All news
Italian DPA July 14, 2026 3 min

Italian DPA to hoteliers: do not keep copies of guests' ID documents

Once guest data is sent to the police portal, document copies must be destroyed or deleted. What changes for hotels, B&Bs and short-term rentals

TL;DR for the DPO

Identifying the guest is a legal duty; KEEPING a copy of the document is not. After transmitting data via the police portal, copies (scans, photos, photocopies) must be destroyed or deleted. Retaining them breaches minimisation and storage limitation (Art. 5 GDPR).

The three points that matter

  • Identifying does not mean archiving: the host must verify identity and transmit the data, not build an archive of ID documents. The 'just in case' photocopy is exactly the practice being challenged.
  • The risk is twofold: a GDPR sanction for unlawful retention and, in case of a breach, an archive of ID documents is the perfect target for identity theft - triggering notification and communication duties.
  • It applies across hospitality: hotels, B&Bs, guesthouses, short-term rentals and the property-management systems used for online check-in, which often store scans by default.

What to do now, in practice

For hospitality clients: 1) review the check-in flow (physical and online): if documents are photocopied or scanned, change the procedure now; 2) clean up the existing archive with documented deletion; 3) check PMS/channel-manager settings (many keep scans: disable it or set automatic deletion); 4) update the privacy notice and the Art. 30 record with the real retention period.

Why it matters for your clients

It is the classic case of 'we have always done it this way' meeting the GDPR: the photocopy at the front desk is a deep-rooted habit that now has an explicit pronouncement against it. For a DPO with tourism clients it is a quick, concrete win that owners immediately understand.

Official source:Italian Data Protection Authority - notice to hoteliers on retention of guests' documents

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Italian DPA
12keuro

Misconfigured document register: 12,000 euro fine for the Metropolitan City of Sassari

Following a data breach notification and a complaint, the Italian data protection authority fined the Metropolitan City of Sassari for misconfiguring its electronic document register, making documents containing personal data accessible to staff who, given their role and duties, were not authorised to process them. The fine is 12,000 euro, but the principle applies to every public body and every company running a document management system: filing is not a neutral activity, and a default of total visibility breaches the principles of integrity and confidentiality.

Jul 29, 2026 6 min
Italian DPA
2/2genitori

Children's photos on social media: both parents must consent

In its 17 June 2026 newsletter the Italian DPA restated a principle that matters well beyond family disputes: publishing photos of minor children on social media requires the consent of BOTH parents. In case of disagreement, the child's protection prevails. For the DPO it is an operational criterion affecting schools, nurseries, sports clubs, parishes and companies publishing images of minors for promotional purposes.

Jul 15, 2026 3 min
Italian DPA
37,7MEUR

Italian DPA annual report: collected fines +54.5%, almost 7 data breaches notified per day, AI at the centre

On 2 July 2026 the Italian DPA presented its 2025 activity report to Parliament: 807 collegial decisions, 506 corrective and sanctioning measures, over EUR 37.7 million in fines collected (+54.5% on 2024), 2,415 data breaches notified (+10%), 130 inspections. AI takes centre stage: from DeepSeek to deepfakes, from facial recognition at the airport to worker surveillance.

Jul 02, 2026 4 min