access requires registration with a name or email address, the hotel is collecting personal data and must inform the user of the purpose of the processing. Those data may not be used for marketing without additional and specific consent for that purpose.

Is the property management system (PMS) a data processor?

As a general rule, yes. The PMS software provider that stores guest, reservation and invoicing data for the hotel may act as a data processor. The exact legal relationship depends on each provider's terms; it is advisable to review them and, where the provider acts as a processor, to formalise the data processing agreement (DPA) and verify where the data are hosted, particularly if the PMS is cloud-based.

Free tool

Data protection self-check

Check in 5 minutes your overall adaptation level in personal data protection.

No email · Anonymous · No commitment

Start the test

Hotel sector

GDPR compliance
for your hotel.

An expert analyses your activity and proposes the right solution. No intermediaries.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →

Proposal within 24 h · info@certix.es

Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.