Regulations & Taxes

Guest Data and Privacy: GDPR-Safe Handling of IDs and Personal Information

Most hosts collect passport scans and IDs by email or chat, then leave them sitting in an inbox forever. This guide explains why that is a real privacy risk, surveys the standard ways to handle guest data safely, and shows what good looks like: collect less, verify IDs through a system that never dumps the document in your inbox, set a deletion clock, and tell guests what you do with their data.

A guest verifying their identity through a secure mobile flow at check-in instead of emailing a passport photo to the host

Verify guests without holding their passports

Sign up free. Nowistay runs guest identity verification through Stripe Identity, so the ID document stays with the verification provider and never lands in your inbox, while you get the result and a fuzzy match against the booking name. Free to try, then $12 per property per month after the trial.

Start free trial

Guest Data and Privacy: GDPR-Safe Handling of IDs and Personal Information

Open your email and search for the word "passport." If you have been hosting for a year or two, you will probably find a dozen attachments: scanned ID pages, photos of driving licenses, the occasional full credit card front. Most of them arrived because you asked a guest to "send a copy of your ID" before check-in, and most of them have been sitting in your inbox ever since, fully indexed, fully searchable, backed up to whatever cloud your mail provider uses, and readable by anyone who ever gets into your account.

That pile is the quiet privacy problem almost every short-term rental host carries. You did not set out to build a database of government IDs. You were trying to follow the law (many countries legally require you to register guests and record their identity documents) or just trying to screen for fraud. But the way most hosts collect that data, over email or a messaging app, with no plan for deleting it, is exactly the kind of handling that data protection rules like the EU's GDPR were written to discourage. The fines are real, the breach risk is real, and the fix is mostly about changing how the data flows, not buying more software.

Why this matters

Personal data has a cost even when nothing goes wrong, and a much bigger cost when something does. Under the GDPR, a passport scan is not ordinary information. It identifies a person, it can be used for identity theft, and in many readings it counts as a sensitive category that demands extra care. The regulation expects you to collect only what you actually need, keep it only as long as you need it, protect it properly, and be able to explain, on request, what you hold and why.

An inbox full of IDs fails most of those expectations at once. There is no retention limit, so you are holding a license you took three summers ago for a guest you will never host again. There is no real access control beyond your password. There is no record of consent or a clear reason for keeping it. And email is one of the most common places data leaks from: a reused password, a phishing link, a forwarded thread, and suddenly someone has a folder of strangers' identity documents.

The numbers are not trivial. GDPR penalties can in theory reach into the millions or a percentage of turnover for serious cases, and while a single host is unlikely to face the headline figure, smaller fines and formal complaints are well within reach, especially if a guest reports you. Property managers handling dozens of units carry proportionally more exposure. Beyond regulators, there is the trust cost: a guest who learns their passport has been floating around your email for years is not booking with you again, and may say so publicly. Treating identity data carelessly is a liability that compounds quietly with every booking.

The full text and plain-language guides live at GDPR.eu; France's regulator explains the essentials in the CNIL's GDPR overview.

Laptop displaying a security lock icon representing guest data protection

The standard solutions hosts use today

There is no single tool that makes guest data handling compliant, but a handful of approaches show up again and again. Most hosts end up combining two or three.

  • Collect IDs by email or chat (the default). The path of least resistance, and the riskiest. The document lands in a place not built to store sensitive data, and it tends to stay there forever. If this is your current method, it is the first thing to change.
  • Dedicated identity-verification services. Specialized providers let a guest upload their ID through a secure flow on the provider's own infrastructure. You receive a pass or fail result, sometimes a name and date-of-birth match, but the raw document never touches your inbox. This is the single biggest improvement most hosts can make, because it removes you as the custodian of the actual scan.
  • Encrypted storage with a retention policy. If you genuinely must keep documents (some local registration laws require holding records for a defined period), the safer pattern is an encrypted, access-controlled store with a written rule for how long files live and an actual process to delete them when the clock runs out.
  • A privacy notice and a defined lawful basis. Not a tool, a document. A short, plain-language notice that tells guests what you collect, why, how long you keep it, and how to ask for deletion. Pairing each type of data with a lawful basis (a legal obligation to register guests, a legitimate interest in fraud prevention, and so on) is what turns "I have this data" into "I am allowed to have this data."
  • Data minimization by design. The cheapest control of all: ask for less. You rarely need a full passport image when a verified yes/no on identity, plus the legally required registration fields, would do. Every field you do not collect is a field you cannot leak.

What good looks like

Strip away the jargon and a privacy-respecting operation passes a few simple tests. These are vendor-neutral; any combination of tools that satisfies them is fine.

  • You collect the minimum. The default for each field is "do we truly need this?" Identity gets verified rather than warehoused. Marketing data is separate from operational data and never assumed.
  • Raw documents never sit in general-purpose tools. No passport scans in your email, your phone's photo roll, or a shared chat thread. If a document must exist at all, it lives behind proper access control, ideally on a specialist provider's system rather than yours.
  • Everything has an expiry date. You can state, per data type, how long you keep it and why, and deletion actually happens. "Forever, because I never got around to it" is not a retention policy.
  • Guests know what you do. A clear privacy notice is available before they hand over anything, written for a human, not a lawyer.
  • You can honor a request. If a guest asks what you hold or asks you to delete it, you can find it and act, because the data lives in known places, not scattered across years of inbox.

How Nowistay handles guest identity

Identity verification is the part of guest data where hosts get into the most trouble, because it is where the most sensitive document, a government ID, changes hands. Nowistay's approach is built so that document never lands with you.

Guest identity verification runs through Stripe Identity. When you ask a guest to verify, they complete the check on Stripe's secure flow, and the ID document is handled by the verification provider, not by Nowistay and not by you. What comes back to your dashboard is the result: whether the guest passed, plus a fuzzy match of the verified name against the name on the booking, so a near-match (a middle name added, an accent dropped) still lines up while a genuinely different person stands out. You get the confidence that the person checking in is who they claimed to be, without becoming the custodian of a passport scan. That is data minimization in practice, and it is exactly the kind of handling data protection rules reward: the riskiest piece of information never enters your inbox, your phone, or your message threads in the first place. You can turn it on per property in a couple of clicks; the steps are in how to enable guest identity verification.

Keeping documents out of your inbox also makes the rest of compliance easier. Because the verification result lives in your dashboard rather than in scattered email threads, answering a guest's question about what you hold is a matter of looking in one place, not searching three years of mail. If you run on more than a handful of properties and want to query your own records in plain language, the connector lets you link ChatGPT, Claude, or Gemini to your live Nowistay data and ask things like which bookings have a completed verification, which is described in how to connect ChatGPT, Claude, or Gemini to Nowistay. To be clear about scope: Nowistay handles the verification flow and keeps the raw document away from you, but it does not provide legal advice, and you remain responsible for your own privacy notice, retention rules, and any local registration obligations. Whether you verify guests through Nowistay or through a separate identity vendor bolted onto a full PMS, the criteria above (collect less, keep documents out of general tools, set an expiry, be transparent) are the test.

Smartphone wrapped in a chain symbolizing personal data privacy

Common mistakes

Treating your inbox as a filing cabinet

The single most common error: asking guests to email a photo of their ID, then never deleting it. Even if you read it once and move on, the file lives on in your sent and received folders and every backup behind them. If you must receive a document at all, get it out of email immediately and delete the original.

Collecting more than you need

"Send a full copy of your passport" is rarely the right ask. For most stays you need to confirm identity and capture the specific fields a local law requires, not warehouse the whole document. Over-collecting turns a minor obligation into a major liability.

No deletion clock

Hosts will set up a tidy storage system and still keep everything indefinitely because no one defined when files should go. Decide the retention period up front (often tied to how long a registration law requires records), write it down, and make deletion a routine, not an afterthought.

Silence instead of a privacy notice

Many hosts collect personal data with no notice at all. Guests are entitled to know what you take and why before they share it. A short, honest notice is quick to write and closes a real gap.

Mixing operational data with marketing

Assuming that because a guest booked, you can add them to a marketing list is a frequent slip. The reason you hold someone's email to coordinate a stay is not the same reason you would need it to send promotions. Keep those purposes separate and do not assume consent you were never given.

A practical plan for this week

You do not need a compliance project to make real progress. A few focused hours covers most of the risk.

  1. Audit the inbox. Search your email and phone for ID documents (try "passport," "ID," "license," "carte"). Note how many you have and how old they are.
  2. Delete what you do not need. Any document from a past guest you have no legal reason to keep should go now, including from sent items and trash.
  3. Switch off email collection. Stop asking guests to email IDs. Move identity checks to a verification flow where the raw document stays with the provider, not with you.
  4. Write a one-paragraph privacy notice. What you collect, why, how long you keep it, and how to request deletion. Plain language. Link it where guests give you data.
  5. Set a retention rule. Pick a period for each data type, write it down, and put a recurring reminder in your calendar to actually delete anything past it.
  6. Check your local registration law. Confirm what your city or country actually requires you to record and for how long, so you collect exactly that and no more.

Where this is heading

Guest expectations around privacy are rising, and so is enforcement. The hosts who will sleep easy are the ones who stopped treating identity data as something to hoard and started treating it as something to verify, use briefly, and let go. The direction of travel is clear: less raw data in your hands, more of the sensitive work done by systems built to hold it safely, and a guest experience where handing over an ID feels secure rather than risky. Get the flow right now (collect less, keep documents off your own devices, set a deletion clock, and say what you do) and the next round of rules, whatever shape it takes, will be a small adjustment rather than a scramble.

One co-host that handles guests and identity

Sign up free. Beyond identity verification, Nowistay's autonomous AI co-host answers guests in seconds, 24/7, in 15+ languages on Airbnb, Booking.com, WhatsApp, and email, and syncs your rates and availability across Airbnb, Booking.com, VRBO, Expedia, and Agoda. Onboard a property in minutes and keep guest data handling tidy from day one.

Try Nowistay free

Bassel Abedi

Founder & CEO of Nowistay

Over 25 years of experience in real estate investing and a recognized expert in short-term rental automation. Bassel helps property managers increase revenue, cut operating costs, and deliver 5-star guest experiences using AI-powered tools he built from firsthand hosting experience.