The European Union’s new rules on data protection (General Data Protection Regulation – GDPR), taking effect as of 25th May 2018, are expected to be far more burdensome for hotels compared to existing regulations, experts said at a briefing organized by the Hungarian Association of Hotels & Restaurants (Magyar Szallodak es Ettermek Szovetsege – MSZESZ) on 16th January.
![]() |
Attila Péterfalvi, president of the National Authority for Data Protection and Freedom of Information (NAIH), said hotels should no longer rely on their current data protection practices, partially as mishandling special personal data requiring high-level protection may even be considered a criminal offense from 25th May.
Such information include the personal data of spa guests about their health or sexual orientation.
He said the future audits of the authority will examine if data protection documents comply with GDPR rules, what efforts were made for full compliance, what types of data are handled and what is the legal basis for data handling.
But it will also look into whether IT systems offer proper data security or if hotels have appropriate mechanisms in place to notify the authority and the clients of any data breaches, Péterfalvi said. (turizmus.com, January 16, 2018)

