Educa.Pro Blog

The GDPR in the hospitality sector: what data do hotels and restaurants collect, and how to manage it in accordance with the law

15 July 2026 - Educa.Pro editorial team
The GDPR in the hospitality sector: what data do hotels and restaurants collect, and how to manage it in accordance with the law

Any hospitality business processes personal data from the moment someone makes a booking. Most are aware of this. What they do not always realise is how many different types of data they are handling, the legal basis for each type of processing, and the consequences of doing it incorrectly. The General Data Protection Regulation It makes no distinction between a large hotel chain and a family-run restaurant: the obligations are the same, and so are the penalties.

What personal data does the hospitality industry process (and why it’s more than it seems)

A hotel or restaurant doesn’t just manage names and email addresses. The scope of data in this sector is broader than many venue managers realise.

A sector with more data than meets the eye

Online bookings and check-in generate contact details, preferences and dates of stay. Payments include bank and card details. Loyalty schemes build up profiles of customer behaviour over time. Security cameras capture images of customers and staff. Public Wi-Fi records devices and, in many cases, browsing habits. Notes on allergies or intolerances constitute health data, a category subject to special protection. Reviews and ratings may contain personally identifiable information. And if the establishment offers services for families, it will also process data relating to minors. Each of these processing operations has its own legal basis, its own retention period and its own documentation requirements.

Legal basis for data processing in the hospitality sector

The GDPR does not require consent for everything. It requires that every processing operation have a valid legal basis and that the data controller be able to demonstrate this. In the hospitality sector, three main legal bases apply: performance of a contract, a legal obligation and a legitimate interest, in addition to consent where none of the above apply.

When to apply each basis and how to document it

GDPR legal requirements in the hospitality sector: what applies and how to document it

Select the type of data processing to view the legal basis, how to document it and the risk of non-compliance

📋 Online bookings
💳 Payment details
📷 Security cameras
📶 Public Wi-Fi
Loyalty schemes
🌾 Health information (allergies)
Reviews and ratings
👶 Data on minors
☝️ Select a type of processing to view the applicable legal basis
📋

Online bookings and check-in

Name, contact details, dates of stay, room preferences, number of guests.

Legal basis: Performance of a contract (Article 6(1)(b) of the GDPR)
Why does it apply?
The processing is necessary to provide the contracted service. No further consent is required.
How to document it
Privacy policy available before booking; information clause on the check-in form.
Retention period
A minimum of 5 years for tax and commercial obligations.
Common mistake
Seeking consent when a contractual basis already exists: this causes confusion and does not provide any additional protection.
✅ Low-risk processing provided that the information provided to the customer is clear and the retention period is specified.
💳

Payment details

Card number, cardholder name, bank details, transaction history.

Legal basis: Performance of a contract (Article 6(1)(b) of the GDPR)
Why does it apply?
Required to complete payment for the service. Card details are also governed by PCI DSS.
How to document it
Certified payment gateway; never store card details on your own systems that are not PCI-certified.
Retention period
What is strictly necessary for the provision of the service and to comply with legal obligations (5-year tax retention period).
Common mistake
Storing card details in Excel spreadsheets or insecure systems: a serious breach.
⚠️ High risk. Data breaches involving payment details must be reported to the AEPD within 72 hours.
📷

Security cameras

Pictures of customers, staff and communal areas within the premises.

Legal basis: Legitimate interest (Article 6(1)(f) of the GDPR)
Why does it apply?
The security of the premises is a recognised legitimate interest, provided that it is proportionate.
How to document it
Information sign visible in the recorded area, record of treatment activity, maximum retention period of 30 days.
Restricted areas
Toilets, changing rooms, staff break areas. Filming in these areas is a very serious offence.
Common mistake
Do not display posters or keep images for more than 30 days without a legitimate legal reason.
⚠️ The AEPD has imposed fines on establishments for failing to display signs and for the improper storage of images.
📶

Public Wi-Fi

Registration details for network access: name, email address, device, browsing history.

Legal basis: Consent (Article 6(1)(a) of the GDPR)
Why does it apply?
Users are free to choose to connect and provide their details in order to access the service.
How to document it
A captive portal with a privacy policy acceptance box, which is unchecked by default.
Limits on use
The data collected may only be used for the Wi-Fi service; it may not be used for marketing purposes without further express consent.
Common mistake
Using email addresses collected via Wi-Fi to send newsletters without specific consent for that purpose.
⚠️ The use of Wi-Fi data for marketing purposes without separate consent is one of the most commonly detected infringements in the sector.

Loyalty schemes

History of stays, preferences, points earned, marketing communications.

Legal basis: Consent + Contract (Articles 6(1)(a) and 6(1)(b) of the GDPR)
Why does it apply?
The management of points is governed by the terms of the contract; the sending of marketing communications requires explicit consent.
How to document it
Registration form with two layers of information: programme details (contract) and communications (separate consent).
Right to cancel
Customers may withdraw their consent to receive communications without losing their membership of the programme.
Common mistake
Making enrolment in the programme conditional on accepting marketing communications: this does not constitute free consent.
✅ Correct, provided that the two legal bases are clearly distinguished and the right to withdraw consent for marketing purposes is guaranteed.
🌾

Health information: allergies and intolerances

Information regarding food allergies, intolerances or medical conditions relevant to the service.

Legal basis: Explicit consent (Article 9(2)(a) of the GDPR) — Special category
Why does it apply?
Health data is a special category of data under the GDPR and requires explicit consent, not implied consent.
How to document it
A signed declaration or a specific box containing information stating that the data is to be used exclusively for the management of the catering service.
Limits on use
They may only be used for the provision of the service. They must not be shared with third parties or used for any other purpose.
Common mistake
Recording allergies in shared systems without access controls, or retaining them beyond the patient’s stay.
⚠️ Highest risk. Health data requires enhanced security measures. Improper handling of such data constitutes a very serious offence.
💬

Reviews and ratings

Reviews posted by customers on the company’s own or external platforms containing personally identifiable information.

Legal basis: Legitimate interest (Article 6(1)(f) of the GDPR)
Why does it apply?
Managing an establishment’s online reputation is a recognised legitimate interest.
How to document it
A privacy policy covering the processing of reviews and the customer’s right to request their removal.
Right to erasure
Customers may request that their review be removed if it contains personally identifiable information.
Common mistake
Posting replies to reviews that include customers’ personal data without their consent.
✅ Low risk if the privacy policy provides for this and the public responses do not include the complainant’s personal data.
👶

Data relating to minors

Information regarding minors accompanying guests in relation to bookings, activities or services provided by the establishment.

Legal basis: Legal obligation + Parental consent (Articles 6(1)(c) and 8 of the GDPR)
Why does it apply?
Children under the age of 14 require the consent of a parent or legal guardian for any treatment.
How to document it
When making a booking, the child’s details are linked to the adult’s contract. Certain activities require written parental consent.
Photographs
Never post images of minors on social media or material relating to the school without the express authorisation of their parents or guardians.
Common mistake
Publishing photos of children’s activities at the hotel or restaurant without the individual consent of each family.
⚠️ High reputational and legal risk. Unauthorised images of minors constitute a serious offence, regardless of the platform.

Specific obligations of accommodation providers under the GDPR

Understanding the legal framework is the starting point, but the GDPR imposes additional obligations that every organisation must have in place.

Record of processing activities

Every data controller must keep a an up-to-date record of all activities the processing carried out: what data, for what purpose, on what legal basis, for how long and with what security measures. This document is not sent to any body, but must be made available in the event of an inspection by the AEPD.

Visible privacy policy and customer information

Information on data processing must be made available before the customer provides their personal data, both online and in-store. A sign next to the check-in form or a clause at the bottom of the booking form are not optional.

Contracts with suppliers who have access to data

Any supplier that accesses the establishment’s personal data – from a booking platform to a CCTV management company – must sign a data processor agreement governing the use of that data. Without such an agreement, liability rests entirely with the establishment.

Security cameras, Wi-Fi and children’s data: the sector’s key issues

Three areas account for the majority of the sanctions and enforcement actions imposed by the AEPD in the hospitality sector.

CCTV

Security cameras must display a visible information sign in every area under surveillance, store footage for a maximum of 30 days unless required by a court order, and must not be installed in toilets, changing rooms or staff break areas under any circumstances. Recording without a sign or retaining footage beyond the legal time limit are two of the most common breaches in the sector.

Public Wi-Fi and children’s data

Registration for Wi-Fi access may only be used for that purpose. Re-using that data to send marketing communications without separate consent is a common and easily detectable breach. With regard to minors, any image published on social media or in the establishment’s materials requires individual written authorisation from their legal guardians, regardless of the channel or intended use.

GDPR fines in the hospitality sector: real-life cases and amounts

The AEPD has issued penalty decisions against hospitality establishments for video surveillance without an information notice, misuse of Wi-Fi data for marketing purposes, the absence of a privacy policy on booking forms, and the inappropriate processing of health data. The amounts vary depending on the severity: Minor infringements may be dealt with by a warning; serious infringements carry fines of up to 300,000 euros; and very serious infringements may result in fines of up to 20 million euros or 4% of total annual turnover. Civil liability in the event of an adverse reaction or a security breach adds an additional risk that standard industry policies do not always cover.

Staff training on data protection: who should receive it and what it should cover

Data protection is not solely the responsibility of the owner or the legal department. Every person who has access to personal data within the organisation has specific obligations.

Levels of education by access to data

Reception and bookings staff need training on customer information, Management of requests regarding dietary requirements and processing of payment details. Front-of-house staff require specific training on health information and the protocol to follow when asked about allergies. Kitchen staff must be aware of the limits on the use and storage of information regarding food intolerances. Management needs an overview of compliance: activity logs, breach management and relations with suppliers. From the Educa.Pro catalogue it is possible to access training on data protection tailored to the hospitality sector, with content tailored to different profiles and funding options through FUNDAE.
The GDPR does not require perfection: it requires evidence that the organisation takes compliance seriously. An up-to-date record, trained staff and properly contracted suppliers are, in most cases, sufficient to demonstrate that the organisation has acted with due diligence.

Latest posts

Scroll to Top