Mascot
Web Design For Accommodation
Menu
Owner Resource

GDPR Compliance
For Accommodation

Data protection isn't just about avoiding fines—it's about building trust with your guests. Here is everything you need to know.

Beyond the Tick Box

GDPR (General Data Protection Regulation) and the Data Protection Act 2018 reshaped how businesses handle personal information. For B&Bs, self-catering cottages, and hotels, this is critical because you handle sensitive personal data every single day.

It doesn't matter if you take bookings via email, a contact form, or a sophisticated booking engine—if you collect data, the law applies to you.

The Core Principle

You must be transparent about what data you collect, why you collect it, and you must keep it secure. Silence is no longer an option.

Is Your Website Compliant?

Any website that collects data (via a contact form, booking system, or newsletter signup) must adhere to these standards.

SSL Encryption

Your site must have the "Padlock" icon (HTTPS). This encrypts data transferring between your guest's computer and your website, ensuring names and details cannot be intercepted.

Explicit Consent

Pre-ticked boxes are illegal. When a guest uses your contact form, they must actively tick a box to say "I consent to you storing my details to reply to this enquiry."

Privacy Policy

You must have a page that clearly explains who you are, what data you collect, and how long you keep it. This must be accessible from every page (usually the footer).

Cookie Control

You need a mechanism to inform users about cookies. Analytics and tracking cookies should ideally be blocked until the user gives consent.

Common Questions

What counts as "Personal Data" in hospitality?

Any data that can be used to identify a living person directly or indirectly. For accommodation owners, this typically includes:

  • Guest Names
  • Email addresses
  • Home Addresses
  • Telephone numbers
  • IP addresses (collected by your website)
  • Dietary requirements (which can imply health data)
Am I a Data Controller?

Yes. If you decide why and how personal data is processed (i.e., you take bookings to run your business), you are a Data Controller. You are accountable for the data you hold.

What rights do my guests have?

Under UK GDPR, individuals have specific rights, including:

  • The Right to be Informed: Knowing how you use their data (via your Privacy Policy).
  • The Right of Access: Requesting a copy of the data you hold on them.
  • The Right to Erasure: Asking to be "forgotten" (deleted from your systems).
We Can Help

GDPR Compliance Package

Don't worry about the technical details. We have over 400 happy customers using our compliance framework. We can audit your site and implement the necessary changes for you.