Skip to content
News calendar_today Updated: 25 September 2026 schedule 5 min read

Hotel Guest Passports and ID Cards: Do's and Don'ts Under GDPR

verified Last reviewed 24 September 2026 · GDPRWise legal team

Scanning a guest's identity document is different from scanning a completed registration card. This article explains how hotels can collect the guest information they need without keeping unnecessary copies of passports or ID cards.

summarize Key Takeaways
  • check_circle Check which guest information and retention rules apply under local and sector-specific law. Do not assume the same fields are required for every guest.
  • check_circle Inspecting an identity document does not automatically justify keeping a full copy. Record only the information needed for a lawful purpose.
  • check_circle A completed paper registration card can generally be scanned and stored electronically, with appropriate security. Check whether another rule or genuine evidentiary need requires the paper original.
  • check_circle Keep guest data only for as long as needed for each purpose, taking account of any applicable legal retention rules.

Scanning a guest’s identity document is different from scanning a completed registration card. This article explains how to collect the guest information you need without keeping unnecessary copies of passports or ID cards.

The problem: hotels collecting too much data

At check-in, a hotel may ask to see a passport or ID card and record certain details. Scanning the entire document also captures information the hotel may not need, such as a photograph or other identifiers. A routine practice of copying every guest’s document therefore needs careful justification.

A registration card is a different document: it contains information collected by the hotel, sometimes with the guest’s signature. Digitising that card does not mean the hotel should also scan the guest’s passport.

What does the law say?

The GDPR requires personal data to be adequate, relevant and limited to what is necessary for each purpose. A hotel must also have an appropriate lawful basis, tell guests how their information is used, secure it and set justified retention periods.

Local or sector-specific laws may require certain guest records or verification steps. Check the requirements that apply where your hotel operates, including which guests and fields are covered, any reporting duty, and how long each required record must be kept. A legal duty to record a detail does not, by itself, mean that a complete identity document must be copied.

Enforcement: fines for hotels

Data protection authorities can scrutinise unnecessary identity-document copies, excessive retention and inadequate security. The question is whether the hotel can explain why each item is needed, who can access it, and when it will be removed. Do not assume that collecting extra data is safer merely because some guest information must be recorded.

Do’s and don’ts for hoteliers

What you SHOULD do

  • Check applicable local hotel-registration and retention rules before designing your check-in process.
  • Record only the information necessary for your identified purposes; distinguish legally required records from information needed for the booking or service.
  • Inspect identity documents when appropriate, without automatically making a copy.
  • Explain to guests what you collect, why, with whom you share it and how long you keep it.
  • Restrict access to guest records, protect devices and storage, and train reception staff.
  • Set and regularly review retention periods for different kinds of guest information.

What you should NOT do

  • Routinely scan passports or ID cards simply because you need to verify a guest’s identity or record some details.
  • Keep photographs, document numbers or other identifiers without checking whether they are needed and lawful in your situation.
  • Store scans or registration cards in broadly accessible folders or on unprotected devices.
  • Treat a statutory minimum retention period as an automatic deadline for deleting every other guest record, or keep all records indefinitely.
  • Use guest details for marketing without an appropriate legal basis and the required information or choices.

By country: what is required?

There is no reliable single list of required guest fields or one retention period that works across countries. Rules can also differ by guest category, purpose and type of accommodation. Check the current local and sector-specific requirements before deciding what your hotel must collect, report or retain. Document the result in your check-in procedure and retention schedule, and review it when the rules change.

What should you do as a hotelier?

  1. Review your check-in procedure. Identify each field and any passport or ID scan you currently collect, and why.
  2. Check local requirements. Confirm what the law applicable to your hotel requires for the relevant guests and records.
  3. Update the registration card. Remove fields you cannot justify; do not automatically copy identity documents.
  4. Digitise carefully if useful. A paper registration card may generally be scanned, checked for completeness and stored in a secured electronic system. Organising records by departure date can help with retrieval and timely review. Securely destroy the paper original only after checking that no separate legal, contractual or evidentiary reason requires it.
  5. Secure the guest register. Give access only to staff who need it and protect local devices, shared storage and backups.
  6. Inform guests and apply retention rules. Explain the processing and use documented periods for each purpose, respecting any applicable legal requirements. Delete or anonymise records when they are no longer needed.
auto_awesome Know what data your hotel website collects?

GDPRWise helps you identify personal data collected through your website's booking forms, cookies and third parties, and document your processing activities.

Share share LinkedIn mail Email
GW
GDPRWise Editorial

This article was written by the GDPRWise team and reviewed by our privacy experts. We regularly review our content for accuracy and legal correctness.