GDPR for small hotels: what you actually have to do
GDPR guidance aimed at hotels tends to come in two unhelpful forms: a law firm's forty-page briefing, or a vendor's scare campaign. For a 20-room independent, the actual obligations are narrower than either suggests. Here is a practical account of what you hold, what you must do, and what you can stop worrying about.
This is general guidance, not legal advice. If you have an unusual arrangement — a large contract client with its own requirements, or CCTV covering a public area — take proper advice on that specific point.
What a hotel actually holds
More than most owners realise:
- Guest names, addresses, phone numbers, email addresses
- Booking history and stay preferences
- Card details, or tokens representing them
- Registration cards, including nationality and passport details where required
- Dietary and accessibility requirements — which are special category data, because they can reveal health or religion
- CCTV footage
- Staff records, which are personal data too and often overlooked
The six things that actually matter
1. Know your lawful basis
For most hotel data the basis is contract — you need the guest's name and contact details to provide the room they booked. That covers the bulk of it and requires no consent.
Consent is needed for marketing: newsletters, offers, "we miss you" emails. It must be freely given and separately opted into. A pre-ticked box is not consent, and neither is burying it in terms and conditions.
Legal obligation covers the records you must keep — guest registration under the Immigration (Hotel Records) Order, and accounting records for HMRC.
2. Have a privacy notice people can find
A page on your website saying what you collect, why, how long you keep it, who you share it with, and how someone can ask for a copy or deletion. Link to it from the booking form and the footer. Write it in plain language — the regulator prefers clear English to legalese.
3. Delete things on a schedule
This is the obligation most hotels fail, because deleting nothing is easier. Decide a retention period for each category and stick to it:
| Data | Typical retention |
|---|---|
| Booking and guest records | Up to 7 years (accounting) |
| Card details | Delete once the stay is settled — do not store the full number at all |
| Marketing list | Until they unsubscribe, reviewed periodically |
| CCTV | Usually 30 days unless there is an incident |
| Registration records | 12 months minimum under the Hotel Records Order |
Ask your PMS vendor how deletion works. If the only way to remove a guest is to ask support, that is a problem waiting for a request.
4. Never store raw card numbers
Card details written on a booking form, emailed, or typed into a notes field are the most common serious failing in small hotels — and it is a PCI issue as much as a GDPR one. Use a payment provider that tokenises, so you hold a reference rather than a number. If you find card numbers in guest notes, clearing them is the highest-value hour you will spend on this.
5. Be able to answer a subject access request
A guest can ask what you hold about them, and you have one month to respond, free of charge. In practice this is rare for hotels, but you should be able to do it: everything from the PMS, plus anything in email or on paper. Knowing where it all lives is most of the work.
6. Know what to do about a breach
If personal data is lost or exposed in a way likely to risk people's rights, you must tell the ICO within 72 hours of becoming aware. A stolen reception laptop with guest data on it counts. Write down who decides and who reports, because 72 hours is short if it happens on a Friday.
What you can stop worrying about
You almost certainly do not need a Data Protection Officer. That is for public bodies and organisations doing large-scale monitoring or special-category processing as a core activity. A 20-room hotel is not that.
You do not need consent for ordinary booking emails. A confirmation, a pre-arrival note with directions, an invoice — these are contract, not marketing.
You do not need a cookie banner for everything. Strictly necessary cookies are exempt. Analytics and advertising cookies do need consent.
Questions for your software vendor
- Where is the data hosted? UK or EU keeps this simple.
- Can I delete a guest and everything attached to them, myself?
- Can I export everything you hold about one guest?
- Are card details tokenised, or stored?
- Will you sign a data processing agreement? (You are the controller, they are the processor.)
- How and when would you tell me about a breach on your side?
A vendor who cannot answer those quickly is a vendor whose answer is no.
A two-hour starting point
- Write down every place guest data lives — PMS, email, paper, spreadsheets, the booking diary.
- Search your PMS notes fields for card numbers and delete what you find.
- Publish or refresh your privacy notice and link it from the booking form.
- Set a retention period for each category and put a reminder in the calendar to apply it.
- Check your marketing list is people who actively opted in.
That covers the overwhelming majority of the real risk for a property your size.
InnCloud is UK-hosted and GDPR compliant, with guest deletion and export built in. Start a 7-day free trial.
One platform for your whole hotel
PMS, channel manager, booking engine and website — flat monthly price, no commission on your bookings.
Start your 7-day free trial

