Your hotel privacy notice must name the data controller, state a separate legal basis for guest registry reporting versus marketing, disclose a retention period for registry data and a required transmission window to SES.HOSPEDAJES, and confirm that you never keep copies of guests’ identity documents. Miss any of these, and you’re exposed to an AEPD complaint, not just a bad guest experience.
TL;DR:
- Hotels must clearly distinguish the legal basis for guest registry reporting under Real Decreto 933/2021 from marketing consent, ensuring separate disclosures and opt-ins.
- Retention periods mandated by law are three years for registry data, with other records like billing following fiscal regulations and marketing data lasting only as long as consent is valid.
- Photocopying or scanning guest IDs is illegal under data minimization principles, but verifying identity through visual checks and logging verification proves lawful.
- Guest data processors, such as property management systems and payment gateways, require contracts that specify processing scope, security measures, hosting location, and retention schedules.
- Automated digital check-in tools help hotels comply with transmission deadlines, reduce errors, and prevent liability from storing ID images or scans.
Table of Contents
- What a Hotel Privacy Notice Must Include
- How GDPR and Real Decreto 933/2021 Work Together
- A Drafting Checklist and Sample Clauses You Can Adapt
- Verifying Guest Identity Without Keeping ID Copies
- What Your Notice Should Say About Processors and Contracts
- Handling a Data Breach and Talking to the AEPD
- Why Automated Check-In Tools Reduce Compliance Risk
- The Gap Between a Compliant-Looking Notice and an Actually Compliant One
- Put Your Privacy Notice Into Practice With Eurocheckin
- Sources
- FAQ
What a Hotel Privacy Notice Must Include
A compliant hotel privacy notice reads like a checklist a guest can actually verify, not a legal disclaimer nobody reads. Every clause needs to answer a specific question: who holds the data, why, for how long, and what a guest can do about it.
At minimum, publish these elements:
- Controller identity and contact details. Full legal name, address, and email, plus a Data Protection Officer contact if you’ve appointed one.
- Purpose-by-purpose legal basis. Separate the legal obligation to report guest data under Real Decreto 933/2021 from the consent you need for marketing emails or loyalty programs.
- Recipients and processors. Name the categories involved, such as SES.HOSPEDAJES, your property management system, and your payment gateway, and state where the data is hosted.
- Retention periods per purpose. Registry data stays three years under the Real Decreto 933/2021 text; billing records follow fiscal rules; marketing data lasts only as long as consent stands.
- Rights and contact steps. Give guests a working email or form for access, rectification, erasure, and objection requests, plus a link to file a complaint with the Spanish Data Protection Agency if they’re unsatisfied.
Skipping the purpose-by-purpose breakdown is the single most common gap reviewers find. Guests, and regulators, want to see registry compliance and marketing consent treated as two entirely different things, not folded into one vague sentence about “improving your stay.”
How GDPR and Real Decreto 933/2021 Work Together
Real Decreto 933/2021 sets the operational rules: hotels must collect a defined set of guest fields, transmit them electronically within the required timeframe in most cases, and retain the registry record for a period established by law, according to the consolidated BOE text. That obligation exists independently of guest consent. Under GDPR Article 6.1.c, it’s processed on the basis of “legal obligation,” which means you don’t ask permission to send data to SES.HOSPEDAJES. You simply disclose that you do it and why.
Marketing sits on entirely different legal ground. Sending a follow-up email about a returning-guest discount requires a genuine opt-in, tracked separately from the registry data you’re required to collect. Treating both under one generic consent checkbox is the mistake compliance reviewers flag most often, according to LetsLaw’s analysis of common hotel data protection pitfalls.
Here’s where the two frameworks create friction: Real Decreto 933/2021 tells you what to collect, but GDPR’s minimization principle limits how much you keep. The AEPD’s guidance on lodging registration resolves this directly. Collecting the required fields is lawful. Photocopying or scanning a guest’s ID card to “prove” you collected them correctly is not, because the registry form itself already satisfies the legal requirement without a document image attached.

A Drafting Checklist and Sample Clauses You Can Adapt
Structure your notice in two layers: a short notice posted at reception or in your booking confirmation, and a fuller version on your website covering every processing activity in detail. Guests should be able to grasp the essentials in fifteen seconds and dig deeper if they want to.
- State the registry legal basis plainly. Something like: “We collect your identification data to comply with our legal obligation under Real Decreto 933/2021, and we transmit it to SES.HOSPEDAJES within the required timeframe.”
- Separate the marketing opt-in. “If you’d like to receive offers and updates, check this box. You can withdraw consent at any time.”
- Name your processors. “Your data may be shared with our property management system, payment processor, and the Spanish Ministry of Interior via SES.HOSPEDAJES, all under contractual data protection safeguards.”
- Publish a retention table. Registry data: 3 years. Billing records: per fiscal requirements. Marketing data: until consent is withdrawn. Security camera footage: typically 30 days unless a specific incident requires longer.
Pro Tip: Keep an internal log of which template clause version is live on your site and when it changed. If the AEPD ever asks for evidence of transparency, dated version history is worth more than a single current snapshot.
A passenger-data collection template built around the official registry fields can help you avoid collecting extra data your notice doesn’t cover.
Verifying Guest Identity Without Keeping ID Copies
The AEPD has been explicit: storing a photocopy, scan, or photograph of a guest’s ID document breaches the data minimization principle, even though checking that ID visually at check-in is entirely lawful. The distinction matters because plenty of hotels still default to scanning a passport “just in case,” which creates liability without any registry benefit.
For online or remote check-in, acceptable alternatives include matching the guest’s payment method to their booking, sending a one-time verification code by phone or email, or using a digital certificate, according to guidance from Mes Advocats on AEPD verification standards.
- Collect only the fields Real Decreto 933/2021 requires, nothing extra.
- Log proof of verification (a timestamp, a matched payment, a confirmed code) instead of an image.
- Train reception staff to check the physical ID and record that the check happened, not the document itself.
Pro Tip: If a guest asks why you’re not photocopying their passport, tell them straight: it’s the law, not a shortcut. Guests generally respond well to hearing you’re protecting their data, not being careless with it.
What Your Notice Should Say About Processors and Contracts
Any supplier touching guest data, your PMS, channel manager, or payment gateway, needs an Article 28 processor contract unless it operates as an independent controller. Your notice should reference the relationship with your data processors including details on scope of processing, security measures, audit rights, hosting location, and mention whether data is hosted within the EU. It should also publish retention schedules by purpose and disclose applicable international data transfer mechanisms clearly.
Periodic audits of data flows between your booking engine, PMS, and payment processor catch mismatches before an AEPD inspector does, a practice compliance commentary consistently recommends.
Handling a Data Breach and Talking to the AEPD
- Contain and assess within hours, not days. Document what happened, what data was exposed, and how many guests are affected.
- Notify the AEPD within 72 hours of becoming aware of a breach that risks guest rights, using the agency’s online reporting form.
- Notify affected guests directly if the breach carries high risk, such as exposed payment or ID data.
- Keep evidence ready, including access logs, deletion certificates, and verification records, in case of an inspection or complaint.
Reference this process briefly in your notice so guests know a procedure exists.
Why Automated Check-In Tools Reduce Compliance Risk
Manual registry entry is where most transmission delays and data errors happen. Hotels that automate the check-in form and identity verification step before arrival consistently meet the 24-hour SES.HOSPEDAJES deadline, according to DLA Piper’s commentary on Royal Decree 933/2021. Automation also makes the “no ID copies” rule easier to enforce, since the system records that verification happened rather than storing an image.
A Madrid hotel case study shows how shifting to digital registration cut reporting errors significantly. If you haven’t already, the next steps are straightforward: update your notice’s legal basis language, test your online form against the registry field list, and confirm your processor contracts cover EU hosting.
The Gap Between a Compliant-Looking Notice and an Actually Compliant One
Most hotel privacy notices I’ve reviewed look fine on the surface. They have a controller name, a retention line, a rights section. What they usually miss is the separation between legal-obligation processing and consent-based processing, and that gap is exactly what the AEPD’s €75,000 enforcement action punished: not the registry collection itself, but excessive ID images and vague information about why data was being processed.

The conventional advice, “just publish a privacy policy,” undersells the actual risk. A notice that lumps registry reporting and marketing into one generic consent clause looks compliant to an untrained eye and fails the moment an inspector asks a specific question. The fix isn’t more legal language. It’s precision: naming each purpose, its basis, and its retention period separately, and matching your actual data collection practices to what the notice claims.
If you prioritize one thing first, make it this: audit whether your front desk or booking form still requests ID photocopies. That single habit, more than any wording choice, is what turns an otherwise solid notice into a liability.
— Sofía Herrera
Put Your Privacy Notice Into Practice With Eurocheckin
A written notice only holds up if your actual data handling matches it, and that’s where manual registration usually breaks down. There are platforms that automate guest data transmission to SES.HOSPEDAJES within the required window, build a fully digital registry book, and verify guest identity without storing ID photos or scans, helping ensure that the practices described in your notice match your front desk’s actions.

The platform’s online check-in and registry system logs verification events instead of documents, keeps registry and marketing data on separate tracks, and hosts everything on infrastructure inside the European Union. If your current process still relies on photocopied passports and spreadsheets, consider testing automated, compliant check-in solutions to improve your data handling.
Sources
- BOE-A-2021-17461 Real Decreto 933/2021
- AEPD note regarding requests for copies of identity documents in lodging
FAQ
Is a Privacy Notice Legally Required for Hotels?
Yes. GDPR requires every business processing personal data, including hotels, to inform guests about how their data is used, and the Real Decreto 933/2021 adds specific transparency obligations around registry data.
Why Am I Receiving a Privacy Notice When I Book a Hotel Room?
You receive one because the hotel is legally obligated to disclose how it processes your registration data for SES.HOSPEDAJES reporting and, separately, how it handles any data used for marketing or loyalty programs.
What Is the 15-5 Rule in Hotels?
There’s no established rule tied to hotel data protection or Spanish registry law. If you encountered this term elsewhere, it likely refers to an unrelated hospitality or service-industry practice, not a privacy or GDPR requirement.
Can a Hotel Restrict Visitors to Guest Rooms?
Yes, hotels can set visitor policies for security and liability reasons, but that’s a property management rule, not a data protection matter. It has no bearing on what must appear in your privacy notice.
Can a Hotel Keep a Copy of My ID?
No. The AEPD has clarified that hotels should verify identity visually or through alternative methods like payment matching or one-time codes, but should not retain photocopies, scans, or photos of identity documents.



