KlarComply
HomeKnowledge › AI in hotels

AI in hotels: what is allowed, what must be disclosed, what is banned

The most sensitive place in a hotel is not reception, it is the spa: a skin analysis creates health data, and it usually lands in the same system as the room booking. Add the chatbot, check-in and scheduling. Most of it is permitted and needs only a notice — one application has been prohibited since February 2025.

By , Founder of KlarComply · Reviewed on

Infographic: AI in hotels: the strongest lever is Article 5 — The sharpest rule in hospitality is not the training duty — it is the ban.
The key points of this article as a graphic — feel free to share or download it.

The most sensitive place is the spa

The hotel spa does what a beauty salon does — with one difference that changes everything: the data lands in the hotel system.

An AI skin analysis produces a finding about pigmentation, redness or wrinkle depth. That finding says something about the guest's state of health, which makes it health data under Art. 4(15) GDPR — a special category under Article 9. Processing it is prohibited in principle and becomes lawful only through explicit consent.

The mistake almost every hotel makes

The spa module is part of the property management system. Treatment notes, skin findings and allergy flags therefore sit in the same database as the room booking and the billing address — visible to anyone with access to the system. Including reception. Including the night shift.

Article 32 GDPR requires measures appropriate to the risk. For health data that means separated permissions: whoever does not treat does not see treatment data. That is not a recommendation, it is the standard a supervisory authority will measure you against.

Who owns the data when the spa is run by an operator?

Many hotel spas are leased or run by a contractor. The question of who is the controller is then not academic — it decides who has to obtain consent and who is liable if something goes wrong:

ArrangementWho is controllerWhat you need
Spa belongs to the hotel, staff are employedthe hotelconsent, separated permissions, a processing agreement with the app vendor
Spa is run by an external operatorusually the operatora clear line on who sees which data — and a contract saying so
Both use the same systemoften jointly (Art. 26)a joint controllership arrangement

The third row is the normal case and is almost never settled. Where hotel and spa operator share a guest database, they are often joint controllers under Article 26 GDPR and must record in writing who discharges which duty. Without that arrangement, both are exposed.

And the images?

Everything that applies in a salon applies to before-and-after shots from the spa — including the advertising ban on injectables in some member states. A hotel posting treatment results on Instagram should know the three questions: may I show it, do I have consent to publish, was AI involved?

And in the rest of the house: start with what is banned

Emotion recognition on staff: prohibited, not regulated

Article 5 of the AI Act prohibits systems that infer emotions of employees in the workplace. This is not a compliance checklist — it is a ban. It has applied since 2 February 2025 and carries the highest penalty in the regulation: up to €35 million or 7 % of worldwide annual turnover.

For a hotel that means: no software measuring friendliness at reception, evaluating the mood of service staff, or drawing conclusions about employees' state of mind from video. Not “for quality assurance” either, and not with the workforce's agreement.

The only exceptions are medical or safety reasons — a system detecting fatigue in drivers, for instance. Guest satisfaction is not one of them.

Also prohibited: untargeted scraping of facial images from the internet or from CCTV material to build a facial recognition database. Anyone introducing an access control system should know that sentence before the vendor explains how well their matching works.

Facial recognition at check-in: one word decides it

Remote biometric identification sits in Annex III of the AI Act and therefore counts as high risk, with everything that follows from it. But there is an exemption, and it decides the entire compliance burden:

What the system doesQuestion it answersClassification
Matches against the guest's own submitted ID photo“Is this the same person?”Verification — exemption applies
Searches a database of many people“Who is this?”Identification — high risk

A check-in kiosk comparing a selfie against the scanned passport verifies. A system matching a person against a list — banned guests, regulars, wanted persons — identifies. The difference is one line in the datasheet and an entirely different workload.

The GDPR applies alongside and independently. Biometric data used for unique identification is a special category under Article 9 — including in pure verification. So you need the guest's explicit consent and a reasonable alternative for anyone who declines. A check-in that does not work without a face scan is not freely given consent.

Chatbots and automated review replies

Both fall under Article 50 and are straightforward — you simply have to do it.

As an aside: guests now spot generic AI replies reliably. A disclosed reply reads as more honest than one everybody notices and nobody mentions.

Scheduling and recruitment

AI that screens applications, allocates shifts or evaluates performance sits in Annex III point 4 — employment. That is high risk, with one important qualification: the Digital Omnibus postponed those duties to 2 December 2027.

So you have time — but two things already apply. First, worker representation: in most member states, introducing systems capable of monitoring behaviour or performance requires involving the works council or its equivalent, and what matters is what the system can do, not what you intend to use it for. The rules differ by country, so check yours. Second, the GDPR, which applies to employee data regardless.

Dynamic pricing

Optimising rates by occupancy, weekday and competition is ordinary business and not high-risk AI. Caution is needed at one point only: prices that follow personal characteristics of the guest rather than demand move quickly towards a prohibited practice — and in any event into a discrimination problem.

What to do

  1. Start in the spa. That is where the most sensitive data sits. Who can see treatment notes — and who actually needs to?
  2. Write down what is running. Skin analysis, chatbot, check-in, revenue system, review replies, scheduling, cameras. Ask IT about features nobody ordered — modern systems acquire AI functions by update.
  3. Rule out emotion recognition. In writing from the vendor, not verbally. It is the one question where a “no” is existential.
  4. Settle the check-in question: verify or identify? The answer belongs in your file.
  5. Put the notices in place — chatbot, review profile.
  6. Train the team and keep the record. With a date.

Frequently asked questions

Can we measure staff satisfaction with AI?

Not through emotion recognition. Systems inferring emotions of employees in the workplace are prohibited under Article 5 of the AI Act, with the highest penalty in the regulation. An anonymous survey remains perfectly possible.

Is facial recognition at check-in allowed?

As pure verification — matching a selfie against the ID the guest presents — the Annex III exemption applies and the system does not count as high risk. As soon as it matches people against a database it is identification, and therefore high risk. Independently of that, Article 9 GDPR requires explicit consent and a genuine alternative for guests who decline.

Do we have to disclose AI replies to reviews?

For longer, substantive replies, yes. For a short thank-you it is disputed. The simplest practical route is a one-off note in your profile saying replies are drafted with AI assistance — that covers every case and reads more openly than it costs.

Our scheduling software just added an AI feature. What does that mean?

Shift allocation and performance evaluation sit in Annex III as high risk, but those duties were postponed to 2 December 2027. What matters immediately is worker representation: in most member states, introducing a system capable of monitoring behaviour or performance requires involving employee representatives — and what counts is what the system can do, not what you intend.

Our spa uses a skin-analysis app. What do we have to do?

Three things. Explicit consent from the guest under Art. 9(2)(a) GDPR, separate from consent to the treatment itself. A data processing agreement with the app vendor. And separated permissions in the hotel system: whoever does not treat has no reason to see skin findings.

Our spa is run by an external operator — does this still concern us?

Almost always, because both use the same guest database. Hotel and operator are then often joint controllers under Article 26 GDPR and must record in writing who discharges which duty. Without that arrangement, both are exposed. It is the most commonly overlooked point in this arrangement.

Does this apply to small hotels?

Yes. The AI Act has no headcount threshold. For penalties, small and medium enterprises face the lower of the two figures — which changes nothing about the obligation itself.

We only use our chain's systems. Are we off the hook?

No. Whoever operates a system is a deployer under the regulation, even if head office selected it. Ask them in writing which AI functions are included — that is also the start of your inventory.

Where does your company stand?

The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.

Start the quick check — free
Read on AI literacy obligation → Building an AI inventory → Labelling AI content (Art. 50) → The AI Act for SMEs → Writing an AI policy → AI in the beauty salon → Appointing an AI lead → ChatGPT at work and the GDPR → Approving AI tools → Finding shadow AI → AI and employee representation → Classifying AI risk → The AI supplier questionnaire → Customer data in an AI tool → Penalties under Article 99 → Trade secrets and AI tools → AI in physiotherapy practices → AI in dental practices → AI in tax and accounting firms → AI in hair salons → AI in advertising agencies → AI for estate agents → AI in car repair shops → AI in trades businesses → AI in law firms → DPO requirements → Records of processing → DPA (Art. 28) → Data breach & 72 hours → GDPR staff training → US tools & transfers →
Sources:
Article 5 AI Act — prohibited practices
Article 50 AI Act — transparency obligations
Annex III AI Act — high-risk areas
Article 9 GDPR — special categories of personal data
Article 26 GDPR — joint controllers
Regulation (EU) 2024/1689 — official full text
Reviewed on 26 August 2026 · Reflects the Digital Omnibus · This article is general information and not legal advice.