Yes, you can collect guest ID online. The law does not require you to photograph or scan a passport, only to gather the specific fields listed in Real Decreto 933/2021, verify the guest through a non-invasive method like an SMS code or payment match, and submit that data to SES Hospedajes within 24 hours. Skip storing ID copies unless you have a documented legal reason to keep them.
TL;DR:
- Only the mandatory fields listed in RD 933/2021 need to be collected and reported within 24 hours of check-in, including full name, birth date, nationality, ID type, and contact details.
- Verifying contactability via SMS or email codes and matching payment metadata are sufficient, while storing scanned IDs or facial recognition data is unnecessary and discouraged by data protection authorities.
- The online check-in process should be launched 24 to 48 hours before arrival, with incomplete guests screened on-site, and key access restricted until identity verification is confirmed.
- Compliance can be managed with a simple HTTPS form, a verification code, and secure data storage for three years, avoiding extra data fields that increase breach risks.
- Using platforms that automate and sync guest data with SES Hospedajes reduces errors, saves time, and ensures legal reporting is completed correctly and securely.
Table of Contents
- What Does the Law Actually Require for Online Guest ID Collection?
- What Are the Best Online Methods to Collect and Verify Guest ID?
- How Should Self Check-In and Late Arrivals Work?
- How Do You Set Up a Compliant Online Check-In Process?
- How Do Compliance Platforms Simplify SES Hospedajes Reporting?
- What Property Managers Consistently Get Wrong About Guest ID
- Automate Your SES Hospedajes Reporting With Eurocheckin
- Where to Verify These Rules Yourself
- Sources
- FAQ
What Does the Law Actually Require for Online Guest ID Collection?
Spanish traveler registration law runs on one core principle: collect what’s mandatory, nothing more. RD 933/2021 sets the required fields in its Annex I, and it also requires you to keep an electronic register, report entries telematically, and preserve those records for a set period.
Here’s what you actually need to collect from each adult guest:
- Full name and surname(s)
- Sex, date of birth, and nationality
- Identity document type and number (passport, DNI, or NIE)
- Date and place of issue of that document
- Contact address and, for the lead guest, contact phone or email
You must send that data to SES Hospedajes, the mandatory reporting channel run by Spain’s Ministry of the Interior, within 24 hours of check-in. Every host, manager, or hotel operator has to register as a reporting party before submitting a single record.
The part most hosts get wrong: the AEPD, Spain’s data protection authority, has been explicit that none of this requires you to keep a copy of the identity document itself. An online form collecting only the Annex I fields, paired with a non-biometric verification method, satisfies the law. Storing scanned IDs or running facial recognition checks adds risk without adding compliance value, and the AEPD has flagged this pattern directly in guidance to the hospitality sector.
Retention matters too: once submitted, records need to be kept for a legally mandated period consistent with GDPR requirements, and that storage has to meet GDPR security standards, not sit in a spreadsheet on someone’s laptop.
What Are the Best Online Methods to Collect and Verify Guest ID?
Building a compliant check-in form is less about technology and more about restraint. The AEPD’s own guidance names the acceptable verification paths, and none of them require an ID photo.
- Build an HTTPS form limited to Annex I fields. Anything beyond name, document number, nationality, and the other required data points is extra liability with zero legal benefit.
- Verify contactability with an SMS or email code. This confirms the phone number or email address actually belongs to a real, reachable person, which is a stronger signal than a blurry photo of a passport.
- Cross-check with payment metadata. Matching the last four digits of the card used for booking against the name on the form adds a second authentication layer without collecting new sensitive data, a method Garrigues’ analysis of traveler registration rules specifically recommends over holding onto full card or ID details.
- If you use OCR to speed up data entry, extract the fields and delete the image immediately. Keeping the underlying scan “just in case” is the exact behavior the AEPD has penalized.
- Reserve digital certificates or Cl@ve for higher-risk bookings. Long stays, high-value reservations, or corporate bookings can justify a stronger identity check, but it shouldn’t be your default for every weekend guest.
Pro Tip: Treat every extra data field you collect as a future breach liability, not a compliance bonus. If a field isn’t in Annex I and doesn’t verify contactability, drop it from your form.
How Should Self Check-In and Late Arrivals Work?
Self check-in only works smoothly when the identity step happens before the guest ever touches a lockbox. Send the online check-in link 24 to 48 hours ahead of arrival, bundled with the verification code that confirms the guest actually controls that phone number or inbox.
- Trigger the verification request the moment the booking is confirmed, not the night before.
- Use calendar sync across your booking platforms so you can spot which arrivals still have an incomplete form the day before check-in.
- If a guest shows up without finishing the online process, do a quick visual check against their document on-site and complete the SES submission within the 24-hour window regardless.
- Hold the key or door code until the identity fields are confirmed. A guest who won’t complete a two-minute form is a guest you want to screen more carefully, not less.
Airbnb’s own host resources acknowledge that many hosts are legally obligated to collect this information, which is exactly why building the check-in link into your pre-arrival messaging matters more than any single verification tool.
How Do You Set Up a Compliant Online Check-In Process?
Getting from zero to a working, legal check-in flow takes a handful of concrete steps, whether you manage one apartment or fifty rooms across a hotel.
- Register with SES Hospedajes and get your access credentials before you build anything else.
- Build your HTTPS form around Annex I fields only, and link a clear privacy policy explaining why you collect each one.
- Turn on SMS or email verification, and add payment-match checks if your booking volume justifies the extra step.
- If you use OCR, configure it to purge images right after extraction. Never let “temporary” storage become permanent by default.
- Set your retention policy to three years in encrypted storage, with access limited to whoever actually needs it for reporting.
- Run a full test submission before going live, and write down your lawful basis for each data point you collect, especially if a data protection impact assessment applies to your setup.
Pro Tip: Small hosts can manage this with a simple form and manual upload to SES; once you’re managing several properties, manual entry stops scaling and API-based reporting becomes the far less error-prone route.
How Do Compliance Platforms Simplify SES Hospedajes Reporting?
Manually re-entering guest data into SES Hospedajes for every booking is exactly the kind of repetitive task that invites mistakes, missed deadlines, and the fines that come with them. A platform built specifically around RD 933/2021 removes that risk by mapping form fields to the required Annex I data automatically and submitting reports on schedule.
Eurocheckin’s approach centers on a few specific mechanics that matter for this exact problem:
- Automated, direct reporting to SES Hospedajes with no manual re-entry
- Data hosted on infrastructure inside the European Union
- Multilingual online check-in links that work across Airbnb, Booking, and Vrbo
- Calendar sync across more than a dozen platforms to prevent overbookings
- Integration with smart locks (Nuki, TTLock, Yale) for identity-verified self check-in
- Digital contracts with e-signatures instead of paper forms at the door
What Property Managers Consistently Get Wrong About Guest ID
The instinct to collect more data than the law asks for comes from a reasonable place. Hosts worry that a name and passport number aren’t enough to catch a bad actor, so they add a photo, then a selfie match, then a full document scan “just to be safe.” That instinct is backwards. Every extra field you store is a field you now have to secure, retain correctly, and eventually justify to a regulator if something goes wrong.
The AEPD’s guidance isn’t a loophole to exploit, it’s a genuinely better security posture: verification signals like SMS codes and payment matches confirm a real, reachable person without creating a trove of scanned passports sitting on a server. If you’re building this yourself, test your SES submission on a development account before you ever touch a live booking, and write down exactly why you collect each field you ask for. That single habit, documenting your method, is the difference between a smooth SES Hospedajes integration and a scramble when an inspector asks a question you can’t answer cleanly.
— Sofía Herrera
Automate Your SES Hospedajes Reporting With Eurocheckin
Building and maintaining a compliant check-in form, verification flow, and SES submission pipeline yourself takes real engineering time, time most hosts and small hotel teams don’t have to spare. The platform sends guest data to SES Hospedajes in line with RD 933/2021 and GDPR, stores data on EU-based infrastructure, and syncs calendars across multiple booking platforms to help avoid double bookings while managing compliance.

The platform connects to smart locks and supports digital contracts with e-signatures, enabling self check-in and prior guest agreement to house rules. Plans start at €5 per month per accommodation for vacation rentals or €3 per month per room for hotels, and if you’d rather have the SES registration itself handled for you, that service starts at €79 one-off per property. Start a free trial today and see your first guest report go out automatically.
Where to Verify These Rules Yourself

Don’t take any compliance claim at face value, including this one. Read the consolidated text of RD 933/2021 on the BOE, the AEPD’s guidance note on identity document copies, and the SES Hospedajes page on the Interior Ministry’s site before finalizing your own process.
Sources
- Real Decreto 933/2021 (consolidated) — BOE
- AEPD note on requesting copies of identity documents in hospitality (guidance PDF)
- SES Hospedajes — Ministry of the Interior (Spain)
FAQ
Is It Legal to Collect Guest ID Online Instead of In Person?
Yes. The AEPD has confirmed that an online form collecting only the fields required by RD 933/2021, combined with non-invasive verification like SMS codes or payment matching, is sufficient. You do not need to see a physical ID in person to comply.
Do I Need to Keep a Copy of the Guest’s ID Document?
No, and the AEPD actively discourages it. Copies or photographs of ID documents aren’t necessary for compliance with RD 933/2021, and storing them unnecessarily increases your data breach exposure without any legal upside.
How Fast Do I Need to Report Guest Data to SES Hospedajes?
Guest data must reach SES Hospedajes within 24 hours of check-in. If a guest completes online check-in in advance, you can submit early; if they arrive without finishing the process, you still have the same 24-hour window from arrival.
How Long Do I Have to Keep Guest Records?
Traveler registration records must be retained for three years under RD 933/2021, stored securely and with access limited to people who need it for reporting or audit purposes.



