Compliance

Hospitality inspection: the unsigned guest report you cannot explain

A host was asked for traveller reports. One had no signature — data typed by hand, ID never shown. Why OCR without storing the document is lawful, and why WhatsApp can cost you the business.

HT

HazCheckin Team

HazCheckin

5 min read
Person signing an official document at a desk

For hosts

The guest checks in. You get the traveler report done.

Create a free account

The call comes on a Tuesday. A hospitality inspection. They want the traveller reports for recent stays. The host opens the dashboard, downloads one, and finds this: the report has no signature. They typed the data themselves. The guest had refused to let the camera read the document. To get it over with, the host copied what was on the booking, did not ask to see the ID and did not ask anyone to sign.

The data does not add up. The inspectors can see it. The property now has a problem.

This is not a hypothetical. It happened to a customer of ours. The trap is always the same: you treat the report as paperwork, and the day someone asks for it you discover it was the evidence.

What the inspection is actually looking at

Royal Decree 933/2021 does not ask for a spreadsheet of names. It asks for a documentary register: accurate data, filed with SES.HOSPEDAJES, and a report the traveller has accepted. When they open the PDF and there is no signature, they are not looking at a missed admin step. They are looking at a record nobody has owned.

If the surname, document number or date of birth also fail to match the person who stayed, the tone changes. A report typed from memory — or copied from Booking — proves nothing. It only proves that somebody, at some point, typed something.

That is exactly what a manual form with no verification produces: a document that looks like a guest report and cannot survive an inspection.

The guest refused OCR. That does not let you invent the report

In this case the guest did not want to photograph the document. That happens. Online check-in is not an interrogation, and a scan should not be a condition of the stay.

What is not acceptable is the shortcut: filling the fields yourself, never seeing the document, never collecting a signature and closing the booking. If the guest declines the automatic read, the lawful path is the old one:

  1. They show the document in front of you. Looking at it is fine. Keeping a photo is not.
  2. You check that the report matches the document.
  3. They sign the report. No signature, no report you can produce.

Skipping those three steps to “avoid a scene” is how you get the scene later. The problem does not show up on check-in day. It shows up on inspection day.

OCR is not a photocopy. WhatsApp is

Two things the AEPD has kept apart.

Asking for a copy of the ID is unlawful. Photocopying it, scanning it “for the file”, or asking the guest to send it on WhatsApp or email is requesting a copy. The document carries more data than SES.HOSPEDAJES needs — photograph, CAN, expiry date, parents’ names — and keeping it breaches GDPR data minimisation. The AEPD has already warned properties for asking for an ID over WhatsApp for the traveller register, and fines for copying the document go up to €100,000. One procedure is enough to sink a holiday rental.

Reading the document to extract only the report fields, without keeping the image, is not that. It is the digital equivalent of looking at the ID and writing down the number. OCR captures the document for a moment, fills name, document type and number, date of birth and nationality — what Annex I of the decree requires — and discards the image. No folder of IDs. No photo sitting in a chat. Verified data, not typed data.

That is the difference that holds up in an inspection: the report comes from the document, not from the booking platform. And the guest’s signature says those data are theirs.

Be wary of check-in that is only a form

Some tools send a link, the guest types whatever they like and you submit to SES.HOSPEDAJES. Fast. And empty of proof. Anyone can enter another passport number. Nobody has seen the document. Nobody has signed. The day the Guardia Civil or the police ask for the report, you have a PDF with fields. You do not have a register.

If you still use a manual form — the guest has no camera, they refused OCR, they arrived late — at least make them show the document. Check it. Get a signature. The report nobody has seen is the one you cannot defend.

And do not replace that check with “send me the ID on WhatsApp”. That verifies no one: the AEPD says in so many words that a photo sent by messenger does not prove who sent it. It also leaves a copy of the document on your phone, which is exactly the processing the Agency treats as excessive.

How to satisfy both the inspection and the AEPD

You do not have to choose between a report that survives an inspection and a data practice that survives the AEPD. The flow that does both is narrow, and it is the one we built into HazCheckin:

  • OCR of the document, no archive. The guest holds their ID or passport to the camera. The system reads the traveller report fields and does not keep the image. More on how we verify identity without turning your database into an album of documents.
  • The traveller’s signature. The report is not accepted until the guest signs it. On inspection day you download a signed document, not an anonymous form.
  • Filing with SES.HOSPEDAJES from the document’s data, not from the booking platform. The SES.HOSPEDAJES guide covers deadlines and codes; check-in covers that those data are true.
  • If the guest cannot or will not use the camera, registration is finished in person: document in sight, data checked, signature. Never WhatsApp. Never “I’ll fill it in myself”.

The inspection does not ask whether check-in was convenient. It asks whether the report belongs to the person who stayed. OCR done properly — no retained document, used only for SES.HOSPEDAJES — is how you can say yes. A blind form is how you have no answer.

The full flow is in HazCheckin’s features. The report you cannot show is the one you should not have filed.

Back to the blog

Related articles

GDPR compliant

We comply with the European Union's General Data Protection Regulation (GDPR). Your data — and your guests' data — stays safe.