GDPR (General Data Protection Regulation)
GDPR (General Data Protection Regulation) is the European Union's data-protection law, in force since May 2018. It governs how organizations collect, store, process and share personal data of individuals in the EU, and applies to hotels, OTAs and technology vendors worldwide when they handle data of EU residents.
Key principles
- Lawful basis: processing needs a valid legal ground, such as contract performance (a booking), consent or legitimate interest.
- Data minimization and purpose limitation: collect only what is needed for a stated purpose.
- Data subject rights: access, correction, erasure and portability.
- Security and breach notification: serious breaches must generally be reported to the supervisory authority within 72 hours.
- Accountability: processors and controllers need clear agreements (data processing agreements) and records.
Example
A hotel shares guest booking data with a marketing tool. Under GDPR it needs a lawful basis for the use, a data processing agreement with the vendor, and a way to honor a guest's request to delete their data. Fines can reach up to €20 million or 4% of global annual turnover, whichever is higher.
Why it matters
Guest data flows constantly between booking channels, PMS, CRM and marketing tools. GDPR shapes how loyalty programs, retargeting, CDP (Customer Data Platform) projects and review solicitations may operate, and how OTAs and hotels allocate responsibility as joint or separate controllers. Strong data governance also supports trust and reduces legal risk.