The GDPR (EU Regulation 2016/679) applies to any company that processes the personal data of European citizens. Hotels do this every day: reservations, check-ins, newsletters, and special requests.
To ensure compliance, five key principles must be followed:
- Lawfulness, Fairness, and Transparency in Data Processing
- Purpose Limitation: Collect Data Only for Legitimate Purposes
- Data Minimization: Ask Only for What Is Necessary
- Safe Storage
- Confidentiality and integrity, including through the use of appropriate technological tools
Translation: Clear disclosure is needed, along with consent when necessary and protection against unauthorized access.



