Compliance
GDPR for hotels: a guest data checklist for check-in
A practical hotel GDPR checklist: lawful basis, ID copies, retention, supplier contracts and access controls, with a separate guide to Spanish registration rules.
HazCheckin Team
HazCheckin
Hotel GDPR compliance starts with knowing what guest data you collect, why you need it and when you will delete it. Online check-in changes how you collect the information; it does not remove the hotel’s responsibility for its use.
This checklist distinguishes the European data protection framework from Spain’s guest registration rules. SES.HOSPEDAJES and the Spanish retention period are not requirements for every hotel in Europe.
1. Separate each purpose and lawful basis
Map guest registration, booking administration, payment and marketing separately. Record the applicable lawful basis for each purpose and explain it in the privacy notice shown when data is collected. A required check-in field should not double as permission for unrelated marketing. See GDPR Articles 6 and 13.
Operational check: open your guest form as a first-time visitor. Can a guest identify the hotel responsible for the data and understand why each required field is needed?
2. Review ID handling separately from registration fields
Do not assume that a duty to register guest details authorises keeping an image of the entire identity document. In Spain, the AEPD says accommodation providers must not request a copy of the ID card or passport to meet the guest registration obligation.
Check what your provider collects, transmits and stores. Avoid routinely asking guests to email or message document copies as a workaround. Document how identity is checked and how a guest can obtain assistance.
3. Set retention by record type and country
For professional accommodation covered by Spain’s Royal Decree 933/2021, Article 5, computerised registration data must be retained for three years from the end of the service. The article provides an exception for non-professional accommodation activities; their communication obligations still apply.
That rule is not a universal retention period for all hotel data. Invoices, marketing records and information needed for a legal claim require their own assessment. It also does not justify retaining passport images. Record the purpose and deadline for each category rather than applying one rule to the entire guest profile.
Operational check: identify who runs deletion, how failed deletions are detected and how backups are handled.
4. Check access and the supplier agreement
Use individual staff accounts, review access when roles change and identify where guest information is exported. Check the processor agreement, subprocessors and any international transfers before choosing a supplier. Match security measures to the risks of the processing. These are addressed by GDPR Articles 28, 32 and Chapter V.
Operational check: ask a receptionist to show which records their account can access. Compare that access with what their job requires.
5. Treat biometric verification as a separate decision
Biometric processing for unique identification requires a lawful basis and an applicable Article 9 condition. Assess necessity, alternatives and whether a data protection impact assessment is required before enabling it. Deleting a selfie quickly does not, by itself, establish that the processing is lawful. See GDPR Articles 9 and 35.
Spain: connect registration to your check-in workflow
For a Spanish property, identify the competent reporting authority and configure the corresponding workflow. The guest reporting overview explains HazCheckin’s approach; the hotel check-in page and product demos show how to evaluate the operational fit.
Test a booking from invitation to completed registration. Confirm which fields remain pending, who reviews them and how the team handles a failed communication. Buying software does not transfer the hotel’s responsibilities to the provider.
Questions hotel teams ask
Does GDPR require guest consent for every registration field?
No. The lawful basis depends on the purpose and applicable law. Identify mandatory registration processing separately from optional uses, and explain both clearly.
Does GDPR set a three-year retention period for hotels?
No. The three-year rule discussed above comes from Spanish guest registration legislation and has a defined scope. Check the rules for the country where your property operates.
Does online check-in automatically make a hotel compliant?
No. Configuration, staff access, contracts and actual handling of data all matter. Use the checklist when comparing features and plans, then verify the complete workflow before rollout.

