Back to Blog
LegalTech & IA

Hotels, Stop Hoarding Guest IDs: Italian Privacy Watchdog Says Delete!

NakedPact Editorial Committee
Reviewer: Carmelo G.
Comitato Editoriale NakedPact
July 20, 2026
10 min read
Hotels, Stop Hoarding Guest IDs: Italian Privacy Watchdog Says Delete!

What Just Happened?

If you've ever handed over your passport at a hotel check-in and wondered where that photocopy ends up, the Italian Data Protection Authority (Garante Privacy) just gave you a satisfying answer: it should be shredded, not stored.

In a recent clarification, the Garante stated that hotels cannot keep copies of guests' identification documents after they've been communicated to the police. This isn't a suggestion—it's a legal obligation under the GDPR's principles of data minimization and proportionality.

Hotels must delete or destroy copies of guest documents immediately after reporting them to authorities. Retaining them violates GDPR data minimization, as the purpose (security reporting) is fulfilled. Keeping them longer is simply hoarding personal data without a valid legal basis.

The Data Minimization Principle: Less is More

Remember when your mom told you to clean your room and you'd hide things under the bed? That's essentially what some hotels have been doing with your data—except the Garante is the mom who checks under the bed. The GDPR's data minimization principle means organizations should only collect what's strictly necessary for a specific purpose. Once that purpose is served, the data must go.

What Does This Mean for Travelers?

For guests, this is a win for privacy. No more worrying about your passport copy sitting in a dusty drawer for years. For hotels, it's a reminder that data hygiene is as important as clean sheets. You can't keep a digital copy 'just in case.' If you do, you're breaking the law.

A Practical Analogy

Think of it like returning a borrowed book. You read it, you give it back. You don't photocopy every page and keep it forever—that would be weird and unnecessary. Hotels should treat your ID the same way: use it, report it, delete it.

What Are the Penalties?

Non-compliance can lead to fines under GDPR up to €20 million or 4% of annual global turnover, whichever is higher. The Garante has not hesitated to impose significant penalties in similar cases. Hotels should take this seriously—it's cheaper to shred than to pay.

How to Complain

If you suspect a hotel is keeping your ID copy after check-out, you can file a complaint with the Garante Privacy. They have a straightforward online form and a history of acting on consumer reports. Your data is worth protecting.

Steps Hotels Must Take

  • Establish a clear procedure for destroying copies immediately after police reporting.
  • Train staff on data minimization and deletion timelines.
  • Review current retention policies and purge any historical copies.
  • Implement technical measures to ensure automatic deletion of digital scans.

The Garante's decision aligns with Article 5(1)(c) of the GDPR, which requires personal data to be 'adequate, relevant and limited to what is necessary.' For more details, check the full GDPR text on EUR-Lex.

FAQ

Can hotels keep copies of my ID for their own records?

No, once the copy has been communicated to the authorities for security purposes, the legal basis expires. Keeping a copy for any other reason (e.g., marketing, loyalty programs) would require separate consent and a different legitimate purpose.

What if I check out and they haven't deleted my data?

You can file a complaint with the Garante Privacy. Hotels are required to have retention and deletion policies. If you suspect your data is being kept longer than necessary, you have the right to request erasure under Article 17 GDPR (right to be forgotten).

Does this apply to digital scans or just paper copies?

It applies to all forms of copies, whether paper, scanned PDF, or digital photo. Once the reporting obligation is met, all copies must be destroyed or permanently deleted.

Hotel Compliance Checklist

  • Train staff on data deletion procedures
  • Implement automatic deletion after report
  • Purge all historical copies
  • Update privacy policy
  • Conduct annual data audit
NakedPact Logo

NakedPact Editorial Committee

Article created by the NakedPact editorial team. Our mission is to analyze, simplify, and expose unfair terms and hidden risks in everyday contracts to protect citizens and consumers.

Do you own a website?

Do you own a website?

Want to communicate your data processing transparency to your users? Dynamically use our badge and showcase your platform's compliance.

🛡️ Protect your rights with one click

Don't risk signing abusive clauses. Install the free NakedPact extension for Chrome or Firefox and instantly analyze any contract on the web.

Don't trust, verify.

Now that you know the risks, don't sign blindly. Upload your contract to NakedPact and let AI find the hidden clauses for you. It's 100% free.

Analyze Your Contract Now

Rispettiamo la tua privacy

Usiamo i cookie per migliorare la tua esperienza e personalizzare gli annunci. Scopri di più.

NakedPact Logo

Estensione Chrome

Analizza i contratti e i Termini di Servizio direttamente sul tuo browser con l'estensione NakedPact.