Any hospitality business processes personal data from the moment someone makes a booking. Most are aware of this. What they do not always realise is how many different types of data they are handling, the legal basis for each type of processing, and the consequences of doing it incorrectly. The General Data Protection Regulation It makes no distinction between a large hotel chain and a family-run restaurant: the obligations are the same, and so are the penalties.
What personal data does the hospitality industry process (and why it’s more than it seems)
A hotel or restaurant doesn’t just manage names and email addresses. The scope of data in this sector is broader than many venue managers realise.
A sector with more data than meets the eye
Online bookings and check-in generate contact details, preferences and dates of stay. Payments include bank and card details. Loyalty schemes build up profiles of customer behaviour over time. Security cameras capture images of customers and staff. Public Wi-Fi records devices and, in many cases, browsing habits. Notes on allergies or intolerances constitute health data, a category subject to special protection. Reviews and ratings may contain personally identifiable information. And if the establishment offers services for families, it will also process data relating to minors. Each of these processing operations has its own legal basis, its own retention period and its own documentation requirements.
Legal basis for data processing in the hospitality sector
The GDPR does not require consent for everything. It requires that every processing operation have a valid legal basis and that the data controller be able to demonstrate this. In the hospitality sector, three main legal bases apply: performance of a contract, a legal obligation and a legitimate interest, in addition to consent where none of the above apply.
When to apply each basis and how to document it
Online bookings and check-in
Name, contact details, dates of stay, room preferences, number of guests.
Payment details
Card number, cardholder name, bank details, transaction history.
Security cameras
Pictures of customers, staff and communal areas within the premises.
Public Wi-Fi
Registration details for network access: name, email address, device, browsing history.
Loyalty schemes
History of stays, preferences, points earned, marketing communications.
Health information: allergies and intolerances
Information regarding food allergies, intolerances or medical conditions relevant to the service.
Reviews and ratings
Reviews posted by customers on the company’s own or external platforms containing personally identifiable information.
Data relating to minors
Information regarding minors accompanying guests in relation to bookings, activities or services provided by the establishment.
Specific obligations of accommodation providers under the GDPR
Understanding the legal framework is the starting point, but the GDPR imposes additional obligations that every organisation must have in place.
Record of processing activities
Every data controller must keep a an up-to-date record of all activities the processing carried out: what data, for what purpose, on what legal basis, for how long and with what security measures. This document is not sent to any body, but must be made available in the event of an inspection by the AEPD.
Visible privacy policy and customer information
Information on data processing must be made available before the customer provides their personal data, both online and in-store. A sign next to the check-in form or a clause at the bottom of the booking form are not optional.
Contracts with suppliers who have access to data
Any supplier that accesses the establishment’s personal data – from a booking platform to a CCTV management company – must sign a data processor agreement governing the use of that data. Without such an agreement, liability rests entirely with the establishment.
Security cameras, Wi-Fi and children’s data: the sector’s key issues
Three areas account for the majority of the sanctions and enforcement actions imposed by the AEPD in the hospitality sector.
CCTV
Security cameras must display a visible information sign in every area under surveillance, store footage for a maximum of 30 days unless required by a court order, and must not be installed in toilets, changing rooms or staff break areas under any circumstances. Recording without a sign or retaining footage beyond the legal time limit are two of the most common breaches in the sector.
Public Wi-Fi and children’s data
Registration for Wi-Fi access may only be used for that purpose. Re-using that data to send marketing communications without separate consent is a common and easily detectable breach. With regard to minors, any image published on social media or in the establishment’s materials requires individual written authorisation from their legal guardians, regardless of the channel or intended use.
GDPR fines in the hospitality sector: real-life cases and amounts
The AEPD has issued penalty decisions against hospitality establishments for video surveillance without an information notice, misuse of Wi-Fi data for marketing purposes, the absence of a privacy policy on booking forms, and the inappropriate processing of health data. The amounts vary depending on the severity: Minor infringements may be dealt with by a warning; serious infringements carry fines of up to 300,000 euros; and very serious infringements may result in fines of up to 20 million euros or 4% of total annual turnover. Civil liability in the event of an adverse reaction or a security breach adds an additional risk that standard industry policies do not always cover.
Staff training on data protection: who should receive it and what it should cover
Data protection is not solely the responsibility of the owner or the legal department. Every person who has access to personal data within the organisation has specific obligations.
Levels of education by access to data
Reception and bookings staff need training on customer information, Management of requests regarding dietary requirements and processing of payment details. Front-of-house staff require specific training on health information and the protocol to follow when asked about allergies. Kitchen staff must be aware of the limits on the use and storage of information regarding food intolerances. Management needs an overview of compliance: activity logs, breach management and relations with suppliers. From the Educa.Pro catalogue it is possible to access training on data protection tailored to the hospitality sector, with content tailored to different profiles and funding options through FUNDAE.
The GDPR does not require perfection: it requires evidence that the organisation takes compliance seriously. An up-to-date record, trained staff and properly contracted suppliers are, in most cases, sufficient to demonstrate that the organisation has acted with due diligence.