← All posts
Administration 4 August 2026 Β· 9 min read

Keeping guest data: what does the GDPR allow, and for how long?

With five rooms you are just as much a data controller as a hotel chain. Which guest data you may collect, what to do with the ID card, how long to keep invoices, email logs and bookings, and how to handle an access or erasure request without losing your figures.

Share on LinkedIn Keeping guest data: what does the GDPR allow, and for how long?

You don't have a legal department. What you do have is a guest list with names, addresses, dates of birth, phone numbers, sometimes a passport number, and a payment history going back years. In the eyes of the GDPR, running five rooms makes you exactly as much a data controller as a chain running five thousand.

The good news: for a small property it comes down to a handful of decisions you make once and then let run. Here are the eight that actually matter.

One note first: this is practical experience, not legal advice. Traveller registration duties differ by region and even by municipality, and accounting retention periods are worth confirming with your accountant.

1. Only collect what you need

The principle is called data minimisation, and it's the easiest one to apply. Walk through your booking form and ask, for every field: what do I do with this?

  • To deliver the booking: name, email, phone, dates, room, number of guests.
  • To invoice: address, plus company name and VAT number for business guests.
  • For legal traveller registration: exactly the fields your municipality or region requires, no more.
  • Practical details: arrival time, breakfast preference, allergies. An allergy is health data β€” note it for the stay, not forever.

What you don't need: a scan of an ID card "just in case", a card number sitting in an email, a national registry number, or a free-text field where someone eventually types something sensitive.

2. Reading an ID card is fine; copying it rarely is

This is the most common question, and the answer is fairly consistent: keeping a copy or scan of an identity document is almost never necessary, and supervisory authorities look at it critically. The card contains far more data than you need.

The practical rule: read off what you're legally required to register, note those fields, hand the card back. No passport photos in WhatsApp, no folder of scans on your desktop. If a guest checks in remotely, let them fill in the details themselves rather than asking for a photo of their card β€” which is also less work for you. How to set that up is in online check-in and the digital guest register.

3. There isn't one retention period β€” there are five

This is the insight that brings the most calm. "How long may I keep guest data?" has no single answer, because every type of data has its own purpose and therefore its own clock:

  • Invoices and accounting: in Belgium there's a seven-year retention duty. That beats an erasure request β€” confirm the exact period for your situation with your accountant.
  • Traveller registration: the period the rules impose, and then gone. Not years "just in case".
  • Booking data with no invoicing duty: three years after departure is a defensible default β€” long enough for disputes or a returning guest, short enough to stay defensible.
  • Newsletter and marketing: as long as consent stands, with an unsubscribe link in every email.
  • Technical logs and backups: months, not years. Email logs about a year, sync and webhook logs a few months, backups a month.

Write this down once as a ten-line table. That table is the core of your processing record, and it's the first thing you'll need if a question ever comes.

4. A booking is not consent for your newsletter

A guest who books consents to having their booking delivered. Not to receiving an offer three times a year. Ask for that opt-in separately, record when and how it was given, and make unsubscribing work in one click.

That's not a formality: a list of people who actually said yes performs better than a list everyone landed on without asking. More on that in an email newsletter for your guests.

5. Not everyone needs to see everything

Your housekeeper needs a room number, a date and a time. Not an address, a date of birth, or payment details. A seasonal staff member handling check-ins doesn't need access to last year's revenue.

So work with roles and permissions instead of one shared login that can do everything. And look critically at shared mailboxes: a booking confirmation in an inbox five people can read has been shared five times.

6. Your suppliers are processors β€” including your PMS

Your PMS, your channel manager, your payment provider, your mail tool: they all process guest data on your behalf. That calls for a data processing agreement, and three questions you're entitled to ask: where is the data stored, who are the sub-processors, and what happens to my data if I leave?

Watch the OTA side too. Booking.com and Airbnb often give you a masked email address that stops working after the stay. Storing that as a "real" contact leaves you with a list that doesn't work and that you arguably shouldn't have built. If you want the real address, ask for it during the stay, with a reason.

7. Access and erasure: anonymising is usually the answer

A guest has the right to ask what data you hold and to have it erased. You have roughly one month to respond.

The trap with erasure: if you simply delete the booking, you also lose your occupancy figures and that year's revenue β€” and you're not allowed to throw away an invoice anyway. The answer is to anonymise rather than delete: name, address and contact details are made unrecognisable, while the booking line with amounts and nights stays put. Your statistics still add up; the person is no longer in there.

Keep a record of who did what and when, too. Being able to show you handled a request properly matters as much as handling it.

8. Put a readable privacy statement on your site

Not three pages of copy-pasted legalese, but honest answers to five questions: what data, why, how long, shared with whom, and how to get in touch. Link to it from your booking form, and don't use a pre-ticked marketing box. If you're still building out direct bookings, take this along in a booking system on your own website.

What your system can take off your hands

The biggest risk at a small property isn't bad intent, it's forgetting to clean up. Data from 2019 still sitting there in 2026 because nobody ever deletes anything.

Which is why this belongs in your system, not in your head. In BedFlow PMS the retention periods are settings β€” by default guest data is anonymised three years after departure, email logs after about thirteen months, sync logs after ninety days, backups after thirty β€” and a nightly pass actually carries that out. There's also a GDPR screen where you can find a person by name or email across all their bookings, export their data, or anonymise or erase it, with a log of every action.

Checklist for this weekend

  • Remove one field from your booking form that you never use.
  • Delete old ID and passport scans from your mailbox and downloads folder.
  • Write your retention periods down in a ten-line table.
  • Give housekeepers and seasonal staff their own login with limited rights.
  • Ask your PMS and channel manager for their data processing agreement.
  • Put the retention periods into your system so cleanup happens automatically.
  • Publish a readable privacy statement and link to it from your booking form.

How to configure retention periods and access rights is in the documentation; what it costs is simply on the pricing page. Want to try it calmly before autumn starts? BedFlow PMS is free for 30 days, no credit card.

Found this useful? Share it: Share on LinkedIn
Want to try BedFlow yourself?

30-day free trial, no credit card. We migrate your MyTourist or other PMS data with you.