Why GDPR applies to guest registration

Collecting a guest’s name, date of birth, nationality, and ID document number — all required for Czech guest-registration compliance — is processing personal data under GDPR. This creates obligations for accommodation providers independent of, but alongside, the UbyPort and House Book requirements: guests need to understand what’s collected and why, the data needs to be stored securely, and it can’t be kept indefinitely without a reason.

In most cases, the lawful basis for collecting guest registration data is that the accommodation provider has a legal obligation to do so (UbyPort reporting, House Book, accommodation tax) — this is a recognized lawful basis under GDPR distinct from consent. That said, providers still need to be transparent with guests about what’s collected and keep a documented basis for processing.

Storage, security, and retention

GDPR expects personal data to be stored securely (encryption, access controls, EU-based infrastructure where relevant) and retained only as long as necessary — which for guest registration data usually means as long as the legally required retention period for House Book and tax records, not indefinitely. A digital signature and timestamped submission record also help demonstrate the guest consented to how their data would be used.