Conformités et obligations

Digital check-in and GDPR: what data should you collect?

4
min de lecture
-
30 September 2026

A guest receives their pre-check-in form before arriving at the hotel.
Name, phone number, email, arrival time, stay preferences, subscription to promotional offers…

At first glance, it may all seem to belong in the same form. However, not all of this data serves the same purpose or is subject to the same rules.

The key for a hotelier is to distinguish between information necessary for managing the stay and data collected for communication or marketing purposes after the stay.

‍

Not all check-in data requires consent

A common mistake is thinking that the GDPR requires asking for guest consent for every piece of information collected.

That is not the case.

Consent is only one of the legal bases provided by the GDPR. When data is objectively necessary for fulfilling a booking or organizing a stay, its processing can be based on the performance of a contract, without asking the guest to check an "I agree" box. 

In a digital check-in, this can apply to information used to:

  • identify the traveler;
  • locate their booking;
  • to prepare for their arrival;
  • to manage a requested service;
  • to fulfill certain administrative obligations.

This does not mean, however, that you should collect as much information as possible.

The GDPR imposes a principle of data minimization : the data requested must be adequate, relevant, and limited to what is strictly necessary for the stated purpose.

A check-in form should therefore not become a pretext for collecting as much information as possible "just in case."

To learn more about legal bases, retention periods, and customer rights, our article on GDPR applied to customer data in the hotel industry covers the subject in greater detail.

‍

Data needed for the stay versus marketing data: where is the line?

The distinction becomes particularly important when it comes to email addresses and phone numbers.

The hotel may need these contact details to send reservation-related information, notify the guest of a change, or facilitate their arrival.

This does not automatically mean that these same contact details can then be used to send a newsletter or promotional offer.

The CNIL distinguishes between transactionalcommunications, which are necessary for the performance of a contract, and relational communications and sales prospecting. The applicable rules are not the same.

Let's take an example.

During their digital check-in, a guest provides their email address to receive practical information about their stay.

The hotel may use this address to manage this specific purpose.

However, if the establishment subsequently wishes to sign them up for a promotional campaign, it must verify that it has the appropriate legal basis for this new use.

For individuals, electronic prospecting is generally based on prior consent. However, the CNIL provides a regulated exception for certain existing customers when it comes to similar products or services, provided in particular that they have been informed and can easily opt out of prospecting.

The key takeaway is simple:

Collecting data for a stay does not automatically grant authorization to use it for all future communications.

‍

What should a well-structured check-in form look like?

The form becomes much clearer when the purposes are separated.

A first section can group together the information necessary for the stay: identity, useful contact details, arrival time, required administrative information, and requests directly related to the booking.

Optional fields related to the comfort of the stay must be identified as such.

If the hotel then wishes to use the guest's contact details for commercial purposes, it must identify the applicable legal basis.

When consent is required, it must be collected separately from the check-in process.

For example:

I would like to receive news and offers from the hotel by email.

This box must not be pre-checked when consent is required. Consent must be freely given, specific, informed, and result from a positive action by the guest.

Most importantly, when marketing consent is not necessary for the stay, refusing it must not prevent the guest from completing their check-in.

In other words:

Check-in must not be conditional upon marketing sign-up.

‍

What about police registration forms?

Hotel check-in also involves a specific regulatory requirement: the individual police registration form for applicable foreign travelers.

Regulations require the collection of specific information, including name, date and place of birth, nationality, usual place of residence, contact details, and arrival and departure dates. These forms must be kept for six months.

Here again, this is not a matter of marketing consent. It is a separate legal obligation, with its own specific purpose.

Digital forms can help prepare and streamline this collection process in advance. However, regulations stipulate that the form must be completed or have the guest complete it, and signed by the foreign traveler upon arrival.

GetWelcom covers this topic in more detail in its article dedicated to hotel police registration forms.

Data collected for this obligation must only be used for that specific purpose.

‍

The specific case of OTA guests

Digital check-in is also often one of the first opportunities for a hotel to directly obtain the actual contact details of a guest who booked via an OTA.

This is particularly useful for preparing for the stay and facilitating communication.

For an OTA guest, the same principle applies: Contact details obtained to prepare and manage a stay do not automatically become data that can be used for commercial purposes.

Digital check-in should not be presented solely as a method for "collecting OTA emails."

It is primarily a tool for preparing for arrival and streamlining the check-in process, and then potentially offering the guest, in a transparent manner, the opportunity to continue the relationship after their stay.

‍

How can consent be made truly actionable?

A checkbox is not enough if the hotel is unable to subsequently retrieve what the guest had agreed to.

When processing is based on consent, the controller must be able to demonstrate that it is valid.

The digital journey must therefore allow for a clear record of the choice made, the time it was collected, and the specific purpose involved.

This traceability is particularly useful when the hotel needs to verify, months later, whether a guest had actually agreed to receive certain communications.

A signed paper form that has been archived is generally more difficult to retrieve and verify than a structured digital process.

The digitization of the guest journey for compliance can facilitate this organization, provided that the purposes, access rights, and retention rules are correctly defined.

It also simplifies the management of consent withdrawals or opt-out requests.

‍

Before putting your form online, check four points

Before deploying or modifying a digital check-in, review each field in the form and ask yourself four questions:

  • Why are we collecting this data?
  • Is it truly necessary for the stay or for a legal obligation?
  • Does the guest clearly understand how it will be used?
  • If it is used for marketing purposes, are the legal basis and the customer's choice being managed correctly?

If you cannot clearly answer one of these questions, the field probably needs to be reviewed.

This method helps to both shorten the form and avoid mixing stay management, regulatory obligations, and commercial prospecting.

‍

Digitize the check-in process without mixing purposes

GetWelcom allows you to digitize the check-in process, centralize information needed upon arrival, and integrate consent collection into the online journey. The solution also generates police registration forms and synchronizes them with the check-in process.

Request a GetWelcom demo

‍

Hadrien REAUD
Co-founder of Getwelcom
30 September 2026

Contact us

Contact
Demo
Required fields are marked with an asterisk*
Thank you, we will get back to you soon!
An error has occurred. Please try again