Checklist for personal data and GDPR at check-in
Safe handling of guest information in practice
Use this checklist when you check in a guest, or otherwise handle personal data at the reception. It gathers the most important points so data protection becomes a natural part of the workflow — not an afterthought.
§Before you register the guest
- 01Ask only for information necessary for the stay and legal requirements
- 02Briefly explain if the guest asks why you are asking for identification
- 03Screen should face away from other guests when entering data
§During the stay.
- 01PLACEHOLDER_69
- 02Do not leave registration cards or printouts visibly out
- 03Share only this link with customers — it does not give employee access.
- 04Use only internal systems to look up guest information — never private messages or emails
§At checkout and afterwards
- 01Delete or destroy printed registration cards when they are no longer needed
- 02Remember that a guest register for foreign guests is kept in accordance with the Aliens Order § 45 (for use by the police) — storage time is governed by GDPR and is typically at most 1-2 years
- 03Do not store contact information for future marketing without consent.
| Situation | Action |
|---|---|
| Guest asks for their information to be deleted | Pass on to responsible supervisor — assessed according to storage obligation |
| Suspected data breach | Report it immediately internally, regardless of scope |
| Phone inquiry about a guest from an unknown person | Never confirm whether a person is a guest at the venue |