All articlesHotels4 min read

How to collect and use guest data in a hotel legally

CTCate Triendl
How to collect and use guest data in a hotel legally (light cover)

Summary

GDPR made hoteliers wary of guest data, and the wariness costs more than the risk. The two rules that cover most of it, and the fields worth collecting.

Guest data is what turns one night into a booking next year. Collecting it properly is less complicated than it looks.

Hoteliers are wary of guest data because GDPR fines are real and the rules read as though they were written for somebody else. The wariness costs more than the risk. Data is what turns a one-night stay into a booking next year, and collecting it properly is not complicated.

Two rules cover most of it. Only collect what you intend to use, and only collect it once you can keep it safe. Everything below follows from those two.

What guest data is actually for

The benefits get recited a lot and stay abstract, so here they are in the terms a hotel manager uses.

Knowing that a guest stays with you every six weeks on business means you stop sending offers they do not need and start sending the one thing that would help: a late checkout, a quiet room, their usual table at breakfast.

Knowing which months your spa guests book in tells you when to run a package, and knowing how they booked tells you where to spend next quarter's budget.

Knowing that a guest arrived with two children and asked for a cot changes the room before they get to it, which is the sort of thing they mention in the review.

The common thread is that the data has to be attached to a person you can contact again. Aggregate numbers tell you what happened. Guest records tell you what to do next.

The fields worth collecting

Contact details first: an email address or a mobile number, with a record of when they opted in and what they agreed to. Without that, nothing else is usable.

Then the stay itself. Reason for visit, who they came with, how they booked, how long they stayed, what they used while they were here. This is the part that lets you segment, and most of it comes from systems you already run rather than from forms you make guests fill in.

Preferences last, and only the ones you will act on. Pillow type is useful if housekeeping reads it. A favourite wine is useful if the bar does. A field nobody opens is risk you are carrying for nothing.

Demographics are the weakest category and the one people over-collect. An age band tells you less than the fact that they booked a family room for four nights in August.

A tick box on the Wi-Fi sign-in is not a legal formality. It is what makes the rest of the list usable. Ask plainly what you will send and how often, and make opting out as easy as opting in was.

Then keep the record. When someone asks what you hold on them, or asks to be deleted, you have a month to answer and you need to be able to prove what they agreed to.

Keeping it safe

Collection is the easy half. The breach risk in hospitality is rarely exotic hacking. It is a spreadsheet of guest emails on a shared drive, a stack of registration cards in a drawer, or a booking export sitting in somebody's inbox for three years.

Three habits cover most of it. Keep guest data in one system rather than in exports. Give staff access to what their job needs and nothing more. Delete what you said you would delete, on the schedule you published.

Pick tools built for hospitality rather than a general spreadsheet, and ask any vendor the same four questions: where the data is stored, who can see it, how long it is kept, and how a deletion request gets actioned.

Start with the sign-in

Guest Wi-Fi is the lowest-friction collection point a hotel has. The guest wants a connection, you want a name and an email address, and both happen in ten seconds while they are standing in your lobby.

In several European countries a hotel already has to record passport details for law enforcement, so the habit of asking for information at check-in is not new. The difference is that a Wi-Fi sign-in asks permission for marketing at the same time, and records the answer.

Guest Wi-Fi captures that sign-in with an explicit opt-in, so the guest decides whether you can write to them, and the record lands on the same guest profile as their bookings and reviews. Our first-party data guide for hotels covers the strategy side.

See it running on your venues

One unified guest record across Wi-Fi, bookings, reviews and loyalty, and the marketing that acts on it.

Explore the platform