The entry into force of Royal Decree 933 / 2021 has put the spotlight on the Data protection in the tourism sectorThe obligation to collect and retain for three years a large volume of sensitive information about travellers has raised concerns among experts, who warn against Privacy risks and potential penalties.
A disproportionate measure?
The data that must be recorded includes personal, financial and contractual information, such as ID, address, bank card number and email addresses. This volume of information, combined with the obligation to store it for three years, increases the chances of leaks and misuse. In addition, some of this data, such as bank cards, are highly sensitive, which increases the identity theft risks in case of security breaches.
Without robust protection guarantees, the risk of losing control over personal data is very high. This rule could also violate fundamental principles of GDPR (General Data Protection Regulation)), such as minimization, which requires limiting data collection to the minimum necessary to meet the intended objective.
Administrative burdens and legal risks for companies
Data protection is not just a Concern for travelers, but also a challenge for companiesThe decree imposes a large administrative burden, especially on small businesses and self-employed workers, who must implement technological systems to properly record, store and protect information.
These investments, in addition to being costly, are complex to implement in companies with limited resources, which can lead to unintentional non-compliance and, ultimately, sanctions.
Fines can be significant. Non-compliance with the GDPR for issues such as leaks, security breaches or misuse of information may result in fines of up to 20 million euros or 4% of the company's annual turnover, whichever is greater.
In addition, the decree provides for specific fines for iViolations related to the registration of travellers, ranging from 100 to 30.000 euros, depending on severity.
No less important is the impact on daily operationsManaging this data can slow down processes at the front desk, lead to conflicts with customers who refuse to provide additional information, and divert resources from other critical areas of the business. This is especially relevant in a highly competitive sector such as tourism, where any delay or problem can negatively impact the customer experience and, ultimately, the reputation of the establishment.
The importance of ensuring data proportionality
The precedent of the annulment of the Directive 2006/24/EC by the Court of Justice of the European Union, due to its indiscriminate nature, should serve as a warning. In the words of Ruth Benito, expert in Elzaburu data protection“The mass storage of personal data without proportionate measures or clear justification generates risks that may be irreversible for privacy.”
This scenario reinforces the need for putting data protection at the heart of any measure involving the mass processing of personal informationOnly a balanced approach, combining robust security guarantees with clear and proportionate justification, will ensure both public safety and the fundamental rights of citizens. At the same time, it is crucial to protect the competitiveness of the tourism sector, one of Spain's economic drivers.
With this framework, companies must prepare to face this challenge, investing in compliance and data protection systems that not only respond to the regulatory requirements, but also reinforce the travelers trust.
Ruth Benito, Of Counsel. Privacy and Data Protection


