Yes, automated self check-in is permitted. It must capture the required guest data and transmit it to SES.HOSPEDAJES within the legal timeframe while producing a verifiable audit trail. That means Real Decreto 933/2021 compliance, correct field capture, identity verification (including DNI Digital), and a system that talks to your PMS in real time. Skip any of those, and unsynced calendars or incomplete records turn into overbookings, failed transmissions, or fines.
TL;DR:
- Automated self check-in must transmit guest data to SES.HOSPEDAJES within 24 hours of specific triggers, including reservation confirmation, stay start, or cancellations.
- The system must verify guest identity using document photo OCR and DNI Digital support to meet legal and inspection standards.
- All data, including signed house rules and guest details, must be stored with a verifiable audit trail for three years, ensuring accuracy and proper correction procedures.
- Real-time integration via a bidirectional API is essential to prevent overbookings, with transmission latency under one minute and credential issuance within five seconds.
- Non-compliance risks fines, operational disruptions, and increased regulatory scrutiny, making automation and reliable data handling critical for legal and financial security.
Table of Contents
- What Real Decreto 933/2021 and SES.HOSPEDAJES Require
- How Do You Build a Compliant Self Check-In Workflow?
- Which Technical Requirements Should You Demand in a Vendor Demo?
- Operational Rules When Automation Breaks Down
- Handling Exceptions Like Missing IDs and Minors
- How Do You Correct Guest Data After Transmission?
- What Happens If You Don’t Comply With Self Check-In Rules?
- Data Security Practices Beyond GDPR Basics
- EuroCheckin’s Perspective: Matching the Checklist to a Working Platform
- Try EuroCheckin With Your Own Reservation Data
- Sources
- FAQ
What Real Decreto 933/2021 and SES.HOSPEDAJES Require
The obligation applies broadly. Any professional hospitality operation, plus many non-professional rentals that function like short-term lodging, must register and transmit guest data under Real Decreto 933/2021. It doesn’t matter if you manage one apartment or a 40-room hotel. If you host paying guests overnight, the rule applies to you.
Data transmission to SES.HOSPEDAJES has to happen within 24 hours of specific triggering events, according to Ministry of Interior guidance: the reservation being confirmed, the guest’s contract taking effect, the start of the actual stay, or a cancellation. Each of those moments resets the clock, so a system built for one trigger but not the others creates a compliance gap the moment a guest cancels or rebooks last minute.
The required fields come straight from the decree’s annexes. At minimum, you need:
- Reservation or booking identifier
- Full legal name of every guest, including minors staying in the unit
- Document type and number (passport, DNI, or NIE)
- Nationality
- Date of birth
- Contact information (phone, address)
- Arrival and departure dates
The BOE’s consolidated annexes spell out the exact format for each field, and getting the document type field wrong is one of the more common rejection reasons hosts run into when they submit manually.
Digital registers must be retained for three years, and you’re responsible for the accuracy of every record, even if a guest mistypes their own passport number during self check-in. That responsibility doesn’t transfer to the platform you use. It stays with the property.
On the GDPR side, keep it simple: collect only what the annexes require, tell guests clearly why you’re collecting it, and don’t repurpose the data for marketing without separate consent. A self check-in workflow that asks for more than the legal minimum invites scrutiny it doesn’t need.
How Do You Build a Compliant Self Check-In Workflow?
A compliant workflow follows a specific order. Skip a step or run them out of sequence, and you either lock out a legitimate guest or issue access to someone who was never verified.
- Send the pre-arrival link only after confirming reservation state. Pull the reservation status directly from your PMS before the check-in form goes live. A canceled or disputed booking should never receive an active check-in link.
- Capture identity through document photo plus OCR, with DNI Digital support built in. The 2026 rollout of DNI Digital changes how documents present themselves to scanners, and a platform still reading only physical cards will start turning away a growing share of Spanish guests. Validate every required field before the guest can move to the next step.
- Run the e-signature step for house rules and required disclosures. Attach the signed document to the guest record permanently, not as a separate file that can get disconnected from the reservation.
- Transmit to SES.HOSPEDAJES and log proof of send. This isn’t optional and it isn’t a “send when convenient” step. Log the timestamp, the payload, and the response code so you have evidence if an inspector asks.
- Issue the access credential only after verification and transmission both succeed. Mobile key, PIN code, or locker combination, whichever your smart lock supports, should never activate before those two steps clear.
- Authorize payment using an auth-then-capture pattern. Authorize the card before arrival, capture at check-in, and build a retry-and-notify flow for declined cards so a payment failure doesn’t silently block a paying guest.
Pro Tip: Test your workflow with a deliberately incomplete reservation, one missing a document number or a mismatched date range, before you trust it with real guests. If the system issues a credential anyway, you’ve found your compliance gap before an inspector does.
Manual entry into SES.HOSPEDAJES still works, but guides comparing manual and automated flows consistently show automated transmission cuts errors and staff time, particularly for hosts managing more than a handful of units.
Which Technical Requirements Should You Demand in a Vendor Demo?
Ask for a bidirectional, synchronous API connection between the check-in portal, your PMS, and your channel manager. Anything less turns into manual reconciliation eventually, and industry architecture guidance from 2026 treats one-way or batch-delayed syncing as the leading cause of overbookings in properties that thought they’d automated the problem away.
During a demo, watch for these nine data groups syncing back to your PMS in real time:
- Guest identity records
- Signed documents (contracts, house rules)
- Payment authorization state
- Credential IDs (mobile key, PIN, locker code)
- Reservation status
- Room or unit assignment
- Guest preferences
- Transmission timestamps
- Audit and access events
Latency matters more than most buyers realize going into a demo. Availability sync should complete in under a minute, and credential issuance should take under five seconds once verification clears. Anything slower means a guest standing at the door waiting on a PIN that hasn’t arrived yet.
Confirm DNI Digital and OCR support explicitly, and ask what accuracy rate the vendor logs for document validation. A system that can’t demonstrate an audit trail beyond a generated PDF will not satisfy an inspection, since authorities now expect access events tied directly to verified guest identities, not a static file sitting in a folder.
Check smart-lock compatibility across mobile key APIs, PIN modules, and locker code systems, and confirm each access event writes back to the guest record automatically. Finally, ask about webhook retry logic. A transmission that fails silently once is a bug. A transmission that fails silently every time your internet blips for ten seconds is a liability.
Operational Rules When Automation Breaks Down
Automation fails sometimes. A guest’s phone dies before they complete pre-arrival check-in, or your API connection drops for twenty minutes. Your policy needs to survive that.
- Offer a backup path: an on-site kiosk, a supervised front-desk document scan, or a scheduled in-person verification slot.
- Never issue access credentials without verified data, full stop, even under guest pressure or a tight arrival window.
- Log every fallback incident with a timestamp and the reason automation didn’t complete, so your audit trail stays intact.
- Assign a specific staff role to catch SES.HOSPEDAJES transmission failures and escalate them the same day, not at week’s end.
- Give staff a short script for guests confused by the check-in link, since most abandoned check-ins come down to guests not understanding what’s being asked of them.
Pro Tip: Build your fallback into the same guest record as the digital workflow, not a separate spreadsheet. Inspectors don’t care which system verified the guest, only that the verification happened and it’s documented.
Handling Exceptions Like Missing IDs and Minors
Guests without acceptable identification are not a rare edge case. Someone loses a passport mid-trip, or a guest’s only document is expired. Your policy should define, in advance, which document types you’ll accept as a fallback (a driver’s license with photo, for example) and require a supervised verification rather than letting the online form wave the field through blank.
Minors present a different challenge because the annexes still require their name and basic details, but a minor typically can’t complete an identity verification flow themselves. The practical fix: collect the minor’s information through the adult guest completing the primary check-in, using the minor’s passport or national ID photo for the document fields, while the adult’s signature covers the accepted terms.
Never let a self check-in flow silently skip a guest because they don’t fit the standard document capture path. Build an explicit exception queue instead, one that flags the reservation for manual review rather than letting it complete with missing fields. A system with a proper audit trail should log exactly which guests were verified through the standard flow and which went through manual review, and why.

Group bookings compound this. If four guests share one reservation and only one completes the online form, don’t issue access credentials to the other three until their fields are verified too, even if it means a short delay at arrival.
How Do You Correct Guest Data After Transmission?
Errors happen even in careful workflows. A guest mistypes a passport number, or OCR misreads a document field during a rushed check-in. SES.HOSPEDAJES doesn’t treat a submitted record as unchangeable, but correcting it requires a deliberate process rather than a quiet edit.
Start by identifying the exact field that’s wrong and cross-checking it against the original document image, not the guest’s memory. Most platforms retain the source photo specifically so you can verify what should have been entered.
Submit a correction through the same telematic channel used for the original transmission, referencing the original submission so the record updates rather than duplicates. Duplicate records create their own inspection headache, since an auditor comparing your PDF-era log against your PMS shouldn’t find two entries for the same guest and stay.
Log the correction itself: what changed, when, and who caught the error. That log becomes part of your three-year retention requirement under Real Decreto 933/2021, and an inspector reviewing your records benefits from seeing that you catch and fix errors rather than assuming your first submission was always clean.
If the error affected a credential already issued (wrong dates triggering early lockout, for example), fix the underlying reservation record first, then re-issue the credential rather than manually overriding the lock. A manual override that isn’t reflected in the guest record is exactly the kind of gap an audit trail is supposed to prevent.
What Happens If You Don’t Comply With Self Check-In Rules?
Non-compliance carries real financial exposure, and the penalties scale with severity and repetition. Spain’s regulatory framework treats failure to register guests, late transmission, and incomplete or inaccurate data as separate violations, each carrying its own risk profile. A breakdown of typical fine ranges shows how these penalties can escalate quickly for repeat or willful violations, which is exactly why relying on a system prone to silent transmission failures is a poor bet financially, not just operationally.
Beyond the fine itself, non-compliance creates secondary exposure. Properties under investigation for guest registration failures sometimes face broader scrutiny of their licensing status, tax reporting, and platform listings. Airbnb, Booking, and Vrbo have all faced regulatory pressure in Spain to verify that listed properties meet local registration obligations, and a documented compliance failure can jeopardize a listing beyond the fine itself.
The safest posture treats every missed transmission as an incident worth investigating immediately, not a batch job to fix at month’s end. A single missed 24-hour window is a correctable mistake if caught fast. A pattern of missed windows across multiple guests starts to look, to an inspector, like a systemic failure rather than an isolated glitch, and that distinction shapes how penalties get applied.
Data Security Practices Beyond GDPR Basics
GDPR sets the legal floor, but the properties that avoid breaches go further than the minimum. Store identity document images and full guest records on infrastructure that sits within the European Union, since data residency affects both your legal exposure and how quickly you can respond to a regulator’s request.
Encrypt guest data both at rest and in transit, and limit staff access to guest records on a need-to-know basis. A cleaning contractor doesn’t need to see a guest’s passport number to know which unit to service.
Set a deletion schedule that runs past your three-year SES.HOSPEDAJES retention requirement but doesn’t run indefinitely. Keeping guest identity documents forever “just in case” turns a compliance asset into a liability the moment your systems get breached.
Audit who accessed guest records and when, not just who submitted them. If a former employee’s login can still pull passport scans six months after they left, that’s a gap worth closing before it becomes a headline. Finally, build a breach notification plan before you need one. Spain’s data protection authority expects notification within 72 hours of a breach becoming known, and scrambling to figure out the process during an actual incident wastes hours you don’t have.
EuroCheckin’s Perspective: Matching the Checklist to a Working Platform
Every requirement above maps directly to a workflow we built specifically because manual compliance doesn’t scale past a handful of units. EuroCheckin automates SES.HOSPEDAJES transmission the moment a guest completes verification, keeps a 100% digital register hosted on EU infrastructure, and ties smart-lock credentials (Nuki, TTLock, Yale) directly to verified guest records rather than issuing access blindly.
Calendar synchronization across major platforms can help prevent the overbooking risk that unsynced systems create. E-signature and invoice OCR can round out workflows involving pre-arrival capture, identity verification, transmission, and credential issuance applied to actual reservations rather than a demo environment.
— Sofía Herrera
Try EuroCheckin With Your Own Reservation Data
You can run this exact checklist against your own bookings before deciding on anything. EuroCheckin lets you test SES.HOSPEDAJES transmission, DNI Digital handling, and credential issuance with real reservation data, not a sanitized demo account, so you see how your specific property type and guest mix behave under the workflow.

Compare that against manually re-entering guest data into SES.HOSPEDAJES every night, or trusting a check-in tool that only generates a PDF and hoping an inspector never asks how it’s tied to your access logs. If you manage several units, the manual route costs hours weekly that automated transmission removes entirely. Review the factors that matter when choosing check-in software, then request a demo or start a free trial to see how EuroCheckin handles a reservation from confirmation through credential issuance, starting at around $5/month per accommodation.
Sources
The legal backbone for everything above comes from Real Decreto 933/2021 and Ministry of Interior guidance on SES.HOSPEDAJES. For implementation detail, the SES Hospedajes registration guide and DNI Digital identification note cover the practical gaps the decree itself doesn’t spell out.
- Real Decreto 933/2021 (BOE)
- Ministerio del Interior — SES.HOSPEDAJES information
- Integration check-in digital ↔ PMS architecture (HotelTech Insight) — 2026-05-14
- Legaltech note on DNI Digital and identification in procedures (EciJA)
FAQ
Is Self Check-In Legal for Vacation Rentals in Spain?
Yes, as long as the system captures every required field from Real Decreto 933/2021 and transmits it to SES.HOSPEDAJES within 24 hours of the triggering event.
How Long Must I Retain Digital Guest Registration Records?
Three years, per the retention requirement set out in Real Decreto 933/2021, and the responsibility for accuracy stays with the property regardless of which platform handles the transmission.
What Happens if I Miss the 24-Hour Transmission Window?
A single missed window is usually correctable if caught immediately, but repeated late transmissions expose you to escalating fines and increased scrutiny of your broader compliance status.
Do I Need to Support DNI Digital in My Check-In System?
Yes. The 2026 DNI Digital rollout changes how identity documents present to scanners, and a system that only reads physical cards will increasingly turn away Spanish guests.
Can I Use a Kiosk Instead of Online Check-In?
Yes, a supervised kiosk or reception scan is an acceptable capture method as long as it verifies the same required fields and produces the same auditable transmission record as an online form.



