Skip to content
Hotelmark
Email + retention

GDPR and privacy on your hotel website, without legal headaches

2026-06-05·9 min read
GDPR and privacy on your hotel website, without legal headaches

The GDPR, the privacy law that applies throughout Europe, does not require you to be a lawyer. For a B&B or small hotel, 80 percent of the obligation sits in 3 things: a readable privacy statement, valid cookie consent, and a clean way to collect email addresses.

The problem

Say you have 6 rooms, a website from 2019 your nephew built, and you finally want to start a newsletter to become less dependent on Booking.com. Then you run into a wall of acronyms: GDPR, GDPR (wait, that is the same thing), cookie consent, data processing agreement. Most hoteliers react the same: either do nothing and hope it is okay, or panic and hire an expensive lawyer for something that takes an afternoon to sort out.

Both reactions cost you. Doing nothing means you collect email addresses you legally are not allowed to use, so your newsletter stands on quicksand: one complaint and your whole list is contaminated. And hiring a lawyer for the foundation is money wasted, because the standard parts are free via generators and plugins that are more than sufficient for your situation.

Let me untangle the two terms. GDPR is the Dutch name for the privacy law. GDPR is exactly the same law, only the English abbreviation you encounter internationally. So it is not two things, it is one law with two names.

The core is simple. As soon as you store data from people, a name, an email address, a payment, you must be able to answer 3 questions: why do I have this, am I allowed to have it, and is it stored safely. The rest is detail.

Important to know: the amount of personal data an average B&B processes is small and not very sensitive. Names, email addresses, arrival dates. No medical files, no social security numbers. That saves enormously in what you have to arrange. The more sensitive the data, the stricter the requirements, and your data is on the light end of the spectrum. That is precisely why the foundation for you takes half a day instead of weeks of project work.

Calculation example

No euros this time, but an honest risk assessment. The legal maximum fine sounds scary (up to 20 million euros or 4 percent of annual revenue), but that applies to big data breaches at big companies. For an accommodation your size, the real risk is different. This table pits effort against risk, so you see where your time brings the most return.

GDPR elementEffort to arrangeRisk if you do not
Privacy statement on your site1 hour (generator + adjust)High: first thing a guest or regulator checks
Cookie consent (banner)1 to 2 hours (set up plugin)High: visible, easy to report
Active opt-in on newsletter form30 minutes (uncheck box)High: unsolicited email is the most reported complaint
Agreement guest data retention1 hour (write policy)Medium: relevant only if complaint or breach
Data processing agreement with your vendors1 hour (request, not write yourself)Medium: vendors supply ready-made
Secure storage (no Excel on an unprotected laptop)VariableHigh if breach, low in daily use

The message from that table: the three elements with "high" risk and little effort (privacy statement, cookie banner, opt-in) you arrange in half a day. That covers the vast majority of what a guest or the Data Protection Authority would notice first.

From a practical standpoint, the Data Protection Authority (the Dutch privacy watchdog, like a police officer for privacy) does not drop by a B&B of 6 rooms spontaneously. Almost every case starts with a report, usually from someone who got unsolicited promotional email. And the first reaction is almost never a fine: you get a request to fix it. A fine only follows if you ignore that. The biggest damage for a small accommodation is usually not financial, it is reputation: a guest who feels overlooked and shares that in a review or Facebook group for hoteliers.

What you can do today

Open your newsletter form and check whether the permission checkbox is pre-checked. If so, uncheck it. A pre-checked box does not count as valid consent under GDPR. This is 1 setting and immediately your biggest risk is gone.

Action plan

  1. Put a privacy statement on your site. Use the free generator from the Data Protection Authority or the standard text your email provider (like Mailchimp or Laposta) offers. Adjust it to your situation: which data, why, how long, with whom shared. Half a page in plain language is enough. Put a link in your footer and by every form.

  2. Set up cookie consent if you use tracking. Do you have Google Analytics, a Facebook pixel, or a chat widget? Then you place non-essential cookies and need a consent banner that really lets the visitor choose before those cookies load. On WordPress use a plugin like Complianz or Cookiebot. If you only place essential cookies, a mention in your privacy statement is enough.

  3. Make your newsletter opt-in active and free. The visitor must themselves check an empty box and cannot be forced to sign up to do something else. Mention briefly what you email about ("offers and news from the region, about once a month") and put an unsubscribe link under in every email. Also keep proof of consent: most email programs automatically log the time and source when someone signs up. That is your safety net if a guest later claims they never gave permission.

  4. Agree on a retention period. Keep booking data as long as you need it for administration (the tax office asks for 7 years for financial records), keep marketing consent until someone unsubscribes. Write this in 1 paragraph in your privacy statement.

  5. Request data processing agreements from your vendors. Every party that processes data for you (your booking engine, your email program, your channel manager) must offer you a data processing agreement. You do not write it yourself, you ask for it. At most tools it sits ready-made in your account settings.

  6. Store guest data safely. A spreadsheet with email addresses on a shared, unprotected laptop is a risk. Keep personal data in your booking engine and your email program, not loose in folders and emails. More about managing that data neatly, read in manage guest data.

Common mistakes

  • Using Booking email addresses for your newsletter. An address you get via an OTA (an online travel agency like Booking.com or Expedia) is meant for that one booking. That is not consent for marketing. Want these guests in your list, ask for separate consent at check-in or via your own form. How to legally build your own list is in build a customer list without Booking.

  • Setting the cookie banner to "everything loads, just click away." Many sites show a bar while tracking already runs. That is not consent, that is a notice. Cookies must only load after the visitor clicks accept.

  • Thinking you are too small for GDPR. The law knows no minimum number of rooms. 6 rooms or 600, the same rules. The difference only is in the amount of data, not in the obligation.

  • Taking over a privacy statement full of legal jargon. A guest must be able to read it. Incomprehensible text formally meets the requirement but misses the point, and a regulator specifically looks at readability.

  • Skipping the data processing agreement because you do not know what it is. A data processing agreement (abbreviated a data processing agreement or in English a DPA) is an agreement between you and a vendor that handles data for you. It settles who is responsible if something goes wrong. You do not have to write or understand it in detail, you only have to request and save it. At Booking, your email provider, and your booking engine it is almost always ready-made in your account.

  • Forgetting that first-party data is your strongest asset. GDPR feels like a burden, but legally collected, own guest data is exactly what makes you independent of OTAs. See it as the foundation under your direct marketing, not a blocker. More about that in first-party data for accommodations.

When in doubt, consult a specialist

This article helps you handle the foundation yourself. If you face a data breach, a guest request to delete all their data, or share sensitive data with multiple parties, that is not DIY work. Consult a privacy specialist or lawyer. This article is not legal advice.

What you can do now

The foundation takes half a day to set up, and the 3 elements with the highest risk cost under 3 hours together: privacy statement, cookie banner, and clean opt-in on your form. Start there, because that is exactly what a guest or the Data Protection Authority sees first.

After that, you have the foundation to legally build your own channel. That is the whole point: once you neatly and with permission collect email addresses, you have a list nobody can take from you. No commission, no algorithm between you and it. Start with build a customer list without Booking and then set up your hotel newsletter.

Plan a fixed recurrence for the rest. GDPR is not a task you check off and then forget. Add a new tool like a chat widget or new booking system, check whether it fits in your privacy statement and if there is a data processing agreement with it. Once a year read through your privacy statement and check whether it still matches what you actually do. Set that as a recurring appointment the same week you review your rates for the new season. So it stays a quarter-hour habit instead of a panic task afterward.

Want to know what you now pay monthly in Booking commission and what a shift to direct earns you? Calculate it through in the savings calculator. And if you would rather not mess with cookie banners and opt-ins yourself, we look at what your accommodation needs at marketing for hotels.

Frequently asked questions

What is GDPR exactly and does it apply to my B&B?
The GDPR (General Data Protection Regulation, the European privacy law) applies to every business that processes personal data from people, including a B&B with 6 rooms. As soon as you store names, email addresses, or payment information from guests, you fall under it. The size of your business does not matter for the rules, only for the amount of work.
Do I need a cookie banner on my hotel site?
Only if your site places cookies that are not strictly necessary, like Google Analytics or a Facebook pixel. A banner must actually let the visitor choose before those cookies load. A notice of 'by continuing to surf you agree' is not valid. If you only place functional cookies, you do not need a permission banner, but you do need a short mention in your privacy statement.
Can I send a newsletter to guests who booked via Booking.com?
No, not just like that. An email address you get via Booking is meant for that one booking, not for marketing. For a newsletter you need separate, active consent. Ask for that at check-in or via a checkbox on your own booking form.
What must be in a privacy statement?
Which data you collect, why, how long you keep it, who you share it with (your booking engine, your email program), and what rights the guest has. Write it in plain language on about half a page, no legal jargon. Generators from the Data Protection Authority and from your email provider help you get started.
What happens if I do not have this in order?
The chance of a spontaneous inspection for a small accommodation is small. The real risk is a complaint from a guest to the Data Protection Authority, for example about unsolicited email. Then comes first a request to fix it, only after ignoring that a fine. The biggest damage for a small accommodation is often reputation, not the fine itself.
Is this legal advice?
No. This is a practical explanation to get you started. With a complicated situation, like a data breach or sharing sensitive guest data with multiple parties, that is not a DIY task. Consult a privacy specialist or lawyer in those cases.

A concrete tip in your inbox each month

Practical marketing and automation tips for small-scale accommodations. No sales talk, unsubscribe anytime.

Your email address is only used for these emails and never shared. You can unsubscribe from any email. See the privacy policy.

Read more

Questions about what this means for you?

Join the waitlist for the launch. We translate the news into concrete steps for your accommodation.