AI in Hospitality6 min read·Aug 27, 2026

Is It GDPR-Compliant to Let AI Answer Guest Emails?

Yes, under conditions. An operator's guide to the conditions, the special category data hiding in ordinary guest requests, the AI Act disclosure duty that went live on 2 August 2026, and thirteen questions to ask any AI vendor before signing.

Image of a person answering emails with AI in a GDPR friendly way.
Image of Kristoffer Pedersen
Kristoffer Pedersen
Co-Founder, Altek AI

Yes, under conditions. A hotel can lawfully let AI read and answer guest emails if it has a lawful basis for each purpose, a data processing agreement with the vendor, data minimisation in practice, transparency towards the guest, and a human decision point wherever the outcome materially affects that guest. This guide explains each condition.

Last updated 20 August 2026.

This is not legal advice. We build hotel software, we are not lawyers, and compliance depends on facts specific to your properties. Take your own counsel, or run this past your data protection officer. What follows is written as an operator's guide to the questions a hotel should ask a vendor, which is both safer and more useful than a legal opinion from a company that sells the product.

One note on scope. This page is about the GDPR, and since 2 August 2026 there is a second regime sitting alongside it: the transparency obligations in the EU AI Act. They are separate laws with separate regulators, and meeting one does not meet the other. There is a section on the AI Act below.

What personal data is actually involved when AI reads a guest email?

More than most vendors admit, and one category more sensitive than most hotels expect. A reservations inbox carries names, contact details, stay dates, rates and booking references. It also carries dietary and accessibility requests, and those can be a different thing entirely under the law.

What is in an ordinary guest email, and how the GDPR treats it

The last three rows are the ones that get skipped in vendor documentation. They are also the ones that decide how careful your configuration has to be.

What is in the emailHow the GDPR treats itWhat that means in practice
Name, email address, telephone numberPersonal data under Article 4Ordinary processing. You still need a lawful basis and you still owe the guest transparency
Stay dates, room type, rate, booking referencePersonal dataContract performance covers most of this for an existing or prospective booking
Payment references and card tokensPersonal data, high risk if mishandledUsually held by the PMS or the payment provider. Confirm in writing that the AI vendor never receives a raw card number
Loyalty tier and stay historyPersonal data, and profiling if used to differentiate what the guest is offeredFine in itself. It becomes an Article 22 question only if a decision is taken solely automatically and significantly affects the guest
Dietary requirementsPotentially special category data under Article 9A coeliac or nut allergy request reveals health. A halal or kosher request can reveal religious belief. Neither is ordinary personal data
Accessibility requestsSpecial category data under Article 9, healthStep-free access, a hearing loop, a service animal. This is health data about a named individual, sitting in a shared mailbox
Free text the guest volunteersUnpredictable, frequently Article 9Guests disclose pregnancies, bereavements and medical conditions unprompted, in a booking enquiry. Any minimisation policy has to survive that

Article references are to Regulation (EU) 2016/679. This table describes the categories commonly present in hotel reservations mail; your own inbox may carry more.

The Article 9 point is the one worth sitting with. Article 9 of the GDPR prohibits processing of data revealing health, religious belief and several other categories, unless a specific exception applies. Hotels have always handled this data. What changes when AI enters the inbox is that the data is now flowing through an additional system, run by an additional company, and your documentation needs to say so.

Is the hotel the controller or the processor?

The hotel is the controller. The AI vendor is a processor. That is the normal arrangement and it decides who is accountable for what. The EDPB's guidance on the two roles is the reference point if you need to argue the case internally.

Practically, controller status means four things sit with you and not with your vendor. You decide the purposes and the means. You own the lawful basis. You answer the guest when they exercise their rights. You are the one a supervisory authority contacts.

The vendor's obligations run through Article 28: process only on your documented instructions, keep the data confidential, apply appropriate security under Article 32, engage no sub-processor without your authorisation, help you respond to guest requests, and delete or return the data when the contract ends. If a vendor tells you it is jointly responsible for compliance, ask what it means. Compliance is a property of how you use a tool, not of the tool.

The stakes are set out in Article 83: the upper tier of administrative fines reaches 20 million euros or 4% of total worldwide annual turnover, whichever is higher. For a group, that is calculated on group turnover.

What lawful basis applies to AI answering a guest email?

It differs by purpose, and more than one basis can apply inside a single email thread. This is the detail most often collapsed.

Contract performance, Article 6(1)(b). Handling an enquiry about an existing booking, or steps taken at the guest's request before entering a contract. This covers the bulk of reservations mail.

Legitimate interests, Article 6(1)(f). Operational uses such as quality review, service level monitoring or fraud prevention. Requires a documented balancing test, and the guest can object.

Consent, Article 6(1)(a). Marketing. Also the realistic route for special category data under Article 9(2)(a), which requires explicit consent rather than ordinary consent.

A single thread can move across all three. A guest asks about availability, mentions a wheat allergy, and later receives a newsletter. Those are three purposes and three bases, and your record of processing activities should show them separately.

Does Article 22 apply to AI replying to a guest?

Usually not, and it is worth being accurate about this rather than overstating it to make a product look necessary.

Article 22 restricts decisions based solely on automated processing that produce legal effects or similarly significantly affect the individual. Three conditions have to be met together: a decision, taken solely automatically, with a legal or similarly significant effect. Answering an availability question almost certainly fails the third condition. Sending a rate quote does not decide anything about the guest's rights.

Some actions sit closer to the line. Cancelling a booking without human involvement. Refusing a rate or a stay to a specific guest on the basis of a profile. Applying a penalty charge. These alter a contractual position, and the argument that they only similarly significantly affect the guest is at least arguable.

Two points from case law and guidance are worth knowing. In Case C-634/21, decided on 7 December 2023, the Court of Justice of the European Union held that an automated probability value produced by one company can itself be an automated individual decision when a third party relies heavily on it. The scope of Article 22 is therefore wider than a narrow reading suggests. Separately, the EDPB's position is that human involvement must be capable of changing the outcome. A person who clicks approve without the authority, information or time to overturn the suggestion is not human involvement in the sense the regulation means.

The practical conclusion is unglamorous. Most guest email handling falls outside Article 22. The subset that might fall inside it is small, identifiable in advance, and easy to route to a person. That is a configuration decision, not a legal problem, provided your tool lets you make it per action type.

What does the EU AI Act add on top of GDPR?

A disclosure duty, and it is already live. Article 50 of the AI Act, Regulation (EU) 2024/1689, became applicable on 2 August 2026 and is enforceable by national authorities from that date.

This is worth stating plainly, because a lot of boards heard the opposite. The AI Act was widely reported as delayed in mid-2026, and the high-risk provisions were: the Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and moved the Annex III high-risk deadline to 2 December 2027 and the Annex I deadline to 2 August 2028. Article 50 was deliberately left out of that deferral. If your compliance plan was built around the high-risk cliff, you gained sixteen months. If it touches anything that talks to a guest, nothing moved at all.

The obligation itself is short. An AI system intended to interact directly with a natural person must be designed and operated so that the person is informed they are dealing with an AI system, unless that is obvious from the context. A website chat widget or a WhatsApp thread answered by an agent is squarely in scope. Email is the more interesting case, and the answer turns on your autonomy setting rather than on your vendor.

If someone on your team reads the suggested reply, can change it, and sends it, a person sent that email. If the reply goes out on auto-send with nobody in the thread, the guest is corresponding with software and has not been told. That second case is where the disclosure belongs. The practical rule is that the disclosure requirement scales with the autonomy level, which makes it a configuration question in exactly the same way approval is.

Two further points for a procurement conversation. Article 50(2) requires machine-readable marking of AI-generated content, and systems already on the market before 2 August 2026 have until 2 December 2026 to comply, so ask your vendor where that work stands rather than assuming it is done. And AI Act transparency breaches sit in a fine tier of up to 15 million euros or 3% of worldwide turnover, which is exposure separate from and additional to Article 83 of the GDPR.

Note also that Article 50 splits duties between the provider of the system and the deployer of it. The vendor builds the capability. You, as the hotel, decide whether it is switched on. Neither of you can point at the other.

What should a hotel ask an AI vendor before signing?

Thirteen questions. They apply to any vendor in this category, including ours, and the third column matters as much as the first.

Thirteen questions to ask an AI vendor, and the answers that should worry you

Send these before the demo rather than after it. A vendor that cannot answer them in writing is telling you something.

Ask thisWhy it mattersA weak answer sounds like
Where is guest data processed and stored, and is the region named in our contract?Determines whether a transfer mechanism is needed at all"We use secure global infrastructure"
Is there a Data Processing Agreement, and can we read it before signing?Article 28 requires one. You are the controller and it is your instrument"We can send one over once you're a customer"
Who are the sub-processors, and how are we notified when the list changes?You authorise them. Silent additions break Article 28(2)"A few standard cloud providers"
Is our data used to train AI models, and separately, is it used to tune prompts or configurations?Two different mechanisms with different implications. Most vendors answer only the first"We never train on customer data", with nothing said about the second
What is the retention period for message content, and who sets it?Storage limitation is a principle, not a setting you can leave at the default"We keep data as long as necessary"
Can data be deleted on request, and how long does deletion take end to end?Includes backups and logs, not only the visible record"You can delete conversations in the interface"
Do you maintain a record of processing activities under Article 30?Processors have their own Article 30 obligation"That's the controller's responsibility"
What happens when a guest makes a subject access request against data in your system?Article 28(3)(e) requires the vendor to assist you"Export the thread yourself"
Is there a human review point, and can it be set per action type and per property?One account-wide switch is not a control, it is a preference"There's an approval toggle"
Is every action logged in an audit trail we can export?Accountability under Article 5(2) means being able to demonstrate it"We have internal logging"
What access scopes do you request in our PMS, and can we see the list?Least privilege is checkable. Ask for the scopes, not a reassurance"Standard read and write access"
What certifications do you hold today, as distinct from in progress?"Working towards ISO 27001" is not ISO 27001"We're fully certified" with no certificate number or auditor named
When a reply sends automatically, is the guest told they are dealing with AI, and where is that configured?AI Act Article 50 has applied since 2 August 2026 and is separate from the GDPR"That's covered in our privacy policy"

Article references are to Regulation (EU) 2016/679. Use this list on every vendor you shortlist, including Altek.

How does data residency work for EU hotels?

If processing and storage stay inside the EEA, there is no international transfer and Chapter V does not apply. That is the simplest position and the one to aim for.

If data leaves the EEA, you need a transfer mechanism. An adequacy decision by the European Commission is the cleanest: the destination is treated as offering essentially equivalent protection, and no further instrument is required. Standard contractual clauses are the usual fallback, and since Schrems II they come with an obligation to assess the destination country's laws and add supplementary measures where the clauses alone are not enough.

Two practical notes. A US-hosted vendor is not automatically a problem, but it is a question with a documented answer rather than a shrug. And adequacy is not permanent: the renewed EU adequacy decisions for the UK, adopted in December 2025, run to 27 December 2031 and are monitored throughout. Build a review date into the contract rather than assuming today's position holds.

What does human in the loop actually mean in practice?

It means a person who can change the outcome, not a person who clicks approve. The distinction is the whole point, and it is where a lot of vendor language goes soft.

Rubber-stamp approval, where a reviewer sees fifty suggestions an hour and approves forty-nine, is not meaningful review. Genuine review requires authority to override, access to the underlying data, and enough understanding of how the suggestion was produced to disagree with it. The ICO's guidance on AI and data protection is the most readable treatment of this if you are building the internal case.

Which is why a single approval switch is the wrong shape. If everything requires review, reviewers stop reading, and the control becomes theatre. If nothing does, you have no control at all. The defensible configuration is three levels set per action type, per property and per risk level: draft only, approve before sending, or send automatically.

And there is a second decision hiding inside the third level. Setting an action to auto-send decides two things, not one. It decides that nobody reviews the message, which is the GDPR question this page started with. It also decides that a machine is now corresponding with your guest under your hotel's name, which is the AI Act question. Where a reply goes out with no person in the thread, say so in the reply. It costs a line and it removes the argument entirely.

A control that fires on every message is a control nobody reads. Let a parking question send itself, and make a cancellation wait for a person. That is what makes the review real when it happens.

Kristoffer Pedersen, co-founder, Altek AI

That granularity is also what makes the Article 22 question answerable. If the small set of actions that could significantly affect a guest is routed to a person by configuration, you are not arguing about whether Article 22 applies. You have removed the condition that would trigger it.

How Altek handles this

Everything above applies to any vendor. This section is about ours, and it is at the end deliberately, because the rest of the page should be usable whether or not you ever talk to us.

Altek processes and stores data in dedicated cloud regions, with the region that applies to your properties named in your DPA. Today that is the EU. A Data Processing Agreement is available, data flows are documented, and retention policies are under your control. The sub-processor list and current certification status are in the security pack, available on request. ISO 27001 and SOC 2 processes are underway and not yet complete, and we will say certified when the audits say so and not before.

On model training, the answer is no, with a distinction most vendors skip. Altek does not train or fine-tune AI models on hotel data. What it does do is measure which replies convert at your property and use that to optimise the prompt itself, so the system gets better at your hotel over time. Training a model and tuning a prompt are different mechanisms, and a vendor that answers only the first half has not answered the question. Ask any vendor, including us, for both answers in writing.

On execution, permissions are defined by property and by action. Altek requests only the access scopes needed for the operations you enable, per system, and every execution is recorded in an audit trail. Approval is the default rather than the ceiling: three levels per action type, configured per property and per risk level. Human approval on every action is the starting configuration.

On disclosure, where a reply is sent automatically with nobody in the thread, Altek tells the guest they are dealing with AI. At the draft and approve levels a member of your team reads the reply and sends it, so a person sent that email. That is the Article 50 point in its practical form: the disclosure follows the autonomy level, which means it is set in the same place and at the same granularity as the approval rule.

We are not going to tell you Altek is GDPR compliant, because that is not a property a piece of software can have on its own. It is a property of how your hotel uses it, on your lawful basis, with your retention policy and your approval configuration. What we can do is answer all thirteen questions above in writing before you sign.

Frequently asked questions

Do we need guest consent for AI to read their email?
Usually not. Handling an enquiry about an existing or prospective booking is normally covered by contract performance under Article 6(1)(b), and consent is not required for that. Consent becomes relevant for marketing, and explicit consent becomes relevant where special category data under Article 9 is involved. What you do owe the guest in every case is transparency, which means your privacy notice should say that AI is used in handling their enquiry.
Can AI process guest passport or ID data?
It can be lawful, but treat it as a separate decision from email handling. Identity documents are often collected under a legal obligation for guest registration, which is a different lawful basis with its own retention rules. The safer configuration is to keep identity documents in the PMS and out of the AI system's scope entirely. Ask your vendor whether their integration can even see those fields.
Is a US-hosted AI vendor a problem for an EU hotel?
Not automatically, but it needs a documented answer. If data leaves the EEA you need a transfer mechanism: an adequacy decision, or standard contractual clauses supported by a transfer impact assessment. The simpler position is a vendor that processes and stores inside the EEA, because then Chapter V does not apply at all. Ask where the data actually sits, and get the region named in the contract.
Do we have to tell guests they are dealing with AI and not a person?
Where the reply is generated and sent without a person in the thread, yes. Article 50 of the EU AI Act has applied since 2 August 2026 and requires that a person interacting directly with an AI system is informed of that, unless it is obvious from context. A website chat widget clearly falls inside it. For email, the honest reading is that it depends on your autonomy setting: if a colleague reviews and sends, a person sent it, and if it auto-sends, the guest has not been told. This is a separate obligation from the GDPR, with a separate fine tier of up to 15 million euros or 3% of worldwide turnover.
Was the EU AI Act delayed?
The high-risk provisions were, and the transparency provisions were not. The Digital Omnibus on AI entered into force on 27 July 2026 and moved the Annex III high-risk deadline to 2 December 2027 and the Annex I deadline to 2 August 2028. Article 50 was excluded from that deferral and applied on schedule from 2 August 2026. Reading only the delay headline is the mistake worth avoiding here.
Will our guest data be used to train the vendor's AI?
Ask two questions rather than one, because they have different answers. The first is whether your data trains or fine-tunes the vendor's AI models. The second is whether it is used to tune prompts, templates or configurations, which is a different mechanism and one most vendors do not volunteer. A vendor can answer no to the first and yes to the second, and both answers belong in your DPA. If prompt tuning is happening, also ask whether the learning stays inside your property or is applied across the vendor's customer base.
What if a guest asks us to delete their data?
You are the controller, so the request comes to you and you answer it. Your vendor's obligation under Article 28(3)(e) is to assist you, which is why deletion mechanics belong in the procurement conversation rather than the support ticket. Ask specifically about backups and logs: deleting a visible conversation is not the same as deleting every copy, and the timeline for the second one is the number that matters.
Does GDPR require a human to approve every AI reply?
No. Article 22 restricts decisions taken solely automatically that produce legal or similarly significant effects, and answering an availability question does not meet that bar. The requirement is targeted rather than blanket. A tool that lets you set approval per action type is the practical way to meet it, because it puts the human where the regulation actually asks for one.
Are dietary requests really special category data?
They can be. A gluten-free or nut allergy request reveals information about health. A halal or kosher request can reveal religious belief. Both are Article 9 categories, which need an Article 9 condition on top of your Article 6 basis. Most hotels have never treated a dinner preference this way, which is exactly why it is worth raising before an AI system starts processing it at volume.

Altek handles hotel email end to end. It reads each guest inquiry, retrieves live availability and reservation data from the hotel's PMS, writes the reply and carries out the work behind it, including reservations, modifications, restaurant and spa bookings and payment links, with human approval on every action. Altek works with Mews, Opera Cloud and Visbook/BookVisit, and is used by 115 hotels across eight countries. Founded in Norway, headquartered in Oslo.