{"id":16898,"date":"2024-11-01T06:00:59","date_gmt":"2024-11-01T06:00:59","guid":{"rendered":"https:\/\/letslaw.es\/?p=16898"},"modified":"2024-10-02T15:05:07","modified_gmt":"2024-10-02T15:05:07","slug":"compliance-gdpr-tourism-sector","status":"publish","type":"post","link":"https:\/\/letslaw.es\/en\/compliance-gdpr-tourism-sector\/","title":{"rendered":"Compliance with the GDPR in the Tourism Sector"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">In the tourism industry, where the collection and processing of personal data are essential for service delivery, it is even more critical to ensure that the handling of customer data is done in accordance with the General <\/span><a title=\"data protection lawyers\" href=\"https:\/\/letslaw.es\/en\/privacy-data-protection-lawyers\/\"><span style=\"font-weight: 400;\">Data Protection<\/span><\/a><span style=\"font-weight: 400;\"> Regulation (GDPR).<\/span><\/p>\n<p><b>It&#8217;s a fact that the supply chain in the tourism sector involves a continuous flow of personal data<\/b><span style=\"font-weight: 400;\">, as information provided by individuals during the booking process (personal data and, in some cases, special categories of personal data) flows between different parties involved in managing the reservation. However, this flow increases the risk of improper handling or exposure of personal data.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The main legal issue arises from how personal data travels through different information systems. From the moment a customer enters their booking information on a particular platform until the reservation is finalized, this data may pass through several intermediaries. Each intermediary maintains a separate agreement between the customer and the service provider, which must correctly define the legal responsibilities regarding data processing. Among the main problems that may arise, we find <\/span><b>the lack of direct control between a platform, the data controller (the company that initially collects the data), and the service provider<\/b><span style=\"font-weight: 400;\"> (for example, if a hotel fails to implement proper data protection practices).<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In addition to this lack of direct control, we can add: (i) the complexity of supervising how the various actors involved process the data; (ii) the fact that personal data may be stored on platforms vulnerable to cyberattacks; and (iii) in cases of international tourism (especially outside the EU), international data transfers may occur without complying with the GDPR&#8217;s requirements.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Another challenge for this sector, considering the demand for personalized services, is balancing service personalization with GDPR compliance.<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">Privacy Violations<\/span><\/h2>\n<p><b>Currently, the most significant privacy violations in the tourism sector include personal data breaches due to cyberattacks or inadequate security measures<\/b><span style=\"font-weight: 400;\">, excessive collection of information, using data without explicit customer consent, and retaining information beyond legal limits.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Additionally, there are issues related to a lack of control over company staff\u2019s access to sensitive data, misuse of data for advertising without consent, and non-compliance with regulations on international data transfers and breach notifications.<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">Non-compliance Cases<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Among the most notorious cases in this sector, we should highlight many businesses&#8217; failure to comply with data protection regulations by <\/span><b>photocopying guests&#8217; identity documents<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Specifically, the extensive inspections carried out by the Spanish Data Protection Agency (AEPD) this summer, capitalizing on the peak tourist season, targeted businesses that photocopy or scan guests&#8217; ID cards. The AEPD has repeatedly emphasized that this practice, though common in the hospitality industry, is illegal as it violates data protection laws.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It is crucial to remember that only adequate, relevant, and<\/span><b> limited information necessary for the purpose for which it is collected should be obtained<\/b><span style=\"font-weight: 400;\">. Therefore, collecting specific information about users and processing personal data is lawful, but photocopying an ID card would be excessive, as some information contained in the ID is not necessary for the intended purpose.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In this context, the AEPD imposed a fine of \u20ac30,000 on a hotel for violating Article 6 of the GDPR. The sanction followed a complaint by the Dutch Data Protection Authority, as the hotel had scanned a guest&#8217;s passport, including their photo, and used that information to verify the guest&#8217;s identity when charging their account, without their consent. Although the hotel collected the data to comply with regulations on traveler registration, the subsequent use of the information for other purposes was deemed illegal.<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">GDPR Penalties<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Penalties for GDPR non-compliance can be extremely high, reaching up to \u20ac20 million or 4% of annual turnover. Although most fines are smaller, such as the \u20ac2,000 penalty imposed on a tourism business for photocopying ID cards, <\/span><b>the AEPD warns that penalties can be severe and increase depending on the gravity of the violation<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<div class=\"cyp_post_formulario\"><h2>Contact Us<\/h2>\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f3074-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"3074\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/16898#wpcf7-f3074-o1\" method=\"post\" class=\"wpcf7-form init wpcf7-acceptance-as-validation\" aria-label=\"Formulario de contacto\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"3074\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.5\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f3074-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<div class=\"campo_nombre\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Name\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span><\/div>\n<div class=\"campo_telefono\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-phone\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-tel wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-tel datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Phone\" value=\"\" type=\"tel\" name=\"your-phone\" \/><\/span><\/div>\n<div class=\"campo_email\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Email\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span><\/div>\n<div class=\"campo_asunto\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-asunto\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Subject\" value=\"\" type=\"text\" name=\"your-asunto\" \/><\/span><\/div>\n<div class=\"campo_mensaje\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-mensaje\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Message\" name=\"your-mensaje\"><\/textarea><\/span><\/div>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"\" type=\"hidden\" name=\"cyp_form_url\" \/>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"cyp_zonaweb\" type=\"hidden\" name=\"zonaweb\" \/>\n<span class=\"wpcf7-form-control-wrap recaptcha\" data-name=\"recaptcha\"><span data-sitekey=\"6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" class=\"wpcf7-form-control wpcf7-recaptcha g-recaptcha\"><\/span>\r\n<noscript>\r\n\t<div class=\"grecaptcha-noscript\">\r\n\t\t<iframe loading=\"lazy\" src=\"https:\/\/www.google.com\/recaptcha\/api\/fallback?k=6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" frameborder=\"0\" scrolling=\"no\" width=\"310\" height=\"430\">\r\n\t\t<\/iframe>\r\n\t\t<textarea name=\"g-recaptcha-response\" rows=\"3\" cols=\"40\" placeholder=\"Aqu\u00ed la respuesta de reCAPTCHA\">\r\n\t\t<\/textarea>\r\n\t<\/div>\r\n<\/noscript>\r\n<\/span>\n<div style=\"width:100%\">\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important;margin-bottom:15px !important\">\nBy clicking on \"Send\" you accept our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup_ingles\">+ Info<\/a>\n<\/p>\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important\">\n<span class=\"wpcf7-form-control-wrap\" data-name=\"checkbox-173\"><span class=\"wpcf7-form-control wpcf7-checkbox wpcf7-exclusive-checkbox\"><span class=\"wpcf7-list-item first last\"><label><input type=\"checkbox\" name=\"checkbox-173\" value=\"\" \/><span class=\"wpcf7-list-item-label\"><\/span><\/label><\/span><\/span><\/span> I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup\">+ Info<\/a>\n<\/p>\n<\/div>\n<div class=\"vc_col-sm-12 botton-datos-contacto\"><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Send\" \/><\/div><input type='hidden' class='wpcf7-pum' value='{\"closepopup\":false,\"closedelay\":0,\"openpopup\":false,\"openpopup_id\":0}' \/><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<div>","protected":false},"excerpt":{"rendered":"<p>It&#8217;s a fact that the supply chain in the tourism sector involves a continuous flow of personal data.<\/p>\n","protected":false},"author":67,"featured_media":16895,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[258],"tags":[],"class_list":["post-16898","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-law"],"_links":{"self":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/16898","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/users\/67"}],"replies":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/comments?post=16898"}],"version-history":[{"count":4,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/16898\/revisions"}],"predecessor-version":[{"id":16899,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/16898\/revisions\/16899"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media\/16895"}],"wp:attachment":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media?parent=16898"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/categories?post=16898"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/tags?post=16898"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}