In short: In tourism, most data is collected at booking and at check-in. Two mistakes keep coming up: copies of passports and IDs kept for no reason, and marketing sent without consent. Simple rules: ask for and keep only what you need, ask for clear consent for newsletters, and have contracts with the booking and payment platforms that touch your customers' data.
Tourism lives on data about people. A booking means a name, a phone number, an email, sometimes an ID document, a card and occasionally intimate details: that you are coming for your honeymoon, that you have an allergy, that you need an accessible room. These are things a guest gives you so they have a good stay, not so they end up somewhere else.
The good news is that a hotel or a guesthouse does not need a team of lawyers to be in order. It needs a few healthy habits, repeated at every booking.
What data tourism collects
More than it seems at first, and from more people.
- At booking: name, contact, payment details, sometimes preferences.
- At check-in: verifying the ID document and filling in the guest register required by law.
- Data about other guests: when someone books for a family or a group, you end up with data about people who are not even there.
- More sensitive data: a food allergy or the need for an accessible room are health data, which call for more care.
The mistakes that keep repeating
In tourism, problems do not come from sophisticated attacks, but from comfortable habits.
- Copies of passports and IDs kept in a drawer at the front desk or, worse, sent over WhatsApp and email. Most of the time you do not even need a copy, it is enough to check the document and note the data.
- Guest lists on an Excel sheet everyone can see, or left in plain sight at reception.
- A newsletter without consent, sent to everyone who ever made a booking.
- Card details written on paper or saved in a file, instead of going through a secure payment system.
Marketing and newsletters
The right offer, sent to the person who wants to receive it, is perfectly fine. The problem starts when you skip the consent.
- For marketing emails you generally need the guest's consent, given clearly and separately, not hidden in a mandatory checkbox at booking.
- Every message has a simple way to unsubscribe, one that actually works.
- Data left to make a booking does not automatically turn into permission to send adverts.
- You do not buy address lists. You do not know how they were collected, so you cannot rely on them.
Payments and booking systems
Almost no one works alone in tourism anymore. You use a booking engine, a property management system (PMS), the big booking platforms, a payment processor. All of them touch your customers' data, and that means responsibility.
- Payments go through a secure system, not through card details written by hand. The processor handles the hard part of the security.
- Providers that keep or process your data need a contract that clearly states what they do with it and how they protect it.
- The responsibility stays with you. If a provider leaks the data, you are still the one who notifies the customers and the authority.
What a hotel or agency can do in practice
- Less data, not more. You do not make useless copies, you do not keep what you do not need. What does not exist cannot be lost.
- Role-based access. Reception sees what it needs for check-in, marketing only sees who agreed to receive offers.
- Retention rules. How long you keep a booking, an invoice, a guest list, and when you delete them.
- Contracts with vendors. With the booking platform, the payment one, the marketing firm.
- Trained people. Reception and the team taught how to ask for a document without making a useless copy and how to send a guest list safely.
- Basic security. Passwords, encryption on laptops, a separate Wi-Fi for guests and for internal systems.
At INFOSHARE we help hotels, guesthouses and travel agencies put all of this in place, simply and in plain terms for the team: from GDPR compliance and the DPO role to information security. And the records sit in one place, in the askGDPR platform.
Frequently asked questions
Can I make a copy of the guest's ID or passport at check-in?
Most of the time, you do not need a copy. At check-in you have to verify identity and fill in the data required by law in the guest register, but that means writing down the data, not making and keeping a photocopy of the document. A pile of passport copies kept at the front desk is exactly the kind of thing that becomes a big problem if it leaks.
Can I send offers and newsletters to guests who have stayed with me?
Yes, but with rules. For email marketing you generally need the guest's consent, given clearly and separately, not hidden in a mandatory checkbox. Every message must have a simple way to unsubscribe. You cannot buy address lists, and you cannot send offers to someone just because they left their details to make a booking.
Am I responsible if the booking platform leaks my customers' data?
As a rule yes, at least in part. If you use a booking engine, a PMS or a marketing platform, that provider processes your customers' data on your behalf. You need a contract that clearly states what it does with the data and how it protects it. If data leaks through their fault, you are still the one who has to notify the customers and the authority.
Does a small guesthouse really have to deal with GDPR?
Yes. A guesthouse with a few rooms works with names, contact details, ID documents and payments, just like a large hotel, only at a different scale. The basic obligations are the same: you use data for a clear purpose, keep it safe, do not keep more than you need and can prove it. The volume is small, but the rules do not change.
Want compliant tourism, with no hassle for reception?
We set the rules from booking to check-out: what data you ask for, how long you keep it, the marketing consent and the contracts with your platforms.