Privacy notice for a hotel or holiday let
A privacy notice for a hotel, bed and breakfast, holiday let or serviced apartment business, drafted for the business with the cookie notice and consent guidance, for a fixed fee of £595 in five working days.
Privacy notice for a hotel or holiday let
Buy now, £595A hotel or holiday let receives most of its guests through booking platforms that hold the guest's data on their own terms, must keep a guest register the law has required for decades, takes card pre-authorisations it should not store, films its public areas, runs a Wi-Fi network, and wants to market to guests after they leave. The privacy notice has to explain the platforms' role, the statutory register, the payment arrangements, the CCTV and the Wi-Fi, the marketing basis, and the position of the guests a booker books for. The pack (privacy notice, cookie notice and consent guidance) is drafted for the business for £595, fixed, in five working days.
Who this is for
Hotels, guest houses, bed and breakfasts, holiday lets, serviced apartments, glamping and short-term rental businesses in England and Wales taking bookings directly and through platforms.
What matters in a hotel or holiday let privacy notice
Guests, bookings and the platforms that bring them
As controller, the business must under Article 13 of the UK GDPR tell guests what it collects: booking details, contact and identity information, payment data handled by the processor, preferences and requests, stay history and the correspondence; most bookings arrive through online travel agents and rental platforms which collect the guest's data under their own notices as controllers and pass to the business what the booking needs, and the notice should explain that the platform's notice covers the booking on the platform and the business's notice covers the stay, that the business may receive only a masked contact address from some platforms, and that the business's own booking engine, channel manager and property management system are its processors under Article 28.
The guest register the law still requires
The Immigration (Hotel Records) Order 1972 requires hotels and other premises providing sleeping accommodation for reward to record every guest aged sixteen or over (full name and nationality, and for guests who are not British, Irish or Commonwealth citizens the passport or identity document number and place of issue, and the next destination), to keep the record for twelve months and to make it available to the police, and the notice should state that the business keeps the register because the law requires it (legal obligation under Article 6(1)(c) of the UK GDPR), what it records, how long it keeps it and who may see it; holiday lets and short-term rentals fall within the Order where they provide accommodation for reward, which many operators do not know.
Payment, pre-authorisations and the card data the business should not hold
The notice should explain that card details for payment, pre-authorisations and incidentals are handled by the payment processor and the property management system's tokenised payment function, that the business does not store full card numbers on paper or in email (the payment card industry standard the processor's terms require), that deposits and damage charges are applied under the booking terms, and that payment records are kept for the period tax law requires; a hotel that keeps card numbers on booking forms in a filing cabinet has the breach and the processor's penalty waiting.
CCTV, Wi-Fi, keys and the data the stay generates
CCTV in public areas, car parks and corridors (never in rooms or bathrooms) is processed under legitimate interests with signage, a stated retention period, limited access and a process for police requests and guests' access requests to footage; the guest Wi-Fi network logs connections and may require registration, with the notice stating what is logged, for how long and why (security, the Wi-Fi provider's terms); electronic key cards and smart locks record entries; and the notice should describe each system, because the data a stay generates goes beyond the booking, and the Information Commissioner's video surveillance guidance expects the business to have assessed its CCTV.
Marketing, reviews and the messages after checkout
Pre-arrival information and post-stay thanks are service messages, but offers, newsletters and loyalty communications are marketing, and email and text marketing to individuals is permitted by regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 only with consent or the soft opt-in (for a guest who booked directly and was given the chance to refuse), with an unsubscribe in every message; guests who booked through a platform have not given the business the soft opt-in and should be asked; review requests sent through the platform follow the platform's rules; and the website's cookies and the booking engine's tracking need the consent mechanism the pack provides guidance on under regulation 6 of those Regulations.
Children, groups and the people the booker books for
A booker often supplies the names of other guests (family members, colleagues, a group), and the notice should say that the business holds the other guests' data as supplied by the booker, that the booker should tell them, that the statutory register records each adult guest, and how a guest other than the booker exercises rights; it should also cover children (whose data is recorded for the stay and for the register from sixteen), accessibility and dietary requests (health data under Article 9 where they reveal it, processed with the guest's explicit consent for the stay), the individual's rights over their data (access, rectification, erasure, restriction, portability, objection), the process and the one-month limit, and the complaint to the Information Commissioner's Office, and where the fee under the Data Protection (Charges and Information) Regulations 2018 applies, the business registers with the Information Commissioner's Office and the notice says so.
What it costs
Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
Do we still have to keep a guest register?
The Order still applies: name and nationality for every guest aged sixteen or over, passport details for guests who are not British, Irish or Commonwealth citizens, kept for twelve months and available to the police. Holiday lets providing accommodation for reward are within it too.
Can we email guests who booked through a platform?
Not under the soft opt-in, which needs the details to have come to the business directly with a chance to refuse. Ask them for consent at check-in or through the platform's rules. The notice states the basis for direct bookers.
Can we keep card details on file for damage charges?
Through the processor's tokenised pre-authorisation, yes; on paper or in email, no. The notice explains that card data is held by the processor and the booking terms set the charges.
Related guidance and services
- Data protection agreements and privacy terms, £595, the service this page describes
- Terms and conditions drafting, £995
- SaaS and technology contracts, £995
- Terms and conditions for a holiday let
- Privacy notice for a restaurant taking bookings
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.