Spanish Hosts: Verify Guests, File SES.HOSPEDAJES in 24 Hours, No ID Copies

Spain hosts: verify guests while meeting RD 933/2021 and file SES.HOSPEDAJES within 24 hours. Avoid passport copies and automate secure check-in with...

Spanish Hosts: Verify Guests, File SES.HOSPEDAJES in 24 Hours, No ID Copies

Acceptable guest ID verification combines minimal lawful data collection with a secure authentication step, such as a digital certificate, payment-method check, or one-time code. Never store full copies of passports or national IDs. Spanish law requires you to collect specific traveler data and report it electronically, but the AEPD draws a hard line against photocopying documents to get there. The sections below walk through the methods, the legal fine print, and the workflow that keeps you compliant without turning check-in into an interrogation.


TL;DR:

  • Using document OCR and MRZ scanning speeds up data entry but requires discarding images after extraction to comply with data minimization laws.
  • Biometric selfie verification provides strong fraud protection but demands explicit guest consent due to GDPR requirements.
  • Automated systems that sync verification data with booking platforms and trigger smart-lock access streamline compliance and improve arrival security.
  • Pre-arrival verification reduces fraud and legal risks by confirming guest identity before check-in, avoiding late disputes or chargebacks.
  • Spanish law explicitly prohibits photocopying IDs, recommending secure forms and telematic verification methods to stay GDPR compliant.

Table of Contents

What Are the Best Methods for Guest ID Verification?

Every verification method trades off speed, cost, and trust differently. Picking the right one depends on your risk profile: a countryside cottage with one booking a week has different needs than a 40 unit portfolio managed by a small team.

Document OCR and MRZ scanning reads the machine-readable zone printed on passports and national ID cards, pulling name, document number, nationality, and expiration date automatically. It speeds up data entry and cuts typos, but running the scan does not require you to keep the image afterward. Extract the fields you need for SES.HOSPEDAJES reporting, then discard the copy.

Document fields extracted while ID copy is discarded

Biometric selfie plus liveness checks compare a guest’s live photo against their ID photo, confirming a real person is present rather than a stolen document. This method adds real fraud protection for high-value bookings, but it also processes biometric data, a special category under GDPR, so it needs a clear legal basis and explicit consent.

Digital certificates and national eID systems (Spain’s DNIe, other EU eIDAS-recognized credentials) offer the highest trust level available for remote verification, since they are cryptographically issued by a government authority. Adoption among everyday travelers is still limited outside certain professional contexts.

Payment-linked checks validate that the name on the booking matches the cardholder or that a small authorization hold clears, giving you a low-friction signal without collecting any document at all.

SMS or email one-time codes confirm the guest controls the contact details on file, catching a large share of casual fraud attempts for almost no cost.

In-person visual checks at arrival remain the simplest option for hosts who greet guests personally. A quick glance comparing the traveler’s face to their ID photo satisfies the intent of verification without any digital tooling at all.

  • Document OCR/MRZ: fast data capture, discard the image after extraction
  • Biometric selfie + liveness: strong fraud defense, needs explicit consent
  • Digital certificate/eID: highest trust, lower guest adoption
  • Payment-linked checks: near-zero friction, moderate assurance
  • SMS/email codes: cheap, catches casual fraud
  • In-person visual match: no tech required, works for owner-operators

Platforms like Airbnb run their own identity verification for certain bookings, but a platform badge does not replace your own legal obligation to collect and report traveler data.

Why Verify Before Arrival?

Verifying identity before a guest gets a key does three jobs at once: it deters fraud, it satisfies your legal reporting duty, and it protects you from disputes you cannot win later. A stolen credit card booking, a party rental disguised as a family trip, or a chargeback filed after checkout all get harder to fight when you have no verified record of who actually stayed.

Pre-arrival verification also shifts the awkward part of the process away from the front door. Nobody wants to stand in a hallway at 11 PM asking a tired traveler for their passport. Front-loading the check into your booking confirmation email means the vast majority of guests never notice it happened.

What Does Spanish Law Require for Guest Registration?

Real Decreto 933/2021 sets the rules every host and hotel in Spain has to follow, and it is more specific than most owners expect.

  1. Collect the required traveler data set: full name, document type and number, nationality, date of birth, and contact information, at minimum.
  2. Keep an electronic register (the “libro de registro de viajeros”) and transmit the data telematically to authorities, generally within 24 hours of check-in.
  3. Retain only what the annexes to the decree specify, for the periods they define, and no longer.
  4. Apply the same data fields and reporting standard to every guest, regardless of nationality or how they booked.

Here is the part that trips up most hosts: the decree tells you what data to collect, but it never tells you to photograph or photocopy an ID. The AEPD has stated explicitly that requesting or storing a copy of a passport or national ID to satisfy RD 933/2021 violates the GDPR principle of data minimization. Its recommended alternatives are a secure form limited to the required fields, plus a telematic verification channel like a digital certificate, payment-method validation, or a security code.

Spanish data protection enforcement has already produced fines against accommodation providers that over-collected ID copies, which makes this more than a theoretical risk. Retention limits matter too: keep records only as long as RD 933/2021 requires, document your legal basis under GDPR for each data point you collect, and give guests a plain-language notice explaining what you collect and why before they arrive.

How Should Hosts Structure a Verification Workflow?

A risk-based workflow beats a one-size-fits-all policy, but “risk-based” only works if you apply it consistently. Define your triggers for a stronger check in advance, in writing, and apply them to every booking that meets them, not just the ones that make you nervous. That consistency matters legally: uneven enforcement is exactly what invites discrimination complaints.

A workable pre-arrival flow looks like this:

  • Send the secure guest form immediately after booking confirmation, requesting only RD 933/2021 fields.
  • Pair the form with one light-authentication step, a payment check or a one-time code, for the majority of standard bookings.
  • Escalate to biometric selfie verification or a digital certificate only for flagged bookings: last-minute reservations, mismatched billing names, or unusually large groups.
  • At arrival, have staff do a quick visual comparison against the ID the guest presents in person, without scanning or photographing it.
  • Never retain a document image once the required fields have been extracted and transmitted.

Write your multilingual messaging so the request feels routine rather than suspicious. A short line like “Spanish law requires us to register your details before check-in, here’s the secure link” does more to reduce friction than any amount of design polish.

Pro Tip: Pre-fill the verification form with booking metadata (name, dates, platform) so the guest only has to confirm and authenticate, not retype information you already have. That single change removes most of the friction guests complain about.

Which Tech Integrations Make Verification Effortless?

The workflow above only survives contact with real guests if the technology behind it removes manual steps rather than adding them.

Calendar and channel synchronization across Airbnb, Booking, and other platforms prevents the classic failure mode: a guest checks in on one platform’s calendar while your verification system still thinks the room is empty. When sync happens automatically, verification triggers the moment a booking is confirmed, not whenever someone remembers to check a spreadsheet.

Automated SES.HOSPEDAJES reporting should pull the verified fields (name, document type and number, nationality, dates of stay) directly from your check-in form and transmit them without a staff member re-typing anything into a government portal. That is where most manual errors, and most missed 24-hour deadlines, actually happen.

  • Channel sync eliminates double bookings and missed verification windows
  • Automated SES reporting removes manual re-entry and deadline risk
  • Smart-lock integration (compatible with brands like Nuki, TTLock, and Yale) releases access codes only after verification completes
  • Digital contracts with e-signatures close the legal loop alongside identity checks
  • EU-based hosting, encryption, and audit logs protect the data you do collect

Smart-lock integrations tie the whole chain together: a guest who completes verification gets their door code automatically, while one who has not finished the process simply does not. That is a stronger enforcement mechanism than any front-desk policy.

Implementation Checklist for Guest ID Verification

Rolling this out does not require a big-bang launch. Work through it in order over a week or two.

  1. Choose your baseline verification method (form plus payment check or code) and define escalation triggers for stronger checks.
  2. Rewrite your pre-arrival messaging and embed the secure check-in link.
  3. Turn on automated SES.HOSPEDAJES transmission and run a test booking to confirm the fields map correctly.
  4. Train arrival staff on visual ID matching and on what to do when a guest lacks a standard document.
  5. Track completion rate, false-positive escalations, and guest complaints about friction for the first month.
MetricWhat it tells you
Verification completion rateWhether your form and messaging are too confusing or slow
Escalation frequencyWhether your risk triggers are too broad or too narrow
SES transmission success rateWhether your automation is actually meeting the reporting deadline
Guest complaints about frictionWhether verification is costing you reviews or bookings

Who Is Behind This Guidance and How Does EuroCheckin Fit?

This guidance reflects standard property-management compliance practice in Spain, written for hosts who need to act on it, not just read about it. A platform built around this exact workflow removes most of the manual risk described above.

  • Automated SES.HOSPEDAJES reporting sends verified guest data directly to authorities, without manual re-entry
  • The traveler registry is hosted on infrastructure inside the European Union
  • Multilingual online check-in forms collect only the fields RD 933/2021 requires
  • Calendar sync across Airbnb, Booking, Vrbo, and other platforms keeps verification tied to real bookings
  • Digital contracts with e-signatures and smart-lock integrations (Nuki, TTLock, Yale) close the loop from verification to arrival
  • Invoice OCR and guest upsells extend the platform beyond compliance into day-to-day operations

A platform combining these pieces means the workflow in this article is not aspirational. It is what running compliant, low-friction check-ins actually looks like when the manual steps are removed.

A Host’s View on What Actually Changes

One property manager who automated pre-arrival verification told us the paperwork disappeared almost overnight. What used to mean chasing photocopies at the front desk became a form guests filled out before they even packed their bags. No-shows on flagged bookings dropped because the system caught mismatched names before check-in day, not after.

The single change that mattered most: pre-filling the verification link with booking details so guests only had to confirm and authenticate. Removing retyping removed almost all the friction.

— Sofía Herrera

Get SES-Compliant Verification Without the Manual Work

Every method in this guide, from payment checks to digital certificates, still leaves you with the same job: collecting the right fields, verifying them, and reporting them to SES.HOSPEDAJES on time, every time. EuroCheckin automates that entire chain instead of leaving it to a spreadsheet and a staff member’s memory.

Eurocheckin

The platform sends automated SES.HOSPEDAJES reports the moment a guest completes online check-in, hosts the registry on EU-based infrastructure, and syncs calendars across Airbnb, Booking, and more than a dozen other platforms to keep every verification tied to a real, current booking. Multilingual check-in links, digital contracts with e-signatures, and smart-lock integrations with Nuki, TTLock, and Yale mean verification and arrival happen in one motion, not two separate headaches. Plans start at $5 per month per property for vacation rentals, or $3 per month per room for hotels, with a free trial to test the workflow on your own bookings before you commit.

FAQ

How Do I Verify a Guest’s ID Before Check-In?

Send a secure pre-arrival form that collects only the fields Real Decreto 933/2021 requires, then confirm identity with one light-authentication step, such as a payment-method match or a one-time code sent by SMS or email. Reserve document OCR or biometric selfie checks for bookings that meet your defined risk triggers, and avoid storing a copy of the ID itself, as the AEPD recommends.

Is Guest ID Verification Safe for Guests’ Data?

It is safe when the process follows data-minimization principles: collect only required fields, use encrypted transmission, host records on EU-based infrastructure, and never retain scanned copies of passports or national IDs longer than the retention period the law allows. The bigger safety risk is over-collection, which is exactly what has triggered enforcement fines against hosts in the past.

What Happens if a Guest Fails or Cannot Complete Verification?

Have a manual fallback ready: a staff member can perform a visual ID match at arrival without scanning or photographing the document, then manually enter the required fields into your registration system. This matters most for guests holding non-standard documents, older passports, or IDs from countries whose formats your automated OCR tool does not recognize.

Does EuroCheckin Handle SES.HOSPEDAJES Reporting Automatically?

Yes. EuroCheckin transmits verified guest data directly to SES.HOSPEDAJES once online check-in is complete, removing the manual re-entry step that causes most missed reporting deadlines. Pricing starts at $5 per month per property for rentals and $3 per month per room for hotels.

Can I Ask Guests for a Photocopy of Their Passport?

No. The AEPD has stated that requesting or storing a photocopy of a passport or national ID to satisfy RD 933/2021 contravenes GDPR data minimization. Collect only the required fields through a secure form and verify identity through an accepted telematic method instead.

Related articles