{"id":3526,"date":"2026-01-19T08:00:36","date_gmt":"2026-01-19T08:00:36","guid":{"rendered":"https:\/\/letslaw.es\/proteccion-datos-hoteles\/"},"modified":"2026-01-14T16:41:14","modified_gmt":"2026-01-14T16:41:14","slug":"data-protection-in-hotels","status":"publish","type":"post","link":"https:\/\/letslaw.es\/en\/data-protection-in-hotels\/","title":{"rendered":"Data protection in the hospitality sector"},"content":{"rendered":"<p>Data protection in the hospitality sector is an essential aspect of managing any establishment that offers accommodation services, whether hotels, hostels, tourist apartments, or rural lodgings. The requirement to record guests\u2019 identities has been reinforced by<strong> Royal Decree 933\/2021<\/strong>, which establishes documentary control obligations with the aim of protecting public security and preventing crimes linked to accommodation logistics.<\/p>\n<p>However, this legal obligation must be interpreted together with the <strong>General Data Protection Regulation (GDPR)<\/strong>, which recognises the fundamental right to the protection of personal data and requires that any processing be lawful, transparent, and limited to what is strictly necessary.<\/p>\n<p>The question is not whether hotels should collect personal data, but <strong>how they should do so, what limits apply and which practices must be avoided<\/strong> to prevent infringements.<\/p>\n<h2>How hotels should handle data<\/h2>\n<p>Accommodation providers are required to collect certain identifying data from their guests prior to the start of the stay, as set out in Annex I of Royal Decree 933\/2021. According to guidance from the Spanish Data Protection Agency (AEPD), this information must be collected using a form, either in person or digitally, through which the guest provides <strong>only the data required by the regulation<\/strong>.<\/p>\n<p>The GDPR provides that personal data may only be processed where there is a lawful basis justifying it. In this case, the basis is compliance with a legal obligation imposed on the establishment. However, the existence of an obligation does not entitle the controller to request any information it wishes. Under the principle of data minimisation, set out in Article 5(1)(c) GDPR, <strong>processing must be limited to the data strictly necessary for the intended purpose<\/strong>. Excessive data collection constitutes non-compliance, even if the guest provides the information voluntarily, because consent cannot be considered freely given where the provision of the service is conditioned on supplying data that are not necessary.<\/p>\n<p>Likewise, identity verification does not require retaining a copy of the identity document. The AEPD indicates that it is sufficient to visually verify that the data provided correspond to the document shown, <strong>without scanning or photocopying it<\/strong>. For online check-in, identity may be verified using secure mechanisms such as electronic certificates, validation of payment means, or verification codes sent to the guest\u2019s phone or email.<\/p>\n<p>Once collected, data must be retained only for the period required by the applicable rules and stored with measures that ensure confidentiality, preventing unauthorised access or data loss. The establishment must clearly inform the guest who the controller is, the purpose of collection, the retention period, and the guest\u2019s rights of access, rectification, and erasure, among others.<\/p>\n<h2>Data that should not be requested from guests<\/h2>\n<p>A frequent question among hotels and lodging providers is whether they may request and retain a copy of the guest\u2019s ID card or passport. According to the AEPD, the answer is clearly negative. The Agency has stated that requesting or keeping a copy of the document <strong>infringes the principle of data minimisation<\/strong>, as the document contains information not necessary to comply with the legal obligation, such as the photograph, expiry date, or family-related data. In addition, retaining copies creates an added risk of identity theft that should be avoided.<\/p>\n<p>Therefore, <strong>the establishment must not require or store copies of the DNI, passport or NIE<\/strong>, photographs of the document, or any additional data not included among those required by the Royal Decree. Nor should it request information relating to health, religious orientation, ethnic origin, or any other data considered sensitive under the GDPR, as this would constitute disproportionate processing lacking a lawful basis.<\/p>\n<p>The purpose of identification is to confirm the guest\u2019s identity, not to collect more information than necessary. Complying properly with this obligation not only avoids penalties but also conveys trust and respect for customers\u2019 privacy, an important differentiator in a sector so focused on user experience as hospitality.<\/p>\n<p>For all these reasons, hotels must collect identification data because the regulations require it, but <strong>they must do so in a proportionate, secure, and GDPR-compliant manner<\/strong>. It is neither necessary nor permitted to photocopy documents or store additional information that is not required. The balance between legal obligation and privacy is attainable if the proportionality required by the GDPR is applied.<\/p>\n<p>At Letslaw, we stay abreast of the applicable regulations and help our clients handle their hotel guests\u2019 data correctly in accordance with the law. Letslaw is a law firm with <a title=\"lawyers specialised in digital law\" href=\"https:\/\/letslaw.es\/en\/digital-lawyers\/\">lawyers specialised in digital law<\/a>, e-commerce, and advertising law.<\/p>\n<div class=\"cyp_post_formulario\"><h2>Contact Us<\/h2>\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f3074-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"3074\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/3526#wpcf7-f3074-o1\" method=\"post\" class=\"wpcf7-form init wpcf7-acceptance-as-validation\" aria-label=\"Formulario de contacto\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"3074\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.5\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f3074-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<div class=\"campo_nombre\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Name\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span><\/div>\n<div class=\"campo_telefono\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-phone\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-tel wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-tel datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Phone\" value=\"\" type=\"tel\" name=\"your-phone\" \/><\/span><\/div>\n<div class=\"campo_email\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Email\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span><\/div>\n<div class=\"campo_asunto\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-asunto\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Subject\" value=\"\" type=\"text\" name=\"your-asunto\" \/><\/span><\/div>\n<div class=\"campo_mensaje\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-mensaje\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Message\" name=\"your-mensaje\"><\/textarea><\/span><\/div>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"\" type=\"hidden\" name=\"cyp_form_url\" \/>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"cyp_zonaweb\" type=\"hidden\" name=\"zonaweb\" \/>\n<span class=\"wpcf7-form-control-wrap recaptcha\" data-name=\"recaptcha\"><span data-sitekey=\"6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" class=\"wpcf7-form-control wpcf7-recaptcha g-recaptcha\"><\/span>\r\n<noscript>\r\n\t<div class=\"grecaptcha-noscript\">\r\n\t\t<iframe loading=\"lazy\" src=\"https:\/\/www.google.com\/recaptcha\/api\/fallback?k=6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" frameborder=\"0\" scrolling=\"no\" width=\"310\" height=\"430\">\r\n\t\t<\/iframe>\r\n\t\t<textarea name=\"g-recaptcha-response\" rows=\"3\" cols=\"40\" placeholder=\"Aqu\u00ed la respuesta de reCAPTCHA\">\r\n\t\t<\/textarea>\r\n\t<\/div>\r\n<\/noscript>\r\n<\/span>\n<div style=\"width:100%\">\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important;margin-bottom:15px !important\">\nBy clicking on \"Send\" you accept our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup_ingles\">+ Info<\/a>\n<\/p>\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important\">\n<span class=\"wpcf7-form-control-wrap\" data-name=\"checkbox-173\"><span class=\"wpcf7-form-control wpcf7-checkbox wpcf7-exclusive-checkbox\"><span class=\"wpcf7-list-item first last\"><label><input type=\"checkbox\" name=\"checkbox-173\" value=\"\" \/><span class=\"wpcf7-list-item-label\"><\/span><\/label><\/span><\/span><\/span> I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup\">+ Info<\/a>\n<\/p>\n<\/div>\n<div class=\"vc_col-sm-12 botton-datos-contacto\"><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Send\" \/><\/div><input type='hidden' class='wpcf7-pum' value='{\"closepopup\":false,\"closedelay\":0,\"openpopup\":false,\"openpopup_id\":0}' \/><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<div>","protected":false},"excerpt":{"rendered":"<p>How hotels should collect personal data, what limits exist and what practices should be avoided in order to prevent violations.<\/p>\n","protected":false},"author":2,"featured_media":2808,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[243],"tags":[],"class_list":["post-3526","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection"],"_links":{"self":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/3526","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/comments?post=3526"}],"version-history":[{"count":10,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/3526\/revisions"}],"predecessor-version":[{"id":19820,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/3526\/revisions\/19820"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media\/2808"}],"wp:attachment":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media?parent=3526"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/categories?post=3526"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/tags?post=3526"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}