POPIA for Guesthouse and Hotel Front Desks: What Staff Must Do

A guest checks in at 21:40 and hands over an ID book. The receptionist photocopies it, leaves the copy on the printer, and later sends a photo of it to the owner on a personal WhatsApp “so you have it”. Nothing bad happens that night. Each of those steps is still a POPIA problem, and each one is a habit you can fix.

POPIA applies to every guesthouse, B&B, lodge and hotel that records guest details, however small. At the front desk it comes down to five habits: collect only what you need, keep it out of sight, share it only with the people who need it, send marketing only with consent, and report any mistake to the Information Officer at once, because every security compromise must be reported to the Information Regulator.

Guest Data Protection (POPIA) for Front Desk and Reservations trains reception and reservations staff in exactly these habits: about 2¾ hours online, R450, picture-based and interactive, with a proctored final assessment and a certificate. It is also part of the Hospitality Short Courses Bundle, four courses for R1 260 instead of R1 800.

POPIA at the front desk: the key facts

The law Protection of Personal Information Act 4 of 2013 (POPIA). In force since 1 July 2020; the one-year grace period ended on 30 June 2021
Who it covers Every business that processes personal information. There is no exemption for small guesthouses
Personal information at reception Names, ID and passport numbers, phone numbers, email addresses, car registrations, card details, dates of stay, room numbers and CCTV images
Special personal information (s26) Religious beliefs, health, race or ethnic origin, biometrics, criminal behaviour, sex life, trade union membership and political persuasion. A kosher or halal breakfast request or a medical need can reveal it
Information Officer (s55) The head of the business by default. Must be registered with the Information Regulator and may appoint deputies
Security safeguards (s19) Reasonable technical and organisational measures: locked cabinets, lock screens, passwords, shredding
Operators (s20 and s21) Booking engines, channel managers and cloud property systems process guest data for you and need a written contract that keeps it secure
Security compromises (s22) No size threshold: every compromise is reported to the Regulator on its eServices Portal as soon as reasonably possible, and affected guests are told in writing
Direct marketing (s69) Email, SMS, WhatsApp and phone calls. Opt-in consent for people who are not existing customers; the Regulator’s December 2024 guidance note treats voice calls as electronic communication. The National Consumer Commission’s opt-out registry (2026) also applies
Penalties Administrative fines of up to R10 million; some offences carry up to 10 years’ imprisonment

Does POPIA apply to a small guesthouse?

Yes. POPIA has no minimum size. A four-room B&B that takes a name, a phone number and a deposit is a “responsible party” in exactly the same way as a hotel group, and the staff who handle that information act on the business’s behalf.

In practice a small property carries more risk per guest, not less. There is often one shared computer, one shared email inbox, a paper register on the counter and a personal cellphone doing the work of a booking system. None of that is unlawful in itself. It simply means the safeguards have to be deliberate, because nobody else is going to build them for you.

What guest information may reception collect?

Only what you need for a clear purpose, and preferably from the guest directly (sections 10, 12 and 13). For a booking that is usually a name, contact details, dates, room requirements and payment. You do not need ID numbers for children to take a booking.

Section 18 also requires you to tell guests what you collect and why. A short notice on the booking confirmation and registration card, with a link to your privacy notice, covers most of it. Train staff to answer the question “why do you need that?” with a real reason. If there is no reason, do not collect it.

What reception typically needs, and why
Information Why it is needed Watch out for
Name and contact number Confirming the booking, emergencies Do not add guests to a marketing list without consent
Email address Confirmation and invoice Check the spelling before you send anything that contains personal details
Dates of stay and room Running the booking Never tell a caller which room a guest is in
Card or payment details Deposit and payment Never write card numbers down or send them by email or WhatsApp
Dietary or access needs Breakfast and room set-up May be special personal information: share only with the kitchen or housekeeping
Car registration Secure parking, where you offer it Keep the parking list at the desk, not on a public clipboard

Can a guesthouse photocopy guests’ ID documents?

Only if there is a real reason. Looking at an ID confirms who the guest is, and you can record the details you need. Copying every ID “just in case” breaks the processing limitation condition, and each copy becomes something you must store securely and destroy later.

If the business does have a lawful reason to keep copies, the Information Officer should write that reason down, decide how long copies are kept and where. Then the everyday rules apply: collect printouts straight away, keep copies in a locked cabinet, never leave them on the printer or the counter, and shred them when the retention period ends. Photographing an ID on a personal phone is the worst of both worlds, because the copy now lives in a private gallery and often in a cloud backup as well.

Who is the Information Officer, and what do they do?

By default the Information Officer is the head of the business: the owner, or the managing director of a company. They must be registered with the Information Regulator, they may appoint deputies, and they handle guest requests, complaints and security compromises.

Front desk staff do not need to know the law in detail. They do need to know who the Information Officer is, how to reach them after hours, and that anything unusual goes to that person the same day: a guest asking what information you hold, a request to delete details, a complaint, a lost register, or an email sent to the wrong address.

Can staff send guest details on WhatsApp?

Not on personal chats. Section 19 requires reasonable safeguards, and a guest’s ID photo or card details sitting in a staff member’s personal WhatsApp is neither controlled nor recoverable. Use the business’s own systems and approved business channels, and send only what the recipient needs.

WhatsApp is fine for telling a guest their room is ready. It is not a filing system. If a message with personal information goes to the wrong person, treat it as a security compromise: contain it where you can (ask the recipient to delete it, recall an email) and tell the Information Officer immediately.

Where may CCTV be used in a guesthouse?

In public areas such as entrances, parking and reception, openly, with signs, and only as far as security requires. Never in bedrooms, bathrooms or changing areas. Footage of guests is personal information, so access to it is restricted and recordings are deleted when no longer needed.

Can we send guests marketing emails, SMS or WhatsApp messages?

Section 69 of POPIA controls direct marketing by electronic communication, and the Information Regulator’s guidance note of 3 December 2024 takes the position that phone calls count (a view the direct marketing industry disputes and the Regulator intends to test in court). Past guests may receive marketing for similar services if they were given a chance to object when their details were collected and are given one again in every message. Anyone else must opt in first.

  • Past guests: an offer for your own accommodation is a similar service. Every message needs a simple way to opt out, and an opt-out is honoured at once.
  • Enquiries that did not book, and bought-in lists: you may approach a person once, only to ask for consent, using the prescribed consent form. If they say no or do not answer, that is the end of it.
  • Check the opt-out registry. Since 15 April 2026, amended Consumer Protection Act regulations require direct marketers to register with the National Consumer Commission’s opt-out registry and not to market to anyone who has registered a block there. Clean your list against it.
  • Keep the proof. Record when and how each person consented. “They gave us their number” is not consent to marketing.

What happens if guest information goes to the wrong person?

Tell the Information Officer immediately. Section 22 requires the business to notify the Information Regulator and the affected guests as soon as reasonably possible. The Regulator requires these reports through its eServices Portal, there is no minimum size, and you do not need to finish investigating before reporting.

Typical front desk compromises are small and common: a registration card left on the counter, an invoice emailed to the wrong “J. Smith”, a laptop stolen from reception, a guest list sent to a supplier who did not need it. The person who spots it should not decide whether it “counts”. Their job is to contain it where they can and report it the same hour.

How long may we keep guest registers and booking records?

No longer than the purpose or the law requires (section 14). The Information Officer sets the retention periods; for example, SARS generally requires financial records to be kept for five years. After that, shred paper and delete digital records permanently.

The classic failure is the storeroom: boxes of old registers and registration cards from years ago, unlocked and forgotten. They are personal information until they are destroyed.

What can guests ask for?

A guest may ask what personal information you hold about them (section 23) and ask you to correct or delete information that is wrong, out of date or should not be held (section 24). Reception refers the request to the Information Officer rather than answering it at the counter.

A front desk POPIA checklist

  • Staff know who the Information Officer is and how to reach them after hours.
  • Booking and registration forms ask only for what is needed, and say why.
  • IDs are viewed, not copied, unless there is a documented reason.
  • The register and registration cards are kept behind the desk, with previous entries covered.
  • Screens lock when staff step away, and passwords are not written on the monitor.
  • Printouts are collected at once; paper waste with personal details is shredded.
  • Guest information is shared only with the people who need it, never on personal chats.
  • Room numbers and guest details are never confirmed to callers.
  • Marketing lists contain only past guests with an opt-out, or people who opted in.
  • Every mistake is reported the same day, and nobody decides alone that it “does not count”.

Frequently asked questions

Does POPIA apply to a small B&B with only a few rooms?

Yes. POPIA has no size threshold. Any business that records guests’ names, contact details, ID numbers or payment details must meet its conditions, and must have a registered Information Officer.

Can a guesthouse keep a copy of a guest’s ID?

Only if there is a lawful reason, documented by the Information Officer. Otherwise view the ID to confirm identity and record only the details you need. Any copies must be stored securely and destroyed when no longer needed.

Who is the Information Officer of a guesthouse?

The head of the business by default, usually the owner. They must be registered with the Information Regulator and may appoint deputies to help.

Do we have to report a small data breach, such as one email sent to the wrong guest?

Yes. POPIA has no reporting threshold. The Information Officer reports every security compromise to the Information Regulator through its eServices Portal as soon as reasonably possible and tells the affected guests in writing.

Can we send past guests a special offer by WhatsApp or email?

Yes, for similar services such as your own accommodation, provided they were given a chance to object when you collected their details and every message includes an easy way to opt out.

Is a guest’s dietary request personal information?

Yes, and it can be special personal information. A kosher or halal request may reveal religious belief, and a medical diet may reveal health information. Share it only with the kitchen staff who need it.

What is the maximum POPIA fine?

The Information Regulator can impose administrative fines of up to R10 million. Some offences, such as certain offences involving account numbers, carry up to 10 years’ imprisonment.

Which ASC course covers this

Guest Data Protection (POPIA) for Front Desk and Reservations is built around the reception desk: what counts as personal information, collecting and using guest information, ID copies and card details, CCTV, marketing consent, guest requests and what to do when something goes wrong. Four short modules with picture-based quizzes and a proctored final assessment, R450, with a certificate on completion.

For a whole team, the Hospitality Short Courses Bundle adds Chemical Safety for Housekeeping and Laundry, Fire Safety and Evacuation for Accommodation and Food Safety for Caterers and Events, all four for R1 260. New support staff can start with Guesthouse Support Staff Essentials. See every course for accommodation and food service on the Hospitality and Foodservice Training page, and the full guesthouse compliance checklist.

Sources

Leave a Comment