GDPR checklist for hoteliers.
A pragmatic checklist written by hoteliers for hoteliers — the parts of GDPR that actually apply to a property that captures a passport at reception and emails guests before arrival.
The GDPR came into effect in 2018 and eight years later there are still hotels operating without a proper privacy policy, without a DPA on file with their PMS vendor, and without a passport-data retention schedule. Most of them will never be inspected. But when inspection does happen, the fines are large and the operational disruption is worse. Here is what to have in place before that becomes a problem.
1. Publish a privacy policy that a real person can read
Your website and your reservation flow must have a privacy policy that names you as the controller, lists the personal data you collect, explains why you collect it, names your data processors (PMS, channel manager, email tool, payment provider), and describes how a guest can exercise their rights. Written in plain language, not lawyer-speak.
See the Sabee privacy policy for a template you can adapt for your own hotel.
2. Have a lawful basis for every data processing activity
Under GDPR, every act of processing personal data must have a lawful basis. For hoteliers, the four bases that matter are: contract (fulfilling the reservation), legal obligation (police registration where required), legitimate interest (fraud prevention, direct email to past guests within limits), and consent (marketing to guests who have not stayed with you). Get the basis for each processing activity clear, and stop relying on consent for things that are actually contract-based.
3. Retention schedules for passport and ID data
Most European countries require hotels to record passport or ID data for arriving guests, and many require that data to be transmitted to a local police portal. GDPR then requires you to delete the data as soon as the legal retention period expires. Write the schedule down: how long does your PMS retain the data, how long does the police portal retain it, when is it deleted. If your PMS retains it forever by default, change the setting.
On Sabee, passport data is auto-deleted 90 days after checkout unless a country-specific rule extends that period. The rule is visible on the guest profile.
4. Consent for pre-arrival and post-stay marketing
Confirmation emails, arrival instructions, and receipts are contract-based — no consent needed. Marketing emails after the stay, newsletter subscriptions, and cross-promotions to sister properties are marketing communications and need consent under GDPR and (in most EU countries) ePrivacy rules. Make the consent granular and revocable.
5. CCTV footage retention
If your property has CCTV, you are processing biometric data every time a guest walks past. The rules: display clear signage that CCTV is in operation and name the controller; retain footage for the shortest period necessary for the stated purpose (typically 14–30 days); do not use the footage for anything other than the stated purpose.
6. A Data Processing Addendum with every technology vendor
Under GDPR Article 28, every third party that processes personal data on your behalf must have a written data processing agreement with you. That includes your PMS, your channel manager, your email marketing tool, your payment provider, your booking engine, and your review-aggregator tool. If any of them cannot produce a DPA on request, that is a compliance risk you own.
Sabee signs a DPA with every paying customer as part of the standard subscription — see the full DPA.
7. Data breach playbook
Under GDPR you must notify your national data protection authority within 72 hours of becoming aware of a data breach that presents a risk to guest rights. Have a playbook: who is on the incident team, how are you notified by your vendors, who calls the regulator, what template do you use, what customer communication goes out. Do not write this at 03:00 during an incident.
8. Data subject rights process
Guests have the right to access, rectify, erase, port and object to processing of their personal data. Write a one-page internal procedure for handling each of these. In practice most requests are erasure requests from past guests who want their data removed. Make sure your PMS actually supports a hard-delete, not a soft-delete that leaves the record in an archive.
9. International transfers
If any of your data processors is outside the EU/EEA (a US-based email tool, an American review aggregator), you need an appropriate transfer mechanism — usually Standard Contractual Clauses. Ask each vendor which mechanism they rely on. If they cannot answer clearly, that is a signal to look for a European alternative.
10. Appoint a DPO if you need to
Small independent hotels usually do not need a formal Data Protection Officer under GDPR Article 37, but larger chains, aparthotel groups running large-scale monitoring, or properties handling large volumes of special-category data (health-related bookings, for example) may need one. If you are not sure, talk to a compliance advisor for one hour — it is cheaper than a mistake.
How Sabee helps
Sabee is EU-hosted, GDPR-compliant, signs a DPA with every customer, gives you a working retention schedule for passport data, and includes a data subject rights request handler in the admin console. See the security page for the full posture and the privacy policy for our own practices as a controller.
Compliance you can actually run.
Start a pilot workspace and see how much of the GDPR posture Sabee handles by default.