Guest Check-In: Exactly Which ID Fields the Law Requires You to Collect (and Which Ones Aren't on the ID)
Guest Check-In: Exactly Which ID Fields the Law Requires You to Collect (and Which Ones Aren't on the ID)
Here is the thing almost no check-in guide says out loud: the identity document does not contain the data the law asks you for. Annex I of Spain's Royal Decree 933/2021 lists around fourteen traveller data points. A Spanish DNI printed card gives you roughly six of them. Email, phone number, the kinship link when a minor is travelling, the entry and exit times, the payment method โ none of that is printed on any ID card in the world. Any workflow built on "we photograph the DNI and we're covered" is structurally incomplete, and the Spanish data protection authority explicitly made that point when it ruled on the practice.
And the second half of the problem: since the AEPD's note of 17 June 2025, keeping a physical or digital copy of a guest's DNI or passport is not an acceptable way to comply. The regulator's reasoning is precise โ the document carries extra data the rule never asked for (photograph, CAN, expiry, parents' names), which is excessive processing under the minimisation principle, and it still doesn't cover all the required fields. So you end up in a position that sounds contradictory but isn't: you must keep the data for three years, and you should not keep the image at all.
This article is the field-by-field split, plus the procedure that satisfies both inspections.
What the law actually demands: traveller data
Annex I of RD 933/2021 splits the register into traveller data and transaction data. On the traveller side:
- Given name
- Surname(s)
- Sex
- Identity document number
- Document type (DNI, passport, TIE)
- Document support number, for Spanish DNI and NIE
- Nationality
- Date of birth
- Habitual residence: full address
- Landline and/or mobile phone
- Email address
- Number of travellers
- Kinship relationship between travellers, where one of them is a minor
Now mark them by source. Readable from the document: name, surnames, sex, document number, document type, support number, nationality, date of birth. On a Spanish DNI, the residence address is not on the card either โ it lives in the chip, not the print. You have to ask for: phone, email, residence address, number of travellers, kinship.
That is the split that decides how you design your check-in. Eight fields you can extract by reading; five you can only obtain by asking a human being a question. A camera alone never closes the gap.
The support number is where most registrations fail
The *nรบmero de soporte* โ IDESP on a DNI, IXESP on a foreigner's card โ identifies the physical card rather than the person. It is a mandatory field when the document is a Spanish DNI/NIE, and it is the single most common source of rejected submissions. Format matters: three letters and six digits on a current electronic DNI, letter E plus eight digits (left-padded with zeros) on a residence card. A passport has no equivalent, so for foreign passports the field simply doesn't apply.
If you take one operational lesson from this article, take that one: build your form so the support number is captured and validated at the moment the guest is physically in front of you with the card. Chasing it by WhatsApp two days later, from a guest already on a plane home, is a lost cause.
Transaction data: the half everyone forgets
The second block of Annex I has nothing to do with identity and everything to do with the stay:
- Contract reference and date, and signatures
- Entry date and time, exit date and time
- Property data: full address, number of rooms, whether it has internet access
- Payment: type of payment, identification of the means of payment, cardholder name, expiry, payment date
Property and payment fields come from your own systems, not from the guest's pocket. The practical consequence is that your register is assembled from three sources โ the document, the guest's answers, and your booking/PMS records โ and the register is only complete when all three land in the same record.
Minors: data, but no signature
Article 4 draws the line at fourteen. A guest over fourteen signs the entry document personally. For anyone younger, the data is supplied by the accompanying adult, and Annex I then requires the kinship relationship between travellers. The minor does not sign and does not need to present a document of their own โ but they are not invisible in the register either. Omitting under-14s entirely is a classic mistake in family bookings, and the kinship field exists specifically for child-protection and anti-trafficking reasons, which is exactly the kind of field an inspection looks at first.
Deadlines: 24 hours in Spain, tighter in Italy, looser in Portugal
- Spain. Article 6 of RD 933/2021: transmission within a maximum of 24 hours. Mandatory for all professional accommodation since 2 December 2024, through the Ministry of the Interior's SES.Hospedajes platform. If you are still finding your way around the portal itself, the operational walkthrough is here: Traveler Registration in SES.Hospedajes: The 2026 Guide for Vacation Rentals.
- Italy. Article 109 TULPS: guest details to the public security authority within 24 hours of arrival, or within 6 hours if the stay does not exceed 24 hours, via the Alloggiati Web portal. The penalty route runs through article 17 TULPS โ it is a criminal offence, not an administrative fine.
- Portugal. The *boletim de alojamento* through SIBA, within 3 working days of entry, and only for foreign guests โ Portuguese nationals are not reported. SIBA has been operated by the PSP since SEF was wound down in October 2023.
One rule that trips up multi-country operators: Spain and Italy require every guest, Portugal only foreigners. If you run one check-in template across borders, build it for the strictest case.
Retention: three years of data, zero days of images
Article 5 of RD 933/2021 sets the retention period for the electronic register at three years from the end of the service. That is the floor for the data.
The image of the document is a different object with a different rule. The AEPD position, published 17 June 2025, is that RD 933/2021 does not authorise keeping a copy of the DNI or passport in any format. The regulator's recommended alternative is direct and workable: prepare a form with the fields the Interior Ministry requires, and verify them in person against the official document. Read, verify, record the fields, don't archive the picture.
If you already have a folder of ID scans from previous seasons, that folder is now your biggest exposure, and the fix is a deletion policy rather than a better password. The reasoning and the clean-up sequence are covered in How to Store Client ID Copies Without Breaking GDPR.
A check-in procedure that survives both inspections
- Capture the document once, at the point of check-in. Photo or scan, taken by you or sent by the guest. This is a working copy with a lifespan measured in minutes.
- Extract the eight document fields automatically. Name, surnames, sex, document type and number, support number, nationality, date of birth. Reading these by hand is where transcription errors are born โ and errors in the register are classified as a minor infringement in their own right.
- Ask the five remaining fields in the same conversation. Phone, email, habitual residence, number of travellers, kinship if a minor is present. One message, five answers.
- Complete from your own records. Entry and exit datetimes, property data, payment fields, contract reference.
- Verify against the physical document while the guest is in front of you. This is the step the AEPD points to as the substitute for keeping a copy.
- Transmit within the deadline โ 24 hours in Spain, 6 or 24 in Italy, 3 working days in Portugal.
- Delete the image. Keep the structured record for three years.
Step 7 is the one people skip, and it's the cheapest one to automate: a rule that purges document images once the fields have been extracted and validated turns an accumulating liability into a non-issue.
What the mistakes actually cost
Under RD 933/2021, the sanction regime runs through chapter V of Organic Law 4/2015 on public security. Not having the required registers, or failing to make the mandatory communications, is a serious infringement โ the band for serious infringements runs from 601 to 30,000 euros. Irregularities or deficiencies in completing the registers, and communications sent late, are minor infringements, in the 100 to 600 euro band.
Read that pairing carefully, because it is the decision criterion for how you spend your effort. A sloppy but submitted register is a minor infringement. A register that was never sent is a serious one. If a check-in is incomplete at hour 23, the right move is to submit what you have within the deadline and correct it, not to hold it back until it's perfect.
A separate exposure sits on the data-protection side entirely: GDPR sanctions for keeping ID copies you had no basis to keep have nothing to do with the Interior Ministry's scale, and one bad practice can put you on both lists at once.
Where the manual work actually goes
A six-person family booking means six documents, eight fields each, transcribed by hand at the reception desk or from a WhatsApp thread at 11pm โ roughly fifty data points before you even open the portal, for one arrival. Multiply by your occupancy and the compliance cost stops being a legal question and becomes a staffing question. The same arithmetic we ran for agency paperwork applies here almost unchanged: How Many Hours a Month Does Your Agency Really Lose to Paperwork?.
The part worth automating is narrow and well defined: turn the document image into the eight structured fields, in seconds, so the human time goes into the five fields only a person can answer and into the verification the regulator actually wants you to perform. The same extraction logic is what agencies use for client identification outside the hospitality context โ see Real Estate Guide: Automate KYC and Client Identification via WhatsApp.
You can test the extraction step on a real document right now, no account needed: try it free โ no signup.
Need to extract data from a document right now?
Try it free in seconds โ no account, no card. Upload an invoice or document and get the data instantly.
Try it free