The most sensitive place in a hotel is not reception, it is the spa: a skin analysis creates health data, and it usually lands in the same system as the room booking. Add the chatbot, check-in and scheduling. Most of it is permitted and needs only a notice — one application has been prohibited since February 2025.
By Patrick de Kathen, Founder of KlarComply · Reviewed on
The hotel spa does what a beauty salon does — with one difference that changes everything: the data lands in the hotel system.
An AI skin analysis produces a finding about pigmentation, redness or wrinkle depth. That finding says something about the guest's state of health, which makes it health data under Art. 4(15) GDPR — a special category under Article 9. Processing it is prohibited in principle and becomes lawful only through explicit consent.
The spa module is part of the property management system. Treatment notes, skin findings and allergy flags therefore sit in the same database as the room booking and the billing address — visible to anyone with access to the system. Including reception. Including the night shift.
Article 32 GDPR requires measures appropriate to the risk. For health data that means separated permissions: whoever does not treat does not see treatment data. That is not a recommendation, it is the standard a supervisory authority will measure you against.
Many hotel spas are leased or run by a contractor. The question of who is the controller is then not academic — it decides who has to obtain consent and who is liable if something goes wrong:
| Arrangement | Who is controller | What you need |
|---|---|---|
| Spa belongs to the hotel, staff are employed | the hotel | consent, separated permissions, a processing agreement with the app vendor |
| Spa is run by an external operator | usually the operator | a clear line on who sees which data — and a contract saying so |
| Both use the same system | often jointly (Art. 26) | a joint controllership arrangement |
The third row is the normal case and is almost never settled. Where hotel and spa operator share a guest database, they are often joint controllers under Article 26 GDPR and must record in writing who discharges which duty. Without that arrangement, both are exposed.
Everything that applies in a salon applies to before-and-after shots from the spa — including the advertising ban on injectables in some member states. A hotel posting treatment results on Instagram should know the three questions: may I show it, do I have consent to publish, was AI involved?
Article 5 of the AI Act prohibits systems that infer emotions of employees in the workplace. This is not a compliance checklist — it is a ban. It has applied since 2 February 2025 and carries the highest penalty in the regulation: up to €35 million or 7 % of worldwide annual turnover.
For a hotel that means: no software measuring friendliness at reception, evaluating the mood of service staff, or drawing conclusions about employees' state of mind from video. Not “for quality assurance” either, and not with the workforce's agreement.
The only exceptions are medical or safety reasons — a system detecting fatigue in drivers, for instance. Guest satisfaction is not one of them.
Also prohibited: untargeted scraping of facial images from the internet or from CCTV material to build a facial recognition database. Anyone introducing an access control system should know that sentence before the vendor explains how well their matching works.
Remote biometric identification sits in Annex III of the AI Act and therefore counts as high risk, with everything that follows from it. But there is an exemption, and it decides the entire compliance burden:
| What the system does | Question it answers | Classification |
|---|---|---|
| Matches against the guest's own submitted ID photo | “Is this the same person?” | Verification — exemption applies |
| Searches a database of many people | “Who is this?” | Identification — high risk |
A check-in kiosk comparing a selfie against the scanned passport verifies. A system matching a person against a list — banned guests, regulars, wanted persons — identifies. The difference is one line in the datasheet and an entirely different workload.
The GDPR applies alongside and independently. Biometric data used for unique identification is a special category under Article 9 — including in pure verification. So you need the guest's explicit consent and a reasonable alternative for anyone who declines. A check-in that does not work without a face scan is not freely given consent.
Both fall under Article 50 and are straightforward — you simply have to do it.
As an aside: guests now spot generic AI replies reliably. A disclosed reply reads as more honest than one everybody notices and nobody mentions.
AI that screens applications, allocates shifts or evaluates performance sits in Annex III point 4 — employment. That is high risk, with one important qualification: the Digital Omnibus postponed those duties to 2 December 2027.
So you have time — but two things already apply. First, worker representation: in most member states, introducing systems capable of monitoring behaviour or performance requires involving the works council or its equivalent, and what matters is what the system can do, not what you intend to use it for. The rules differ by country, so check yours. Second, the GDPR, which applies to employee data regardless.
Optimising rates by occupancy, weekday and competition is ordinary business and not high-risk AI. Caution is needed at one point only: prices that follow personal characteristics of the guest rather than demand move quickly towards a prohibited practice — and in any event into a discrimination problem.
Not through emotion recognition. Systems inferring emotions of employees in the workplace are prohibited under Article 5 of the AI Act, with the highest penalty in the regulation. An anonymous survey remains perfectly possible.
As pure verification — matching a selfie against the ID the guest presents — the Annex III exemption applies and the system does not count as high risk. As soon as it matches people against a database it is identification, and therefore high risk. Independently of that, Article 9 GDPR requires explicit consent and a genuine alternative for guests who decline.
For longer, substantive replies, yes. For a short thank-you it is disputed. The simplest practical route is a one-off note in your profile saying replies are drafted with AI assistance — that covers every case and reads more openly than it costs.
Shift allocation and performance evaluation sit in Annex III as high risk, but those duties were postponed to 2 December 2027. What matters immediately is worker representation: in most member states, introducing a system capable of monitoring behaviour or performance requires involving employee representatives — and what counts is what the system can do, not what you intend.
Three things. Explicit consent from the guest under Art. 9(2)(a) GDPR, separate from consent to the treatment itself. A data processing agreement with the app vendor. And separated permissions in the hotel system: whoever does not treat has no reason to see skin findings.
Almost always, because both use the same guest database. Hotel and operator are then often joint controllers under Article 26 GDPR and must record in writing who discharges which duty. Without that arrangement, both are exposed. It is the most commonly overlooked point in this arrangement.
Yes. The AI Act has no headcount threshold. For penalties, small and medium enterprises face the lower of the two figures — which changes nothing about the obligation itself.
No. Whoever operates a system is a deployer under the regulation, even if head office selected it. Ask them in writing which AI functions are included — that is also the start of your inventory.
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free