GDPR and personal data in reception
How you put the patient's privacy first
In reception, you are daily in contact with guests' personal information — name, address, passport number, payment card and often more. Therefore, the Data Protection Regulation (GDPR) is not just something for the IT department; it is part of your daily work.
§What information are you allowed to collect?
According to the Data Authority, the company has a legal basis for collecting the information necessary to fulfil the agreement with the guest. This typically includes name, date of birth, nationality, address and passport or other identification. You may not ask for more information than the purpose requires — this is called data minimisation.
- 01Name, address and contact information for the reservation
- 02Date of birth and nationality, where required by authorities
- 03Passport or other identification at check-in
- 04Payment card details for settlement
- 05Special wishes such as allergies — only when the guest tells you
§How long may you store data?
A main rule in GDPR is that data must not be stored longer than necessary. You cannot save a guest's information 'in case' of a future visit unless the guest has consented for example to a loyalty program. At the same time the foreigner rules (foreigner order § 45 on guest register) require that information about foreign guests can be provided to police — but the order itself does not set the legal storage period; it follows GDPR's proportionality principle where the Data Authority in practice applies a ceiling typically at most 1-2 years for complete guest register data. Some information must therefore be kept for a period even though the agreement is finished.
| Situation | Guideline |
|---|---|
| Regular booking | Deleted when the purpose is fulfilled, unless otherwise agreed |
| Guest registration (passport/ID) | Guest register is kept in accordance with the foreign regulations § 45 (for police use); the retention period is governed by GDPR — typically at most 1–2 years |
| Consent to rewards programme | Can be stored as long as consent applies |
| Payment information | Stored only as long as accounting law and payment security require |
§Data security in a busy day
- 01PLACEHOLDER_71
- 02Do not leave guest folders or registration cards lying out
- 03Don't talk about a guest's information where other guests can hear it
- 04Never confirm to outsiders that a particular person is staying at the hotel
§If something goes wrong
If there is a data breach — for example guest information being sent to the wrong recipient or lost — the company must assess whether the Data Authority should be notified within 72 hours. As a receptionist your role is to know the procedure and report it internally immediately so management can act. The sooner an error is discovered the smaller the damage typically is.
“Good data processing is invisible to the guest — but it is there every time you type a name into the system.”