GDPR (EU Reg. 2016/679) applies to any company that processes personal data of European citizens. Hotels do it every day: reservations, check-ins, newsletters, special requests.
To be compliant, 5 key principles must be followed:
- Lawfulness, fairness and transparency in processing
- Purpose limitation: collect data only for legitimate purposes
- Data minimization: asking only what is needed
- Safe storage
- Confidentiality and integrity, including through appropriate technological tools
Translated: you need clear disclosure, consent when needed, and protection against unauthorized access.



