Check In Scan Logo
Fines for tourist accommodations

Published on: 18/05/2026

Fines for tourist accommodations for non-compliance with traveller registration legislation

Over the past few years, both the police and the AEPD (Spanish Data Protection Agency) have significantly intensified their interventions to detect tourist accommodations that were not properly complying with Organic Law 4/2015, as well as with the General Data Protection Regulation (GDPR). The intention of these regulations is to ensure the correct identification of guests staying in tourist and holiday rental properties, in order to guarantee public safety and control of tourist accommodations.

Important Update – June 2025: On 17 June 2025, the AEPD issued an official informational note clarifying that it is not permitted to request, scan, photograph or retain copies of the ID card or passport of guests for the purpose of traveller registration, even if the images are not stored.

Tightening of Sanctions in 2025-2026

From 1 July 2025, under Royal Decree 1312/2024 and applicable European regulations, failure to comply with obligations such as registration in the Unified National Registry of Tourist Rentals, or advertising without a registration number, may result in fines of up to €600,000 depending on the severity and the autonomous community. This measure represents a radical tightening of sanctions to ensure legality and safety in the tourism sector.

In 2025, the AEPD has considerably increased its fines, sanctioning hospitality companies that scan ID cards with up to €70,000, even when they claim not to retain the image. This action signals a tougher enforcement approach and a clear warning to all accommodation providers.

Concerning Data 2025-2026: Small businesses and self-employed workers in the tourism sector face a complex situation due to the contradiction between the legal obligation to identify guests and the AEPD’s express prohibition on digitising or scanning documents. This discrepancy creates high levels of legal uncertainty.

What Does Organic Law 4/2015 Entail?

Organic Law 4/2015 on the Protection of Public Safety establishes obligations related to the documentary registration of guests. These provisions are designed to guarantee public safety through the collection and monitoring of data on individuals staying at tourist establishments such as hotels, apartments, rural houses, campsites, and others.

What Is the GDPR?

The GDPR (General Data Protection Regulation) is European Union legislation (Regulation (EU) 2016/679) that governs the processing of personal data of citizens and residents in the EU. It came into force in May 2018 and aims to strengthen the privacy and data protection of individuals.

Obligations of Tourist Accommodations

Those responsible for tourist accommodations are required to register the data of all guests staying at their establishments. This registration must include the information provided in Annex I of RD 933/2021.

Accommodations must submit this information to the authorities via the SES HOSPEDAJES platform. The mandatory data under Annex I includes:

  • Guest’s first and last name
  • Identity document number (number only, NOT a copy)
  • Nationality
  • Date of birth
  • Sex
  • Place of origin
  • Check-in and check-out dates

What the AEPD Expressly Prohibits

Since June 2025, the AEPD has definitively clarified that the following are not permitted:

  • Photocopying the full ID card
  • Scanning the ID card or passport
  • Taking photographs of the document with a mobile phone or camera
  • Requesting images of the ID card via WhatsApp, email or other channels
  • Storing or retaining copies, even if deletion is promised afterwards

This prohibition is justified by the fact that the data minimisation principle of the GDPR establishes that data which exceeds what is strictly necessary may not be collected or stored. A full ID card contains information that is not required, such as a photograph, expiry date, parents’ names and biometric data.

Sanction Cases: Detailed Analysis

Case 1: Hotel in Cantabria – ID Card Photograph During Online Check-in

A hotel in Cantabria was fined for attempting to obtain photographs of a guest’s ID card through the online check-in process. The platform requested that guests fill in their details and attach photographs of both sides of their ID card.

What happened? The guest refused to attach the images but completed the rest of the form. On the day of arrival, the hotel demanded that the guest provide their ID card so a photograph could be taken. The guest refused again and the hotel decided to cancel the reservation.

Resolution: The AEPD determined that scanning or photocopying the full ID card exceeds the necessary data processing, even when the images are not stored. What is required is an in-person visual check or the use of electronic means that do not retain copies of the document.

Lesson: Even the intention to photograph (without saving) is subject to sanction.

Case 2: Fines for Tourist Apartments in Jaca

During police inspections at public holidays (Easter Week and the Quebrantahuesos march), 2 tourist flats were found where hosts had not completed guest registration within the mandatory 24-hour deadline.

Fine imposed: Sanctions for non-compliance with Organic Law 4/2015.

Lesson: Authorities intensify checks during peak seasons. Registration must be completed within 24 hours.

Source: heraldo.es

Case 3: Hostel in Cala de Blanes – Failure to Register

A hostel located in Cala de Blanes faced a fine of up to €30,000 for failing to comply with Organic Law 4/2015 by omitting the mandatory documentary registration of guests, following several police warnings.

Case 4: Rural Hotel in Badajoz – Requesting ID via WhatsApp

A rural hotel in Badajoz requested images of guests’ ID cards (both sides) via WhatsApp. When the customer repeatedly refused, the hotel denied access to the apartment, which had been paid for in advance.

Complaint and resolution: The customer filed a complaint with the Civil Guard and the AEPD, which imposed a fine of €2,000 for a serious infringement.

Critical lesson: Requesting ID images via WhatsApp is directly subject to sanction, even before the images are saved.

Source: Diario Sur

Case 5: Mobile Application – Request for Full ID Card (2025)

The AEPD sanctioned the operator of a mobile application with €1,000 (reduced to €600 for early payment) for requesting a full copy of users’ ID cards to verify identifying data submitted via a form.

Resolution: It was deemed disproportionate to request the full ID card when less invasive means are available.

Case 6: Hotel – Passport Scanning (Severe Sanction 2025)

The AEPD fined a hotel €30,000 for systematically scanning the ID cards/passports of its customers at check-in without legal necessity, even without retaining the images.

Key message: The act of scanning itself, regardless of whether the data is retained or not, is subject to sanction.

Accepted Methods for Verifying Identity

The AEPD permits the following methods for verifying guests’ identity without violating the GDPR:

For In-Person Check-in:

  • Visual verification: The receptionist checks that the data on the form matches the document shown, WITHOUT scanning or copying it
  • The document is shown and returned; it is not archived or photographed
  • Via the MiDNI application

For Online/Remote Check-in:

  • Authentication codes (OTP): A one-time code sent to the customer’s mobile or email
  • Cross-verification with payment method: Comparing form data with the data of the payment method used (card, PayPal, etc.)
  • Digital certificates: If the guest holds a valid digital certificate
  • Bank data verification: Where applicable, verifying that details match those on the document

Consequences of Non-Compliance in 2025-2026

Failure to comply with these obligations may be considered an administrative infringement under Organic Law 4/2015 and/or a serious infringement of the GDPR. Sanctions may include:

Fines under Organic Law 4/2015:

  • Minor infringements: from €600
  • Serious infringements: from €10,000 to €600,000
  • Closure of the establishment (precautionary measures)

Fines under the GDPR (Traveller Registration Infringements):

  • Serious infringements for scanning/photographing ID cards: €30,000 to €70,000
  • Serious infringements for requesting ID via WhatsApp/email: €2,000 to €10,000
  • Failure to register within 24 hours: €600 to €30,000

Important note: In 2025, municipalities such as Alicante have acquired their own sanctioning capacity to fine illegal tourist properties with amounts ranging from €10,000 to €600,000 depending on severity.

Intensification of Inspections

Authorities have significantly stepped up controls:

  • Police inspections particularly during peak seasons and public holidays
  • Digital audits combined with in-person inspections
  • Verification of correct traveller registration and GDPR compliance
  • Active detection of infringements, even for apparently minor actions
  • Monitoring of advertising platforms (Airbnb, Booking, etc.) to verify registration

How to Comply Correctly: A Practical Guide

Essential Steps to Avoid Being Fined

  1. Implement approved digital systems: Use platforms that automate the collection of guest data while avoiding the storage of images
  2. Collect ONLY data from Annex I:
    • First and last name
    • Document number (number only)
    • Nationality
    • Date of birth
    • Other data specified in Annex I
  3. NEVER request or retain: Copies, scans or photographs of ID cards, in any format
  4. Submit automatically to SES HOSPEDAJES: The official platform must receive the data within the legal deadline
  5. Register within 24 hours: Registration must be completed on the same day or at most the day after the guest’s arrival
  6. Document the verification method: If you use OTP, payment verification or in-person visual checks, document this in a risk analysis
  7. Update your privacy policy: Clearly state what data is collected, for what purpose and how it is protected
  8. Establish a deletion schedule: Data must be retained for only 3 years as required by regulations, after which it must be deleted
  9. Train staff: Ensure that receptionists and check-in staff are aware of the prohibition on photographing ID cards
  10. Review communication processes: If you use WhatsApp with customers, never request document images through these channels

Recommended Tools and Platforms

To adapt to these regulations in 2025-2026, it is highly advisable to implement digital systems that:

  • Automate the collection of guest data while avoiding the storage of images
  • Automatically submit information to official platforms such as SES HOSPEDAJES
  • Use less intrusive verification methods (OTP, payment verification, etc.)
  • Ensure legal compliance with Organic Law 4/2015 and the GDPR
  • Protect the rights of travellers
  • Significantly reduce the likelihood of sanctions

Current Situation: Legal Uncertainty and Opportunities

This regulatory tightening is generating growing concern among small businesses and self-employed workers in the tourism sector. However, it also presents a clear opportunity:

The fundamental recommendation is to comply with the Law and the GDPR by limiting data collection exclusively to what is required for registration, and by using official tools to submit this information without retaining any documentation.

Those who invest in appropriate digital solutions now will be protected from future sanctions and will have a competitive advantage over less careful competitors.

Recent Regulatory Changes (2025-2026)

  • 17 June 2025: AEPD publishes official informational note prohibiting copies of documents
  • 2025: Fines for scanning ID cards increased to €70,000
  • February 2026: Municipalities such as Alicante receive sanctioning capacity of up to €600,000
  • 2025-2026: More than 29,000 tourist properties have been deregistered for non-compliance in the Valencia Region

Frequently Asked Questions

Q: Can I temporarily store a photo of the ID card if I delete it afterwards?

A: No. The AEPD has made it clear that the act of capturing/scanning is itself an infringement, even if the image is deleted immediately afterwards. The prohibition applies prior to storage.

Q: Can I ask the customer to send me a photo of their ID card via WhatsApp?

A: No. This has been sanctioned with fines of €2,000 or more. The act of requesting it is already an infringement.

Q: Do I need to verify that the name matches the document?

A: Yes, but through in-person visual verification or non-invasive digital methods (OTP, payment verification). Never by scanning or photographing.

Q: What is the deadline for registering a guest?

A: Within 24 hours of their arrival. Failure to meet this deadline is also subject to sanction.

Request more information and try it out
14 days FREE
Create and register your online travellers registration form, manage rental agreements or tourist taxes.
Privacy Policy*
Newsletter
Leave a Reply

Your email address will not be published. Required fields are marked *

Email
    Check in scan Logo
    Made in Mijas, Malaga with