HOTELLEX → The full register → By law
The full register — every obligation, by law
The same 49 obligations organised by the instrument that creates them. This is the view an auditor arrives with.
Instruments that bind this property
| Instrument | Obligations |
|---|---|
| EU AI Act | 13 |
| Consumer Rights Directive | 4 |
| GDPR | 3 |
| European Accessibility Act | 2 |
| Unfair Commercial Practices Directive | 2 |
| Besluit bouwwerken leefomgeving (Bbl) | 2 |
| ePrivacy Directive | 1 |
| Short-Term Rental Regulation | 1 |
| Unfair Contract Terms Directive | 1 |
| Payment Services Directive (PSD2) | 1 |
| Package Travel Directive | 1 |
| Schengen Convention | 1 |
| Fire Safety in Hotels Recommendation | 1 |
| Food Hygiene Regulation | 1 |
| Food Information to Consumers Regulation | 1 |
| Copyright in the Information Society Directive | 1 |
| Drinking Water Directive | 1 |
| VAT Directive | 1 |
| DAC7 | 1 |
| ADR Directive | 1 |
| Implementatiewet toegankelijkheidsvoorschriften | 1 |
| Huisvestingswet 2014 | 1 |
| Wetboek van Strafrecht | 1 |
| Warenwetbesluit hygiëne van levensmiddelen | 1 |
| Alcoholwet | 1 |
| Auteurswet | 1 |
| Drinkwaterbesluit | 1 |
| Gemeentewet | 1 |
| Wet op de omzetbelasting 1968 | 1 |
EU AI Act — 13 obligations
Regulation (EU) 2024/1689
Ensure staff who operate or use your AI systems have sufficient AI literacy
If the property operates any AI system — a booking chatbot, dynamic pricing, a CV screener, guest sentiment analytics — it must take measures to ensure a sufficient level of AI literacy among staff and others dealing with the system on its behalf, taking into account their technical knowledge, experience and training, and the context the system is used in. This is a duty on DEPLOYERS, not only on the company that built the tool.
Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staffArt. 4
PROHIBITED: inferring staff emotions in the workplace with AI
Placing on the market, putting into service or using AI systems to infer the emotions of a natural person in the workplace is PROHIBITED, save where the system is intended for medical or safety reasons. This is a prohibition, not a requirement to manage — there is no compliance path that makes it permissible for staff-monitoring or performance purposes.
the placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasonsArt. 5(1)(f)
AI used to hire or sift staff is HIGH-RISK — deployer duties apply to you
AI systems intended to be used for the recruitment or selection of natural persons — placing targeted job adverts, analysing and filtering applications, or evaluating candidates — are high-risk under Annex III. A property using such a system is a DEPLOYER and must, among other duties, use it in accordance with the provider's instructions, assign human oversight to people with the competence, training and authority to exercise it, monitor operation, and keep the automatically generated logs it controls.
AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidatesAnnex III, 4(a)
Deployers of high-risk AI systems shall take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use accompanying the systemsArt. 26(1)
Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support.Art. 26(2)
Tell your staff before you put a high-risk AI system to work on them
Before putting a high-risk AI system into service or use at the workplace, a deployer that is an employer must inform workers' representatives and the affected workers that they will be subject to its use. This is a duty owed to staff, and it sits alongside — not instead of — any information duty owed to candidates or guests.
Before putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers' representatives and the affected workers that they will be subject to the use of the high-risk AI system.Art. 26(7)
AI that allocates shifts, monitors or rates staff is HIGH-RISK too
Annex III is not limited to hiring. An AI system used to allocate tasks based on individual behaviour or personal traits, to monitor or evaluate the performance and behaviour of staff, or to inform decisions on promotion or termination, is high-risk in its own right. Rota optimisation that scores individuals, and performance dashboards that rank them, are squarely within this limb — and it catches far more hotels than CV screening does.
to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons in such relationshipsAnnex III, 4(b)
Guests must be told when they are talking to an AI, not a person
An AI system intended to interact directly with people must be designed so those people are informed they are interacting with an AI — unless it is obvious to a reasonably well-informed, observant and circumspect person in the context. For a booking chatbot or concierge assistant, assume it is not obvious and disclose.
AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspectArt. 50(1)
- The exact wording shown to the user, and at what point in the conversation
- That it appears at or before the FIRST interaction, which is what Art. 50(5) requires
- Whether it is served in the page markup or injected later by script — a disclosure that only exists after hydration is not reliably present
- How it behaves on the surfaces we actually run: web widget, WhatsApp, voice, in-app
- Whether we can alter or remove it in configuration, and what happens to your compliance position if we do
Tell people when a system is reading their face or inferring emotion
A deployer of an emotion recognition system or a biometric categorisation system must inform the people exposed to it that it is operating, and must process the personal data in accordance with the GDPR. Unlike Art. 50(1), this duty sits with the DEPLOYER — it is yours, not your vendor's.
Deployers of an emotion recognition system or a biometric categorisation system shall inform the natural persons exposed thereto of the operation of the system, and shall process the personal data in accordance with Regulations (EU) 2016/679Art. 50(3)
Commission a bespoke AI system and run it as your own, and your vendor's duties become yours
A "provider" is anyone who develops an AI system — OR HAS ONE DEVELOPED — and puts it into service under their own name or trademark. Buy an off-the-shelf chatbot and use it, and you are a deployer. Commission one, or have a vendor build a bespoke assistant you run as your own, and you are the PROVIDER of that system. Every duty this register describes as "your vendor's" then belongs to you: the Art. 50(1) disclosure design, the Art. 50(2) marking of generated content, and, if the system is ever high-risk, the whole Chapter III conformity apparatus.
that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademarkArt. 3(3)
using an AI system under its authority except where the AI system is used in the course of a personal non-professional activityArt. 3(4)
the supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purposeArt. 3(11)
Machine-readable marking of AI-generated content — your vendor's duty, and what to demand
Providers of AI systems generating synthetic audio, image, video or text must ensure the output is marked in a machine-readable format and detectable as artificially generated or manipulated. This duty is the PROVIDER's. Use a third-party tool to produce marketing copy or imagery and the marking duty is that tool vendor's, not yours. What is yours is the consequence of publishing unmarked synthetic content, and the Art. 50(4) disclosure duty where that content is a deep fake. The action here is procurement, not engineering.
Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulatedArt. 50(2)
- Which technique is used — C2PA / Content Credentials manifest, a SynthID-style watermark, a cryptographic signature, or metadata only
- Whether the mark survives what we actually do to files: re-encoding, resizing, CDN transformation, screenshotting
- A named tool or endpoint we can run against an output file to confirm the mark is present and valid
- Which output types are marked and which are not — text is frequently unmarked even where images are
- For systems on the market before 2 August 2026, the date they will meet Art. 50(2), which cannot be later than 2 December 2026
Publish AI-generated or materially altered imagery of your property, and you must disclose it
A deployer who generates or manipulates image, audio or video content constituting a deep fake must disclose that the content has been artificially generated or manipulated. A deep fake is content resembling existing persons, objects, places, entities or events that would falsely appear to a person to be authentic. A fully generated room, or a composite showing a view the room does not have, is squarely within it. Unlike Art. 50(1) and 50(2), this duty is the DEPLOYER's — it is yours, and it does not move to the tool vendor.
Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulatedArt. 50(4)
The disclosures must land at first interaction, and be accessible
Every disclosure required by Art. 50(1), 50(3) and 50(4) must be given to the person concerned clearly and distinguishably, at the latest at the time of the first interaction or exposure, and must meet the applicable accessibility requirements. A disclosure buried in a privacy policy, or shown after the guest has already typed a message to the chatbot, does not discharge the duty.
The information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposureArt. 50(5)
Running a high-risk system: oversight, monitoring, and six months of logs
A deployer of a high-risk AI system must use it in accordance with the instructions for use; assign human oversight to named people with the competence, training, authority and support to exercise it; ensure input data it controls is relevant and sufficiently representative; monitor operation and suspend use and inform the provider where the system presents a risk; and keep the logs the system generates automatically for at least six months. Where a decision affects a person, that person must be told a high-risk system is being used on them.
take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use accompanying the systemsArt. 26(1)
assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary supportArt. 26(2)
keep the logs automatically generated by that high-risk AI system to the extent such logs are under their control, for a period appropriate to the intended purpose of the high-risk AI system, of at least six monthsArt. 26(6)
inform the natural persons that they are subject to the use of the high-risk AI systemArt. 26(11)
- 13(3)(a) — provider identity and contact details, and those of any authorised representative
- 13(3)(b) — intended purpose; accuracy level WITH THE METRICS IT WAS TESTED AGAINST, robustness and cybersecurity per Art. 15; circumstances that degrade them; known risks; performance for the specific groups the system is used on; input data specification
- 13(3)(c) — pre-determined changes to the system and its performance fixed at conformity assessment
- 13(3)(d) — the human oversight measures under Art. 14, including the technical measures that help us interpret output
- 13(3)(e) — computational and hardware requirements, expected lifetime, and required maintenance and software updates
- 13(3)(f) — the mechanisms for collecting, storing and interpreting the logs
- How we export or retain the logs ourselves, not merely view them in your console
- Your retention period, and what happens to logs if we terminate the contract
- Confirmation the logs cover the events Art. 12 requires the system to record
- The format, so the logs are readable without your product
- A named contact and channel for notifying us, not a general support queue
- Your reporting deadlines to market surveillance authorities: 15 days ordinarily, 2 days for widespread infringement or serious disruption of critical infrastructure, 10 days where a death is involved
- That you will notify US on becoming aware, since our monitoring duty under Art. 26(5) depends on it
- What you treat as a serious incident under Art. 3(49)
- The declaration identifying this system and the version we are running
- Which conformity assessment route was used
- The harmonised standards or common specifications applied
A rejected candidate can demand to know what the AI did in the decision
Where you take a decision on the basis of output from an Annex III high-risk system, and that decision produces legal effects or similarly significantly affects the person adversely in their health, safety or fundamental rights, that person has the right to obtain from YOU — the deployer, not the vendor — clear and meaningful explanations of the role the AI system played in the decision procedure and the main elements of the decision taken. A rejected job applicant, or an employee refused a promotion where a scoring tool contributed, is exactly this person.
shall have the right to obtain from the deployer clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision takenArt. 86(1)
- The technical capabilities of the system to provide information relevant to explaining its output
- Which features or inputs drove an individual decision, retrievable for a named case after the fact
- How long that per-decision explanation data is retained and how we export it
- Any documented limits on explainability, stated plainly rather than implied
Consumer Rights Directive — 4 obligations
Directive 2011/83/EU (consolidated)
Display the total price of the stay, inclusive of taxes, before the guest books
Before the guest is bound by a distance or off-premises booking, give the total price of the stay inclusive of all taxes, or — where the price genuinely cannot be calculated in advance — the method by which it will be calculated, together with any additional charges that will become payable. Drip-pricing a mandatory fee into a later step of the booking flow does not satisfy this.
the total price of the goods or services inclusive of taxesArt. 6(1)(e)
Tell the guest when the room rate shown to them was personalised by an algorithm
If the rate presented to a particular guest was personalised on the basis of automated decision-making — dynamic pricing driven by profiling of that guest rather than by inventory and date alone — say so in the pre-contract information. This is an information duty, not a prohibition: personalised pricing remains lawful, undisclosed personalised pricing does not.
where applicable, that the price was personalised on the basis of automated decision-makingArt. 6(1)(ea), inserted by Dir. (EU) 2019/2161
There is no 14-day cooling-off right for a stay booked for a specific date
Accommodation provided for a specific date or period is exempt from the distance contract right of withdrawal. The operator sets its own cancellation policy — but that policy must be disclosed before booking, and it is what the guest is held to. Do not tell a guest they have a statutory 14-day right; do not tell them no consumer protection applies either, because the terms remain reviewable for fairness.
the provision of accommodation other than for residential purpose, transport of goods, car rental services, catering or services related to leisure activities if the contract provides for a specific date or period of performanceArt. 16(1)(l)
Disclose city or tourist tax before booking — the RATE is municipal and not in v1
Where a city, tourist or overnight tax is payable by the guest, it forms part of what the guest must be told before being bound. State that the tax applies, and state the amount or the basis on which it is calculated, in the pre-contract information rather than at check-out.
the total price of the goods or services inclusive of taxesArt. 6(1)(e)
GDPR — 3 obligations
Regulation (EU) 2016/679
CCTV, door locks and guest data need a lawful basis and a privacy notice
Personal data collected from guests — booking records, identity documents, CCTV footage, electronic door-lock logs, Wi-Fi and captive-portal data, loyalty profiles — must be processed lawfully, fairly and transparently, limited to what is necessary, and the guest must be told at the point of collection who is processing it, why, on what basis, for how long and what rights they have. CCTV needs signage at the point of entry to the monitored area, and cameras must not cover rooms, bathrooms or changing areas.
processed lawfully, fairly and in a transparent manner in relation to the data subjectArt. 5(1)(a)
adequate, relevant and limited to what is necessary in relation to the purposes for which they are processedArt. 5(1)(c)
Delete guest data when the purpose it was collected for has ended
Personal data may be kept in identifiable form only for as long as is necessary for the purpose it was collected for. Set and actually apply a retention period per category — booking records, CCTV, door-lock logs, marketing consents — and delete or anonymise on schedule. Where a guest asks for erasure and no other basis to keep the data applies, erase it. "We keep everything" is not a retention policy.
kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processedArt. 5(1)(e)
Facial check-in is prohibited processing unless you have explicit consent and a real alternative
Matching a guest's face to their booking is the processing of biometric data for the purpose of uniquely identifying a natural person. Article 9(1) GDPR PROHIBITS that outright, and it becomes lawful only if one of the Article 9(2) exceptions applies. For a hotel the only realistic one is 9(2)(a) explicit consent. Consent is valid only if it is freely given, which means a guest who declines must be able to check in another way, just as quickly and without disadvantage. If facial check-in is the only route, or the alternative is a longer queue, the consent is not freely given and the processing has no lawful basis at all.
the processing of genetic data, biometric data for the purpose of uniquely identifying a natural personArt. 9(1)
the data subject has given explicit consent to the processing of those personal data for one or more specified purposesArt. 9(2)(a)
European Accessibility Act — 2 obligations
Directive (EU) 2019/882
Make the ONLINE BOOKING JOURNEY accessible — website, app, e-ticketing (NOT the building)
The property's e-commerce service — the booking website and mobile app, the path from search through to a concluded reservation, and the confirmation and support that go with it — must meet the accessibility requirements in Annex I of the European Accessibility Act, as transposed nationally. This is a requirement about SOFTWARE AND INFORMATION, not about the premises.
(e) e-books and dedicated software; and (f) e-commerce services.Art. 2(2)(f) — the scope limb that catches accommodation
means services provided at a distance, through websites and mobile device-based services by electronic means and at the individual request of a consumer with a view to concluding a consumer contractArt. 3(30) — definition of 'e-commerce services'
Microenterprises providing services shall be exempt from complying with the accessibility requirements referred to in paragraph 3 of this ArticleArt. 4(5)
They shall apply those measures from 28 June 2025.Art. 31(2)
Physical accessibility of the premises is NOT governed by the European Accessibility Act
Nothing to do at EU level. This entry exists to close a gap rather than to impose a duty: step-free access, doorway widths, accessible rooms and bathrooms, lifts and signage are set by NATIONAL building regulation, and the European Accessibility Act does not require them. Look for the duty in this register's national layer for your country; where that layer is absent, this register does not answer the question and you must check the national building code yourself.
Member States may decide, in the light of national conditions, that the built environment used by clients of services covered by this Directive shall comply with the accessibility requirements set out in Annex IIIArt. 4(4) — permissive, not mandatory
Unfair Commercial Practices Directive — 2 obligations
Directive 2005/29/EC (consolidated)
Star ratings, classification claims and property descriptions must not mislead
Do not state or imply a star rating, classification, award or facility the property does not have, and do not present true information in a way that is likely to deceive. Where a star rating comes from a national or regional classification scheme, only that scheme's award may be presented as a classification; a self-assigned or marketing "star" must not be presented as one. The same rule catches photographs, room descriptions, "sea view", scarcity claims and discounted-rate announcements.
A commercial practice shall be regarded as misleading if it contains false information and is therefore untruthful or in any way, including overall presentation, deceives or is likely to deceive the average consumer, even if the information is factually correctArt. 6(1)
Guest reviews: no fakes, no cherry-picking, and verify that reviewers actually stayed
If the property states or implies that the reviews it displays come from guests who actually stayed, it must take reasonable and proportionate steps to check that they did. Submitting, commissioning or incentivising false reviews, and misrepresenting reviews — including by publishing only the positive ones while implying the set is complete — are prohibited in all circumstances, with no need to prove that any consumer was actually harmed.
Stating that reviews of a product are submitted by consumers who have actually used or purchased the product without taking reasonable and proportionate steps to check that they originate from such consumers.Annex I, point 23b
Submitting or commissioning another legal or natural person to submit false consumer reviews or endorsements, or misrepresenting consumer reviews or social endorsements, in order to promote products.Annex I, point 23c
Besluit bouwwerken leefomgeving (Bbl) — 2 obligations
Buildings Decree
PHYSICAL accessibility of the building — Bbl, not the Accessibility Act
A building must have spaces that are sufficiently accessible to persons with a functional impairment. For the use functions listed in table 4.183 this is satisfied by complying with the designated rules on an accessibility sector (toegankelijkheidssector): its presence, its floor area, which specific rooms it must contain, how it must be reached, permitted height differences and lift dimensions. Thresholds turn on the use function and the gross floor area.
Een bouwwerk heeft ruimten die voldoende toegankelijk zijn voor personen met een functiebeperking.Art. 4.183 lid 1 (aansturingsartikel)
Als voor een gebruiksfunctie in tabel 4.183 regels zijn aangewezen, wordt voor die gebruiksfunctie aan het eerste lid voldaan door naleving van die regels.Art. 4.183 lid 2
Fire safety: notify the municipality before using the building for accommodation
Using a building for a lodging function generally requires a prior use notification (gebruiksmelding) to the competent authority, with drawings and particulars about escape routes, occupancy and fire-safety installations. The paragraph applies to a use function only in so far as table 6.6 designates it, and the trigger is stated as a number of persons present rather than a number of rooms.
De regels in deze paragraaf zijn op een gebruiksfunctie van toepassing voor zover deze in tabel 6.6 voor die gebruiksfunctie zijn aangewezen.Art. 6.6 (aansturingsartikel)
ePrivacy Directive — 1 obligation
Directive 2002/58/EC (consolidated)
Get consent before setting non-essential cookies or trackers on the booking site
Storing information on, or reading information from, a visitor's device is allowed only with that visitor's prior consent, given after clear and comprehensive information about the purposes. Strictly necessary storage — the session that carries a booking through checkout — is exempt. Analytics, advertising, remarketing pixels, chat widgets and A/B testing are not.
Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consentArt. 5(3), as amended by Dir. 2009/136/EC
Short-Term Rental Regulation — 1 obligation
Regulation (EU) 2024/1028
Short-term rental: obtain a registration number and show it on every listing
Where the Member State (nationally, regionally or locally) has established a registration procedure for the area the unit is in, the host must declare to the online platform whether the unit is subject to that procedure and, if it is, supply the registration number. The number must be obtained by declaration to the competent authority before the unit is offered.
hosts are required, when offering their short-term accommodation rental services via an online short-term rental platform, to declare to the online short-term rental platform whether the unit offered is subject to a registration procedure and, if it is, to provide the registration numberArt. 4(3)(h)
Any registration procedure established by a Member State, at national, regional or local level, for units located in its territory, shall comply with the provisions of this Chapter.Art. 4(1)
It shall apply from 20 May 2026.Art. 19
Unfair Contract Terms Directive — 1 obligation
Directive 93/13/EEC
Deposit, prepayment and cancellation terms must survive an unfairness test
Standard terms the guest did not individually negotiate are void if, contrary to good faith, they create a significant imbalance to the guest's detriment. The Annex names two patterns a hotel routinely writes: keeping the guest's deposit when the guest cancels without giving the guest an equivalent sum when the HOTEL cancels, and requiring a disproportionately high sum from a guest who fails to pay. Non-refundable rates are not automatically unfair — asymmetric ones are the exposure.
A contractual term which has not been individually negotiated shall be regarded as unfair if, contrary to the requirement of good faith, it causes a significant imbalance in the partiesArt. 3(1)
permitting the seller or supplier to retain sums paid by the consumer where the latter decides not to conclude or perform the contract, without providing for the consumer to receive compensation of an equivalent amount from the seller or supplier where the latter is the party cancelling the contractAnnex, point 1(d)
Payment Services Directive (PSD2) — 1 obligation
Directive (EU) 2015/2366
Card payments taken online need strong customer authentication
An electronic payment initiated by the payer through a remote channel must be authenticated with two independent elements from knowledge, possession and inherence, dynamically linked to the amount and the payee. In practice the operator's obligation is to route online card payments through a payment service provider that applies SCA, and to design the booking flow so authentication can complete rather than dropping the booking.
Member States shall ensure that a payment service provider applies strong customer authentication where the payerArt. 97(1)
payment service providers apply strong customer authentication that includes elements which dynamically link the transaction to a specific amount and a specific payeeArt. 97(2)
Package Travel Directive — 1 obligation
Directive (EU) 2015/2302
Bundling a room with a transfer, tour or ticket can turn you into a package organiser
Selling accommodation together with at least one other travel service — airport transfer, car hire, excursion, event ticket sold as part of the stay — can make the sale a package or a linked travel arrangement. If it does, obligations attach that a hotel does not otherwise carry: prescribed pre-contract information, liability for performance of the whole package, and mandatory INSOLVENCY PROTECTION for the money taken. Decide deliberately whether your add-ons cross the line; do not discover it after the fact.
means at least two different types of travel services purchased for the purpose of the same trip or holiday, not constituting a package, resulting in the conclusion of separate contracts with the individual travel service providersArt. 3(5) — linked travel arrangement
Schengen Convention — 1 obligation
Convention implementing the Schengen Agreement
Guest registration: foreign guests complete and sign a registration form on arrival
Managers of establishments providing accommodation must ensure that non-national guests personally complete and sign a registration form and confirm their identity with a valid identity document. Completed forms are kept for, or forwarded to, the competent authorities. Accompanying spouses, accompanying minors and members of travel groups are excepted.
personally complete and sign registration forms and confirm their identity by producing a valid identity documentArt. 45(1)(a) CISA
the completed registration forms will be kept for the competent authorities or forwarded to them where such authorities deem this necessaryArt. 45(1)(b) CISA
Fire Safety in Hotels Recommendation — 1 obligation
Recommendation 86/666/EEC
Fire safety in hotels — the EU instrument is a RECOMMENDATION and binds nobody
No directly binding EU duty exists. Council Recommendation 86/666/EEC sets out principles for fire precautions in existing hotels — reduce the risk of a fire starting, prevent the spread of flame and smoke, ensure all occupants can be evacuated safely, enable the emergency services to act — and invites Member States to legislate. The enforceable requirements (detection, compartmentation, escape routes, occupancy limits, use notifications) are in NATIONAL building and fire regulation.
to take all appropriate measures in so far as existing laws are not already sufficient to meet the requirements of this recommendationRecommendation, point (1)
Food Hygiene Regulation — 1 obligation
Regulation (EC) No 852/2004
Food service: put HACCP-based procedures in place and keep them running
A food business operator — which includes a hotel kitchen, restaurant, bar, breakfast buffet or room service — must put in place, implement and maintain a permanent procedure based on HACCP principles: identify hazards, identify critical control points, set critical limits, monitor, correct, verify and keep records. A written plan that is not actually operated does not satisfy this.
Food business operators shall put in place, implement and maintain a permanent procedure or procedures based on the HACCP principles.Art. 5(1)
Food Information to Consumers Regulation — 1 obligation
Regulation (EU) No 1169/2011
Allergen information must be given for unpackaged food — distinct from HACCP
Where food is offered to the final consumer without prepackaging — a buffet, a plated restaurant dish, a bar snack — the 14 substances listed in Annex II must be declared. This is MANDATORY for non-prepacked food; only the MEANS of providing it (menu, notice, verbal on request with a written back-up) is left to national measures. Being able to answer "does this contain celery?" correctly is the duty.
Where foods are offered for sale to the final consumer or to mass caterers without prepackagingArt. 44(1)
the provision of the particulars specified in point (c) of Article 9(1) is mandatoryArt. 44(1)(a) — Art. 9(1)(c) is the allergen particular
Copyright in the Information Society Directive — 1 obligation
Directive 2001/29/EC
Playing music or television in guest rooms and public areas needs a licence
Authors hold the exclusive right to authorise communication of their works to the public. Transmitting a signal to television or radio sets in guest rooms, and playing recorded or broadcast music in a lobby, bar, restaurant, gym or spa, is such a communication and requires a licence from the relevant collecting societies — normally one for the authors' rights and a second for performers' and producers' related rights.
Member States shall provide authors with the exclusive right to authorise or prohibit any communication to the public of their works, by wire or wireless meansArt. 3(1)
Drinking Water Directive — 1 obligation
Directive (EU) 2020/2184
Legionella risk in the building's water system must be assessed and managed
Member States must ensure a risk assessment of domestic distribution systems is carried out, and may focus Legionella monitoring on PRIORITY PREMISES — large non-household premises with many users, which is what a hotel is. Where a risk is found, remedial measures follow. The operator-facing duty (a written risk analysis, a control plan, temperature regimes, flushing of little-used outlets, sampling and a logbook) is created by the national transposition.
Member States shall ensure that a risk assessment of domestic distribution systems is carried out.Art. 10(1)
In relation to Legionella or lead, Member States may decide to focus the monitoring referred to in point (b) of the first subparagraph on priority premises.Art. 10(1), final subparagraph
means large non-household premises with many users potentially exposed to water-related risks, in particular large premises for public use, as identified by Member StatesArt. 2(6) — 'priority premises'
VAT Directive — 1 obligation
Directive 2006/112/EC
Issue a compliant VAT invoice for business stays
A taxable person must ensure an invoice is issued for supplies made to another taxable person or to a non-taxable legal person, and for payments on account received before such a supply. In accommodation that means corporate bookings, company-paid stays and prepaid deposits from business customers. The invoice must carry the particulars the Directive prescribes, and the issuing and storage rules are then set nationally.
Every taxable person shall ensure that, in respect of the following, an invoice is issuedArt. 220
supplies of goods or services which he has made to another taxable person or to a non-taxable legal personArt. 220(1)
DAC7 — 1 obligation
Directive (EU) 2021/514
DAC7: the PLATFORM reports your rental income to the tax authority — you do not
Reporting platform operators must run due-diligence procedures on their sellers and report them annually to a Member State tax authority, which then exchanges the data automatically across the Union. The host's own position is consequential rather than procedural: identity, address, tax identification number, property address and the consideration credited each quarter are collected and reported, so income declared to the tax authority must match what the platform has already told it. Expect the platform's data requests and answer them accurately.
Each Member State shall take the necessary measures to require Reporting Platform Operators to carry out the due diligence procedures and fulfil reporting requirements laid down in Sections II and III of Annex V.Art. 8ac(1), inserted into Dir. 2011/16/EU
no later than 31 January of the year following the calendar year in which the Seller is identified as a Reportable SellerAnnex V, Section III, paragraph A(1)
ADR Directive — 1 obligation
Directive 2013/11/EU
Tell guests which ADR body covers you — the EU ODR platform NO LONGER EXISTS
Where the operator is committed to, or required to use, an alternative dispute resolution entity, it must tell consumers which entity or entities those are and give the entity's website address, clearly and accessibly on its own website and in its terms and conditions. Where a complaint cannot be settled directly, the consumer must be told on paper or another durable medium whether the operator will use ADR to resolve it.
Member States shall ensure that traders established on their territories inform consumers about the ADR entity or ADR entities by which those traders are coveredArt. 13(1)
shall be provided in a clear, comprehensible and easily accessible way on the tradersArt. 13(2)
Implementatiewet toegankelijkheidsvoorschriften — 1 obligation
EAA implementing act
NL transposition of the European Accessibility Act — e-commerce gets NO transitional relief
The Netherlands transposed Directive (EU) 2019/882 by amending the Warenwet, the Wet gelijke behandeling op grond van handicap of chronische ziekte, the Telecommunicatiewet, Book 6 of the Burgerlijk Wetboek and the Wet handhaving consumentenbescherming. The transitional article softens the landing for most services — pre-28 June 2025 service contracts may run to expiry, and existing products may keep being used — but article VIII(4) EXCLUDES e-commerce service providers from that relief. A Dutch hotel's booking website therefore had to be accessible from 28 June 2025 with no grace period.
Dienstverleningscontracten die gesloten zijn vóór 28 juni 2025 kunnen ongewijzigd doorlopen totdat zij verstrijken, evenwel uiterlijk tot vijf jaar na die datum.Art. VIII lid 2
niet van toepassing op dienstverleners van e-handelsdiensten als bedoeld in artikel 2, tweede lid, onderdeel f, van de richtlijnArt. VIII lid 4
Huisvestingswet 2014 — 1 obligation
Housing Act
Short-term rental: display the municipal registration number on every listing
Where the municipal council has designated a category of dwelling and an area in its huisvestingsverordening, it is prohibited to offer that dwelling for the form of tourist letting described in the ordinance without stating the dwelling's registration number in EVERY listing. The number is applied for by the person offering the dwelling. Publishing a listing without the number is separately prohibited.
voor een in die verordening omschreven vorm van toeristische verhuur aan te bieden zonder het registratienummer van die woonruimte te vermelden bij iedere aanbieding van die woonruimte voor toeristische verhuurArt. 23a lid 1
Een registratienummer als bedoeld in het eerste lid, wordt aangevraagd door degene die een woonruimte aanbiedt voor toeristische verhuur.Art. 23a lid 2
Wetboek van Strafrecht — 1 obligation
Dutch Criminal Code
Night register: check ID on arrival and keep a continuous guest register
Anyone whose business is providing overnight accommodation must, immediately on a guest's arrival, have a valid travel document or identity document produced, and must keep a CONTINUOUS register recording without delay the guest's name, place of residence and date of arrival, the nature of the document produced, and on departure the date of departure. Failing to do so is a criminal offence (overtreding), not an administrative one.
Hij die er zijn beroep van maakt aan personen nachtverblijf te verschaffen wordt gestraft met hechtenis van ten hoogste een maand of geldboete van de tweede categorieArt. 438 lid 1 Sr
geen doorlopend register houdt of nalaat daarin onverwijld bij de aankomst van die persoon zijn naam, woonplaats en dag van aankomst aan te tekenen of te doen aantekenenArt. 438 lid 1 sub 2e Sr
Warenwetbesluit hygiëne van levensmiddelen — 1 obligation
Food hygiene decree
Food hygiene: breaching Regulation 852/2004 is a Dutch offence in its own right
It is prohibited to act contrary to the specified articles of Regulation (EC) 852/2004 — including article 5, the HACCP obligation — and of Regulations 853/2004 and 854/2004 where relevant. In other words the EU hygiene rules are not merely directly applicable; the Warenwetbesluit makes breaching them a discrete enforceable prohibition under Dutch law, policed by the NVWA.
Het is verboden te handelen in strijd met de artikelen 3, 4, eerste, tweede en derde lid, 5, eerste lid, tweede lid, laatste alinea, en vierde lid, en 6, tweede lid en derde lid, onderdelen a en b, van verordening (EG) 852/2004Art. 2 lid 1
Alcoholwet — 1 obligation
Alcohol Act
Serving alcohol requires a licence from the mayor
It is prohibited to operate a licensed-hospitality business (horecabedrijf) or an off-licence without a licence to that effect from the mayor. For a hotel this captures the bar, the restaurant, banqueting and in-room service of alcoholic drinks. The licence is tied to premises and to named managers, and it does not travel with a change of operator.
Het is verboden zonder daartoe strekkende vergunning van de burgemeester het horecabedrijf of slijtersbedrijf uit te oefenen.Art. 3 lid 1
Auteurswet — 1 obligation
Copyright Act
Music and television in the hotel is a communication to the public and needs a licence
Performance or presentation of a work in public is a form of making the work public, which is reserved to the rightholder. Playing music in a lobby, bar, restaurant, gym or spa, and relaying a television or radio signal to guest rooms, therefore requires permission — in practice a licence from Buma/Stemra for authors' rights and from Sena for performers' and producers' related rights.
Onder de openbaarmaking van een werk van letterkunde, wetenschap of kunst wordt mede verstaanArt. 12 lid 1
de voordracht, op- of uitvoering of voorstelling in het openbaar van het geheel of een gedeelte van het werkArt. 12 lid 1 sub 4
Drinkwaterbesluit — 1 obligation
Drinking Water Decree
Legionella: a written risk analysis and control plan is required for lodging buildings
Chapter 4 of the Drinkwaterbesluit applies to the owner of a collective water supply or collective pipe network serving taps in, among others, a building with a lodging function (logiesfunctie), a dwelling function providing commercial overnight accommodation to more than five persons, and a bathing establishment. Those owners must carry out a legionella risk analysis, draw up and execute a control plan, keep a logbook, sample at the prescribed frequency, and inform the inspector and take measures when limits are exceeded.
Dit hoofdstuk is van toepassing op de eigenaar van een collectieve watervoorziening of collectief leidingnetArt. 35 lid 1
met uitzondering van recreatieverblijven, huisjes op volkstuincomplexen en gebouwen waar uitsluitend wordt overnacht door personen die ter plaatse werkzaam zijnArt. 35 lid 1 onder c sub 1
waar bedrijfsmatig nachtverblijf wordt verleend aan meer dan vijf personenArt. 35 lid 1 onder c sub 2
Gemeentewet — 1 obligation
Municipalities Act
Tourist tax: the municipality MAY levy it, and may recover it from you as the host
Municipalities are empowered — not required — to levy a tourist tax in respect of overnight stays by persons not registered as residents at an address in that municipality. Where the tax is levied on the person PROVIDING the opportunity to stay, that person is entitled to pass it on to the guest whose stay gives rise to it. In practice the operator collects and remits, under a municipal ordinance.
kan een toeristenbelasting worden gehevenArt. 224 lid 1 — enabling, not mandatory
Voor zover de belasting wordt geheven van degene die gelegenheid tot verblijf biedt, is deze bevoegd de belasting als zodanig te verhalen op degene ter zake van wiens verblijf de belasting verschuldigd wordt.Art. 224 lid 2
Wet op de omzetbelasting 1968 — 1 obligation
Turnover Tax Act
VAT invoices must carry the prescribed particulars
An invoice must state the prescribed particulars: the date of issue, a sequential number from one or more series that uniquely identifies it, the VAT identification number under which the supply was made, the customer's VAT identification number where relevant, and the further items listed in the article. A periodic invoice may cover several supplies provided the period is no longer than one calendar month, and self-billing by the customer is permitted only where agreed in advance and subject to an acceptance procedure.
Op de factuur zijn de volgende vermeldingen verplichtArt. 35a lid 1
Voor verscheidene afzonderlijke leveringen of diensten kan een periodieke factuur worden opgemaakt, mits de periode waarop de factuur betrekking heeft niet langer is dan een kalendermaand.Art. 35 lid 1