The short answer
There is no single legal number for how long a hotel may keep guest data. The storage-limitation principle requires that personal data be kept only as long as the purpose it serves still justifies it, and never indefinitely 'just in case.' So split guest data by purpose — booking, billing, security, loyalty — set a documented retention period for each category, respect statutory floors for accounting and tax records, and delete or anonymise data once the purpose ends or the legal minimum expires.
Key takeaways
- There is no single retention period for all guest data; under the storage-limitation principle the period follows the purpose of processing.
- Split data by category — registration, booking, billing, payment, loyalty, Wi-Fi and CCTV — because each has its own purpose, legal basis and period.
- Respect statutory floors for accounting and tax records, which often justify keeping invoices several years after check-out.
- Registration or police forms, CCTV and Wi-Fi logs are short-lived by design and should not become open-ended customer history.
- Document a retention schedule and enforce it through automation and periodic review, making sure deletion also covers backups.
- Marketing and loyalty data should expire a defined period after the last active contact unless consent is renewed.
- Deletion should pause when a dispute, inspection or claim is pending; get qualified advice for multi-jurisdiction operations.
Retention is a purpose decision, not a hoarding habit
Keeping every guest file 'just in case' is easy when storage is cheap, but it is exactly what data-protection rules discourage. The storage-limitation principle in Article 5(1)(e) of the UK GDPR and the equivalent principle in the EU GDPR requires that personal data be kept in an identifiable form only as long as necessary for the purposes for which it is processed. Regulators put it bluntly: you must not keep data indefinitely 'just in case' or when there is only a small chance you will use it.
Retention is therefore a decision made record by record against the purpose that justified collecting the data. The law does not set one universal number of days or years for hotels. Instead, you must be able to justify each period you choose and document it in a policy or retention schedule. If you cannot explain why a record still exists, you are unlikely to have a lawful basis for holding it, and stale data inflates the cost of storage, security and subject-access responses.
- Identify the purpose before you decide how long to keep a record.
- Justify each period in writing; a retention schedule supports documentation duties.
- Review holdings regularly and erase or anonymise what is no longer needed.
- Deleting from live systems is not enough — handle backups and offline copies too.
Guest data is not one single category
A hotel collects far more than a name and a folio number. Identity and registration details, booking and contact information, payment card data, stay preferences, consumption history, Wi-Fi connection logs, loyalty profiles and CCTV images each follow different purposes and different legal bases. Because the retention period is tied to purpose, you cannot apply one deletion date to an entire guest profile.
Practical splits that matter: contract data needed to run the stay (usually deleted soon after check-out unless a longer basis applies); billing and tax records that must survive for statutory periods; security footage that answers a short window of incidents; and marketing data that survives only while consent is valid and recent. Special categories such as allergies or health notes deserve the strictest minimisation and earliest deletion.
- Identity and registration records support the stay and regulatory duties.
- Payment card data should not sit on hotel servers; use a PCI-compliant provider.
- Loyalty and marketing profiles depend on consent and expire after the last contact.
- Wi-Fi logs and CCTV answer narrow security purposes and should be short-lived.
Benchmarks: legal floors, not universal answers
There is no fixed GDPR time limit for each type of data, so you set periods based on purpose — but you must respect statutory floors and sector practice. Where an invoice or accounting document contains guest data, the business record normally has to be kept for the statutory accounting period, which in several European countries runs to about eight to ten years. That obligation is what justifies the retention even after the guest relationship ends.
Sector practice in some markets offers useful reference points, and it varies by country. In France, for example, police registration forms for non-EU guests are typically held about six months and then destroyed, prospecting and loyalty data are generally limited to three years after the last active contact, and CCTV is commonly kept around thirty days unless an incident requires longer. In the United States, tax-related guest records such as registration cards and folios are often kept about four years, and individual states may add their own minimums.
- The figures above are market examples, not legal advice; always check national and state rules.
- Registration and police forms usually have a short, authority-driven window, not indefinite history.
- Marketing and loyalty data is generally cut off a few years after the last contact, with consent renewed.
- CCTV and Wi-Fi logs are kept longer only while an incident is being examined.
Building a defensible retention schedule
Start with an inventory of every place guest data lives: the property management system, booking engine, channel manager, email and marketing tools, Wi-Fi provider, loyalty database, payment gateway and camera system. For each, list what data is collected, the legal basis and the purpose. Only then can you assign a realistic retention period instead of a blanket 'keep it all.'
For each processing activity set a documented standard retention period: the active period while the purpose is live, an archiving step for legal or claim reasons where needed, and a deletion trigger. Apply the earlier of 'purpose achieved' or 'fixed term expired' unless a statutory minimum forces longer. Keep the schedule flexible enough for early deletion, for example when a guest exercises the right to erasure.
- Inventory every system and every data field you collect.
- Record the legal basis and purpose next to each category.
- Define active period, archiving step and deletion trigger separately.
- Apply early deletion whenever a guest withdraws consent or requests erasure.
Making deletion happen
A retention policy that nobody enforces is nearly worthless. Automate what you can: configure the property system and marketing platform to flag or purge records at the end of their period, and schedule periodic reviews of anything held on a discretionary basis. Fewer manual steps mean less risk that old profiles quietly survive for years.
Decide between deletion and anonymisation. Deletion must also cover backups and archived copies; simply moving data offline still counts as processing. Anonymise where you need aggregate statistics without identifying individuals. Remember that an individual can request erasure at any time, and you must be able to act on that request promptly and show that you did.
- Automate flagging and deletion at the end of each record's period.
- Review discretionary holdings on a fixed schedule.
- Delete from backups and archives, not only from the live database.
- Anonymise where only statistics are needed, not identities.
Limits, jurisdiction and when to get advice
All of this is general guidance, not legal advice. Periods differ across the EU, the UK, the US and other jurisdictions, and chains operating in several countries face overlapping rules. If a dispute, inspection or claim is pending, retention may legitimately be frozen — always confirm before deleting records relevant to active proceedings.
Special-category data such as health information should be kept only for a clearly justified purpose and erased as soon as it is no longer needed. For a single independent property, a few hours of careful mapping and a simple written schedule usually bring most of the benefit; for international chains, sensitive processing or a breach, a qualified data-protection lawyer should review the approach.
Put it into practice
Guest Data Retention Decision Matrix
A fill-in template to decide, for each data category, the purpose, legal basis, benchmark period and deletion trigger. Complete it once for your property, then review yearly or whenever you change tools or purposes.
- Identity and registration records — purpose: run the stay and meet registration duties — benchmark: active stay plus short compliance window — trigger: delete once purpose ends unless a legal floor requires more.
- Booking and contact details — purpose: perform the reservation — benchmark: through the stay plus booking-related claim period — trigger: delete afterwards unless consent extends marketing use.
- Invoices, folios and tax documents — purpose: accounting and tax compliance — benchmark: statutory accounting period (commonly several years) — trigger: delete after the statutory floor expires.
- Payment card data — purpose: take payment — benchmark: do not store full card data on hotel systems — trigger: route via a PCI-compliant provider with its own limits.
- Loyalty and marketing profiles — purpose: personalised offers — benchmark: a defined period after the last active contact — trigger: delete unless consent is renewed.
- Wi-Fi connection logs — purpose: network security and traceability — benchmark: short defined window — trigger: delete at the end of the window.
- CCTV footage — purpose: safety of people and property — benchmark: days to about a month — trigger: delete earlier if no incident; retain longer only while an incident is examined.
- Special-category data (allergies, health notes) — purpose: specific service — benchmark: minimum necessary — trigger: erase as soon as the purpose ends.
- Subject-access and erasure requests — purpose: honour rights — benchmark: log each request — trigger: export or delete within the required timeframe and record the action.
- Review of this matrix — purpose: keep the schedule current — benchmark: annual or event-based review — trigger: update when you add tools or change purposes.
Questions people ask
What is the storage-limitation principle and what does it require hotels to do?
The storage-limitation principle, in Article 5(1)(e) of the GDPR and the equivalent UK GDPR provision, requires that personal data be kept in a form that allows identification only as long as necessary for the purposes for which it is processed. For hotels this means you may not keep guest data indefinitely 'just in case.' You must set a retention period for each purpose, document it in a policy or schedule, review what you hold regularly and erase or anonymise data once the purpose ends.
Is there a single time limit for how long a hotel can keep guest data under the GDPR?
No. The GDPR does not set specific time limits for different types of data; it is up to the hotel to justify each period based on its purposes. However, you must respect statutory retention floors that apply to certain records, such as accounting and tax documents, which often must be kept for several years. Because these obligations justify retention even after the guest relationship ends, they are an important input to your schedule.
Which guest data can a hotel keep after check-out, and for how long?
Contract data needed only to run the stay should generally be deleted soon after check-out. What can be kept longer depends on purpose: invoices and tax records for the statutory accounting period; registration or police forms for the short period authorities require; loyalty and marketing data for a defined period after the last active contact unless consent is renewed; and CCTV or Wi-Fi logs only for a short security window, longer only while an incident is examined.
Do loyalty and marketing databases need a different retention period from stay records?
Yes. Marketing and loyalty data are processed on a different basis — usually consent — and therefore should not be kept for the full length of a business or tax record. A common practice in several European markets is to delete prospecting and loyalty data three years after the last active contact unless the guest renews consent. You must also be able to act quickly when a guest withdraws consent or requests erasure.
Can a hotel keep CCTV footage of guests indefinitely?
No. CCTV footage of identifiable people is personal data and should be kept only for a short period that matches the security purpose, for example days to about a month, and longer only when an incident is being investigated or a crime has been reported and authorities need time to collect the material. Keeping footage indefinitely 'just in case' is not compatible with the storage-limitation principle.
What should a hotel do when a guest asks for their data to be deleted?
The guest has a right to erasure where you no longer need the data for the purposes for which it was collected. Review all systems where the data may live, including backups and archives, and delete or anonymise accordingly within the required timeframe. You may keep records that a statutory obligation requires you to retain, such as invoices for accounting purposes, but you should explain this to the guest and confirm what has been removed.
If national law sets a retention period, does it override the GDPR storage-limitation rule?
A genuine statutory retention duty is a legitimate reason to keep personal data longer than the GDPR's general 'no longer than necessary' rule, because the purpose of complying with law continues to apply. This is common with accounting and tax records or registration obligations. The caveat is that the longer retention must actually be required by a specific rule for that record, not a general assumption, and you should document that legal basis in your retention schedule.
Sources and further reading
Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.
- Principle (e): Storage limitationInformation Commissioner's Office (ICO)
- GDPR in Hospitality: Managing Customer Data Without RiskGetWelcom
- Common Record Retention Time PeriodsTexas Hotel and Lodging Association
- Работа с персональными данными в гостиничном бизнесеКонтур (СКБ Контур)
- 152-ФЗ для гостиниц и отелей: какие документы нужныCyberOsnova
- Сроки хранения и порядок уничтожения первичных учетных и связанных с ними документов, содержащих персональные данныеГАРАНТ