< Back to all clusters
[BUSINESS] · Greece · 4 sources

Greek Data Protection Authority bans hotels from photocopying IDs and credit cards

The Greek Data Protection Authority has issued formal compliance recommendations to tourist accommodations, ordering them to stop photographing or photocopying guests’ identity documents and credit‑card details. The guidance follows citizen complaints about hotels keeping such copies for tax or transaction verification. The Authority warned that the practice breaches GDPR principles of legality, transparency and data minimisation, and it raises unnecessary risks of fraud or unauthorised access.

Hotel associations, including the National Federation of Hoteliers and the Greek Hotel Chamber, were instructed to promptly inform their members of the new obligations. Establishments must ensure a lawful basis for any personal‑data processing, conduct necessity assessments, provide clear information to customers, and redesign check‑in, payment and reservation procedures to comply with the data‑protection rules.