The GDPR (EU Regulation 2016/679) applies to any entity that processes the personal data of European citizens, regardless of its size. A campsite with 30 pitches that stores guests’ passports in a drawer, or sends newsletters without consent, is already non-compliant.
What data a campsite typically collects
- Personal details: first name, last name, date of birth, nationality (mandatory for Alloggiati Web).
- Identity document: number, type, expiry date (required by public security law).
- Contact details: email address, telephone number, address (for bookings and communications).
- Payment data: credit card, IBAN (if charged).
- Images: video surveillance, check-in photos.
- Behavioral data: bar purchases, rentals, pitch preferences (for customer loyalty).
The 5 key compliance requirements
- 1Privacy notice accessible before data collection (on the website, in the booking contract, at reception).
- 2Legal basis for each processing activity: Alloggiati Web = legal obligation; newsletter = explicit consent; invoicing = contractual obligation.
- 3Record of processing activities (mandatory for organizations with more than 250 employees or high-risk processing activities).
- 4Limited retention: identity documents for up to 6 months from arrival, video surveillance footage for up to 72 hours.
- 5Data breach procedures: in the event of a data breach, notify the Garante della Privacy within 72 hours.
⚠ The Garante della Privacy has already penalized accommodation facilities for: excessive retention of documents, failure to provide a privacy notice, un signposted video surveillance, and sending newsletters without consent. Penalties vary depending on the severity and may be significant even for small facilities.
