logo Lawwwing

Managing a Hotel: How to Survive Summer Without the AEPD Ruining My Holidays

I run a hotel. It's August, my pool is packed, the restaurant is serving gazpacho at a rate that would make Wimbledon jealous of their strawberries and cream service, and yet there's something keeping me up at night more than the double booking in room 204: data protection. Although it may seem dreadfully dull, I've […]
Legal Lawwwing
July 30, 2026

I run a hotel. It's August, my pool is packed, the restaurant is serving gazpacho at a rate that would make Wimbledon jealous of their strawberries and cream service, and yet there's something keeping me up at night more than the double booking in room 204: data protection.

Although it may seem dreadfully dull, I've spent years learning this the hard way through scares, so I'm going to tell you everything I do to avoid ending up as a headline in the business section of the newspaper.

1. The Applicable Legal Framework (The Rules of the Game)

A hotel is not governed by a single data protection regulation, but rather by several overlapping ones:

  • The GDPR, the European Union regulation
  • The LOPDGDD, its Spanish implementation
  • The AI Regulation for the artificial intelligence of my website chatbot
  • The European Accessibility Act for my website accessibility
  • The Traveler Registry (RD 933/2021): the obligation to send my guests' data to the police
  • Video surveillance regulations under private security law
  • Labor law, for my employees
  • The LSSI for when I send them the email "come back this summer with a 15% discount" and newsletters

2. My Guests: Much More Than Just a Name and ID

From the moment someone makes a reservation (even if they're doing it from their couch with their second cup of coffee in the morning) I already have some of their personal data: their name, email address, phone number, payment card details, and sometimes even whether they're allergic to tree nuts because they mentioned it in the "comments" section without anyone asking (thanks, Marisa from Valladolid).

What I do:

  • Have a clear privacy policy, not an unreadable wall of text buried at the bottom of the website.
  • Define the legal basis for each processing activity. I know why I have every piece of data: some because we've entered into an accommodation contract, others because the law requires it (guest registration), and others because the guest has said, "Yes, send me offers" (consent).
  • Practice data minimization. Don't ask for more than I need. If I don't need the ID details of all six family members to book a double room with an extra bed, I don't ask for them.

Every guest who stays at the hotel goes through the mandatory guest registration process: name, identity document, nationality, and signature. This information is sent directly to the SES.Hospedajes platform. It's not my curiosity—it's a legal obligation.

What I do control:

  • Ensure that only the staff members who genuinely need access to this data can see it (the entire team doesn't need to know the name of the guest staying in room 142).
  • Keep the data only for as long as the law requires, not a single day longer.
  • Make sure the connection to the police platform is secure, using individual user accounts (not Username: reception, Password: reception123).

If a guest tells me they have celiac disease or need an accessible room, that's health information and therefore sensitive personal data. That's why we can't write it on a whiteboard where everyone can see it, including the beverage supplier who drops by at 9:00 a.m.

I only send newsletters such as "Get 10% off if you book in August" to guests who have clearly said yes. Consent must be explicit, not pre-ticked or hidden in the general terms and conditions. And if someone wants to unsubscribe, they should be able to do so with a single click, without having to go through any additional steps.

For years, in many hotels, it was almost automatic: the guest arrived, we asked for their ID card or passport, and... snap, a photo, a scan, or a photocopy "just in case." However, in 2025, the Spanish Data Protection Agency (AEPD) published guidance making it clear that hotels are not allowed to request or retain copies of guests' ID cards or passports, whether on paper, scanned, or photographed with a mobile phone.

This is because Royal Decree 933/2021 requires accommodation providers to collect certain specific information, such as the guest's name, surname, identity document details, and nationality, but it does not require them to keep a complete copy of the document. An ID card contains information that is unnecessary for this purpose, such as the photograph, expiry date, or the names of the holder's parents. Keeping all of that information breaches the GDPR's data minimization principle, and the AEPD has imposed sanctions for this practice on numerous occasions.

So, this is how we handle it at my hotel today:

  • Visual verification: The guest shows me their ID document, I check that it matches the information I already have, and I do not make a photocopy or take a photograph.
  • Registration forms (in person or online): I only collect the information required under Annex I of Royal Decree 933/2021.
  • Online bookings and self-check-in: I use image-free verification methods, such as a one-time code sent by text message or email, or verification against the payment card details.
  • If a guest sends me a photo of their ID "to help": I thank them, but I don't keep it. I don't need it, and storing it would only create unnecessary data protection risks with the AEPD.

3. Employees: The Employment Relationship Also Involves Data Protection

My waiters, chefs, receptionists, lifeguards, housekeeping staff—in fact, all of my employees—have personal data that I am responsible for protecting:

  • Recruitment: The CVs of unsuccessful candidates should be deleted after a reasonable period unless the candidate has given consent for them to be retained.
  • Payroll, Social Security, and bank account details: These must be handled securely and only by authorized personnel.
  • Time and attendance records: Employees must be clearly informed about the processing of this data, and it must be used solely for the purpose of managing working hours and employment obligations.
  • CCTV: Cameras should only be installed in justified areas (such as kitchens, storerooms containing valuable goods, or cash handling areas), and never in changing rooms, bathrooms, or staff break areas.
  • Employees' health data (such as sick leave records or fitness-for-work certificates): These should be handled by the occupational health service and access must be strictly restricted, including from Human Resources where appropriate.

4. Catering: The Hotel Restaurant Has Its Own Data Protection Rules

Although part of the same business, the restaurant activity requires specific data treatment measures:

  • Even though it is part of the same business, the restaurant operates its own specific data processing activities.
  • Table reservations, whether made directly or through platforms such as TheFork.
  • Allergen information is legally required, but I handle it carefully: I don't display it on a screen where anyone can see it. It is only accessible to the staff responsible for preparing or serving the food.
  • Corporate invoices: When a guest requests an invoice in the name of their company, it often includes the personal data of a contact person, not just the company's tax identification number.
  • We have created a "Gourmet Club" offering discounts at the restaurant. Since it operates as a loyalty program, we obtain clear and specific consent before sending promotional communications or processing members' data for marketing purposes.

5. Sharing Data with Third Parties: The Most Sensitive Area

I don't handle everything myself, and it's common to share personal data with, or entrust its processing to, third parties, such as:

  • Booking platforms (Booking.com, eDreams, Trivago, Kayak, etc.): These may act either as data controllers or data processors, so it's essential to review the contracts carefully to determine the role and responsibilities of each party.
  • The hotel's Property Management System (PMS): The PMS provider acts as a data processor and must sign a data processing agreement specifying the purpose of the processing, its duration, the security measures to be applied, and what happens to the data when the contract ends.
  • External laundry services, catering providers, and maintenance companies: If they have access to personal data (for example, lists of occupied rooms), they must also have an appropriate data processing agreement in place.
  • The payment gateway: This involves the processing of payment card information and is subject to additional security requirements, including compliance with the PCI DSS (Payment Card Industry Data Security Standard), to help prevent any compromise of guests' card data.
  • The security company responsible for the CCTV system: It acts as a data processor, so we sign a data processing agreement with the company, and it is subject to enhanced confidentiality obligations.

6. Security Cameras: one of the main compliance risk areas

Video surveillance in hotels is one of the areas most frequently inspected by the Spanish Data Protection Agency (AEPD). That's why I make sure to comply with the following requirements:

  • Clear signage in every area under surveillance, identifying the data controller and explaining where individuals can exercise their data protection rights.
  • Proportionality: Cameras should only be installed in justified locations, such as the reception area, corridors, car park, and other common areas. No cameras should ever be placed in guest rooms, changing rooms, or bathrooms.
  • No audio recording.
  • Retention period: CCTV footage is kept for a maximum of one month, unless there has been a genuine incident (such as theft or an assault) that justifies retaining the recordings for a longer period.
  • Restricted access: Only authorized personnel may view the recordings, and a record is kept of who accessed the footage and when.

7. Minors

I love welcoming families during the summer, and that includes children. But when it comes to minors, extra care is required. I only collect the minimum amount of information necessary about them, such as their age or any dietary restrictions.

8. Technical and Organizational Security Measures

  • Access controls for reservation systems and the Property Management System (PMS): individual user accounts with permissions based on each employee's role.
  • Encryption of payment card data and any stored identity document information.
  • Regularly performed and tested backups.
  • Clean desk policy at reception: passports, payment cards, and guest registration forms should never be left visible.
  • Regular staff training on data protection and information security.

9. Data Protection Officer (DPO)

Not every hotel is required to appoint a Data Protection Officer (DPO). However, it is advisable to assess whether one should be appointed if you process personal data on a large scale—for example, if you are part of a hotel chain or operate a large hotel.

10. Data Subjects' Rights

Both guests and employees have the right to access, rectify, erase, restrict the processing of, object to the processing of, and request the portability of their personal data. To ensure these rights can be exercised effectively, we have:

  • A clear and straightforward channel for submitting requests—in our case, a simple online form.
  • Internal procedures to ensure requests are answered within the legal deadline of one month.
  • Particular care when dealing with requests for erasure where there is a legal obligation to retain guest registration records. Data cannot always be deleted immediately, and it is important to explain this clearly to the individual concerned.

11. The Hotel Compliance Checklist

Every summer, I pull out my personal checklist to make sure we're up to date with our data protection obligations:

  • Map all personal data flows: guests, employees, restaurant operations, suppliers, and CCTV.
  • Identify the legal basis for every processing activity.
  • Sign data processing agreements with every supplier that processes personal data on behalf of the hotel.
  • Review the placement, signage, and proportionality of CCTV systems.
  • Train staff regularly, with particular emphasis on reception employees.
  • Maintain a clear incident response procedure for handling personal data breaches

I Trust Lawwwing. What Are You Waiting For?

Since I started relying on Lawwwing, I can finally relax knowing that my website complies with all the relevant legal requirements because it:

  • Generates and keeps my website's legal documents up to date, including the Privacy Policy, Cookie Policy, Legal Notice, and Terms and Conditions.
  • Provides a cookie banner fully compliant with Google Consent Mode v2.
  • Automatically updates the legal texts whenever the regulations change.
  • Includes the mandatory right of withdrawal information, as required since June.
  • Keeps my website accessible to all of my customers, helping me comply with the European Accessibility Act (EAA).
  • Includes an AI transparency widget that informs users about the use of artificial intelligence and helps meet the obligations of the EU AI Act, without negatively affecting my conversions or sales.

So don't wait any longer and stay compliant with Lawwwing.

Blog

Related Articles

Businesses trust Lawwwing to ensure their legal compliance, keeping their documents up-to-date and avoiding penalties.
cross