Bidda Sovereign Intelligence · 10,090 Verified Nodes · 39 Sovereign Pillars

GDPR (Hospitality Specifics)

Significant compliance deficiencies exist regarding the lawful basis for processing personal data within a hospitality context. Current configuration…

What GDPR (Hospitality Specifics) requires

Significant compliance deficiencies exist regarding the lawful basis for processing personal data within a hospitality context. Current configuration confirms `guest_consent_marketing_obtained` is false, violating GDPR Article 6(1)(a) requirements for consent in marketing communications, a gap mirrored by the `loyalty_program_explicit_opt_in` also being false. More critically, explicit consent for special categories of data under Article 9(2)(a), such as guest health information, is not being obtained, since `special_category_data_consent_obtained` registers false. While essential controls like enabling `pii_encryption_at_rest_enabled` and meeting processor stipulations per Article 28 through a signed `ota_data_sharing_agreement_signed` are in place, these consent failures present substantial regulatory risk. Positive measures include adherence to data minimisation principles from Article 5(1)(c), evidenced by `passport_copy_deleted_after_verification` being true and a defined `guest_data_retention_days_limit` of 1095 days. Furthermore, the framework correctly supports an individual's right to erasure under Article 17, as `right_to_erasure_supported` is confirmed true, `guest_profiling_automated_opt_out_honored` procedures are operational, and `minor_guest_data_processing_restricted` is active. Breach notification protocols align with Article 33, mandating supervisory authority contact within the `breach_notification_max_hours` threshold of 72. Immediate remediation must focus on implementing compliant consent collection mechanisms to rectify these critical gaps.

Pillar: Data Protection & Privacy · Authority: GDPR.eu (EU Regulation) · Version: 1.1.0 · Last updated:

Primary source: https://gdpr-info.eu/art-6-gdpr/

SHA-256 integrity: 2bdaa030fbc28be7acdd25541e5b1047019c94468b011b7199016f94ca08780f

Primary Citations — 7 traced to source

  • GDPR Article 5(1)(c): Data minimisation (relevant to booking engines and passport copies at check-in)
  • GDPR Article 6(1)(a): Lawfulness of processing based on consent (relevant to hotel marketing and loyalty programs)

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.