Modern Hotel Booking — WordPress Hotel Booking Plugin Logo

Modern Hotel Booking

GDPR Compliance for Hotel Booking Plugins — Complete Guide

GDPR Hotel Booking WordPress — Pro Compliance Guide

As a hotel owner collecting guest data through your WordPress site, GDPR applies to you. This guide covers your obligations as a data controller, how to configure consent checkboxes, and how to handle guest PII erasure requests — both with and without the Pro version.

⏱️ Setup time: Under 10 minutes

🔒 Consent checkbox & erasure: Pro required

🌍 Applies to: All EU/EEA property owners

📅 Last updated: July 2026

GDPR hotel booking WordPress — Modern Hotel Booking Pro privacy and GDPR settings panel showing consent checkbox and PII erasure tools
Hotel Booking → Settings → Privacy & GDPR — the consent and erasure configuration panel

⚠️ Consent checkbox and PII erasure tools require Pro. Free version users can still meet GDPR obligations manually — see the free version section below. Get Modern Hotel Booking Pro →

⚖️ Important Disclaimer — Please Read

This guide is for informational purposes only. It is not legal advice. Modern Hotel Booking provides technical tools — a consent checkbox, a privacy policy link field, and a PII erasure utility — to help you manage guest data within your WordPress installation. Providing these tools does not make the plugin developer responsible for your site’s compliance with GDPR, CCPA, or any other privacy law.

Compliance with all applicable local, national, and international privacy laws is entirely the responsibility of the end user — the person or business operating the WordPress site and collecting guest data. Privacy law varies significantly by country, jurisdiction, and business type. What is sufficient in one country may not be sufficient in another.

The developer of Modern Hotel Booking accepts no liability for any failure to comply with GDPR, CCPA, or any other data protection regulation arising from the use or configuration of this plugin. For advice specific to your jurisdiction, business structure, and guest data practices, consult a qualified data protection professional or legal adviser.

✅ Recommended: Complianz GDPR Plugin

Modern Hotel Booking works seamlessly alongside Complianz GDPR/CCPA Cookie Consent ↗ with no conflicts. We use it on beachhouse.ro and recommend it for any property owner who wants comprehensive, country-specific compliance coverage beyond what a booking plugin alone can provide.

Complianz is maintained specifically for privacy law compliance across multiple jurisdictions — GDPR, CCPA, PIPEDA, LGPD, and more. It includes a guided setup wizard, a cookie scanner that automatically identifies all cookies and scripts on your site, geo-targeted consent banners that adapt to the visitor’s country, and a regularly updated legal database. The team behind it tracks regulatory changes actively so you don’t have to.

  • Covers GDPR, CCPA, PIPEDA, LGPD, and more
  • Country-specific consent banners — automatically geo-targeted
  • Cookie scanner identifies all tracking scripts on your site
  • Regularly updated legal database maintained by compliance specialists
  • Free version available on WordPress.org
  • Guided setup wizard — no legal expertise required
  • Works with Modern Hotel Booking — no conflicts
  • Used on beachhouse.ro alongside this plugin

Install Complianz on WordPress.org ↗

Your Role as Data Controller — What GDPR Hotel Booking Compliance Actually Requires

If your property accepts bookings from guests in the EU or EEA, GDPR applies to you. Full stop. It doesn’t matter whether your property is in the EU — if you’re marketing to or accepting bookings from EU residents, you fall within GDPR’s scope. Running beachhouse.ro on Romania’s Black Sea coast, this applies to me directly, which is part of why these tools were built into the plugin from the start. On beachhouse.ro I use Modern Hotel Booking alongside the Complianz GDPR plugin — the two work together without any conflicts, and Complianz handles the cookie consent and country-specific legal requirements that go beyond what a booking plugin alone covers.

Under GDPR, you are the data controller — you decide what data to collect, why, and how long to keep it. Modern Hotel Booking is a data processor tool — it stores the data you collect in your own WordPress database. The plugin developer never receives your guest data and is not your data processor in the legal GDPR sense.

What GDPR actually requires of you as a hotel owner:

  • Collect only the data you genuinely need to process a booking
  • Inform guests what data you collect and why — at the point of booking
  • Have a privacy policy and link to it from your booking form
  • Have a process for responding to guest data requests (access, erasure, portability)
  • Not keep personal data longer than necessary for its purpose
  • Disclose any third-party services that process guest data (Stripe, PayPal, AI Concierge provider)

The plugin’s GDPR tools handle the technical enforcement side of points 2, 3, and 4. The rest — your privacy policy content, your data retention decisions, your disclosure of third-party services — is your responsibility as the property operator.

Lawful Basis for Processing Hotel Booking Guest Data

Every data processing activity under GDPR must have a lawful basis. For hotel booking data, that basis is contractual necessity under Article 6(1)(b) — you need a guest’s name, email address, and booking dates to fulfil the reservation they requested. You cannot process the booking without this information.

This is important: contractual necessity means you do not need to ask guests for separate consent to collect their booking information. The data is necessary to provide the service they’ve requested. Where this changes is if you want to use guest data for purposes beyond the booking — sending marketing emails after their stay, for example. That requires explicit consent collected separately at booking.

Contractual Necessity (Article 6(1)(b))

Applies to: name, email, booking dates, room selection, number of guests, payment method. Needed to process the reservation — no separate consent required.

⚠️

Explicit Consent (Article 6(1)(a))

Applies to: post-stay marketing emails, promotional newsletters, sharing data with third parties for marketing. Requires a separate, specific consent checkbox — not bundled with booking acceptance.

How Modern Hotel Booking Handles Guest Data

The plugin’s data architecture was designed with GDPR in mind from the start — and this matters more than most WordPress booking plugins acknowledge. Here is exactly what happens to guest data:

Data Type Where It’s Stored Sent Externally? Retention
Guest booking records
name, email, dates, room, guests
Your WordPress database only ❌ Never Until you delete or Pro erasure
Payment credentials
Stripe keys, PayPal credentials, Revolut link
Your WordPress options table (encrypted) ❌ Never (to developer) Until removed from settings
AI Concierge conversations WordPress Transients (temporary cache) ✅ To AI provider only (OpenAI or Gemini — your chosen provider) Auto-deleted after 2 hours
Rate limiting data
anonymised per-IP request counts
WordPress Transients ❌ Never Auto-deleted after 2 minutes
Pro licence check
licence key + site URL only
Developer licence server ✅ To developer — licence key and site URL only, no guest data Per licence check only

✅ Privacy-first architecture: All third-party JavaScript libraries used by the plugin are bundled locally and served from your own server. Nothing is loaded from external CDNs. This means no third-party tracking scripts are injected onto your booking pages — a meaningful GDPR advantage over plugins that rely on external script loading.

GDPR Compliance Setup — Step by Step (Pro)

Requires an active Modern Hotel Booking Pro licence

The GDPR settings panel is straightforward. This takes under 10 minutes from a fresh Pro install. Before starting, make sure your property has an actual privacy policy page published on your site — you’ll need its URL for step 2.

1

Open the Privacy & GDPR settings panel

In your WP admin go to Hotel Booking → Settings → Privacy & GDPR. If this section is not visible, confirm your Pro licence is entered and active under Hotel Booking → Licence.

2

Enter your privacy policy URL

In the Privacy Policy URL field, enter the full URL of your property’s privacy policy page. This link will appear on your booking form so guests can read your policy before completing a reservation. If you don’t have a dedicated privacy policy page yet, create one before enabling the consent checkbox — guests need to be able to read what they’re agreeing to.

3

Enable the consent checkbox

Toggle Enable Privacy Checkbox to On. The checkbox becomes mandatory — guests cannot submit the booking form without ticking it. This creates a documented, timestamped record that the guest was presented with your privacy terms and actively accepted them before booking.

4

Write your consent text

Enter the text that appears next to the checkbox. Keep it plain and specific — avoid vague legal boilerplate. A good example:

“I have read and agree to the privacy policy. I consent to my name, email address, and booking details being stored to process this reservation.”

Do not use this checkbox to bundle consent for marketing emails — that needs a separate checkbox. One checkbox, one purpose.

5

Save settings and test the booking form

Save your settings. Visit your booking form as a guest would and confirm the consent checkbox appears, the privacy policy link works, and the form cannot be submitted without ticking the checkbox. Test in an incognito window to see the true guest experience.

Handling Hotel Booking PII Erasure Requests

Under GDPR Article 17, guests have the right to request erasure of their personal data — the “right to be forgotten.” When a guest makes a formal erasure request, you have one month to respond and act on it. The Pro version includes an automated PII erasure tool to handle this without manual database editing.

Running the Erase PII tool (Pro)

  1. Go to Hotel Booking → GDPR Suite in your WP admin
  2. Enter the guest’s email address in the search field
  3. The tool shows all booking records associated with that email address
  4. Review the records and click Erase PII to run the anonymisation
  5. The guest’s name, email, and contact details are replaced with anonymised values in your database
  6. Booking statistics and dates are retained for your records — only personally identifiable information is removed
  7. Confirm the erasure by checking the records no longer show the guest’s personal details

💡 Practical tip: Keep a simple log of erasure requests and the date you processed them. GDPR requires you to be able to demonstrate compliance — a basic spreadsheet noting the request date, processing date, and outcome is sufficient for most small properties. You don’t need elaborate systems.

Guest Rights Under GDPR — Your Obligations as a Hotel Owner

Guests who book through your Modern Hotel Booking-powered site have six data rights under GDPR. These are exercised against you as the data controller — not against the plugin developer, who holds no copy of their data. All guest data is in your WordPress admin, so you can respond to any of these requests directly.

  • Right of Access — guest can request a copy of all personal data you hold. Respond by exporting their booking records from your WP admin.
  • Right to Rectification — guest can ask you to correct inaccurate data. Update their booking record directly in Hotel Booking → Bookings.
  • Right to Erasure — guest can request deletion of their records. Use the Pro PII erasure tool under Hotel Booking → GDPR Suite.
  • Right to Portability — guest can request their data in a portable format. Export their booking details as a CSV from your WP admin.
  • Right to Restrict Processing — guest can ask you to limit how their data is used while a dispute is resolved.
  • Right to Object — guest can object to processing based on legitimate interests. For contractual necessity processing, this right typically does not override your legal basis.

⚠️ Response deadline: GDPR requires you to respond to data rights requests within one calendar month of receiving them. This can be extended by two months in complex cases, but you must notify the guest of the extension within the first month. Missing this deadline is a compliance violation.

Data Retention — How Long to Keep Hotel Booking Records

GDPR’s storage limitation principle requires you not to keep personal data longer than necessary for the purpose it was collected. The plugin doesn’t enforce automatic retention periods — that’s your decision as the data controller, based on your legal obligations in your jurisdiction.

For practical guidance: most EU hospitality businesses retain booking records for the duration required by local tax and accounting regulations — typically 5 to 7 years — then delete or anonymise them. Romania, where beachhouse.ro operates, requires accounting records to be kept for 10 years. Check the requirement for your country.

Data Type Automatic Deletion Your Responsibility
AI Concierge conversations ✅ Auto-deleted after 2 hours None required — plugin handles this
Rate limiting data (per-IP counts) ✅ Auto-deleted after 2 minutes None required — plugin handles this
Booking records (guest PII) ❌ Not automatic Define your retention period. Use Pro erasure tool when period expires or on guest request.
Payment gateway credentials ❌ Not automatic Remove from plugin settings when no longer in use.

Free Version: Meeting GDPR Without the Pro Tools

The automated consent checkbox and PII erasure tools are Pro features. But GDPR obligations apply regardless of which version you run — and you can meet most of them manually on the free version. Here’s what you can do without Pro:

  • Link to your privacy policy — add a privacy policy link manually to your booking page using a standard WP paragraph or button block above the booking form block.
  • Inform guests in the confirmation email — use the email template editor under Hotel Booking → Settings → Email Templates to add a paragraph explaining how their data is used and referencing your privacy policy.
  • Handle erasure requests manually — go to Hotel Booking → Bookings, find the guest’s records by email, and manually delete or edit their personal information fields.
  • Respond to access requests manually — export booking details from your WP admin and send them to the guest in a readable format.
  • Install Complianz — the free version of Complianz GDPR handles cookie consent banners, geo-targeted notices, and country-specific compliance requirements — all at no cost and with no conflicts alongside Modern Hotel Booking.

If you’re handling more than a handful of guest data requests per year, the Pro GDPR tools pay for themselves in time saved. But for small properties with low booking volumes, manual handling is workable.

Upgrade to Pro → to unlock the automated consent checkbox enforcement, GDPR Suite with one-click PII erasure, and documented consent records stored per booking.

Frequently Asked Questions

Does the Modern Hotel Booking plugin make my site GDPR compliant?

The plugin provides tools that help you meet your obligations — consent checkboxes, privacy policy linking, and automated PII erasure. But GDPR hotel booking WordPress compliance is your responsibility as the data controller. You also need your own privacy policy, a process for handling guest rights requests, and awareness of your local data protection requirements.

Is the GDPR consent checkbox available in the free version?

No. The automated consent checkbox and PII erasure tools are Pro features. Free version users can still meet their GDPR obligations by linking to their privacy policy from the booking page and handling data requests manually through the WordPress admin.

What is the lawful basis for processing hotel booking guest data under GDPR?

Contractual necessity under GDPR Article 6(1)(b). You need a guest’s name, email, and booking dates to fulfil their reservation — that is the legal basis. You do not need separate consent to collect booking information, but you must inform guests about it at the point of booking and link to your privacy policy.

What happens to guest data when I run the hotel booking PII erasure tool?

The Erase PII utility in Modern Hotel Booking Pro anonymises the guest’s personal information in your WordPress database. Names, email addresses, and contact details are replaced with anonymised values. Booking statistics and dates are retained — only the personally identifiable information is removed.

Does the plugin send guest data to the developer’s servers?

No. All guest booking data stays in your WordPress database. The plugin developer never receives, accesses, or processes your guest data. The only external connection is the Pro licence checker — this transmits your licence key and site URL only, never guest data or booking records.

What guest rights under GDPR do I need to handle as a hotel owner?

Six: Access (copy of their data), Rectification (correct inaccurate data), Erasure (delete records — use the Pro tool), Portability (data in a portable format), Restrict Processing, and Object. All guest data is in your WP admin — you have full control to respond to any of these within GDPR’s one-month deadline.

How long should I keep hotel booking records under GDPR?

GDPR requires you not to keep data longer than necessary. For hotel bookings, most EU tax and accounting regulations require records for 5 to 7 years (Romania requires 10 years). After that period, use the Pro PII erasure tool or manually anonymise records. The plugin doesn’t auto-delete booking records — that retention decision is yours as the data controller.

What GDPR plugin do you recommend alongside Modern Hotel Booking?

We recommend the Complianz GDPR/CCPA Cookie Consent plugin ↗ — it works alongside Modern Hotel Booking with no conflicts and is used on beachhouse.ro. Complianz covers GDPR, CCPA, PIPEDA, LGPD, and other country-specific privacy laws with geo-targeted consent banners, an automatic cookie scanner, and a regularly updated legal database. It handles cookie consent and country-specific requirements that go beyond what a booking plugin alone covers.

Is the plugin developer responsible for my site’s GDPR compliance?

No. The developer provides technical tools — a consent checkbox, privacy policy link, and PII erasure utility. Compliance with GDPR, CCPA, and all other applicable privacy laws is entirely the responsibility of the end user operating the WordPress site. Privacy law varies by jurisdiction and business type. The plugin developer accepts no liability for any compliance failure. Consult a qualified data protection professional for advice specific to your situation.

Need the GDPR tools?

Automated consent checkboxes, one-click PII erasure, and documented consent records per booking are all Pro features.

Modern Hotel Booking is a lightweight, zero-commission reservation engine and 24/7 AI Concierge receptionist for WordPress.

Keep 100% of your revenue and own your guest data.

© 2026 Modern Hotel Booking. All rights reserved.

Built with love for independent property owners.