
Guest Screening and Privacy: What You May Collect, and What You May Not
Registration rules ask hosts to record specific facts and report them within a day. They rarely ask for an image, and Spain's data protection authority said on 17 June 2025 that requesting one exceeds data minimisation. This article compares the Spanish and Italian register duties, sets out the controller obligations that follow, and shows how to keep a compliant file without keeping documents.

Registering a guest is a legal duty. Keeping a photo of their passport is a separate act nobody asked for, and one regulator has already priced it.
Last updated: September 22, 2026
Registration rules ask hosts to record specific facts about a person and report some of them within a day. In Spain that means collecting the Annex I traveller data set under Royal Decree 933/2021 and reporting it through SES.HOSPEDAJES within 24 hours of the service starting. In Italy it means verifying the identity document of every guest and notifying the Questura within 24 hours of arrival. Both of those duties attach to the data. Neither of them attaches to the picture — and on 17 June 2025 the Spanish data protection authority said in terms what many hosts assumed rather than checked. What follows sets out what each system actually asks for, the privacy obligations that attach once you hold it, and how to keep a check-in file that satisfies the register without keeping documents nobody gave you a reason to keep.
Key Takeaways
- Registration is not photocopying. Both regimes require recorded data; neither requires an image of the document.
- Spain: twenty-four hours, three years. Annex I data reported to SES.HOSPEDAJES within 24 hours of start, retained three years from the end of the service.
- Italy: presence first, then twenty-four hours. Each guest's ID checked with the guest there, Questura notified within 24 hours of arrival, receipts kept five years.
- Your legal basis is a duty, not consent. Under GDPR Article 6(1)(c), asking a guest to tick "I agree" weakens rather than strengthens your position.
- Keep the field, delete the image. Record what the register lists; discard what only habit ever justified keeping.
Why registration duty is not copying duty
Two separate acts happen at a check-in, and they get confused because both involve the same document. Verification is satisfying yourself and the authority that the person in front of you is who they say they are. Retention is keeping something afterwards. Registration law in both Spain and Italy is explicit about the first and largely silent about the second, and silence is not permission.
The Spanish obligation under Royal Decree 933/2021 is to collect the Annex I data set and transmit it through SES.HOSPEDAJES within 24 hours of the service starting, keeping records for three years from the service ending. The listed fields are conventional: name, gender, document type and number, nationality, date of birth, usual residence, telephone, email, number of occupants, family relationship for minors, and the contract, arrival, departure, property and payment details. Note what is absent from that list — a picture of anything.
Italy runs along similar lines. Article 109 of the consolidated public security law requires every guest's valid identity document to be checked and notified to the Questura within 24 hours of arrival, with Alloggiati Web receipts retained for five years. Italy goes further than Spain on verification: a Ministry of the Interior circular in 2024 and a Council of State decision of 21 November 2025 confirmed that the check has to happen with the person present, or through a device at the door as the person enters. That is a harder operational constraint, but it still concerns the moment of arrival rather than what you keep for the next five years.
The distinction matters commercially because a copy is a liability with no offsetting benefit. If a phone holding photographs of forty passports goes missing, the first question asked is why you held them at all. "Registration required it" is a poor answer, because it did not. Media reports put practical fines here at the €30,000 and €25,000 level, though those are press figures rather than a schedule anyone should plan against.
It also changes what you can safely hand to someone else. Most hosts do not greet every guest in person; a cleaner, a co-host or a neighbour does, and that person needs an arrival window and nothing else. Availability and rates for Airbnb, Booking.com, Agoda and Trip.com sit on one grid at localsbnb.com, so handing somebody the running of a particular week does not mean handing them a folder of guest documents. That separation is far easier to maintain before the folder exists than after.

Two national systems, read side by side
Beside each other, the deadlines look close and the mechanics do not.
| Requirement | Spain — RD 933/2021 | Italy — Art. 109 TULPS |
|---|---|---|
| What is recorded | Annex I traveller data set | Valid identity document of each guest |
| Reporting channel | SES.HOSPEDAJES | Questura, via Alloggiati Web |
| Deadline | 24 hours from service start | 24 hours from arrival |
| Retention | 3 years from end of service | Receipts retained 5 years |
| Verification | As collected, no presence rule | With the guest present, or door device on entry |
Two consequences follow. First, the clock is short in both countries and it starts at arrival rather than at departure, so whatever you do with the data has to happen inside the first day — in practice before the guest has finished unpacking. Second, retention outlasts interest. Three years and five years both exceed the window in which you would contact that guest about anything, so the record is archive material for most of its life.
One further difference is easy to assume in the wrong direction. Spain's regime is not built around face-to-face verification, so a self check-in handled entirely remotely still carries its own reporting duty. Italy's regime is built around presence, and the 2024 circular plus the Council of State ruling of 21 November 2025 have tightened rather than relaxed it. Operating in both means running the stricter discipline in both, since the deadline is identical anyway.
What follows once you are the controller
Collecting mandated data makes you its controller, and the obligations that follow do not depend on the collection having been your idea.
The first is the basis. Under Article 6(1)(c) GDPR, processing required by law rests on legal obligation, not consent. That has one counterintuitive consequence: a check-in form with a box reading "I agree to the processing of my data" does not help you. Consent can be withdrawn, and offering it implies a choice that does not exist. The useful line on the form is one stating the purpose and pointing to your notice.
The second is notice. Article 13 requires that the guest be told at the point of collection who you are and how to reach you, why you are processing, on what legal basis, the categories of recipients, and whether anything goes outside the EEA. It belongs where details change hands, not inside a link nobody opens.
The third is afterwards. Mandated retention is a floor, not a licence: keeping the register entry does not entitle you to reuse the same names for a mailing list, and having seen a document once is not a reason to hold a second copy of it indefinitely. Write down when you collected, when you reported, and when deletion becomes due. Guest names, phone numbers and identity numbers are masked in the interface, and access is granted per domain — worth checking how your own tooling behaves before a season starts.

A check-in file that satisfies both
The test people actually remember at the door is short: keep the field, delete the image. Everything else is the working version of that sentence.
| Keep, because the register asks for it | Drop, because nothing asks for it |
|---|---|
| The listed traveller fields, captured as text | A photo or scan of the identity document |
| The transmission receipt and its timestamp | A duplicate sitting in a personal inbox |
| A dated copy of the notice you handed over | Payment details past the point they are needed |
| Proof of when and to whom you reported | A further copy of a minor's document where the relationship field covers the minor (inferred) |
Two habits carry most of the weight. Capture directly into whatever holds the property's records rather than into a personal phone gallery, so the register entry and the guest record cannot drift apart. Set the deletion date when you create the record rather than when you remember it — three- and five-year walls are invisible until someone asks you to prove when they began.
Screening itself is unaffected by any of this. Nothing in these regimes stops you from declining a booking, from asking what brings someone to town, or from requiring a signed agreement. What stops is the assumption that because you were entitled to see a document, you were entitled to store a likeness of it. If part of the answer is working with tools that do not require a folder of documents to function in the first place, that is worth judging with your own eyes at localsbnb.com.

FAQ
Does Spanish law actually let me refuse to photograph a passport?
Yes, in the sense that no listed field under Royal Decree 933/2021 is an image, and the AEPD stated on 17 June 2025 that requesting copies exceeds the data minimisation required by Article 5.1.c GDPR. Record the document type and number and report them; do not retain the photograph. Confirm specifics with a local adviser before changing what you already do.
Should I still ask guests to tick a consent box?
No. Where processing is mandated, Article 6(1)(c) supplies the basis and consent is the wrong instrument — it can be withdrawn and it misdescribes why you are asking. Replace the tick box with a short reference to the purpose and a pointer to your Article 13 notice.
How long should I keep register data if I want to welcome repeat guests?
Keep it for the statutory period and then delete it. The retention period exists for the regulator, not for your marketing, and reusing mandated data for a new purpose is its own problem. If you want to contact guests again, that relationship needs its own basis and its own record.
None of this adds a minute to a check-in done properly, and most of it removes something instead: an image you were never obliged to take, in a place you cannot properly control. Start with the smallest change, which costs nothing — stop asking for the copies. If you want availability, rates and all four of your channels sitting behind one login instead of several, you can start free with LOCALSBNB.
Requirements differ by country and city and they change; treat everything above as a starting point and confirm the current position with the authority in the place your property sits. This page is information, not legal advice. LOCALSBNB provides software, not legal advice.
审核
Localsbnb 内容团队