The Hospitality Newsletter
Today Thursday, August 13, 2026

Regulation & risk

GDPR

What GDPR means

The General Data Protection Regulation (GDPR) is a European Union law enforcing strict rules on how organizations collect, process, store, and delete personal data of individuals located within the EU, regardless of where the hotel operating company itself is legally headquartered.

How it is used

Hotels process massive volumes of guest data, including passport numbers, credit card details, and dietary preferences. GDPR mandates explicit guest consent for marketing, strict data retention policies, and robust vendor data processing agreements (DPAs) with tech providers like PMS, CRS, and Wi-Fi portals. Non-compliance risks regulatory fines up to €20 million or 4% of global annual turnover, whichever is higher. Revenue managers and marketers must ensure mailing lists rely on active opt-ins rather than pre-ticked boxes, while IT directors must enforce data minimization and immediate breach reporting within 72 hours.

Worked example

A boutique hotel group in London fails to secure an old guest database, leading to a breach exposing 50,000 guest records. The supervisory authority determines the hotel lacked adequate encryption and organizational safeguards. Under GDPR rules, regulators assess the severity and fine the property €1.2 million, representing 2.5% of the hotel group's annual global turnover.

Common mistake

Hotels located outside Europe frequently assume GDPR does not apply to them, ignoring that it covers any property processing the personal data of EU residents.

Related terms