What GDPR (Hospitality Specifics) requires
Significant compliance deficiencies exist regarding the lawful basis for processing personal data within a hospitality context. Current configuration confirms `guest_consent_marketing_obtained` is false, violating GDPR Article 6(1)(a) requirements for consent in marketing communications, a gap mirrored by the `loyalty_program_explicit_opt_in` also being false. More critically, explicit consent for special categories of data under Article 9(2)(a), such as guest health information, is not being obtained, since `special_category_data_consent_obtained` registers false. While essential controls like enabling `pii_encryption_at_rest_enabled` and meeting processor stipulations per Article 28 through a signed `ota_data_sharing_agreement_signed` are in place, these consent failures present substantial regulatory risk. Positive measures include adherence to data minimisation principles from Article 5(1)(c), evidenced by `passport_copy_deleted_after_verification` being true and a defined `guest_data_retention_days_limit` of 1095 days. Furthermore, the framework correctly supports an individual's right to erasure under Article 17, as `right_to_erasure_supported` is confirmed true, `guest_profiling_automated_opt_out_honored` procedures are operational, and `minor_guest_data_processing_restricted` is active. Breach notification protocols align with Article 33, mandating supervisory authority contact within the `breach_notification_max_hours` threshold of 72. Immediate remediation must focus on implementing compliant consent collection mechanisms to rectify these critical gaps.
Pillar: Data Protection & Privacy · Authority: GDPR.eu (EU Regulation) · Version: 1.1.0 · Last updated:
Primary source: https://gdpr-info.eu/art-6-gdpr/
SHA-256 integrity: 2bdaa030fbc28be7acdd25541e5b1047019c94468b011b7199016f94ca08780f
Primary Citations — 7 traced to source
- GDPR Article 5(1)(c): Data minimisation (relevant to booking engines and passport copies at check-in)
- GDPR Article 6(1)(a): Lawfulness of processing based on consent (relevant to hotel marketing and loyalty programs)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/gdpr-hospitality-nuance.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/gdpr-hospitality-nuance.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/gdpr-hospitality-nuance
- Back to registry: Browse all 10,090 compliance nodes