New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
Commerce & industry
Privacy & Security for Hospitality & Hotels
Hotels hold something few other businesses do: a record of who slept where, on which night, with which vehicle in the lot. That record lives in a PMS and CRS stack shared with brands, OTAs and channel managers, beside three kinds of card payment and a phishing campaign aimed squarely at front-desk inboxes. Privacy Horizon helps Canadian operators, from a single independent property to a management company running dozens of flags, put working privacy and security governance around all of it.
Reviewed by the Privacy Horizon team · Last reviewed
Who this is for
We work with general managers, owners and asset managers, controllers facing PCI attestations, and the operations or IT lead of a management company responsible for a portfolio of properties. Franchisees of the major flags and independent resort owners fit here too; most have one regional IT manager and an MSP rather than a security team.
The call usually follows a trigger: an acquirer letter about front-desk terminals and the booking engine, a phished Booking.com extranet account, a cloud PMS migration to OPERA Cloud, Cloudbeds or Mews, a cyber-insurance renewal, or the guest-register duties Ontario brought into force on January 1, 2026.
Timing matters in this industry, so we plan engagements for the shoulder seasons and keep hands off your systems through the summer peak and the holidays. Budgets set in September and October can carry a January start.

Services
Privacy & security services for hospitality & hotels
Each service below is scoped for how hospitality & hotels actually operate — their systems, their regulators and the reviews they face.
Virtual CISO
Virtual CISO for Hospitality & Hotels
vCISO for hotels and management companies: fractional security leadership that speaks PMS, PCI and brand standards across a multi-property Canadian portfolio.
Virtual Privacy Officer
Virtual Privacy Officer for Hospitality & Hotels
Virtual Privacy Officer for hotels: a named privacy lead for guest data, Law 25 duties, CASL marketing and register questions across all your properties.
Penetration Testing
Penetration Testing for Hospitality & Hotels
Hotel penetration testing: booking engine, guest Wi-Fi segmentation, POS networks and front-desk phishing resilience, tested without disturbing a single stay.
Incident Response Planning
Incident Response Planning for Hospitality & Hotels
Hotel incident response planning: playbooks for OTA account hijacks, PMS outages and card compromises, with OPC, CAI, acquirer and brand notifications mapped.
Privacy & Security Policy Development
Privacy & Security Policy Development for Hospitality & Hotels
Privacy policy development for hotels: guest notices covering CCTV, Wi-Fi and ID collection, retention schedules for registers and folios, and staff policies.
Privacy & Security Training
Privacy & Security Training for Hospitality & Hotels
Privacy and security training for hotel teams: front-desk phishing defence, card handling for F&B and spa staff, VIP confidentiality and guest-register rules.
Vendor Security Review & Questionnaire Support
Vendor Security Review & Questionnaire Support for Hospitality & Hotels
Vendor security review for hotels: assess the PMS, channel manager, POS, payment and door-lock providers your property depends on, after Otelier and Unsaflok.
Minimum Viable Privacy Program
Minimum Viable Privacy Program for Hospitality & Hotels
Minimum Viable Privacy for independent hotels: a $5,499 CAD/year program covering the guest register, ID retention, CASL and front-desk breach basics.
What you hold
What needs protecting in a hotel's data estate
Guest data is not one database. It is a web of operational systems, each holding a different slice of a person's stay, and each with its own way of going wrong.
Guest whereabouts and stay history
A folio and guest profile record who stayed, when, in which room and with whom. Merged profiles and loyalty accounts stretch that history across years and properties, which is exactly why reservation databases attract patient, long-dwell intrusions.
The statutory guest register
Ontario properties must now capture guest names, residence or billing addresses, phone numbers and on-site vehicle information, hold the register for six years and produce it to police under defined rules. It needs deliberate access and retention controls, not a binder behind the desk.
Cards in three channels at once
Card-present lanes at the front desk, restaurant and spa sit beside MOTO reservations taken over the phone and card-not-present bookings online, with OTA virtual credit cards flowing through the same PMS. Few other buildings combine all of these under one roof.
ID collected at check-in
Passports and driver's licences get photocopied or keyed into the PMS at the desk during every arrival rush. What may be kept, and for how long, should be a policy decision rather than a habit inherited from the last front office manager.
The building's own trails
CCTV, key-card audit logs and guest Wi-Fi records track people through the property. Each is personal information with its own retention question, and each attracts disclosure requests from lawyers, insurers and police.
Regulatory map
The regulatory stack sitting on Canadian hotels
Hotels answer to general privacy law, a sector statute unique to accommodation, payment-card rules and anti-spam law all at once. The overlaps are where operators get caught.
PIPEDA and its breach duties
Hotels are commercial actors under PIPEDA: breaches creating a real risk of significant harm must be reported to the OPC and to affected guests as soon as feasible, and records of every breach must be kept for two years.
Ontario's ASRGA, in force January 1, 2026
The Accommodation Sector Registration of Guests Act replaced the old Hotel Registration of Guests Act. Hotels, motels, resorts and online accommodation platforms must keep a guest register, retain it six years, and answer police production orders and urgent demands tied to human-trafficking investigations.
Quebec Law 25 for hotel enterprises
Quebec properties need a person in charge of personal information, privacy impact assessments for new systems and for communication outside the province, which captures a US-hosted PMS or CRS, plus incident notification to the CAI and an incident register.
Alberta and BC PIPA differences
Alberta requires notice to the Commissioner of harmful breaches without unreasonable delay, while BC imposes no mandatory reporting and treats notice as voluntary best practice. Operators spanning both provinces need one process that satisfies each regulator.
PCI DSS v4.0.1 across every lane
Front-desk terminals, F&B outlets, spa payments, card-on-file in the PMS and the online booking engine all sit in scope, and the SAQ A changes of March 31, 2025 altered what booking pages must demonstrate.
CASL on pre- and post-stay email
Marketing to past and future guests needs consent, clear sender identification and an unsubscribe honoured within ten business days, whether the list came from folios, the booking engine or the loyalty program.
What goes wrong
How hotel operators actually get breached
The incidents that define this sector run through the reservation stack and the people at the desk, not through exotic exploits.
Phished OTA extranet accounts
Microsoft attributes to Storm-1865 an ongoing campaign impersonating Booking.com to hotel staff, using fake-CAPTCHA ClickFix pages to install credential stealers. The stolen extranet login is then used to defraud the hotel's own guests through the platform's messaging.
A breached back-office platform
The Otelier incident showed how one hospitality back-office vendor, compromised through stolen credentials, exposed reservation data for properties under several major flags at once. Your exposure includes every platform your nightly data flows into.
Long-dwell reservation-database compromise
The OPC's Marriott/Starwood finding described an intrusion that ran undetected for years, with failures in access controls, monitoring and over-retention, and set out pointed expectations for security due diligence when properties change hands.
Forged key cards at the room door
The Unsaflok research demonstrated forged keycards opening doors fitted with a widely deployed lock line. Door hardware is part of a hotel's security scope, because a lock flaw is a guest-safety and premises-liability problem, not an IT footnote.
Deposit fraud on groups and events
Wedding and conference deposits move on emailed instructions between couples, planners and the sales office, which is the classic setup for business email compromise. A convincing spoof can redirect a deposit before anyone thinks to pick up the phone.
When organisations call us
The moments hotels pick up the phone
Privacy and security work in hospitality is event-driven. These are the situations that start engagements.
An acquirer or processor demands PCI evidence
A letter from Moneris, Global Payments or Elavon asks how the front-desk lanes, restaurant POS and booking engine are secured, and the controller needs credible answers before the attestation deadline.
The extranet hijack already happened
Guests received scam messages through Booking.com, the OTA suspended the account, and the brand wants an explanation. Recovery has to run alongside an honest look at how the credentials were lost.
A cloud PMS migration is on the calendar
Moving to OPERA Cloud, Cloudbeds, Mews or StayNTouch, or adding a channel manager like SiteMinder, changes where guest data lives and who can reach it. The migration window is the cheapest moment to fix access, retention and contract terms.
A brand or management-agreement audit is coming
Flags and owners increasingly fold IT and payment-security expectations into their audits. Management companies want their houses in order before the auditor books a room.
Cyber-insurance renewal raises the bar
Renewal questionnaires ask about MFA, backups, incident plans and training across every property. Answers stretch thin when each hotel runs its own habits.
A property is being bought or sold
Since the OPC's findings on the Starwood acquisition, security due diligence on a target's reservation systems is an explicit expectation, not a nice-to-have in the data room.
The register deadline arrived
Ontario's guest-register duties took effect January 1, 2026, and operators need collection, retention and police-request procedures the night shift can actually follow.
Hospitality & Hotels: privacy & security questions, answered
PIPEDA covers commercial guest data in most of the country, while Alberta and BC apply their own PIPAs and Quebec applies Law 25 with its person-in-charge, assessment and incident duties. Sector obligations stack on top: Ontario's ASRGA guest-register requirements, PCI DSS through your acquirer agreements, and CASL for marketing email. Most groups build one program to the strictest applicable rule and adjust per province rather than running separate regimes.
Both hold pieces. The brand typically operates the CRS and loyalty platform under its own accountability, while the franchisee or management company remains responsible for the property's PMS, payment lanes, staff conduct and the guest register. Management agreements and brand standards allocate some duties, but a regulator looks at who controls the information in question, so the property cannot simply point at the flag.
Yes. ASRGA reaches hotels, motels and resorts and also online accommodation platforms, which must keep the required register information and retain it for six years. If you operate a property and take direct bookings, the duty is yours regardless of channel; listing through a platform does not transfer it.
The extranet login is the shortcut to money. With access to Booking.com or Expedia Partner Central, an attacker reads upcoming reservations and messages guests as the hotel, asking them to verify payment details. Guests trust those messages because they arrive inside the platform's own channel. Hardening that one account with unique credentials, MFA and restricted devices buys more protection than most website spending.
Shoulder seasons. January through April and late fall are when occupancy allows assessments, migrations and testing; July, August and the holiday period are effectively frozen. Budgets are typically set in September and October, so operators who scope work in the fall can start in the new year without competing with peak operations.
When they can identify a person, yes, and in a hotel they usually can, because footage, lock events and network sessions tie back to a named guest or employee. That means each needs a defined purpose, a retention period and a controlled process for disclosure requests. Handing footage or logs to anyone who asks at the desk is one of the most common failures we see in this sector.
Related industries
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.