Accommodation providers process sensitive personal data during guest registration — names, document numbers, nationality, home address. GDPR sets the rules for how that data can be handled, regardless of the size of the operation.

Guest registration actually has two legal bases: fulfilling a legal obligation (UbyPort reporting, the house book, the accommodation fee) and performing the accommodation contract. Guest consent usually isn’t needed as the primary legal basis — but guests should still be clearly informed what their data is used for.

Data minimization

GDPR requires collecting only the data actually needed for a given purpose. For guest registration, that means not collecting anything beyond what UbyPort, the house book, and the accommodation fee require.

Retention period

Data should only be kept for the period set by law for the relevant record (house book, registration book), then securely destroyed or anonymized. Keeping data indefinitely “just in case” conflicts with GDPR.

Guest rights

Guests have the right to access their data, correct it, and, under certain conditions, have it erased. An accommodation provider should have a clear process for handling such requests.

Data security

GDPR requires reasonable technical and organizational security measures — typically encryption at rest and in transit, role-based access control, and keeping sensitive data separate from routine operations.

How BestGuest handles this

BestGuest is designed around GDPR principles from the ground up — data minimization, role-based access control, and EU-based hosting. See our Security & Trust Center for the full picture, and How BestGuest Protects Your Guests’ Data for a summary.

Official sources

Always verify against the current official text of the law.