Does GDPR Apply to California Hotels? What Portfolio Operators Need to Know

Share

California hotel operators usually think first about CCPA and CPRA. That makes sense. But for many hotel portfolios, GDPR is not just a European issue.

A California hotel can fall within GDPR in certain situations, even if the business is based in the United States. For portfolio operators, management companies, and asset managers, the real question is not “Do we have a property in Europe?” It is “Are we processing personal data in a way that puts part of our operation inside GDPR’s scope?” GDPR’s territorial scope is activity-based, not just location-based.

The short answer

Yes, GDPR can apply to California hotels.

The two most common triggers are straightforward:

First, GDPR applies when personal data is processed in the context of the activities of an establishment in the EU or EEA, even if the actual processing happens elsewhere. Second, GDPR can also apply to a business outside the EU if it offers goods or services to people in the EU or EEA, or monitors their behavior there.

For hotels, that means GDPR risk is often tied to how reservations are marketed, booked, managed, and analyzed across a portfolio.

When GDPR is more likely to apply to a California hotel

1. You market rooms or hotel services to guests in the EU or EEA

GDPR can apply when a non-EU business offers goods or services to individuals in the EU or EEA. The rule is not limited to physical delivery in Europe. The question is whether the business is intentionally targeting or serving people there. Official guidance looks at indicators such as using EU languages or currencies, referencing customers in EU markets, or otherwise showing an intention to reach people in the Union.

For a California hotel, practical examples might include:

  • booking flows built to attract travelers in Germany, France, or Spain
  • paid campaigns aimed at EU audiences
  • localized reservation pages for EU travelers
  • accepting bookings from EU residents through channels clearly designed for that market

A hotel does not become subject to GDPR merely because an EU resident happens to visit its website. The stronger case is intentional targeting.

2. You monitor behavior of people in the EU or EEA

GDPR can also apply to a business outside the EU when it monitors the behavior of individuals in the EU. The European Commission notes that this includes tracking and profiling online behavior, and the EDPB guidance takes a broad view of monitoring, including behavioral analysis tied to prediction or profiling.

In hospitality, that can come up through:

  • adtech and retargeting
  • behavioral analytics tied to booking journeys
  • loyalty profiling
  • mobile app usage analytics
  • location-aware marketing
  • personalized offers based on browsing or stay behavior

This does not mean every analytics tool automatically triggers GDPR. It means hotels should assess whether their tracking is aimed at observing and influencing people while they are in the EU or EEA. That is a facts-and-context question.

3. Your portfolio has an EU establishment connected to the processing

GDPR applies where processing is carried out in the context of the activities of an establishment in the EU, regardless of where the data is actually processed. So if a hotel group has an EU office, sales operation, reservation support function, or affiliated entity whose activities are tied to the relevant processing, GDPR can attach even when systems or servers are in the United States.

For hotel portfolios, this matters when reservations, CRM operations, marketing coordination, or guest support are centralized across jurisdictions.

Common hotel scenarios

Here is the practical version.

A California hotel is more likely to have GDPR exposure if it:

  • actively markets to EU travelers
  • profiles EU users for marketing or booking conversion
  • uses an EU-based sales or reservation function tied to guest data
  • processes guest, loyalty, or employee data through EU operations

A California hotel is less likely to have GDPR exposure if it:

  • only serves guests in California without targeting EU markets
  • does not monitor behavior of people in the EU
  • has no EU establishment tied to the processing
  • only receives occasional bookings from EU travelers without purposeful targeting

The important point is that GDPR is not triggered just because someone from Europe stays at a California property. The trigger is usually the hotel’s own conduct: establishment, offering, or monitoring.

What data puts this on the radar for hotels

Hotels routinely process personal data across:

  • reservations and folios
  • payment data
  • loyalty records
  • guest preferences
  • CCTV footage
  • spa, dining, and amenity usage
  • marketing lists
  • employee records
  • vendor and platform integrations

That does not mean all of it is subject to GDPR. It does mean that when GDPR does apply, the operational footprint can be wide. The issue is rarely one database. It is the full workflow across PMS, CRM, booking engines, marketing platforms, support teams, and third-party vendors.

If GDPR applies, what changes operationally?

For hotel operators, GDPR is not just a website notice issue. It affects the operating model.

A few immediate implications:

You need a clear lawful basis for processing

GDPR requires a lawful basis for each processing activity, such as contract, legal obligation, legitimate interests, consent, vital interests, or public task. Hotels often rely on contract for reservation fulfillment, legal obligation for certain records, and legitimate interests for some operational activities, but the basis should be mapped activity by activity.

You need to support data subject rights

GDPR gives individuals rights including access, rectification, erasure in some circumstances, restriction, objection, and data portability where applicable. Access rights in particular require operational discipline because the response must include both the personal data and the Article 15 information that accompanies it.

Your request timelines may be shorter than California’s

Your internal privacy workflow cannot assume a single deadline. HotelComply’s own product model reflects this difference: GDPR requests are typically handled on a 30-day track, while CCPA/CPRA workflows use a 45-day track. That operational distinction matters for multi-jurisdiction guest request handling.

International transfers need attention

If personal data moves from the EEA to the United States, transfer rules come into play. The European Commission explains that transfers outside the EEA require an approved mechanism such as an adequacy decision or other safeguards, including Standard Contractual Clauses in the appropriate cases.

You may need an EU representative

Where a non-EU controller or processor is subject to GDPR under the “offering goods or services” or “monitoring behavior” route, Article 27 can require designation of an EU representative, subject to exceptions. EDPB guidance on breach notification also reiterates that Article 27 applies where Article 3(2) applies.

What California hotel portfolios should do now

If you operate multiple properties, this should be an operational review, not a one-page legal memo.

Start with four questions:

  1. Are we intentionally marketing rooms, stays, memberships, or offers to people in the EU or EEA?
  2. Are we tracking or profiling people in the EU or EEA through booking tools, loyalty systems, apps, or ad platforms?
  3. Do we have any EU establishment, affiliate, or function tied to the processing?
  4. If GDPR applies, can we actually execute the workflow across requests, vendor oversight, records of processing, and transfer documentation?

That is where hotel teams often discover the real issue. The problem is not whether the law exists. The problem is whether the workflow exists.

The real takeaway

For California hotels, GDPR is not automatic. But it is also not rare.

If your hotel portfolio reaches into EU markets, profiles EU users, or processes personal data through EU-linked operations, GDPR may apply to at least some of your processing activities. The right question is not “Are we a European hotel?” It is “Which parts of our guest, employee, and vendor data workflows create GDPR exposure?”

For hospitality operators, that answer usually lives in the details: booking journeys, loyalty programs, marketing tech, vendor contracts, and request-handling procedures.

Need a clearer view of where GDPR and CCPA/CPRA intersect across your portfolio? HotelComply helps hotel operators operationalize privacy workflows across guest requests, records of processing, vendor oversight, retention controls, and audit-ready documentation.

Not legal advice: This post is for operational guidance and does not replace advice from qualified counsel.