Hotels, Stop Hoarding Guest IDs: Italian Privacy Watchdog Says Delete!

Table of Contents
What Just Happened?
If you've ever handed over your passport at a hotel check-in and wondered where that photocopy ends up, the Italian Data Protection Authority (Garante Privacy) just gave you a satisfying answer: it should be shredded, not stored.
In a recent clarification, the Garante stated that hotels cannot keep copies of guests' identification documents after they've been communicated to the police. This isn't a suggestion—it's a legal obligation under the GDPR's principles of data minimization and proportionality.
Featured Snippet: Why can't hotels keep copies of guest IDs?
Hotels must delete or destroy copies of guest documents immediately after reporting them to authorities. Retaining them violates GDPR data minimization, as the purpose (security reporting) is fulfilled. Keeping them longer is simply hoarding personal data without a valid legal basis.
The Data Minimization Principle: Less is More
Remember when your mom told you to clean your room and you'd hide things under the bed? That's essentially what some hotels have been doing with your data—except the Garante is the mom who checks under the bed. The GDPR's data minimization principle means organizations should only collect what's strictly necessary for a specific purpose. Once that purpose is served, the data must go.
What Does This Mean for Travelers?
For guests, this is a win for privacy. No more worrying about your passport copy sitting in a dusty drawer for years. For hotels, it's a reminder that data hygiene is as important as clean sheets. You can't keep a digital copy 'just in case.' If you do, you're breaking the law.
A Practical Analogy
Think of it like returning a borrowed book. You read it, you give it back. You don't photocopy every page and keep it forever—that would be weird and unnecessary. Hotels should treat your ID the same way: use it, report it, delete it.
What Are the Penalties?
Non-compliance can lead to fines under GDPR up to €20 million or 4% of annual global turnover, whichever is higher. The Garante has not hesitated to impose significant penalties in similar cases. Hotels should take this seriously—it's cheaper to shred than to pay.
How to Complain
If you suspect a hotel is keeping your ID copy after check-out, you can file a complaint with the Garante Privacy. They have a straightforward online form and a history of acting on consumer reports. Your data is worth protecting.
Steps Hotels Must Take
- Establish a clear procedure for destroying copies immediately after police reporting.
- Train staff on data minimization and deletion timelines.
- Review current retention policies and purge any historical copies.
- Implement technical measures to ensure automatic deletion of digital scans.
Legal Background
The Garante's decision aligns with Article 5(1)(c) of the GDPR, which requires personal data to be 'adequate, relevant and limited to what is necessary.' For more details, check the full GDPR text on EUR-Lex.
FAQ
Can hotels keep copies of my ID for their own records?
No, once the copy has been communicated to the authorities for security purposes, the legal basis expires. Keeping a copy for any other reason (e.g., marketing, loyalty programs) would require separate consent and a different legitimate purpose.
What if I check out and they haven't deleted my data?
You can file a complaint with the Garante Privacy. Hotels are required to have retention and deletion policies. If you suspect your data is being kept longer than necessary, you have the right to request erasure under Article 17 GDPR (right to be forgotten).
Does this apply to digital scans or just paper copies?
It applies to all forms of copies, whether paper, scanned PDF, or digital photo. Once the reporting obligation is met, all copies must be destroyed or permanently deleted.

NakedPact Editorial Committee
Article created by the NakedPact editorial team. Our mission is to analyze, simplify, and expose unfair terms and hidden risks in everyday contracts to protect citizens and consumers.
Sources and Legal References

Do you own a website?
Want to communicate your data processing transparency to your users? Dynamically use our badge and showcase your platform's compliance.
Recommended Readings
🛡️ Protect your rights with one click
Don't risk signing abusive clauses. Install the free NakedPact extension for Chrome or Firefox and instantly analyze any contract on the web.
Don't trust, verify.
Now that you know the risks, don't sign blindly. Upload your contract to NakedPact and let AI find the hidden clauses for you. It's 100% free.
Analyze Your Contract Now
