← Back to the EU AI Act duties
A completed Data Protection Impact Assessment for a hotel guest agent doing bookings, dynamic pricing and biometric check-in — the document Article 35 requires before that system goes live.
Data Protection Impact Assessment: GuestFlow
This document constitutes a Data Protection Impact Assessment (DPIA) for the AI agent GuestFlow, as required by Article 35 of the General Data Protection Regulation (GDPR). This DPIA is a scaffold for completion and sign-off by a qualified Data Protection Officer (DPO) or compliance officer.
1. Description of Processing Operations and Purposes (GDPR Art. 35(7)(a))
GuestFlow is an AI-powered hotel concierge system operating across a multi-jurisdictional hotel group in the EU. Its processing operations are designed to streamline guest interactions from booking to post-stay feedback.
-
Purposes of Processing:
- To manage guest bookings, answer enquiries, and check room availability by interfacing with the Property Management System (PMS).
- To perform 1:1 identity verification at check-in by matching a guest's government-issued ID scan against their reservation details. This involves processing special category biometric data with explicit consent.
- To apply dynamic pricing based on objective criteria such as booking channel and loyalty program tier.
- To screen reservations for indicators of payment fraud or high chargeback risk.
- To enhance guest experience by proposing personalised room upgrades based on guest history and availability.
- To manage guest complaints by drafting responses and autonomously issuing goodwill refunds up to a pre-defined threshold.
-
Categories of Personal Data:
- Identity Data: Name, contact details, nationality.
- Booking Data: Reservation details, stay dates, room preferences, guest history.
- Financial Data: Payment card information (tokenised), transaction history, fraud risk score.
- Special Category Data: Biometric data derived from passport or ID scans for identity verification.
- Interaction Data: Logs of communications with the agent, complaint details, feedback.
-
Recipients of Data: Data is shared internally with hotel staff (e.g., duty managers for refund approvals) and with the central Property Management System. No third-party sharing occurs outside of payment processing gateways.
-
Cross-border Transfers: Data is processed within the EU (Netherlands, Germany, France). While this constitutes cross-border processing, all data resides within the GDPR's territorial scope, and transfers are subject to uniform protection standards.
MUST
clause_type: MUST
framework_reference: "EU GDPR Article 13"
confidence: 0.98
confidence_threshold: 0.90
flagged_for_review: false
The agent MUST, before or at the time of first collecting personal data (e.g., during booking or ID upload), provide the data subject with a clear and concise privacy notice. This notice MUST include the identity of the controller, the purposes of processing (including biometric verification, dynamic pricing, and fraud screening), the lawful bases, the retention periods, and the data subject's rights. This notice must be made available within the agent's user interface within 1 second of the user initiating interaction.
2. Assessment of Necessity and Proportionality (GDPR Art. 35(7)(b))
The processing of personal data by GuestFlow is necessary for the performance of the contract with the guest (booking and stay management) and for pursuing the legitimate interests of the business (fraud prevention, service personalisation). The processing of special category biometric data is strictly limited to identity verification at check-in and is contingent on explicit consent.
- Necessity: Automated processing is necessary to provide 24/7, multilingual service consistently across 40 properties, which would be operationally infeasible to achieve with human staff alone. Biometric verification enhances security and streamlines check-in.
- Proportionality: Data processing is limited to what is required for each specific purpose. For example, biometric data is used only for the 1:1 match and is deleted immediately after, not used for any other purpose. Dynamic pricing is based on non-discriminatory commercial factors.
MUST
clause_type: MUST
framework_reference: "EU GDPR Article 5(1)(b)"
confidence: 1.0
confidence_threshold: 0.90
flagged_for_review: false
The agent MUST process personal data solely for the declared purposes of booking management, biometric verification, dynamic pricing, fraud screening, service personalisation, and complaint management. The agent is prohibited from using this data for any other purpose unless a new lawful basis is established and this DPIA is updated, with the change taking effect only after DPO approval.
MUST NOT
clause_type: MUST NOT
framework_reference: "EU GDPR Article 5(1)(e)"
confidence: 1.0
confidence_threshold: 0.90
flagged_for_review: false
The agent MUST NOT retain personal data beyond the retention periods defined in the organisation's Records of Processing Activities (RoPA). Specifically, biometric data and associated identity documents used for check-in verification MUST be permanently deleted from all operational systems within 24 hours of successful verification.
3. Assessment of Risks to the Rights and Freedoms of Data Subjects (GDPR Art. 35(7)(c))
The following risks to the rights and freedoms of data subjects have been identified.
| Risk | Likelihood | Severity | Residual risk after mitigation |
|---|---|---|---|
| Unauthorised access to special category (biometric) data leading to identity theft or fraud. | Medium | High | Low |
| Inaccurate or unfair automated decisions (e.g., incorrect fraud flag, biased pricing). | Medium | Medium | Low |
| Lack of transparency in how automated decisions are made, eroding guest trust. | Low | Medium | Low |
| Data breach due to processing across multiple properties and systems. | Medium | High | Low |
MUST
clause_type: MUST
framework_reference:
- "EU GDPR Article 32(1)(a)"
- "NIST SP 800-53 Rev 5 AC-3"
- "NIST SP 800-53 Rev 5 SC-28"
confidence: 0.99
confidence_threshold: 0.90
flagged_for_review: false
The agent MUST encrypt all special category biometric data both in transit (using TLS 1.3 or higher) and at rest (using AES-256 or stronger) throughout its lifecycle, from upload to its mandatory deletion. Access to decryption keys MUST be restricted to specifically authorized system processes performing the verification function, in line with established access control policies.
MUST NOT
clause_type: MUST NOT
framework_reference: "EU GDPR Article 9(2)(a)"
confidence: 1.0
confidence_threshold: 0.90
flagged_for_review: false
The agent MUST NOT perform the 1:1 biometric verification without first obtaining and logging the data subject's explicit, freely given, specific, and informed consent for this specific purpose. The consent request interface MUST be presented separately from general terms and conditions and must be actioned by the user before the ID upload function is enabled.
4. Measures Envisaged to Address the Risks (GDPR Art. 35(7)(d))
The following technical and organisational measures will be implemented to mitigate the identified risks.
-
Technical Measures:
- Pseudonymisation and Encryption: All personal data will be encrypted in transit and at rest. Special category data will be subject to state-of-the-art encryption and will be deleted within 24 hours of use.
- Access Control: Strict role-based access controls (RBAC) will be enforced, ensuring that data is only accessible to authorised personnel and system processes with a legitimate need-to-know.
- Human Review: A simple, accessible interface will be provided for guests to request human review of any automated decision that significantly affects them (e.g., a declined booking due to a fraud flag), in line with GDPR Article 22.
- Audit Logging: All access to and processing of personal data, particularly special category data, will be logged in an immutable audit trail to detect and investigate potential misuse.
-
Organisational Measures:
- Policy and Training: All relevant staff will be trained on data protection principles, security protocols, and their responsibilities regarding the
GuestFlowsystem. - Consent Management: A robust framework for obtaining, recording, and managing explicit consent for biometric data processing will be implemented.
- Incident Response: A dedicated incident response plan is in place to manage any potential data breaches, including notification procedures for supervisory authorities and affected data subjects.
- Data Protection by Design: The system is built on the principles of data minimisation, purpose limitation, and security by default. The DPIA will be reviewed annually or upon any material change to processing.
- Policy and Training: All relevant staff will be trained on data protection principles, security protocols, and their responsibilities regarding the
MAY
clause_type: MAY
framework_reference: "EU GDPR Article 12"
confidence: 0.92
confidence_threshold: 0.90
flagged_for_review: false
The agent MAY provide a "privacy dashboard" within the guest's booking profile, allowing the data subject to review the personal data held, see a log of its use (e.g., "ID verified at 14:02 on 2026-09-15"), and exercise their data subject rights directly through an automated interface.
5. Consultation and Sign-off
-
Consultation with the DPO:
- Status:
[ ] Pending/[ ] Completed - DPO Opinion: [Placeholder for DPO to provide their written advice on the risks and proposed measures. This must be completed before sign-off.]
- Status:
-
Consultation with the Supervisory Authority (GDPR Art. 36):
- Based on the mitigating measures outlined in Section 4, the residual risk is assessed as LOW. Therefore, prior consultation with the supervisory authority is not deemed necessary at this stage. This conclusion must be validated by the DPO.
Approval and Sign-off
This DPIA has been reviewed and approved. The deployment and operation of the GuestFlow agent, in accordance with the measures described herein, is authorised.
- Data Protection Officer / Compliance Officer Name:
- Signature:
- Date:
PRO TIER — COMMERCIAL DEPLOYMENT
LICENCE: Commercial deployment rights included. This bundle may be used to operate the described agent in production under your Pro subscription terms. Compliance-officer review and approval remain required before deployment.
HUMAN REVIEW REQUIRED — DO NOT DEPLOY WITHOUT COMPLIANCE-OFFICER SIGN-OFF
This file was generated by the C2MD Compliance Agent. It has not been reviewed or approved by a qualified compliance officer or legal counsel.
Compliance-officer review and written approval are MANDATORY before this file may be deployed, published, or relied upon in any regulatory, contractual, or operational context.
The C2MD agent produces approval-ready governance artefacts. It does not produce legal compliance determinations and makes no representation that following these artefacts will satisfy any legal or regulatory obligation. All outputs require human validation and professional sign-off before use.