Data Protection for Hotels and Hospitality
Introduction
Swiss hotels and hospitality businesses process guest data every day – identity data (for the foreign nationals' notification duty), payment data, allergies and preferences, reviews, loyalty data, and video recordings from the lobby. They operate at the intersection of the revised Federal Act on Data Protection (DSG), the Foreign Nationals and Integration Act with the notification duty under Art. 16 AIG (formerly AuG), PCI DSS requirements imposed by the card networks, industry guidance from hotelleriesuisse and GastroSuisse, and – for EU guests and booking platforms – the GDPR. Mishandled in 2026 this exposes the operator to fines under Art. 60 DSG, PCI-related sanctions (withdrawal of card acceptance) and – not to be underestimated – TripAdvisor damage from visible incidents.
What this article delivers:
- How to select and run a PMS and restaurant software in compliance
- Payment data, PCI DSS and tokenisation
- Marketing consent and loyalty programmes done properly
- Operating the Schengen notification duty under Art. 16 AIG cleanly
- Video, smart-lock data and employee data
- A 10-point checklist for hotel management and front office
Legal framework
Swiss hotels and hospitality businesses operate under at least five parallel bodies of law:
- FADP: processing of guest and employee data; information, access, rectification and notification duties.
- GDPR: applies to guests from the EU/EEA (marketplace principle, Art. 3(2) GDPR), where booking-platform contracts originate in the EU, and to marketing in the EU.
- AIG/AIV with Art. 16 AIG (notification duty): hotels must report the presence of foreign guests to the competent cantonal authority. In practice this is done through electronic registration services (CheckIN, eMeldedienst, KIDS) per cantonal rules.
- PCI DSS v4.0: card-accepting merchants commit to compliance; minimum requirements vary by SAQ level (SAQ A, A-EP, B, B-IP, C, D) independent of Swiss law.
- Industry concordats: hotelleriesuisse classification, cantonal tourism laws, association privacy guidance.
For most Swiss hotels: the DSG forms the foundation, GDPR and PCI DSS overlay locally, and the AIG notification duty is an everyday operational matter. Hotels systematically processing EU guests need a dedicated GDPR privacy notice and, where applicable, an EU representative.
PMS and restaurant software
The Property Management System (PMS) is the heart of data processing in a hotel. Common 2026 Swiss solutions include Protel, Mews, Apaleo, Oracle Opera Cloud, Casablanca, Lobbi and smaller Swiss vendors. Data-protection-relevant selection criteria:
- Data location: Switzerland or EU/EEA; sub-processor transparency; clean DPA under Art. 9 DSG.
- Tokenisation: card data is tokenised by the payment service provider and not stored in the PMS. If the PMS stores plaintext PAN, configuration must change or the system must.
- Roles and permissions: reception, reservations, accounting and management have different rights; need-to-know on special requests and allergies (sensitive data).
- Audit logs: complete access logging retained for at least 12 months.
- Data return and erasure: on contract end and on request per Art. 32 DSG.
- Interfaces: channel managers (SiteMinder, D-EDGE, Cubilis), booking platforms (Booking.com, Expedia), trust and accounting systems – every interface needs its own DPA and purpose check.
Restaurant POS systems (Gastrofix, Aera, Tiller, Lightspeed) process payment data, employee and tip data, and ordering behaviour. Reservation platforms (OpenTable, Bookatable, local Swiss tools) transmit guest data to third parties – the privacy notice must say so transparently.
Payment data and PCI DSS
Hotels and hospitality businesses are merchants in the card ecosystem and bound by PCI DSS v4.0 regardless of transaction volume. Most Swiss SME hotels operate as SAQ A or SAQ A-EP through a hosted payment page or PSP tokenisation (Worldline/SIX, Datatrans, Wallee, Adyen), so card data never enters the hotel network. This architecture is strongly recommended in 2026 – it significantly reduces compliance burden and minimises risk from hotel Wi-Fi, employee access and front-office PCs.
Frequent weaknesses found in on-site audits: PAN in e-mails from guests, handwritten notes with card numbers for no-show charging, shared front-office logins, unpatched POS endpoints, missing network segmentation between guest Wi-Fi and hotel network, insufficiently encrypted backups. Payment data is not automatically "sensitive personal data" under Art. 5(c) DSG, but the harm leverage is so high that it must be treated as such. A breach with card PAN exfiltration triggers Art. 24 DSG notification, information of guests, and immediate notification to the acquirer and the card networks. Pre-prepared response plans are mandatory.
Schengen registration and guest data
Swiss hotels are required under Art. 16 AIG to report the presence of foreign guests to the competent cantonal authority. Operationally this is handled via cantonal electronic registration services (e.g. CheckIN BS/BL, eMeldedienst ZH, ZeroEntry, eGuest, KIDS) with electronic transmission after front-office capture.
From a data-protection standpoint: the notification duty is a statutory obligation; processing is grounded under Art. 31(1)(c) DSG. The hotelier must:
- Inform guests in the privacy notice about this processing and its legal basis.
- Not retain or repurpose collected data beyond the statutory requirement – registration data is not for marketing.
- Observe the cantonal retention period (typically 6 months). Erase after expiry.
- Transmit data to the cantonal authority through secure channels (TLS, authentication).
- Distinguish: Swiss guests are not subject to the notification duty – collection must reflect that.
Passport and ID copies are only permissible where statutorily required, and only for identity verification (Art. 16 AIG). Systematic storage of passport scans in the PMS is data-protection-problematic and unnecessary from a PCI standpoint – a single visual check plus entry into the registration system suffices.
Marketing, loyalty and reviews
Hotels run active marketing: newsletters, birthday specials, return-guest offers, loyalty programmes, partnerships with restaurants and event organisers, presence on review platforms. The 2026 ground rules:
- Newsletters: double opt-in, documented consent, clear unsubscribe, separation between booking confirmation (legitimate, no consent) and marketing (consent required).
- Birthday specials and personalisation: profiling under Art. 5(f) DSG; information in the privacy notice sufficient where risk is low; for extensive segmentation with behaviour analytics a DPIA is wise.
- Loyalty programmes: separate consent with clear information about data use, retention, sharing with programme partners (important in hotel chains and alliances).
- Post-stay review requests: mailings without consent are tolerable as customer communication with a clearly visible unsubscribe; be restrictive on multiple sends.
- Replies to reviews: avoid personal references in the reply; even where the guest signed a review by name, do not disclose additional stay details.
- Social-media photos of guests: consent required, including for weddings, parties and special events.
Video, smart locks and employee data
Video surveillance in hotels is common (lobby, garage, lift) and permitted under cantonal law and FDPIC guidance where: there is a legitimate purpose (security, evidence), clear signage (pictogram plus reference to privacy notice), short retention (typically 72 hours) and a tightly defined access circle (management, security lead). Recordings in guest rooms or sanitary areas are not permitted. Microphones and speakers in smart TVs or voice assistants in rooms require information and, in doubt, opt-out.
Smart locks (Salto, dormakaba, Häfele) log access per key card or app. These logs allow movement profiling of guests and staff – they must be strictly purpose-bound (security, damage investigation), never repurposed for staff performance monitoring. Employee data is governed by its own obligations: HR file, employment contract, payroll, possibly a tip system. The FDPIC has marked the limits of employee monitoring (Art. 26 OLA 3) in several statements: performance and behaviour monitoring only under strict conditions, no blanket tracking, clear information. Tip distribution, shift scheduling and engagement surveys are also data-protection-relevant and need clear rules.
How SIDD supports you
SIDD supports Swiss hotels from boutique guesthouses to chains with pragmatic data-protection and security advice. We deliver a hotel-specific privacy notice in multiple languages, DPA templates for PMS, channel managers, booking platforms and accountants, a PCI DSS readiness assessment, an incident handbook and staff training material. Our data-protection adviser mandate for hospitality is tailored to daily operations. For hotels with relevant EU guests we add the GDPR DPO and, where applicable, the EU representative under Art. 27 GDPR. On the security side we recommend an annual vulnerability scan of the hotel infrastructure and – for larger properties – a penetration test including a Wi-Fi audit. Our IT security workshops for hotel teams cover phishing, card hygiene and incident response. Speak with us via our contact form or request a quote.
