Scanning a guest’s identity document is different from scanning a completed registration card. This article explains how to collect the guest information you need without keeping unnecessary copies of passports or ID cards.
The problem: hotels collecting too much data
At check-in, a hotel may ask to see a passport or ID card and record certain details. Scanning the entire document also captures information the hotel may not need, such as a photograph or other identifiers. A routine practice of copying every guest’s document therefore needs careful justification.
A registration card is a different document: it contains information collected by the hotel, sometimes with the guest’s signature. Digitising that card does not mean the hotel should also scan the guest’s passport.
What does the law say?
The GDPR requires personal data to be adequate, relevant and limited to what is necessary for each purpose. A hotel must also have an appropriate lawful basis, tell guests how their information is used, secure it and set justified retention periods.
Local or sector-specific laws may require certain guest records or verification steps. Check the requirements that apply where your hotel operates, including which guests and fields are covered, any reporting duty, and how long each required record must be kept. A legal duty to record a detail does not, by itself, mean that a complete identity document must be copied.
Enforcement: fines for hotels
Data protection authorities can scrutinise unnecessary identity-document copies, excessive retention and inadequate security. The question is whether the hotel can explain why each item is needed, who can access it, and when it will be removed. Do not assume that collecting extra data is safer merely because some guest information must be recorded.
Do’s and don’ts for hoteliers
What you SHOULD do
- Check applicable local hotel-registration and retention rules before designing your check-in process.
- Record only the information necessary for your identified purposes; distinguish legally required records from information needed for the booking or service.
- Inspect identity documents when appropriate, without automatically making a copy.
- Explain to guests what you collect, why, with whom you share it and how long you keep it.
- Restrict access to guest records, protect devices and storage, and train reception staff.
- Set and regularly review retention periods for different kinds of guest information.
What you should NOT do
- Routinely scan passports or ID cards simply because you need to verify a guest’s identity or record some details.
- Keep photographs, document numbers or other identifiers without checking whether they are needed and lawful in your situation.
- Store scans or registration cards in broadly accessible folders or on unprotected devices.
- Treat a statutory minimum retention period as an automatic deadline for deleting every other guest record, or keep all records indefinitely.
- Use guest details for marketing without an appropriate legal basis and the required information or choices.
By country: what is required?
There is no reliable single list of required guest fields or one retention period that works across countries. Rules can also differ by guest category, purpose and type of accommodation. Check the current local and sector-specific requirements before deciding what your hotel must collect, report or retain. Document the result in your check-in procedure and retention schedule, and review it when the rules change.
What should you do as a hotelier?
- Review your check-in procedure. Identify each field and any passport or ID scan you currently collect, and why.
- Check local requirements. Confirm what the law applicable to your hotel requires for the relevant guests and records.
- Update the registration card. Remove fields you cannot justify; do not automatically copy identity documents.
- Digitise carefully if useful. A paper registration card may generally be scanned, checked for completeness and stored in a secured electronic system. Organising records by departure date can help with retrieval and timely review. Securely destroy the paper original only after checking that no separate legal, contractual or evidentiary reason requires it.
- Secure the guest register. Give access only to staff who need it and protect local devices, shared storage and backups.
- Inform guests and apply retention rules. Explain the processing and use documented periods for each purpose, respecting any applicable legal requirements. Delete or anonymise records when they are no longer needed.
GDPRWise helps you identify personal data collected through your website's booking forms, cookies and third parties, and document your processing activities.