TL;DR for the DPO
Identifying the guest is a legal duty; KEEPING a copy of the document is not. After transmitting data via the police portal, copies (scans, photos, photocopies) must be destroyed or deleted. Retaining them breaches minimisation and storage limitation (Art. 5 GDPR).
The three points that matter
- Identifying does not mean archiving: the host must verify identity and transmit the data, not build an archive of ID documents. The 'just in case' photocopy is exactly the practice being challenged.
- The risk is twofold: a GDPR sanction for unlawful retention and, in case of a breach, an archive of ID documents is the perfect target for identity theft - triggering notification and communication duties.
- It applies across hospitality: hotels, B&Bs, guesthouses, short-term rentals and the property-management systems used for online check-in, which often store scans by default.
What to do now, in practice
For hospitality clients: 1) review the check-in flow (physical and online): if documents are photocopied or scanned, change the procedure now; 2) clean up the existing archive with documented deletion; 3) check PMS/channel-manager settings (many keep scans: disable it or set automatic deletion); 4) update the privacy notice and the Art. 30 record with the real retention period.
Why it matters for your clients
It is the classic case of 'we have always done it this way' meeting the GDPR: the photocopy at the front desk is a deep-rooted habit that now has an explicit pronouncement against it. For a DPO with tourism clients it is a quick, concrete win that owners immediately understand.
Official source:Italian Data Protection Authority - notice to hoteliers on retention of guests' documentsLooking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free