Cybersecurity Policy Report, Luxembourg DPA: Tourist Accommodation Operators May Not Copy ID Documents, (Jun 1, 2026)
By Tony Foley
As summer tourist season opens, Luxembourg’s data protection authority, the National Commission for Data Protection (CNPD), has reminded operators of tourist accommodations that they are not allowed under data protection law to copy the identification documents of their clients.
The agency said in a May 28 news release that under legislation enacted in February 2025, operators were obliged to establish an accommodation record for each traveler aged 15 and older and for each stay. To fulfill this obligation, operators are allowed to consult the identity documents of their clients, but CNPD emphasized that they may not make copies of the documents, as doing so constitutes a violation of the data minimization requirements of article 5(1)(c) of the European Union’s General Data Protection Regulation (GDPR).
News: InternationalLegislation DataPrivacy GDPR