Article
Guest Privacy in Hotels: A 2026 Guide to Protecting Guest Data
Guest privacy in hotels now means protecting guest data. See what the 2025 to 2026 Booking.com phishing wave exposed and how to close the gap.
The short answer
Guest privacy in hotels means controlling who can see, store and use a guest's personal data, and where guest conversations physically live, from reservation details and payment data to ID scans and message history. Protecting it requires collecting only necessary data, keeping it no longer than needed, and knowing exactly which systems and vendors can access it.
What Does Guest Privacy in Hotels Actually Mean in 2026?
Guest privacy in hotels used to mean a locked door and a "do not disturb" sign. In 2026, it mostly means data: who can see a guest's reservation, payment details, ID scan and message history, and where that information physically sits once it has been collected. A guest's privacy is compromised just as badly by a leaked WhatsApp thread with their card number in it as by a staff member walking into the wrong room.
That shift matters because the biggest privacy failures hitting hotels right now are not physical, they are digital, and they run through channels hotels already trust. It also makes privacy an operational question, not only a legal one: a tool like Timo's AI receptionist keeps guest messaging and the data inside it in one controlled place, which is the opposite of the scattered personal-phone setup most privacy incidents exploit.
Why Did a Booking.com Phishing Wave Become a Guest Privacy Story?
A phishing campaign that ran from at least April 2025 through early October 2025 turned a routine hotel inbox into the entry point for guest fraud. Security firm Sekoia documented the campaign, nicknamed "I Paid Twice," in detail: attackers sent hotel staff a spoofed "new booking" email, and clicking through led to a fake CAPTCHA page using the "ClickFix" trick, which coaxes a person into copying and running a PowerShell command themselves (Sekoia's research on the campaign). That command installed PureRAT malware and handed attackers the hotel's real Booking.com extranet login.
With legitimate extranet access, the attackers did not need to guess anything. They pulled real guest names, dates and booking references, then messaged those guests directly over WhatsApp and email, posing as the hotel or Booking.com, to harvest card data. The trust that made those messages convincing was the trust guests already had in the hotel, which is precisely what makes this a guest privacy failure, not just an IT incident.
Booking.com later confirmed a customer data breach in April 2026 that exposed reservation data, including names, email addresses, physical addresses, phone numbers, booking dates, hotel names and special requests, following this hotel-partner phishing wave, according to security reporting from Malwarebytes and Infosecurity Magazine. Microsoft has attributed much of this ClickFix-driven hotel phishing activity to a criminal group it tracks as Storm-1865.
Where Does Guest Data Actually Live in a Typical Hotel?
Guest data in most hotels is scattered across more systems than anyone can easily list: the property management system, the booking platform extranet, the payment processor, the front-desk email inbox, and, increasingly, whichever app or phone a staff member used to answer a guest's question that day. Each of those is a separate place a guest's personal data can sit, and each is a separate thing that has to be secured and eventually deleted.
The weakest link is usually the least official one. When a guest texts the front desk's personal WhatsApp number for a late checkout, that conversation, and everything in it (room number, dates, sometimes a photo of an ID or a card), now lives on one employee's personal device, outside the hotel's own records and retention policy. Consolidating that messaging into Timo's AI receptionist removes dozens of these weak points at once, because guest conversations and the data in them stay in one auditable system rather than spread across personal phones.
What Does GDPR Actually Require Hotels to Do With Guest Data?
GDPR requires hotels to collect only what they need and keep it only as long as they need it, not to hit a specific retention number. Article 5(1)(c), the data minimisation principle, states that personal data must be "adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed" (GDPR Article 5 on gdpr-info.eu). In practice, that means a hotel collecting a copy of every guest's passport "just in case," when local law only requires the primary guest's ID, is already over the line.
Article 5(1)(e), the storage limitation principle, adds that data must be "kept... for no longer than is necessary for the purposes" it was collected for (same source). GDPR deliberately does not set a fixed number of days or years here: the hotel, as the data controller, has to be able to justify its own retention period, whether that is tied to tax law, dispute windows, or loyalty programme terms. A hotel still holding three-year-old WhatsApp threads with card details on a former employee's phone would struggle to justify that under either principle.
What Should a Hotel Check Before Using Any Guest-Facing Tool?
Before adopting any tool that touches guest data (a chatbot, a booking widget, an upsell platform), a hotel should confirm the vendor will sign a Data Processing Agreement. GDPR Article 28 requires a formal DPA with any vendor or processor that handles guest data on the hotel's behalf, spelling out what the vendor can do with that data and what security it commits to. A vendor that cannot produce one is a sign the hotel would be adding privacy risk, not removing it.
Three other checks matter in practice:
- Where is data stored, and for how long? Ask for the vendor's specific retention period, not a vague "industry standard" answer.
- Who at the vendor can see raw guest messages? A tool that routes guest conversations through unnamed subprocessors adds people who can read a guest's data without the hotel knowing.
- Can the hotel export and delete guest data on request? Guests can ask for their data under GDPR's access and erasure rights, so the hotel needs a tool that makes that possible, not another silo to search by hand.
Is WhatsApp Itself the Privacy Problem?
No, the messaging app is rarely the weak point, the account and device behind it are. WhatsApp messages are end-to-end encrypted by default, according to the WhatsApp Help Center, which means the content is protected in transit between sender and recipient. The Sekoia-documented campaign did not break that encryption: attackers got in through stolen Booking.com credentials on a hotel employee's machine, then sent guests messages that looked legitimate because they carried real booking details.
The practical lesson for hotels using WhatsApp for guest communication, a channel covered in more depth in this guide to WhatsApp automation for hotels, is that the tool is not the risk. The risk is running guest messaging through personal accounts with no central login control, no audit trail, and no way to cut off access the moment someone leaves the hotel or a device is compromised. The same logic runs through the wider rules of communicating with hotel guests across every channel, not just WhatsApp.
How Should a Hotel Respond If Its Booking Platform Account Is Compromised?
The first move is credential containment, not guest outreach. Reset the extranet password and any connected email account immediately, and have IT check the machine that was logged in for malware, since the Sekoia research shows the entry point was a single infected staff device, not a platform-wide flaw. Only after the compromised account is locked down should the hotel warn guests, and it should do so through a channel it controls (its own verified number or email domain), never by replying inside the same thread an attacker may have hijacked.
Documentation matters too. Under the accountability expectations tied to GDPR Article 5, a hotel needs to be able to say what data was exposed and to whom. Hotels that already keep guest conversations in one system, rather than across dozens of personal phones, can answer that in minutes instead of days, because there is one place to check instead of asking every staff member what they remember sending.
The Bottom Line on Guest Privacy in Hotels
Guest privacy in hotels is now a data discipline as much as a physical one: collect less, keep it for a defined reason, know every vendor that touches it, and stop guest conversations from defaulting to whichever personal device happens to be closest. The 2025 to 2026 Booking.com phishing wave did not exploit a new kind of weakness, it exploited an old one: guest data spread across too many uncontrolled places, with a single compromised login enough to reach real guests convincingly.
Centralising guest messaging is one of the most direct ways to close that gap, and it is worth seeing what that looks like against your own property's real guest conversations.
Frequently asked questions
Is guest data protected by GDPR?
Yes, if the hotel operates in the EU or processes data of EU residents. GDPR Article 5(1)(c) requires data minimisation: personal data must be adequate, relevant and limited to what is necessary for the purpose it was collected for, per gdpr-info.eu. That means a hotel should not collect or retain guest data (ID scans, payment details, preferences) beyond what the stay actually requires, and should be able to explain why it holds what it holds.
How long can a hotel keep guest data?
GDPR does not set a fixed number of days or years. Article 5(1)(e), the storage limitation principle, requires that personal data be kept for no longer than necessary for the purposes it was collected for, per gdpr-info.eu. In practice a hotel should define its own retention schedule, for example tied to tax or accounting obligations, and delete or anonymise guest data, including old WhatsApp threads and email chains, once that purpose has passed.
Is it safe to message hotel guests on WhatsApp?
The messages themselves are protected in transit: WhatsApp is end-to-end encrypted by default, according to the WhatsApp Help Center. The real risk is not the encryption, it is where those conversations are stored and who can access them afterward. If guest chats live on individual staff members' personal phones, that data leaves the hotel's control the moment a phone is lost, sold, or the employee leaves.
What guest data should a hotel collect at check-in?
Only what is legally required or operationally necessary: identity verification, contact details, payment method, and any accessibility or preference notes tied to the current stay. Under GDPR's data minimisation principle (Article 5(1)(c), gdpr-info.eu), collecting extra fields just in case, such as passport scans of every companion or unrelated personal notes, creates liability without an operational reason, and it is exactly the kind of extra data a breach would expose.
How do hotels get hacked through Booking.com?
Security firm Sekoia documented a campaign, active from at least April 2025 through early October 2025, where hotel staff received spoofed new-booking emails using the ClickFix trick: a fake CAPTCHA page instructed them to copy and run a PowerShell command, which installed PureRAT malware and stole their real Booking.com extranet credentials. Attackers then used those credentials to message the hotel's actual guests with real reservation details.
What should a hotel do after a guest data breach?
Contain the compromised account first (reset extranet and email credentials, check for malware on any machine that was logged in), then warn current and recent guests directly through a channel the hotel controls, not the one that was compromised. Booking.com itself confirmed a customer data breach in April 2026 following this phishing wave, per security reporting from Malwarebytes and Infosecurity Magazine. Document what data was exposed, since GDPR Article 5 means the hotel must account for what it held.
Book a short call to see how Timo's AI receptionist keeps guest messaging and the data inside it in one controlled, auditable system instead of scattered across staff phones.
Keep guest data in one place