{"id":12575,"date":"2026-07-30T09:15:11","date_gmt":"2026-07-30T08:15:11","guid":{"rendered":"https:\/\/lawwwing.com\/?p=12575"},"modified":"2026-09-04T16:22:04","modified_gmt":"2026-09-04T15:22:04","slug":"hotel-data-protection-gdpr-guide-2","status":"publish","type":"post","link":"https:\/\/lawwwing.com\/en\/hotel-data-protection-gdpr-guide-2\/","title":{"rendered":"Managing a Hotel: How to Survive Summer Without the AEPD Ruining My Holidays"},"content":{"rendered":"\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>I run a hotel. It's August, my pool is packed, the restaurant is serving gazpacho at a rate that would make Wimbledon jealous of their strawberries and cream service, and yet there's something keeping me up at night more than the double booking in room 204: data protection.<\/p>\n\n\n\n<p>Although it may seem dreadfully dull, I've spent years learning this the hard way through scares, so I'm going to tell you everything I do to avoid ending up as a headline in the business section of the newspaper.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">1. The Applicable Legal Framework (The Rules of the Game)<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>A hotel is not governed by a single data protection regulation, but rather by several overlapping ones:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The <strong>GDPR<\/strong>, the European Union regulation<\/li>\n\n\n\n<li>The <strong>LOPDGDD<\/strong>, its Spanish implementation<\/li>\n\n\n\n<li>The <strong>AI Regulation<\/strong> for the artificial intelligence of my website chatbot<\/li>\n\n\n\n<li>The <strong>European Accessibility Act<\/strong> for my website accessibility<\/li>\n\n\n\n<li>The Traveler Registry (<strong>RD 933\/2021<\/strong>): the obligation to send my guests' data to the police<\/li>\n\n\n\n<li><strong>Video surveillance regulations<\/strong> under private security law<\/li>\n\n\n\n<li><strong>Labor law<\/strong>, for my employees<\/li>\n\n\n\n<li>The <strong>LSSI <\/strong>for when I send them the email \"come back this summer with a 15% discount\" and newsletters<\/li>\n<\/ul>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/media1.giphy.com\/media\/v1.Y2lkPTc5MGI3NjExNTUxOGJteHFpYW15ajZiMGF6dG5yYnFkNmRwaTdqOTI2ZTAwa2traiZlcD12MV9pbnRlcm5hbF9naWZfYnlfaWQmY3Q9Zw\/igIxLk1UMgRbgGNVNc\/giphy.gif\" alt=\"\"\/><\/figure><\/div>\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">2. My Guests: Much More Than Just a Name and ID<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading has-contrast-3-color has-text-color has-link-color wp-elements-9d081957df85f60059a7771f987bf839\">The booking<\/h3>\n\n\n\n<p>From the moment someone makes a reservation (even if they're doing it from their couch with their second cup of coffee in the morning) I already have some of their personal data: their name, email address, phone number, payment card details, and sometimes even whether they're allergic to tree nuts because they mentioned it in the \"comments\" section without anyone asking (thanks, Marisa from Valladolid).<\/p>\n\n\n\n<p>What I do:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Have a clear <strong>privacy policy<\/strong>, not an unreadable wall of text buried at the bottom of the website.<\/li>\n\n\n\n<li>Define the <strong>legal basis<\/strong> for each processing activity. I know why I have every piece of data: some because we've entered into an accommodation contract, others because the law requires it (guest registration), and others because the guest has said, \"Yes, send me offers\" (consent).<\/li>\n\n\n\n<li>Practice <strong>data minimization<\/strong>. Don't ask for more than I need. If I don't need the ID details of all six family members to book a double room with an extra bed, I don't ask for them.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading has-contrast-3-color has-text-color has-link-color wp-elements-73d98911ecf9d36b605e3eb6e15787d0\">The police registration<\/h3>\n\n\n\n<p>Every guest who stays at the hotel goes through the mandatory guest registration process: name, identity document, nationality, and signature. This information is sent directly to the SES.Hospedajes platform. It's not my curiosity\u2014it's a legal obligation.<\/p>\n\n\n\n<p>What I do control:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Ensure that only the staff members who genuinely need access to this data can see it (the entire team doesn't need to know the name of the guest staying in room 142).<\/li>\n\n\n\n<li>Keep the data only for as long as the law requires, not a single day longer.<\/li>\n\n\n\n<li>Make sure the connection to the police platform is secure, using individual user accounts (not Username: reception, Password: reception123).<\/li>\n<\/ul>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading has-contrast-3-color has-text-color has-link-color wp-elements-09e48d4ccec1237be21d13c8afd99fb7\">Health Data<\/h3>\n\n\n\n<p>If a guest tells me they have celiac disease or need an accessible room, that's health information and therefore sensitive personal data. That's why we can't write it on a whiteboard where everyone can see it, including the beverage supplier who drops by at 9:00 a.m.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading has-contrast-3-color has-text-color has-link-color wp-elements-5ecc6a1dbe446930ddbe2f566d8850c7\">The Loyalty Program (or \"See You Again Next Summer\")<\/h2>\n\n\n\n<p>I only send newsletters such as \"Get 10% off if you book in August\" to guests who have clearly said yes. Consent must be explicit, not pre-ticked or hidden in the general terms and conditions. And if someone wants to unsubscribe, they should be able to do so with a single click, without having to go through any additional steps.<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/media2.giphy.com\/media\/v1.Y2lkPTc5MGI3NjExY3dxdWoxZGk2NnNpcDBiMGFxMmptemswcXg1aXB0N2VsYTN3YXh2diZlcD12MV9pbnRlcm5hbF9naWZfYnlfaWQmY3Q9Zw\/S2IfEQqgWc0AH4r6Al\/giphy.gif\" alt=\"\"\/><\/figure><\/div>\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading has-contrast-3-color has-text-color has-link-color wp-elements-d782fc05ab8a752e9e83d9a918bc9ebd\">Copying Guests' ID Cards: The Classic Mistake Almost All of Us Used to Make<\/h3>\n\n\n\n<p>For years, in many hotels, it was almost automatic: the guest arrived, we asked for their ID card or passport, and... snap, a photo, a scan, or a photocopy \"just in case.\" However, in 2025, the Spanish Data Protection Agency (AEPD) published guidance making it clear that hotels are not allowed to request or retain copies of guests' ID cards or passports, whether on paper, scanned, or photographed with a mobile phone.<\/p>\n\n\n\n<p>This is because Royal Decree 933\/2021 requires accommodation providers to collect certain specific information, such as the guest's name, surname, identity document details, and nationality, but it does not require them to keep a complete copy of the document. An ID card contains information that is unnecessary for this purpose, such as the photograph, expiry date, or the names of the holder's parents. Keeping all of that information breaches the GDPR's data minimization principle, and the AEPD has imposed sanctions for this practice on numerous occasions.<\/p>\n\n\n\n<p>So, this is how we handle it at my hotel today:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Visual verification: T<\/strong>he guest shows me their ID document, I check that it matches the information I already have, and I do not make a photocopy or take a photograph.<\/li>\n\n\n\n<li><strong>Registration forms (in person or online): <\/strong>I only collect the information required under Annex I of Royal Decree 933\/2021.<\/li>\n\n\n\n<li>Online bookings and self-check-in: I use image-free verification methods, such as a one-time code sent by text message or email, or verification against the payment card details.<\/li>\n\n\n\n<li>If a guest sends me a photo of their ID \"to help\": I thank them, but I don't keep it. I don't need it, and storing it would only create unnecessary data protection risks with the AEPD.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">3. Employees: The Employment Relationship Also Involves Data Protection<\/h3>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>My waiters, chefs, receptionists, lifeguards, housekeeping staff\u2014in fact, all of my employees\u2014have personal data that I am responsible for protecting:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Recruitment<\/strong>: The CVs of unsuccessful candidates should be deleted after a reasonable period unless the candidate has given consent for them to be retained.<\/li>\n\n\n\n<li><strong>Payroll, Social Security, and bank account details<\/strong>: These must be handled securely and only by authorized personnel.<\/li>\n\n\n\n<li><strong>Time and attendance records<\/strong>: Employees must be clearly informed about the processing of this data, and it must be used solely for the purpose of managing working hours and employment obligations.<\/li>\n\n\n\n<li><strong>CCTV<\/strong>: Cameras should only be installed in justified areas (such as kitchens, storerooms containing valuable goods, or cash handling areas), and never in changing rooms, bathrooms, or staff break areas.<\/li>\n\n\n\n<li><strong>Employees' health data<\/strong> (such as sick leave records or fitness-for-work certificates): These should be handled by the occupational health service and access must be strictly restricted, including from Human Resources where appropriate.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">4. Catering: The Hotel Restaurant Has Its Own Data Protection Rules<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Although part of the same business, the restaurant activity requires specific data treatment measures:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Even though it is part of the same business, the restaurant operates its own specific data processing activities.<\/li>\n\n\n\n<li>Table reservations, whether made directly or through platforms such as TheFork.<\/li>\n\n\n\n<li>Allergen information is legally required, but I handle it carefully: I don't display it on a screen where anyone can see it. It is only accessible to the staff responsible for preparing or serving the food.<\/li>\n\n\n\n<li>Corporate invoices: When a guest requests an invoice in the name of their company, it often includes the personal data of a contact person, not just the company's tax identification number.<\/li>\n\n\n\n<li>We have created a \"Gourmet Club\" offering discounts at the restaurant. Since it operates as a loyalty program, we obtain clear and specific consent before sending promotional communications or processing members' data for marketing purposes.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/media3.giphy.com\/media\/v1.Y2lkPTc5MGI3NjExbjFrbmttbHo3cnRzaHNidnI1OXM5Y29jZ285YXBzczR4c2tqeWt3NyZlcD12MV9pbnRlcm5hbF9naWZfYnlfaWQmY3Q9Zw\/11QEuO6MtKCl6E\/giphy.gif\" alt=\"\"\/><\/figure><\/div>\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">5. Sharing Data with Third Parties: The Most Sensitive Area<\/h3>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>I don't handle everything myself, and it's common to share personal data with, or entrust its processing to, third parties, such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Booking platforms<\/strong> (Booking.com, eDreams, Trivago, Kayak, etc.): These may act either as data controllers or data processors, so it's essential to review the contracts carefully to determine the role and responsibilities of each party.<\/li>\n\n\n\n<li><strong>The hotel's Property Management System (PMS): <\/strong>The PMS provider acts as a data processor and must sign a data processing agreement specifying the purpose of the processing, its duration, the security measures to be applied, and what happens to the data when the contract ends.<\/li>\n\n\n\n<li><strong>External laundry services, catering providers, and maintenance companies: <\/strong>If they have access to personal data (for example, lists of occupied rooms), they must also have an appropriate data processing agreement in place.<\/li>\n\n\n\n<li><strong>The payment gateway:<\/strong> This involves the processing of payment card information and is subject to additional security requirements, including compliance with the PCI DSS (Payment Card Industry Data Security Standard), to help prevent any compromise of guests' card data.<\/li>\n\n\n\n<li><strong>The security company responsible for the CCTV system:<\/strong> It acts as a data processor, so we sign a data processing agreement with the company, and it is subject to enhanced confidentiality obligations.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">6. Security Cameras: one of the main compliance risk areas<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Video surveillance in hotels is one of the areas most frequently inspected by the Spanish Data Protection Agency (AEPD). That's why I make sure to comply with the following requirements:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Clear signage in every area under surveillance, identifying the data controller and explaining where individuals can exercise their data protection rights.<\/li>\n\n\n\n<li>Proportionality: Cameras should only be installed in justified locations, such as the reception area, corridors, car park, and other common areas. No cameras should ever be placed in guest rooms, changing rooms, or bathrooms.<\/li>\n\n\n\n<li>No audio recording.<\/li>\n\n\n\n<li>Retention period: CCTV footage is kept for a maximum of one month, unless there has been a genuine incident (such as theft or an assault) that justifies retaining the recordings for a longer period.<\/li>\n\n\n\n<li>Restricted access: Only authorized personnel may view the recordings, and a record is kept of who accessed the footage and when.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/media.giphy.com\/media\/v1.Y2lkPTc5MGI3NjExOTRna3pxd3NxNXFlMnpsaHE2MzI2cDlkMmhnYjB4NG82OTh0ZmJ6OCZlcD12MV9naWZzX3NlYXJjaCZjdD1n\/3o84TPp52n6X73S728\/giphy.gif\" alt=\"\"\/><\/figure><\/div>\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">7. Minors<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>I love welcoming families during the summer, and that includes children. But when it comes to minors, extra care is required. I only collect the minimum amount of information necessary about them, such as their age or any dietary restrictions.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">8. Technical and Organizational Security Measures<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Access controls for reservation systems and the Property Management System (PMS): individual user accounts with permissions based on each employee's role.<\/li>\n\n\n\n<li>Encryption of payment card data and any stored identity document information.<\/li>\n\n\n\n<li>Regularly performed and tested backups.<\/li>\n\n\n\n<li>Clean desk policy at reception: passports, payment cards, and guest registration forms should never be left visible.<\/li>\n\n\n\n<li>Regular staff training on data protection and information security.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">9. Data Protection Officer (DPO)<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Not every hotel is required to appoint a Data Protection Officer (DPO). However, it is advisable to assess whether one should be appointed if you process personal data on a large scale\u2014for example, if you are part of a hotel chain or operate a large hotel.<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/media.giphy.com\/media\/v1.Y2lkPTc5MGI3NjExcTQ2bWdqZ3F5ZDM5cjQ0NGpxeDMxYnc4Ymk4cWR5dnQ5ZzZtM2Q1NyZlcD12MV9naWZzX3NlYXJjaCZjdD1n\/geXJ0CoZr9PyM\/giphy.gif\" alt=\"\"\/><\/figure><\/div>\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">10. Data Subjects' Rights<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Both guests and employees have the right to access, rectify, erase, restrict the processing of, object to the processing of, and request the portability of their personal data. To ensure these rights can be exercised effectively, we have:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>A clear and straightforward channel for submitting requests\u2014in our case, a simple online form.<\/li>\n\n\n\n<li>Internal procedures to ensure requests are answered within the legal deadline of one month.<\/li>\n\n\n\n<li>Particular care when dealing with requests for erasure where there is a legal obligation to retain guest registration records. Data cannot always be deleted immediately, and it is important to explain this clearly to the individual concerned.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">11. The Hotel Compliance Checklist<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Every summer, I pull out my personal checklist to make sure we're up to date with our data protection obligations:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Map all personal data flows: guests, employees, restaurant operations, suppliers, and CCTV.<\/li>\n\n\n\n<li>Identify the legal basis for every processing activity.<\/li>\n\n\n\n<li>Sign data processing agreements with every supplier that processes personal data on behalf of the hotel.<\/li>\n\n\n\n<li>Review the placement, signage, and proportionality of CCTV systems.<\/li>\n\n\n\n<li>Train staff regularly, with particular emphasis on reception employees.<\/li>\n\n\n\n<li>Maintain a clear incident response procedure for handling personal data breaches<\/li>\n<\/ul>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/media.giphy.com\/media\/v1.Y2lkPTc5MGI3NjExNGhqZHZ6bzNkMzB5Mm95eTg1MTJoOHoyMXBiMXZ1M3JwNDV4dWVzOSZlcD12MV9naWZzX3NlYXJjaCZjdD1n\/JO5BSisIsfgfSAIYd2\/giphy.gif\" alt=\"\"\/><\/figure><\/div>\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">I Trust Lawwwing. What Are You Waiting For?<\/h2>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>Since I started relying on Lawwwing, I can finally relax knowing that my website complies with all the relevant legal requirements because it:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Generates and keeps my website's legal documents up to date, including the Privacy Policy, Cookie Policy, Legal Notice, and Terms and Conditions.<\/li>\n\n\n\n<li>Provides a cookie banner fully compliant with Google Consent Mode v2.<\/li>\n\n\n\n<li>Automatically updates the legal texts whenever the regulations change.<\/li>\n\n\n\n<li>Includes the mandatory right of withdrawal information, as required since June.<\/li>\n\n\n\n<li>Keeps my website accessible to all of my customers, helping me comply with the European Accessibility Act (EAA).<\/li>\n\n\n\n<li>Includes an AI transparency widget that informs users about the use of artificial intelligence and helps meet the obligations of the EU AI Act, without negatively affecting my conversions or sales.<\/li>\n<\/ul>\n\n\n\n<p>So don't wait any longer and stay compliant with Lawwwing.<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/media3.giphy.com\/media\/v1.Y2lkPTc5MGI3NjExYzE2Ynk5cXkzajhyczIycmdvdmQ0ZDNkY2FsNHkxdXY0aDRlZWEzZiZlcD12MV9pbnRlcm5hbF9naWZfYnlfaWQmY3Q9Zw\/WbwVuQ5rtauFW\/giphy.gif\" alt=\"\"\/><\/figure><\/div>\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-1 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link has-background wp-element-button\" href=\"https:\/\/lawwwing.com\/en\/blog\/\" style=\"background:linear-gradient(135deg,rgb(132,206,249) 0%,rgb(219,180,255) 100%)\">DIGITAL LAW AND DATA PROTECTION BLOG<\/a><\/div>\n<\/div>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<blockquote class=\"instagram-media\" data-instgrm-captioned data-instgrm-permalink=\"https:\/\/www.instagram.com\/reel\/DbaVkp-FDzW\/?utm_source=ig_embed&amp;utm_campaign=loading\" data-instgrm-version=\"14\" style=\" background:#FFF; border:0; border-radius:3px; box-shadow:0 0 1px 0 rgba(0,0,0,0.5),0 1px 10px 0 rgba(0,0,0,0.15); margin: 1px; max-width:540px; min-width:326px; padding:0; width:99.375%; width:-webkit-calc(100% - 2px); width:calc(100% - 2px);\"><div style=\"padding:16px;\"> <a href=\"https:\/\/www.instagram.com\/reel\/DbaVkp-FDzW\/?utm_source=ig_embed&amp;utm_campaign=loading\" style=\" background:#FFFFFF; line-height:0; padding:0 0; text-align:center; text-decoration:none; width:100%;\" target=\"_blank\"> <div style=\" display: flex; flex-direction: row; align-items: center;\"> <div style=\"background-color: #F4F4F4; border-radius: 50%; flex-grow: 0; height: 40px; margin-right: 14px; width: 40px;\"><\/div> <div style=\"display: flex; flex-direction: column; flex-grow: 1; justify-content: center;\"> <div style=\" background-color: #F4F4F4; border-radius: 4px; flex-grow: 0; height: 14px; margin-bottom: 6px; width: 100px;\"><\/div> <div style=\" background-color: #F4F4F4; border-radius: 4px; flex-grow: 0; height: 14px; width: 60px;\"><\/div><\/div><\/div><div style=\"padding: 19% 0;\"><\/div> <div style=\"display:block; height:50px; margin:0 auto 12px; width:50px;\"><svg width=\"50px\" height=\"50px\" viewBox=\"0 0 60 60\" version=\"1.1\" xmlns=\"https:\/\/www.w3.org\/2000\/svg\" xmlns:xlink=\"https:\/\/www.w3.org\/1999\/xlink\"><g stroke=\"none\" stroke-width=\"1\" fill=\"none\" fill-rule=\"evenodd\"><g transform=\"translate(-511.000000, -20.000000)\" fill=\"#000000\"><g><path d=\"M556.869,30.41 C554.814,30.41 553.148,32.076 553.148,34.131 C553.148,36.186 554.814,37.852 556.869,37.852 C558.924,37.852 560.59,36.186 560.59,34.131 C560.59,32.076 558.924,30.41 556.869,30.41 M541,60.657 C535.114,60.657 530.342,55.887 530.342,50 C530.342,44.114 535.114,39.342 541,39.342 C546.887,39.342 551.658,44.114 551.658,50 C551.658,55.887 546.887,60.657 541,60.657 M541,33.886 C532.1,33.886 524.886,41.1 524.886,50 C524.886,58.899 532.1,66.113 541,66.113 C549.9,66.113 557.115,58.899 557.115,50 C557.115,41.1 549.9,33.886 541,33.886 M565.378,62.101 C565.244,65.022 564.756,66.606 564.346,67.663 C563.803,69.06 563.154,70.057 562.106,71.106 C561.058,72.155 560.06,72.803 558.662,73.347 C557.607,73.757 556.021,74.244 553.102,74.378 C549.944,74.521 548.997,74.552 541,74.552 C533.003,74.552 532.056,74.521 528.898,74.378 C525.979,74.244 524.393,73.757 523.338,73.347 C521.94,72.803 520.942,72.155 519.894,71.106 C518.846,70.057 518.197,69.06 517.654,67.663 C517.244,66.606 516.755,65.022 516.623,62.101 C516.479,58.943 516.448,57.996 516.448,50 C516.448,42.003 516.479,41.056 516.623,37.899 C516.755,34.978 517.244,33.391 517.654,32.338 C518.197,30.938 518.846,29.942 519.894,28.894 C520.942,27.846 521.94,27.196 523.338,26.654 C524.393,26.244 525.979,25.756 528.898,25.623 C532.057,25.479 533.004,25.448 541,25.448 C548.997,25.448 549.943,25.479 553.102,25.623 C556.021,25.756 557.607,26.244 558.662,26.654 C560.06,27.196 561.058,27.846 562.106,28.894 C563.154,29.942 563.803,30.938 564.346,32.338 C564.756,33.391 565.244,34.978 565.378,37.899 C565.522,41.056 565.552,42.003 565.552,50 C565.552,57.996 565.522,58.943 565.378,62.101 M570.82,37.631 C570.674,34.438 570.167,32.258 569.425,30.349 C568.659,28.377 567.633,26.702 565.965,25.035 C564.297,23.368 562.623,22.342 560.652,21.575 C558.743,20.834 556.562,20.326 553.369,20.18 C550.169,20.033 549.148,20 541,20 C532.853,20 531.831,20.033 528.631,20.18 C525.438,20.326 523.257,20.834 521.349,21.575 C519.376,22.342 517.703,23.368 516.035,25.035 C514.368,26.702 513.342,28.377 512.574,30.349 C511.834,32.258 511.326,34.438 511.181,37.631 C511.035,40.831 511,41.851 511,50 C511,58.147 511.035,59.17 511.181,62.369 C511.326,65.562 511.834,67.743 512.574,69.651 C513.342,71.625 514.368,73.296 516.035,74.965 C517.703,76.634 519.376,77.658 521.349,78.425 C523.257,79.167 525.438,79.673 528.631,79.82 C531.831,79.965 532.853,80.001 541,80.001 C549.148,80.001 550.169,79.965 553.369,79.82 C556.562,79.673 558.743,79.167 560.652,78.425 C562.623,77.658 564.297,76.634 565.965,74.965 C567.633,73.296 568.659,71.625 569.425,69.651 C570.167,67.743 570.674,65.562 570.82,62.369 C570.966,59.17 571,58.147 571,50 C571,41.851 570.966,40.831 570.82,37.631\"><\/path><\/g><\/g><\/g><\/svg><\/div><div style=\"padding-top: 8px;\"> <div style=\" color:#3897f0; font-family:Arial,sans-serif; font-size:14px; font-style:normal; font-weight:550; line-height:18px;\">Ver esta publicaci\u00f3n en Instagram<\/div><\/div><div style=\"padding: 12.5% 0;\"><\/div> <div style=\"display: flex; flex-direction: row; margin-bottom: 14px; align-items: center;\"><div> <div style=\"background-color: #F4F4F4; border-radius: 50%; height: 12.5px; width: 12.5px; transform: translateX(0px) translateY(7px);\"><\/div> <div style=\"background-color: #F4F4F4; height: 12.5px; transform: rotate(-45deg) translateX(3px) translateY(1px); width: 12.5px; flex-grow: 0; margin-right: 14px; margin-left: 2px;\"><\/div> <div style=\"background-color: #F4F4F4; border-radius: 50%; height: 12.5px; width: 12.5px; transform: translateX(9px) translateY(-18px);\"><\/div><\/div><div style=\"margin-left: 8px;\"> <div style=\" background-color: #F4F4F4; border-radius: 50%; flex-grow: 0; height: 20px; width: 20px;\"><\/div> <div style=\" width: 0; height: 0; border-top: 2px solid transparent; border-left: 6px solid #f4f4f4; border-bottom: 2px solid transparent; transform: translateX(16px) translateY(-4px) rotate(30deg)\"><\/div><\/div><div style=\"margin-left: auto;\"> <div style=\" width: 0px; border-top: 8px solid #F4F4F4; border-right: 8px solid transparent; transform: translateY(16px);\"><\/div> <div style=\" background-color: #F4F4F4; flex-grow: 0; height: 12px; width: 16px; transform: translateY(-4px);\"><\/div> <div style=\" width: 0; height: 0; border-top: 8px solid #F4F4F4; border-left: 8px solid transparent; transform: translateY(-4px) translateX(8px);\"><\/div><\/div><\/div> <div style=\"display: flex; flex-direction: column; flex-grow: 1; justify-content: center; margin-bottom: 24px;\"> <div style=\" background-color: #F4F4F4; border-radius: 4px; flex-grow: 0; height: 14px; margin-bottom: 6px; width: 224px;\"><\/div> <div style=\" background-color: #F4F4F4; border-radius: 4px; flex-grow: 0; height: 14px; width: 144px;\"><\/div><\/div><\/a><p style=\" color:#c9c8cd; font-family:Arial,sans-serif; font-size:14px; line-height:17px; margin-bottom:0; margin-top:8px; overflow:hidden; padding:8px 0 7px; text-align:center; text-overflow:ellipsis; white-space:nowrap;\"><a href=\"https:\/\/www.instagram.com\/reel\/DbaVkp-FDzW\/?utm_source=ig_embed&amp;utm_campaign=loading\" style=\" color:#c9c8cd; font-family:Arial,sans-serif; font-size:14px; font-style:normal; font-weight:normal; line-height:17px; text-decoration:none;\" target=\"_blank\">Una publicaci\u00f3n compartida de Lawwwing (@wearelawwwing)<\/a><\/p><\/div><\/blockquote>\n<script async src=\"\/\/www.instagram.com\/embed.js\"><\/script>\n","protected":false},"excerpt":{"rendered":"<p>I run a hotel. It's August, my pool is packed, the restaurant is serving gazpacho at a rate that would make Wimbledon jealous of their strawberries and cream service, and yet there's something keeping me up at night more than the double booking in room 204: data protection. Although it may seem dreadfully dull, I've [&hellip;]<\/p>\n","protected":false},"author":22,"featured_media":12724,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"categories":[203,242,345,209,326,211,202,246,339,247],"tags":[427,832,677,833,863],"class_list":["post-12575","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance-en","category-consumo-en","category-datos-personales-en","category-gdpr-en","category-legislacion-web-en","category-privacy-policy-en","category-rgpd-en","category-seguridad-en","category-sin-categorizar-en","category-verano-en","tag-data-protection","tag-holidays","tag-proteccion-de-datos-en","tag-summer","tag-vacation"],"acf":[],"_links":{"self":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/12575","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/users\/22"}],"replies":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/comments?post=12575"}],"version-history":[{"count":2,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/12575\/revisions"}],"predecessor-version":[{"id":12583,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/12575\/revisions\/12583"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/media\/12724"}],"wp:attachment":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/media?parent=12575"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/categories?post=12575"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/tags?post=12575"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}