Almost everything written about data protection and Spanish holiday lets covers one thing: the ban on keeping a copy of the guest’s ID. It makes a good headline and it is true, but it leaves out the rest of the file. An inspector from the AEPD, Spain’s data protection authority, will not ask only about photocopies.
The underlying reason is that Real Decreto 933/2021 orders you to collect personal data from every guest and keep it for three years, and that order exempts you from nothing: it makes you, without anyone telling you so, the controller of a processing operation with duties of its own. The rule that makes you collect is not the rule that tells you how.
This article is the other side of the file: which role you hold, which legal basis covers you, what you must have in writing, and what to sign with whoever runs your check-in.
Two rules, two processing operations: RD 933/2021 and the GDPR
The decree splits the roles across two articles that are almost never read together.
Article 4.1 puts collection on you: operators of lodging activities shall collect users’ data in order to register and communicate it as their legal obligations require1. Article 5 puts custody on you: a computerised register holding the Annex I data, kept for three years from the end of the service2.
Article 7 describes a different processing operation, and it is not yours. The data you send is kept in two files held by the Secretaría de Estado de Seguridad, may be processed only by the state security forces, and is governed by Ley Orgánica 7/2021, the law-enforcement data act, not by the GDPR3.
That is the key to the whole split: the police file is not yours and its regime does not apply to you. Yours is yours, and its regime is the GDPR.
You are the data controller for your guests’ data
A small property rarely sees itself as the controller of a processing operation. It is one from the very first guest: you decide which data you ask for, on which form, where you store it, who can see it and when it is deleted. That decision-making power is exactly what defines the role.
And you do not stop being the controller by hiring someone. If you use a check-in app, a PMS or an accountant, that third party processes the data on your behalf and on your instructions: it is a processor, and you remain the controller towards the guest and towards the AEPD.
Your legal basis is legal obligation, not consent
This is the most widespread mistake and the one that ages worst: the “I consent to the processing of my data” tickbox on the check-in form.
The processing the decree requires rests on GDPR article 6(1)(c), compliance with a legal obligation to which the controller is subject4. You do not need the guest’s consent, and asking for it weakens your position twice over. First, it suggests the guest may refuse, and they may not: without their data you cannot comply with the Ministry. Second, consent conditioned on being handed the keys is hardly freely given, so it would not be valid even if you needed it.
The privacy notice at check-in: what it must say
Not needing consent does not mean not having to inform. They are different duties and the second one always applies.
GDPR article 13 requires you to provide the information at the time the data is obtained, that is, on the check-in form itself, not in a link buried in your website footer. The minimum list covers your identity and contact details, those of the data protection officer if you have one, the purposes and the legal basis, the recipients or categories of recipients, and any international transfers5.
For a lodging business, three items on that list are the ones that usually fail:
- Purpose and legal basis. Name Real Decreto 933/2021 and say the basis is compliance with a legal obligation.
- Recipients. The Ministerio del Interior is a recipient, and it has to be named. So is your check-in provider and any other processor.
- The retention period. Three years from the end of the service, with its article.
This is not cheap formalism. In decision PS/00499/2022, the AEPD fined a manager of holiday apartments 75,000 euros in total, and 50,000 of that was for the article 13 breach: the information given to guests was incomplete. The other 25,000 was for demanding an image of the ID6. The most expensive part of the file was not the document copy, it was the text nobody had reviewed.
The record of processing activities applies to you too
This is where almost every small property writes itself out, and almost always wrongly.
GDPR article 30 requires a record of processing activities, and its paragraph 5 carries an exception that sounds like a lifeline:
“The obligations referred to in paragraphs 1 and 2 shall not apply to an enterprise or an organisation employing fewer than 250 persons unless the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10.”
Read the exception to the exception: it is enough that the processing is not occasional. Registering every traveller who walks through your door, all year, under a legal mandate, is the definition of non-occasional processing. The 250-person exception does not save you.
The document itself is not complicated: which processing you carry out, for what purpose, over which categories of data and data subjects, who it is disclosed to, how long it is kept and which security measures you apply. It goes in writing, electronic form is fine, and you must make it available to the AEPD on request.
Three years of retention: article 5.3 of RD 933/2021
The retention period is not yours to choose. Article 5.3 of the decree sets it at three years counted from the end of the service or contracted supply, and that starting point matters as much as the number: it does not run from check-in, nor from the booking2.
Once the period is up, the data is deleted. Keeping it “just in case” loses its legal cover at the exact moment the obligation expires, and runs straight into the storage limitation principle. The sensible way to handle it is for deletion to be automatic rather than a task somebody has to remember.
There is a nuance almost nobody mentions. Article 5.4 exempts from the registration and retention duties anyone carrying on lodging activity on a non-professional basis, who remains subject only to the communication duty2. It is a narrow exception with no practical development, so do not assume it is yours without advice: if you charge per night and advertise on platforms, you are not the case it describes.
The processor agreement with your check-in provider
If a third party processes your guests’ data on your behalf, the GDPR does not let you settle it with an invoice and a handshake.
Article 28(3) requires a contract or other legal act binding the processor to the controller and setting out “the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller”. That contract must stipulate, among other things, that the processor acts only on documented instructions from you. The AEPD publishes guidance on what it must contain and how to validate it8.
Before signing, four questions that separate a serious provider from one improvising:
- Is there a processor agreement, or only terms of service?
- Who else sees the data (sub-processors: hosting, backups, support, AI assistants) and are they disclosed?
- Where is the data hosted and what international transfers are involved?
- What happens when the contract ends: return or deletion?
That contract is yours even though the system is somebody else’s. If a guest complains or the AEPD inspects, you answer first.
Copying the ID is not a compliance measure
It is worth closing where most people start, because the order matters: keeping a copy of the document does not strengthen your compliance with the decree, it weakens your compliance with the other rule.
The AEPD settled it in its note on lodging registration: asking for a copy of the DNI or passport breaches the data minimisation principle in GDPR article 5(1)(c) and amounts to excessive processing9. The decree asks for data, not images. The full treatment, with the fines already imposed and the alternatives the Agency itself accepts, is in photocopying a guest’s ID at check-in.
The asymmetry is what defines this ground: fail to file the parte and the state penalises you through the Ley Orgánica 4/2015 penalty regime; collect or keep too much and the AEPD penalises you. Compliance means hitting the middle exactly: every Annex I field, not one more, and not one day longer than required.
Frequently asked questions
Who is the data controller for the guest report data? The data controller for the guest report data is the lodging business itself, for the data it collects at check-in and keeps in its register. The Ministerio del Interior is the controller of the police files that data is sent to, which under article 7 of Real Decreto 933/2021 are held by the Secretaría de Estado de Seguridad and governed by Ley Orgánica 7/2021 rather than by the GDPR.
Do I need the guest’s consent to file the parte de viajeros? You do not need the guest’s consent to file the parte de viajeros. The legal basis is compliance with a legal obligation under GDPR article 6(1)(c), because Real Decreto 933/2021 imposes both the collection and the communication. Asking for consent here is a mistake: it suggests the guest may refuse, and consent conditioned on receiving the keys would not be freely given anyway. You do need your own basis, normally consent, for anything you collect beyond the Annex I fields.
Do I need a record of processing activities if I am a small property? Yes, you need a record of processing activities even as a small property. The GDPR article 30(5) exception for organisations with fewer than 250 employees falls away when, among other cases, the processing is not occasional, and registering every traveller all year under a legal mandate is not occasional. The record must be in writing, electronic form is acceptable, and it has to be made available to the supervisory authority on request.
What must I tell the guest at check-in? At check-in you must tell the guest, at the moment you collect the data, what GDPR article 13 lists: your identity and contact details, those of the data protection officer where there is one, the purposes and legal basis of the processing, the recipients or categories of recipients, any international transfers and the retention period. For a lodging business that means naming Real Decreto 933/2021, saying that the Ministerio del Interior is a recipient, and explaining the three-year retention.
How long must I keep guest data? You must keep guest data for three years counted from the end of the service or contracted supply, under article 5.3 of Real Decreto 933/2021. The starting point is not check-in and not the booking, it is the end of the stay. Once the period is up the data is deleted: the period is fixed by the decree and is not a setting you can raise or lower.
Do I need to sign anything with my online check-in provider? Yes, you need a processor agreement with your online check-in provider. GDPR article 28(3) requires a contract or other legal act setting out the subject matter, duration, nature and purpose of the processing, the type of personal data and categories of data subjects, and binding the provider to process the data only on your documented instructions. Without it you are processing data through a third party with no cover, and the one who answers to the guest and to the AEPD is still you.
How the roles split with RegistroViajero
RegistroViajero is the data processor and you are the controller. That is not our reading of an ambiguous contract: clause 7 of the terms of service and the privacy policy say it in those words, and both are published so you can read them before signing up for anything.
The four questions from the previous section are answered there, which is exactly what you should be able to do with any provider:
- Contract or terms. The split of roles sits in clause 7 of the terms you accept on sign-up, not in a sales promise. If your adviser also wants a signed processor annex, ask for one before you sign, from us and from whoever else you are comparing.
- Who else sees the data. The policy names the recipients: the Ministerio del Interior, the hosting provider (in Germany, within the EEA), the payment gateway, and the AI assistant provider, based in the European Union and bound by the GDPR, which processes the conversations and receives the guest’s identification data where a query concerns a specific guest. The signature is never sent to it.
- Where the data sits and which transfers there are. Your guests’ data does not leave the European Economic Area: hosting is in Germany and the assistant is processed in the European Union. The payment gateway sees no guest data, only your agency’s billing details.
- What happens at the end. Guest data and signatures delete themselves after three years, assistant conversations after ninety days of inactivity, and clause 9 of the terms recognises the right to request full deletion of the account and its data at any time.
One more answer, because it is what brings most people here: the guest data listed in the policy is the Annex I fields plus the handwritten signature that article 4.2 of the decree requires from anyone over fourteen. There is no image of the document on that list, and there is none because the check-in never asks for one: the guest types the data rather than photographing the ID.
In practice that means the guest fills in the Annex I fields in their own language, the system validates the format before letting them continue, the parte goes out to SES.HOSPEDAJES within the deadline, and every communication is kept in an auditable log. Register data is deleted automatically after the three years the decree sets, with nobody needing to remember.
What we cannot do for you is the rest of your file: the privacy notice shown on your check-in, your record of processing activities and your judgement on which extra data to request are the controller’s decisions, and the controller is you. If you are comparing tools, online check-in apps for holiday apartments has the landscape, and the four questions in the processor agreement section are a good filter for any of them.
This article is for information only and does not replace professional legal advice on data protection. Whether a given processing operation is compliant depends on its circumstances; if you face a complaint or an inspection, consult a specialist.
Sources
-
Real Decreto 933/2021, article 4, consolidated text (BOE, in Spanish). ↩
-
Real Decreto 933/2021, article 5, consolidated text (BOE, in Spanish). ↩ ↩2 ↩3
-
Real Decreto 933/2021, article 7, consolidated text (BOE, in Spanish). ↩
-
Regulation (EU) 2016/679, article 6(1)(c), English version (EUR-Lex). ↩
-
Regulation (EU) 2016/679, article 13, English version (EUR-Lex). ↩
-
Decision in sanctioning procedure PS/00499/2022, PDF (AEPD, in Spanish). ↩
-
Regulation (EU) 2016/679, article 30(5), English version (EUR-Lex). ↩
-
Guidelines for drafting controller-processor contracts, PDF (AEPD, in Spanish). ↩
-
Note on requests for copies of identity documents in lodging, 17 June 2025, PDF (AEPD, in Spanish). ↩



