Posada El Azufral – €1,200 Fine (Spain, 2024)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
Posada El Azufral was fined for asking guests to provide photo ID during check-in, which they refused. The hotel needed to keep records of guests, but the request for ID was seen as excessive. This case shows that businesses must limit the personal information they ask for to what is truly necessary.
What happened
Posada El Azufral required guests to provide photo ID for hotel check-in, which was refused by a visitor.
Who was affected
Visitors trying to check into the hotel who were asked for their photo ID.
What the authority found
The Spanish Data Protection Agency ruled that the hotel did not have a valid reason to request photo IDs, violating the principle of data minimization under GDPR.
Why this matters
This ruling emphasizes that businesses should only collect personal data that is necessary for their operations. Hotels and similar businesses should review their data collection practices to avoid excessive requests.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
The data subject was asked by the controller to provide photo ID to complete hotel check in, as part of the controller's legal obligations to maintain records of staying guests. The data subject refused to do so (both online and at the hotel on the day of check-in) on grounds of excessiveness when it became apparent the ID would be kept on file by the controller, and was refused accommodation. The controller alleged photo ID was necessary to verify the accuracy of travellers data provided in entry and exits forms and the registration sheets required from hotel establishments (per Article 4(3) RD 933/2021 establishing the obligations of documentary registration and information of natural or legal persons who carry out activities of hosting and rental of motor vehicles). While the check-in software used by the controller had options to allow travellers to check in online or in person without providing ID, the controller maintained the need for a copy of travellers IDs. Further, while the software would only keep the ID image for 5 days per its privacy policy, the controller confirmed it would keep images for 3 years in order to fulfil its tax obligations. The DPA found that the controller did not have a legal basis for requesting a copy of travellers' identity documents as a condition of their registration (check-in), which was determined to be excessive and unnecessary processing of personal data contrary to the data minimisation principle (Article 5(1)(c) GDPR). The DPA determined that requiring a traveller to provide a copy of their identity documents constituted excessive processing of personal data, since the documents contained personal data that was inadequate, not pertinent and not necessary for the specific purpose of the processing in question (compliance with the legal obligations in force regarding registration of entry and exit of travellers (Article 4(3) RD 933/2021)). The DPA noted that the law (both [https://www.boe.es/diario_boe/txt.php?id=BOE-A-20
Related Enforcement Actions (0)
No other enforcement actions found for Posada El Azufral in ES
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
30 September 2024
Authority
Agencia Española de Protección de Datos
Fine Amount
€1,200
GDPRhub ID
gdprhub-8876About this data
Cite as: Cookie Fines. Posada El Azufral - Spain (2024). Retrieved from cookiefines.eu
Last updated: