Skip to main content

GDPR compliance for hoteliers

Which parts of GDPR touch guest messaging, what to set up in Bookboost, and where the responsibility sits.

Bookboost is the tool you use to reach guests. Compliance with GDPR and any other data protection law that applies to you is the hotelier's responsibility, not Bookboost's, and Bookboost does not assume liability for how the platform is used against your legal obligations.

This article maps the parts of GDPR that touch guest communication onto the features that support them. It is not legal advice, and it is not a substitute for advice from someone qualified in your jurisdiction.

The principles that apply to guest messaging

  • Consent. Guests must explicitly agree to marketing communications. Operational messages about a stay generally rest on a different basis.

  • Right of access and erasure. Guests can ask what data you hold, and can ask you to delete it.

  • Data protection. Personal information has to be handled securely.

  • Purpose limitation. Data collected for one purpose should be used for that purpose.

Where this bites in Bookboost

  • Sending marketing campaigns: Broadcasts, newsletters, promotions.

  • Running guest journey communications, such as booking confirmations and pre-stay messages.

  • Importing and storing guest profiles.

  • Handling a guest's request to have their data removed.

What to set up

  • Collect consent properly. Define what you are asking for, and record where it came from. See Collecting marketing consent and Consent configurations.

  • Understand the statuses. Granted, implicit, pending, and revoked each mean something different to a campaign. See Consent management essentials, which also covers the consent dates you will need for an audit.

  • Give guests a way out. An unsubscribe route in every marketing message. See Set up opt-out and unsubscribe options.

  • Keep external systems in step. A PMS integration can sync consent both ways, and the API can push newsletter subscriptions in from your own platforms, so a guest who opts out in one place is not still marketable in another.

  • Watch your opt-outs. Campaign reports show unsubscribe trends, which is both a compliance signal and a deliverability one.

What this does not do

  • Bookboost does not make you compliant. It records and respects consent. Whether your setup meets the law where you operate is your decision, and worth checking with your own advisers.

  • Rules differ by country. GDPR is applied differently across member states, and some countries add their own requirements on top. Check local law.

  • Retention obligations can conflict with erasure. Some countries require hotels to keep reservation data for a set period, which limits what you can delete on request.

  • Pending double opt-ins stay pending. A guest who never confirms is not marketable, and no reminder is sent automatically.

  • Spam complaints affect more than compliance. A high complaint rate can restrict your email deliverability regardless of whether your consent records are in order.

What to do next

Start with Consent management essentials, which is the foundation the rest of this collection builds on.

Getting help

Open Help at the bottom of the left menu and choose Talk to Us, or email support@bookboost.io.

Did this answer your question?