Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Commerce & industry

Privacy & Security for Hospitality & Hotels

Hotels hold something few other businesses do: a record of who slept where, on which night, with which vehicle in the lot. That record lives in a PMS and CRS stack shared with brands, OTAs and channel managers, beside three kinds of card payment and a phishing campaign aimed squarely at front-desk inboxes. Privacy Horizon helps Canadian operators, from a single independent property to a management company running dozens of flags, put working privacy and security governance around all of it.

Reviewed by the Privacy Horizon team · Last reviewed

Who this is for

We work with general managers, owners and asset managers, controllers facing PCI attestations, and the operations or IT lead of a management company responsible for a portfolio of properties. Franchisees of the major flags and independent resort owners fit here too; most have one regional IT manager and an MSP rather than a security team.

The call usually follows a trigger: an acquirer letter about front-desk terminals and the booking engine, a phished Booking.com extranet account, a cloud PMS migration to OPERA Cloud, Cloudbeds or Mews, a cyber-insurance renewal, or the guest-register duties Ontario brought into force on January 1, 2026.

Timing matters in this industry, so we plan engagements for the shoulder seasons and keep hands off your systems through the summer peak and the holidays. Budgets set in September and October can carry a January start.

Gourmet dish served elegantly with fresh ingredients at a fine dining restaurant during the evening

Services

Privacy & security services for hospitality & hotels

Each service below is scoped for how hospitality & hotels actually operate — their systems, their regulators and the reviews they face.

What you hold

What needs protecting in a hotel's data estate

Guest data is not one database. It is a web of operational systems, each holding a different slice of a person's stay, and each with its own way of going wrong.

Guest whereabouts and stay history

A folio and guest profile record who stayed, when, in which room and with whom. Merged profiles and loyalty accounts stretch that history across years and properties, which is exactly why reservation databases attract patient, long-dwell intrusions.

The statutory guest register

Ontario properties must now capture guest names, residence or billing addresses, phone numbers and on-site vehicle information, hold the register for six years and produce it to police under defined rules. It needs deliberate access and retention controls, not a binder behind the desk.

Cards in three channels at once

Card-present lanes at the front desk, restaurant and spa sit beside MOTO reservations taken over the phone and card-not-present bookings online, with OTA virtual credit cards flowing through the same PMS. Few other buildings combine all of these under one roof.

ID collected at check-in

Passports and driver's licences get photocopied or keyed into the PMS at the desk during every arrival rush. What may be kept, and for how long, should be a policy decision rather than a habit inherited from the last front office manager.

The building's own trails

CCTV, key-card audit logs and guest Wi-Fi records track people through the property. Each is personal information with its own retention question, and each attracts disclosure requests from lawyers, insurers and police.

Regulatory map

The regulatory stack sitting on Canadian hotels

Hotels answer to general privacy law, a sector statute unique to accommodation, payment-card rules and anti-spam law all at once. The overlaps are where operators get caught.

PIPEDA and its breach duties

Hotels are commercial actors under PIPEDA: breaches creating a real risk of significant harm must be reported to the OPC and to affected guests as soon as feasible, and records of every breach must be kept for two years.

Read our guide →

Ontario's ASRGA, in force January 1, 2026

The Accommodation Sector Registration of Guests Act replaced the old Hotel Registration of Guests Act. Hotels, motels, resorts and online accommodation platforms must keep a guest register, retain it six years, and answer police production orders and urgent demands tied to human-trafficking investigations.

Primary source →

Quebec Law 25 for hotel enterprises

Quebec properties need a person in charge of personal information, privacy impact assessments for new systems and for communication outside the province, which captures a US-hosted PMS or CRS, plus incident notification to the CAI and an incident register.

Primary source →

Alberta and BC PIPA differences

Alberta requires notice to the Commissioner of harmful breaches without unreasonable delay, while BC imposes no mandatory reporting and treats notice as voluntary best practice. Operators spanning both provinces need one process that satisfies each regulator.

Read our guide →

PCI DSS v4.0.1 across every lane

Front-desk terminals, F&B outlets, spa payments, card-on-file in the PMS and the online booking engine all sit in scope, and the SAQ A changes of March 31, 2025 altered what booking pages must demonstrate.

Primary source →

CASL on pre- and post-stay email

Marketing to past and future guests needs consent, clear sender identification and an unsubscribe honoured within ten business days, whether the list came from folios, the booking engine or the loyalty program.

Primary source →

What goes wrong

How hotel operators actually get breached

The incidents that define this sector run through the reservation stack and the people at the desk, not through exotic exploits.

  • Phished OTA extranet accounts

    Microsoft attributes to Storm-1865 an ongoing campaign impersonating Booking.com to hotel staff, using fake-CAPTCHA ClickFix pages to install credential stealers. The stolen extranet login is then used to defraud the hotel's own guests through the platform's messaging.

    Source →

  • A breached back-office platform

    The Otelier incident showed how one hospitality back-office vendor, compromised through stolen credentials, exposed reservation data for properties under several major flags at once. Your exposure includes every platform your nightly data flows into.

    Source →

  • Long-dwell reservation-database compromise

    The OPC's Marriott/Starwood finding described an intrusion that ran undetected for years, with failures in access controls, monitoring and over-retention, and set out pointed expectations for security due diligence when properties change hands.

    Source →

  • Forged key cards at the room door

    The Unsaflok research demonstrated forged keycards opening doors fitted with a widely deployed lock line. Door hardware is part of a hotel's security scope, because a lock flaw is a guest-safety and premises-liability problem, not an IT footnote.

    Source →

  • Deposit fraud on groups and events

    Wedding and conference deposits move on emailed instructions between couples, planners and the sales office, which is the classic setup for business email compromise. A convincing spoof can redirect a deposit before anyone thinks to pick up the phone.

When organisations call us

The moments hotels pick up the phone

Privacy and security work in hospitality is event-driven. These are the situations that start engagements.

  • An acquirer or processor demands PCI evidence

    A letter from Moneris, Global Payments or Elavon asks how the front-desk lanes, restaurant POS and booking engine are secured, and the controller needs credible answers before the attestation deadline.

  • The extranet hijack already happened

    Guests received scam messages through Booking.com, the OTA suspended the account, and the brand wants an explanation. Recovery has to run alongside an honest look at how the credentials were lost.

  • A cloud PMS migration is on the calendar

    Moving to OPERA Cloud, Cloudbeds, Mews or StayNTouch, or adding a channel manager like SiteMinder, changes where guest data lives and who can reach it. The migration window is the cheapest moment to fix access, retention and contract terms.

  • A brand or management-agreement audit is coming

    Flags and owners increasingly fold IT and payment-security expectations into their audits. Management companies want their houses in order before the auditor books a room.

  • Cyber-insurance renewal raises the bar

    Renewal questionnaires ask about MFA, backups, incident plans and training across every property. Answers stretch thin when each hotel runs its own habits.

  • A property is being bought or sold

    Since the OPC's findings on the Starwood acquisition, security due diligence on a target's reservation systems is an explicit expectation, not a nice-to-have in the data room.

  • The register deadline arrived

    Ontario's guest-register duties took effect January 1, 2026, and operators need collection, retention and police-request procedures the night shift can actually follow.

Hospitality & Hotels: privacy & security questions, answered

PIPEDA covers commercial guest data in most of the country, while Alberta and BC apply their own PIPAs and Quebec applies Law 25 with its person-in-charge, assessment and incident duties. Sector obligations stack on top: Ontario's ASRGA guest-register requirements, PCI DSS through your acquirer agreements, and CASL for marketing email. Most groups build one program to the strictest applicable rule and adjust per province rather than running separate regimes.

Both hold pieces. The brand typically operates the CRS and loyalty platform under its own accountability, while the franchisee or management company remains responsible for the property's PMS, payment lanes, staff conduct and the guest register. Management agreements and brand standards allocate some duties, but a regulator looks at who controls the information in question, so the property cannot simply point at the flag.

Yes. ASRGA reaches hotels, motels and resorts and also online accommodation platforms, which must keep the required register information and retain it for six years. If you operate a property and take direct bookings, the duty is yours regardless of channel; listing through a platform does not transfer it.

The extranet login is the shortcut to money. With access to Booking.com or Expedia Partner Central, an attacker reads upcoming reservations and messages guests as the hotel, asking them to verify payment details. Guests trust those messages because they arrive inside the platform's own channel. Hardening that one account with unique credentials, MFA and restricted devices buys more protection than most website spending.

Shoulder seasons. January through April and late fall are when occupancy allows assessments, migrations and testing; July, August and the holiday period are effectively frozen. Budgets are typically set in September and October, so operators who scope work in the fall can start in the new year without competing with peak operations.

When they can identify a person, yes, and in a hotel they usually can, because footage, lock events and network sessions tie back to a named guest or employee. That means each needs a defined purpose, a retention period and a controlled process for disclosure requests. Handing footage or logs to anyone who asks at the desk is one of the most common failures we see in this sector.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.