HotelOnlineAIHotelOnlineAI
All articles
Compliance6 min read· September 4, 2026

Web check-in and privacy: collecting guest documents GDPR-compliant

Web check-in and GDPR: which guest data you can collect, how long to keep it and where not to store copies of documents. A practical privacy guide for hotels and B&Bs.


Web check-in saves time for you and the guest: documents and data collected before arrival, no queues at reception. But collecting identity documents means processing personal data, so the GDPR comes into play. Let’s see what you can collect, for how long and, above all, where not to keep the copies. For any doubtful cases, get the support of a privacy consultant.

Why check-in touches privacy

Name, document, sometimes its image: these are personal data. The GDPR does not forbid you from collecting them — in fact the law requires it for obligations such as the report to the police authority (Alloggiati Web) — but it asks you to do so sensibly: only what is needed, for as long as needed, kept secure.

Collect only what you need (minimisation)

The key principle is minimisation: no data “just in case”. For identification and the obligations you need the personal details and the document references; you do not need information unrelated to the stay.

  • Personal details and document references for identification and for Alloggiati Web.
  • The data needed for the booking and the stay.
  • Marketing consent is separate and optional: it must not be a condition for check-in.

The legal basis: legal obligation or consent

Not everything rests on consent. Collecting data for the report to the public-security authority is based on a legal obligation, not on the guest’s consent (who therefore cannot “refuse” the obligation). Consent is instead needed for further uses, such as sending marketing communications: keep it distinct and optional.

How long to keep it (and what not to keep)

A point often misunderstood: for the report to the police you transmit the data, and you are not required to keep a copy of the document scan indefinitely. Keeping copies of documents “for safety”, with no expiry, is exactly what the GDPR asks you to avoid. Set a retention period consistent with the purposes and, once it has passed, delete the data you no longer need.

Where NOT to keep guest documents

Convenience is the enemy of privacy. Avoid having documents arrive over unprotected channels and being left scattered around.

  • No photos of documents on WhatsApp or personal email.
  • No shared folders or chats where anyone can see them.
  • No forgotten copies on unprotected phones or PCs.
  • Access limited to those who really need it.

Privacy notice and guest rights

The guest must be given a clear privacy notice: who processes the data, for what purposes, for how long and how to exercise their rights (access, rectification, erasure). A good web check-in shows the notice before collection, not after.

How to do it well, without complicating your life

The solution is not to collect less and risk the obligations, but to collect in a structured and secure way: a single, encrypted channel, with controlled access and defined retention periods.

With HotelOnlineAI the guest uploads their data from a protected link, the data feeds the obligations such as Alloggiati Web without travelling through chats and emails, and remains accessible only to those who should see it. You get a fast check-in; the guest, respect for their data. For the specific aspects of your property, still assess with a privacy consultant. Want to see it? Request a free demo.

In summary

Web check-in and the GDPR are not in conflict: the law asks you to collect certain data and, at the same time, to process it with restraint. Collect only what is needed, distinguish the legal obligation from marketing consent, set how long to keep it and delete the rest, and don’t leave documents on WhatsApp or email. For specific cases, a privacy consultant remains the reference.

Take your business beyond every border.

Choose your profile and tell us about yourself. We'll get back to you shortly.