Are we treating our guests with respect online?
In hospitality, trust is built at the front desk and should extend to every digital touchpoint. The same standards that prevent a stranger from viewing registration cards or a supplier from taking a guest list should guide what happens on your website and booking engine. For many hotels, the digital equivalent of those scenarios occurs—often without clear visibility or accountability.
This article outlines practical steps hotels can take to protect guests online, meet regulatory obligations, and uphold the brand promise of care. It is intended as guidance, not legal advice.
Why GDPR still matters
The General Data Protection Regulation (GDPR) and related privacy laws formalized principles most hoteliers already value: transparency, purpose limitation, consent where needed, and accountability. Guests should understand what data is collected as they browse, how it is used, and have meaningful choices. Despite progress, the digital ecosystem still enables extensive data collection and profiling beyond what many users expect. Hotels need to know what is happening on properties they own or control—especially websites, booking engines, and campaign landing pages.
AI raises the stakes for guest data
Advances in AI have lowered the cost and increased the sophistication of social engineering and fraud. Authentic booking details—names, dates, property, rate, confirmation numbers—make phishing convincing. If attackers gain access to reservation data anywhere in your vendor chain, your guests become targets.
Every hotel should be able to answer, in writing:
Where is guest data stored (systems, locations, subcontractors)?
What security controls protect it (access, encryption, monitoring, retention)?
Who is the data controller and who is the processor for each system, and where does liability sit if a partner is compromised?
These are governance questions, not technical ones. They belong in your vendor management and risk frameworks.
Tracking is no longer just about cookies
For years, cookies were the focal point for online privacy. Today, tracking can occur without them. Techniques such as browser or device fingerprinting collect signals (for example, screen size, fonts, graphics and audio hardware) to recognize returning users even if cookies are cleared. Under GDPR and ePrivacy rules, these methods generally require the same standard of transparency and consent as cookies. A cookie banner alone does not guarantee compliance if other identifiers or tags load before consent.
Know what fires on your pages
On hotel sites and booking engines, third-party scripts are often added for analytics, advertising, chat, or A/B testing. In some cases we see third-party tags loaded by default in booking engines without clear disclosure. Hotels must understand:
Which third-party codes execute on each page, including the booking flow
What data each tag collects and where it is sent
The lawful basis relied upon (for example, consent) and when collection begins • The role assignment for each party (controller, joint controller, processor)
Document these arrangements. Even where the booking engine is responsible for tags on its pages, the guest perceives the experience as yours. Duty of care extends through that journey.
Two areas to treat with particular caution
International transfers: For hotels operating in the EU or processing EU residents’ data, personal data cannot be transferred outside the EEA without a lawful transfer mechanism and appropriate safeguards. “The script came pre-installed” is not a basis for transfer.
“Free” tools: If a tool is free and offers attractive insights, assume data is the currency. Distinguish between privacy-compliant campaign measurement and user identification that feeds broader profiling, resale, or undisclosed enrichment.
What to do this week
Ask every vendor holding guest data to confirm, in writing:
Where the data is stored and processed (including sub-processors)
Security measures in place and certifications (for example, ISO 27001)
Roles and responsibilities (controller/processor), and breach notification terms
Request from your booking engine a list of all third-party scripts that load across the booking flow, what each collects, where it sends data, whether it runs before consent, and who the data controller is.
Review every “free” or bundled tool. Identify what the provider gains. If the value exchange is unclear, reconsider deployment.
Key takeaways
Apply the same standard online that you uphold at the front desk. If you would not allow it at reception, question why it runs on your website or booking engine.
AI has made targeted fraud cheaper and more convincing. Know where guest data lives, how it is secured, and how liability is shared across your vendors.
Blocking cookies does not stop tracking. Techniques like fingerprinting require the same rigor around consent and governance.
Map and govern third-party code. Confirm roles, data flows, and lawful bases—especially on booking pages guests perceive as your brand.
Treat “free” with caution. Campaign measurement is one thing; cross-site user identification and profile building for resale is another.
How Internet Affected can help
End-to-end data flow and tag audits across websites and booking engines
Controller/processor role mapping, vendor due diligence, and DPA review
Consent and preference management design and testing
International transfer assessments and safeguard recommendations
Governance for tag management, server-side collection, and minimization
Staff awareness and playbooks for phishing and reservation-related fraud
To discuss a privacy and tracking audit tailored to your hotel group, contact Internet Affected.
Get in touch and let us help your hotel.
About the author
Glyn Spencer Hopkins is the owner of Internet Affected and has been working exclusively with hotels and luxury brands for over a decade.
Internet Affected provides digital revenue services tailored to the individual characters of hotels; a complete range of services designed to help them take back ownership of their hotel brand from the OTAs. Specialized marketing solutions to increase guest loyalty, food & beverage bookings, events and wedding inquiries, clearly reported in straightforward language.
Blocking cookies no longer stops tracking, and scammers quote real bookings. This edition of Revenue Insights covers the questions every hotel should put to its booking engine and advertising partners.