Skip to main content

GDPR Compliance for Hotels

Hotels hold more personal data than almost any small business — passports, card tokens, dietary notes, movement records. Here is what GDPR actually asks of you, and what the software should be doing rather than you.

First: Are You the Controller?

For guest data, the hotel is the controller and the software vendor is the processor. That distinction decides every obligation that follows. The hotel decides what guest data is collected, why, and how long it is kept. The PMS vendor acts only on the hotel’s documented instructions — which means a vendor cannot lawfully delete or retain guest data on its own initiative, and a vendor that promises to "handle GDPR for you" has misunderstood its own role.

The practical consequence surprises people: a well-built PMS ships its retention engine switched off. Automatically deleting a controller’s data without instruction would itself be a breach of Article 29. You turn retention on, per data category, because you are the one entitled to make that decision.

Who Holds Which Hat

Data Controller Processor
Guest profiles, stays, folios, ID documentsThe hotelThe PMS vendor
Hotel staff accounts and audit logsThe hotelThe PMS vendor
Booking-engine visitors on the hotel’s own domainThe hotelThe PMS vendor
The hotel’s own billing and account data with the vendorThe vendor—

You need a Data Processing Agreement with every processor touching guest data — the PMS, the channel manager, the payment gateway, the email provider. Ask each for theirs, and ask for their sub-processor list while you are there.

The Six Obligations That Actually Bite

GDPR is long. For a hotel, the day-to-day reality reduces to six things.

  1. Answer data subject requests within one month. A guest can ask for a copy of their data, its correction, its deletion, or a portable export. The clock starts when the request arrives, extendable by two further months only with a recorded reason. You must verify identity before releasing or erasing anything — handing a stranger a guest’s stay history is itself a breach.
  2. Record consent properly where you rely on it. Consent must be freely given, specific and evidenced: what wording the guest saw, when, and through which channel. Pre-ticked boxes are not consent. Withdrawal must be as easy as giving it — which in practice means a guest can unsubscribe without an account or a login.
  3. Do not keep data forever. Storage limitation means each category needs a retention period with a reason. Some categories have legal floors that override your preference — invoices and tax records typically must be kept for years regardless of a deletion request.
  4. Report a personal data breach within 72 hours. That is 72 hours from becoming aware, to the supervisory authority, and it applies to a lost laptop or a misdirected email just as much as a hack. If the risk to guests is high, you must tell them too.
  5. Keep a record of processing activities. Article 30 expects a written record of what you process, why, on what lawful basis, who you share it with and how long you keep it. This is the document a regulator asks for first.
  6. Collect less. Data minimisation is the cheapest compliance win available. Every passport image you store is a liability you chose to take on — check whether your market’s law actually requires retaining the scan or only the details from it.

Guest Data Requests, Step by Step

The obligation most hotels are least prepared for.

  1. Log the request the moment it arrives, whatever channel it came through. An email to reception counts. A verbal request counts. The one-month deadline runs from receipt, not from when someone noticed.
  2. Verify identity before acting. Match against the booking, or request proportionate proof. Do not demand a passport scan to prove identity for a deletion request — that collects more data to delete less.
  3. Work out which right is being exercised. Access and portability mean producing the data. Rectification means correcting it. Erasure means removing it, subject to exemptions. Restriction means freezing processing while a dispute is resolved.
  4. Apply the legal holds honestly. Erasure is not absolute. Invoices, tax records, an unpaid balance, an ongoing legal claim — these are grounds to refuse, and a lawful refusal must state the grounds and the guest’s right to complain.
  5. Erase by anonymisation where records must survive. You usually cannot delete a folio row without destroying your accounts. Stripping the personal identifiers while leaving the financial record intact satisfies both obligations at once.
  6. Record what you did and when. Accountability means being able to show the decision, not merely assert it.

Frontdesko handles this as tooling rather than a process document: a public intake endpoint a guest can use without an account, the deadline computed on arrival and flagged when overdue, identity verification enforced before any export or erasure, erasure implemented as anonymisation-in-place with legal-hold grounds, and a record written for every action.

What to Ask a PMS Vendor

Six questions that separate real tooling from a compliance page.

  • Can I answer an access, deletion, correction or portability request from the admin, with the one-month deadline tracked — or does it become a support ticket to you?
  • Is consent stored append-only with the wording and version the guest actually saw? A boolean flag is not evidence.
  • Are retention periods configurable per data category, with legal floors that cannot be overridden by accident?
  • Is there a breach register with the 72-hour clock, or do I track that in a spreadsheet?
  • Will you give me a Data Processing Agreement and a current sub-processor list without a sales call?
  • Where is the data hosted, and what happens to it if I leave?

One honest note on certifications: SOC 2, ISO 27001 and PCI DSS are held by infrastructure providers and payment gateways far more often than by small PMS vendors themselves. Ask who actually holds the certificate. A vendor claiming its own SOC 2 should be able to produce the report; a vendor whose data centres are certified should say so in those words. Frontdesko runs on managed infrastructure from SOC 2 and ISO 27001 certified providers, and card details are entered on the payment provider’s hosted checkout, so card numbers never reach Frontdesko at all.

This page is an engineering and operational summary, not legal advice. Data protection obligations differ by market and change; take professional advice on your own position, particularly on lawful basis, international transfers and whether you need a DPO.

Frequently Asked Questions

Does GDPR apply to hotels?

Yes, to any hotel processing personal data of people in the EU or EEA, and a closely equivalent regime applies in the UK. It applies regardless of where the hotel is based if it offers services to guests in those territories. Hotels are high-exposure because they hold identity documents, payment tokens, stay histories and free-text notes that often contain health or dietary information.

Is the hotel or the PMS vendor the data controller?

For guest data the hotel is the controller and the PMS vendor is the processor. The hotel decides what is collected, why and for how long; the vendor acts only on the hotel’s documented instructions. That is why a well-built PMS ships its retention engine switched off — deleting a controller’s data without instruction would itself breach Article 29.

How long does a hotel have to answer a guest data request?

One month from receiving the request, extendable by a further two months only where the request is complex and you record the reason for the extension. The clock starts when the request arrives through any channel, including an email to reception. You must verify the requester’s identity before releasing or erasing anything.

Can a hotel refuse to delete a guest’s data?

Sometimes, and lawfully. Invoices and tax records usually carry statutory retention periods that override a deletion request, and an unpaid balance or an ongoing legal claim are also grounds. A refusal must state the grounds and tell the guest how to complain. The usual resolution is erasure by anonymisation — stripping the personal identifiers while the financial record survives intact.

How long can a hotel keep guest data?

Only as long as there is a purpose, with the period documented per category. Marketing consent data ends when consent is withdrawn; booking records typically persist while a commercial relationship or claim window lasts; invoices and tax records carry statutory floors of several years depending on your market. Retention should be configured per category rather than applied as one blanket rule.

What must a hotel do after a data breach?

Notify the supervisory authority within 72 hours of becoming aware, unless the breach is unlikely to risk individuals’ rights. Where the risk is high, affected guests must be told as well. The 72 hours cover misdirected emails and lost devices, not only attacks. Keep a breach register recording every incident and the reasoning, including incidents you decided not to report.

Do I need a DPA with my PMS provider?

Yes. Article 28 requires a written contract with every processor handling personal data on your behalf — the PMS, channel manager, payment gateway and email provider included. Ask each for their Data Processing Agreement and their current sub-processor list. A provider that cannot produce either on request is a risk in itself.

Answer a Guest Data Request in Minutes

Access, deletion, correction and portability handled from the admin with the deadline tracked, consent recorded with evidence, retention set per category and a breach register with the 72-hour clock — free with the PMS.

Start Live Demo See How We Protect Data
✓ Deadline Tracked ✓ Consent With Evidence ✓ Free Forever