Μετάβαση στο περιεχόμενο

Hotel GDPR Guest Data: What to Keep and What to Delete

01 Σεπ 2026 | Petar Petrov
Hotel GDPR Guest Data: What to Keep and What to Delete
Αυτό το άρθρο δεν είναι ακόμη διαθέσιμο στη γλώσσα σας. Η μετάφραση θα προστεθεί σύντομα!

A small hotel can hold an unusually intimate picture of a person: identity details, payment records, travel dates, family composition, dietary requests and accessibility needs. The problem with hotel GDPR guest data is rarely that the property deliberately collects everything. It is that nobody has written down what exists, where the copies went or why they are still there.

This article provides general information, not legal advice. Data obligations and retention requirements differ by country, region and purpose and change over time, so your property’s lawyer, data-protection adviser and accountant are the authorities for its situation.

Inventory the data before writing the policy

You cannot decide what to keep until you know what you hold. Beginning with a polished privacy policy often produces a document about the official systems while ignoring the copies that create the real exposure.

Trace a guest journey from enquiry to departure and after-stay contact. List each place where information is received, created, copied or exported:

  • the booking engine, channel accounts and property-management records;
  • the payment provider and fiscal or accounting system;
  • email, marketing tools and shared inboxes;
  • spreadsheets saved on a reception computer;
  • phone message threads used for arrivals or guest requests;
  • paper registration cards and printed arrival lists in a drawer;
  • identity-document scans in a shared folder or attached to email;
  • maintenance or housekeeping notes that identify a room and guest;
  • personal notebooks, downloads and removable storage.

Do the inventory with reception, reservations, finance, marketing and operations. A manager may believe passport images are deleted after check-in while a night receptionist keeps a desktop folder “in case the report fails.” Finance may export every booking into a spreadsheet and never remove old copies. A housekeeping message can disclose an accessibility or health need even though it does not look like a guest database.

For every location, record the data category, purpose, source, people with access, recipient or vendor, expected retention and deletion method. Mark the system of record and every duplicate. “We keep bookings” is not an inventory; “the reservation platform holds contact and stay data for operations, while an exported arrival list is deleted after its task ends” is actionable.

Only then write policy. It should describe the operation you actually have and assign an owner for closing each informal route.

Some categories require much more care

A guest’s name and email already deserve protection. Identity and travel documents, payment credentials and information revealing health, disability, belief-linked dietary choices or other sensitive circumstances require tighter handling because misuse can cause greater harm.

An identity document is not merely a convenient image of a guest. It may contain a photograph, document number, date and place of birth, nationality, signature and other details irrelevant to most hotel tasks. If local registration requires staff to inspect or report particular fields, that does not automatically justify preserving a full scan for unrelated convenience.

Separate the action from the evidence. Staff may need to verify a document, enter required information and complete a report. Ask your adviser whether the image itself must remain after that purpose ends. “The scanner saves it automatically” is a technical default, not a retention reason.

Payment deserves a similar distinction. The hotel may need transaction references, invoice status and evidence of a refund. That does not mean reception should see or store full card credentials. Keep payment processing in an appropriate provider and retain only what the hotel genuinely needs for reconciliation and lawful records.

Free-text notes are another risk. “Needs step-free shower because of recent surgery” is more revealing than “accessible bathroom requested.” Record the operational instruction in the least intrusive form that still lets the team deliver it. Do not turn a practical request into an indefinite guest profile.

Use a short sensitivity review:

  1. Is this field required for law, contract, safety or delivery?
  2. Could a less detailed value serve the same purpose?
  3. Which role needs to see it, and for how long?
  4. Does a duplicate or export survive after the source is updated?

Retention needs rules by category, not one date

Two duties pull in opposite directions. You should remove personal information when its purpose has ended, while other rules may require the property to preserve certain fiscal, contractual or registration records. Those requirements differ by data type and country. The answer is not “delete every guest after checkout” or “keep everything in case.”

Build a retention schedule by category and purpose with your lawyer and accountant. A fiscal invoice, an operational arrival note, an identity scan, a marketing contact and an unresolved complaint do not belong under one blanket period. State what event starts the retention clock, which rule or need supports it and what happens at the end.

Use operational triggers where possible:

  • departure completed;
  • registration or reporting purpose fulfilled;
  • payment dispute resolved;
  • legal record no longer required;
  • consent withdrawn or marketing relationship ended;
  • support case closed;
  • duplicate export replaced by the current source.

An exception needs an owner and reason. If a record must be held because of an active dispute, suspend its ordinary deletion only to the extent needed and document the decision. Do not silently convert a temporary hold into permanent storage.

Deletion must include practical copies. Removing a guest from the main application while leaving exported spreadsheets, message attachments and paper cards untouched does not complete the task. Backups and third-party systems need documented treatment too, based on advice appropriate to the property’s setup.

HotPilot supports retention policies, encrypted personal data and per-property isolation. Those controls can enforce an agreed approach; they cannot decide the lawful purpose or category for you.

Hotel GDPR Guest Data: What to Keep and What to Delete

An erasure request usually means “most, but not the invoice”

When a guest asks for deletion, the honest answer is often: “We can erase most of it, but not the fiscal invoice.” The property may still be required to preserve fiscal or accounting evidence even when marketing details, preference notes, message history and unnecessary identity copies can be removed.

Do not answer with an automatic yes or a defensive no. Verify the requester appropriately, search the inventory and divide the information into categories. For each one, decide whether it can be erased, must be retained, should be restricted or belongs to a processor that needs an instruction.

A useful response workflow is:

  • log the request and assign one owner;
  • verify identity without collecting excessive new information;
  • search systems of record and known informal copies;
  • remove data whose purpose has ended;
  • preserve only records supported by a continuing obligation or defensible need;
  • explain plainly what remains and why;
  • record the actions taken without recreating the deleted profile.

Deleting the booking entry that carries a fiscal invoice can create a different compliance and reconciliation problem. Conversely, retaining an entire CRM profile merely because one invoice must remain is not proportionate. Separate the invoice and its necessary audit trail from optional contact history and service notes.

This is where hotel data compliance and erasure controls should help staff execute a reviewed decision across stores. HotPilot supports guest erasure across its stores and audit logging, but the property still determines scope with its advisers and coordinates any external systems.

Knowing what you hold, restricting who sees it, and being able to answer an erasure request without a search party — those are the achievable three. We can show you how each is handled for a property your size.

Give each role only the view it needs

Access control is often the cheapest effective safeguard. A receptionist needs today’s arrivals, contact details required for service and current requests. That does not mean they need years of stay history, archived identity scans or every marketing interaction.

Map access to tasks:

  • reception sees active and near-term stays;
  • housekeeping sees room status and the minimum service instruction;
  • finance sees invoices, payments and records needed for accounting;
  • marketing sees contacts supported by the appropriate permission and purpose;
  • management receives aggregated operational information unless individual detail is necessary;
  • technology providers receive only the access required for a defined support case.

Shared accounts defeat this structure because nobody can tell who opened, exported or changed a record. Use named accounts, remove access promptly when roles change and review powerful permissions. Audit logging is valuable only if someone examines unexpected access or bulk exports.

Paper needs equivalent control. Do not leave an arrival list visible at reception or old registration cards in an unlocked drawer. Provide a secure collection point and a routine for destruction once the agreed purpose ends.

Train through scenarios rather than abstract slogans. Ask what a receptionist should do with a passport photo sent through a messaging app, where a dietary request belongs and whether an old spreadsheet may be emailed to a new agency. The answers expose gaps that a generic annual presentation will miss.

Make the minimum workable for a small property

A small hotel does not need to begin with a grand compliance programme. It needs an accurate map, owners and a few repeatable controls.

Start with the highest-risk routes. Stop routine identity scans unless a reviewed requirement supports them. Remove old exports from desktops and personal drives. Move guest communication out of employees’ private accounts. Lock paper records. Restrict broad system access.

Then establish a monthly exception review rather than manually reading every record. Look for files without owners, deletion jobs that failed, former staff with access, large exports and requests awaiting action. Review the inventory when you introduce a new booking, messaging, payment or marketing tool.

The practical minimum is clear:

  1. Know what guest data exists and where every important copy lives.
  2. Give each category a purpose and an adviser-reviewed retention rule.
  3. Limit sensitive information to roles that need it.
  4. Remove informal copies when their task finishes.
  5. Be able to answer an erasure request without a search party.

Software can make deletion, isolation and audit activity consistent. It cannot fix an unknown spreadsheet on someone’s laptop or decide why the hotel keeps a passport image. Governance begins with the real working habits.

Let’s sum up!

  • Inventory official systems and informal spreadsheets, phone threads and paper cards before writing a retention policy.
  • Treat identity documents, payment information and sensitive guest needs with tighter minimisation and access controls.
  • Set retention by data category and purpose with your lawyer and accountant, not through one blanket rule.
  • An erasure request often means deleting most information while retaining the fiscal invoice and necessary audit trail.
  • Give reception, housekeeping, finance and marketing only the guest information required for their roles.
  • A small property can begin with an accurate map, controlled access and repeatable deletion rather than an oversized programme.

If you are not certain what guest data you hold or where, book a HotPilot demo — starting with an inventory is the useful first hour.

Petar Petrov

Petar Petrov

VP of Engineering

VP of Engineering at HotPilot, where I work across the whole platform — from the booking engine and channel distribution to payments, operations and compliance. My focus is on what the hotelier actually feels: bookings that complete, reporting that doesn't need doing by hand, and features that hold up under real load rather than in a demo. Most of what I write here started as a specific problem at someone's front desk — and that is the measure I use for what is worth solving.