What Happens When a Hotel Guest Submits a CCPA Data Request — A Step-by-Step Walkthrough
It starts with an email. Or a phone call to the front desk. Or a form submission on your website.
A guest — maybe someone who stayed three months ago, maybe someone who booked through an OTA and never actually checked in — asks your hotel for all the personal data you've collected on them.
Under the California Privacy Rights Act (CPRA), you have 45 calendar days to respond. Here's exactly what that process looks like for a hotel.
Day 0: The Request Arrives
DSARs (Data Subject Access Requests) can come through any channel. There's no required format. A guest might say:
- "I'd like a copy of all personal information your hotel has collected about me."
- "Under CPRA, I'm requesting access to my data."
- "What do you have on file for my stay last October?"
All of these count. The clock starts the day you receive the request.
Realistic scenarioA guest named Maria Chen emails [email protected] on March 1st. She stayed at your property twice in 2025 and wants to know what data you've collected.
What you need to do immediately:
1. Log the request — date received, channel, guest name, and contact information
2. Verify identity — you need to reasonably verify this is actually Maria Chen, not someone impersonating her. For a known guest, matching the email to your PMS reservation record is typically sufficient. For unverifiable requests, you can ask for additional verification (but you can't use this as a stalling tactic)
3. Acknowledge receipt — while not legally required, best practice is to confirm you received the request within 48 hours
4. Assign an owner — someone at your property needs to be responsible for this request through completion
Days 1–14: The Data Inventory
This is where most hotels panic. Because "all personal data you've collected" means you need to check **every system** that might hold Maria's information:
Your PMS (Property Management System)
- Reservation details (dates, room type, rate)
- Government ID information (if collected at check-in)
- Guest preferences and notes
- Payment card data (last four digits)
- Loyalty program information
Your Email Marketing Platform
- Email address
- Open and click history
- Segmentation tags
- Subscription status
Your Spa/Wellness Software
- If Maria booked a spa treatment, this system may hold health intake form data — which qualifies as **sensitive personal information** under CPRA §1798.140(ae)
Your Guest WiFi Provider
- Device identifiers (MAC address)
- Browsing session data
- Login credentials (name, email, room number)
Your Payment Processor
- Transaction records
- Tokenized payment data
Your CRM
- Stay history
- Communication logs
- Guest satisfaction scores
OTA Records
- If Maria booked through Booking.com or Expedia, those platforms are independent data controllers — you cannot fulfill a DSAR for data they control. But you need to know what data *you* received from the OTA and retained in your own systems.
The hard part:
Most hotels have never mapped which systems hold guest data. This is exactly what a Record of Processing Activities (ROPA) is designed to solve — but if you don't have one, Day 1 of a DSAR is not the time to build it.
Days 14–30: Compile and Review
Once you've pulled records from every system, you need to:
1. Compile everything into a single response — organized by data category
2. Redact third-party information — if Maria's reservation notes reference another guest ("traveling with John Smith"), that name needs to be redacted
3. Review with legal if necessary— especially if the request involves sensitive PI (spa health data, government IDs)
4. Format the response— CPRA requires the response be in a "readily usable format" if the guest requests it electronically
What the response must include:
Under CPRA §1798.110, your response needs to cover:
- The categories of personal information collected
- The specific pieces of personal information collected
- The categories of sources from which the information was collected
- The business or commercial purpose for collecting the information
- The categories of third parties to whom the information was disclosed
Days 30–45: Deliver the Response
Send the compiled response to Maria through a secure channel — encrypted email, a secure download link, or registered mail. Do not send unencrypted files containing government IDs or payment data via regular email.
Your response should also inform Maria of her other rights under CPRA:
- Right to delete her personal information
- Right to correct inaccurate personal information
- Right to limit use of sensitive personal information
- Right to opt out of the sale or sharing of personal information
What if you need more time?
CPRA allows a one-time 45-day extension if reasonably necessary. You must notify the guest of the extension and the reason for it within the initial 45-day window. That gives you 90 days total — but using the extension signals to a regulator that your processes aren't mature.
Where Hotels Get This Wrong
Mistake #1: No assigned owner. The request lands in a shared inbox and nobody picks it up for two weeks.
Mistake #2: Incomplete data inventory. You pull PMS records but forget about the guest WiFi system, the spa software, and the email marketing platform.
Mistake #3: OTA confusion. You try to provide data that Booking.com controls, or worse, you tell the guest you don't have any data because "they booked through Expedia."
Mistake #4: No documented process. Even if you handle the request correctly, you have no audit trail to prove it. When the CPPA asks how you handle DSARs, "we figure it out each time" is not an answer.
Mistake #5: Ignoring the request entirely. This is the most common — and most dangerous — response. A single unresponded DSAR is a provable violation at $2,500 to $7,500 per incident.
The Bottom Line
A DSAR isn't optional. It's not a suggestion. And the 45-day clock doesn't pause because you're short-staffed or because it's your busy season.
The hotels that handle DSARs well are the ones that have three things in place before the request arrives:
1. A documented DSAR workflow with an assigned owner
2. A complete data inventory mapping every system that holds guest PI
3. Response templates that cover the required disclosures
The ones that don't have those things? They're the ones scrambling on Day 1 — and hoping the CPPA doesn't come asking questions on Day 46.
HotelComply's DSAR Management module builds the workflow, assigns the owner, and maps the data inventory before your first request arrives.
Ready to document your guest-request process?
Start with a Property Snapshot to identify documentation gaps across your guest-data workflow and vendor stack. HotelComply then prepares the DSAR procedure, ROPA records, vendor documentation, and audit-ready Compliance Package for your portfolio.