Operations

GDPR for small hotels: what you actually have to do

22 September 2026 · InnCloud
A hotel registration card and a locked filing cabinet in an office

GDPR guidance aimed at hotels tends to come in two unhelpful forms: a law firm's forty-page briefing, or a vendor's scare campaign. For a 20-room independent, the actual obligations are narrower than either suggests. Here is a practical account of what you hold, what you must do, and what you can stop worrying about.

This is general guidance, not legal advice. If you have an unusual arrangement — a large contract client with its own requirements, or CCTV covering a public area — take proper advice on that specific point.

What a hotel actually holds

More than most owners realise:

The six things that actually matter

1. Know your lawful basis

For most hotel data the basis is contract — you need the guest's name and contact details to provide the room they booked. That covers the bulk of it and requires no consent.

Consent is needed for marketing: newsletters, offers, "we miss you" emails. It must be freely given and separately opted into. A pre-ticked box is not consent, and neither is burying it in terms and conditions.

Legal obligation covers the records you must keep — guest registration under the Immigration (Hotel Records) Order, and accounting records for HMRC.

2. Have a privacy notice people can find

A page on your website saying what you collect, why, how long you keep it, who you share it with, and how someone can ask for a copy or deletion. Link to it from the booking form and the footer. Write it in plain language — the regulator prefers clear English to legalese.

3. Delete things on a schedule

This is the obligation most hotels fail, because deleting nothing is easier. Decide a retention period for each category and stick to it:

DataTypical retention
Booking and guest recordsUp to 7 years (accounting)
Card detailsDelete once the stay is settled — do not store the full number at all
Marketing listUntil they unsubscribe, reviewed periodically
CCTVUsually 30 days unless there is an incident
Registration records12 months minimum under the Hotel Records Order

Ask your PMS vendor how deletion works. If the only way to remove a guest is to ask support, that is a problem waiting for a request.

4. Never store raw card numbers

Card details written on a booking form, emailed, or typed into a notes field are the most common serious failing in small hotels — and it is a PCI issue as much as a GDPR one. Use a payment provider that tokenises, so you hold a reference rather than a number. If you find card numbers in guest notes, clearing them is the highest-value hour you will spend on this.

5. Be able to answer a subject access request

A guest can ask what you hold about them, and you have one month to respond, free of charge. In practice this is rare for hotels, but you should be able to do it: everything from the PMS, plus anything in email or on paper. Knowing where it all lives is most of the work.

6. Know what to do about a breach

If personal data is lost or exposed in a way likely to risk people's rights, you must tell the ICO within 72 hours of becoming aware. A stolen reception laptop with guest data on it counts. Write down who decides and who reports, because 72 hours is short if it happens on a Friday.

What you can stop worrying about

You almost certainly do not need a Data Protection Officer. That is for public bodies and organisations doing large-scale monitoring or special-category processing as a core activity. A 20-room hotel is not that.

You do not need consent for ordinary booking emails. A confirmation, a pre-arrival note with directions, an invoice — these are contract, not marketing.

You do not need a cookie banner for everything. Strictly necessary cookies are exempt. Analytics and advertising cookies do need consent.

Questions for your software vendor

A vendor who cannot answer those quickly is a vendor whose answer is no.

A two-hour starting point

  1. Write down every place guest data lives — PMS, email, paper, spreadsheets, the booking diary.
  2. Search your PMS notes fields for card numbers and delete what you find.
  3. Publish or refresh your privacy notice and link it from the booking form.
  4. Set a retention period for each category and put a reminder in the calendar to apply it.
  5. Check your marketing list is people who actively opted in.

That covers the overwhelming majority of the real risk for a property your size.

InnCloud is UK-hosted and GDPR compliant, with guest deletion and export built in. Start a 7-day free trial.

One platform for your whole hotel

PMS, channel manager, booking engine and website — flat monthly price, no commission on your bookings.

Start your 7-day free trial