HOTELLEX → The full register

The full register — every obligation, by guest journey

All 49 obligations in the register, grouped by when they bite. Real generated output, every one cited to source.

This is a fixed worked example — not your property. It is computed for a hotel in Amsterdam so you can read the whole register without entering anything. For your own property, run a lookup.
PropertyAmsterdam, NL
NUTS NL329
Obligations found49
Layers searched4
and each one reports what it found

Coverage — what was actually checked

Every layer reports its own status. A layer that was not searched says so, because a silent gap in a compliance register is worse than a stated one.

eu
covered — 38 obligations (EUR-Lex / CELLAR)
Hand-curated and cited to CELEX. Every source identifier was resolved against CELLAR and its title read back from EUR-Lex on the verification date. EUR-Lex publishes all 24 official language versions of each act, so the native text and the English text are both official at this layer. Most of these instruments are DIRECTIVES: they bind Member States, and the rule an operator is actually held to is the national transposition, which is where wording, thresholds and penalties vary.
national
covered — 11 obligations (BWB — wetten.overheid.nl (officiële geconsolideerde tekst))
Hand-curated from the official consolidated text. The native-language text is the legally operative version; the English is an unofficial machine translation. Municipal rules — tourist-tax rates, night-register mechanics, licensing conditions, noise and terrace hours — are NOT IN THIS VERSION and several obligations here point at that gap explicitly.
regional
not in this version
Regional obligations (classification schemes, some licensing) are not covered in this version.
municipal
not in this version
Tourist tax rates, night-register mechanics, noise and terrace hours, waste separation and local licensing conditions are commonly municipal. Obligations almost certainly exist here. This version does not cover them. Check the Amsterdam municipal site directly.

PRE-BOOK — 14 obligations

How the property is presented, before anyone books.

Display the total price of the stay, inclusive of taxes, before the guest bookseubindingConsumer Rights Directive

Before the guest is bound by a distance or off-premises booking, give the total price of the stay inclusive of all taxes, or — where the price genuinely cannot be calculated in advance — the method by which it will be calculated, together with any additional charges that will become payable. Drip-pricing a mandatory fee into a later step of the booking flow does not satisfy this.

Applies when: always
Mandatory local charges an operator collects on the state's behalf (city or tourist tax) are part of what a guest must be able to see before booking. The RATE is set municipally in most Member States and is out of scope in v1 — see eu.tax.tourist-tax-disclosure.
This is an EU Directive. It binds Member States, and the duty an operator can actually be prosecuted under is the national law transposing it — wording, thresholds and penalties vary by Member State. The national layer is where that lands; where this register has no national layer for your country, treat this as the duty category, not the rule text.
What the text actually says
the total price of the goods or services inclusive of taxesArt. 6(1)(e)
Source: 02011L0083-20220528 · verified 2026-08-21
Tell the guest when the room rate shown to them was personalised by an algorithmeubindingConsumer Rights Directive

If the rate presented to a particular guest was personalised on the basis of automated decision-making — dynamic pricing driven by profiling of that guest rather than by inventory and date alone — say so in the pre-contract information. This is an information duty, not a prohibition: personalised pricing remains lawful, undisclosed personalised pricing does not.

Applies when: always
Yield management that varies price by date, occupancy or lead time is not personalisation and does not trigger this. What triggers it is varying the price by inferred characteristics of the individual guest.
The Omnibus Directive's "prior price" rule for announced price reductions was inserted into Directive 98/6/EC, which applies to GOODS. It does not catch a hotel advertising a discounted room rate. That conduct is assessed under the Unfair Commercial Practices Directive instead — see eu.ucpd.misleading-claims.
This is an EU Directive. It binds Member States, and the duty an operator can actually be prosecuted under is the national law transposing it — wording, thresholds and penalties vary by Member State. The national layer is where that lands; where this register has no national layer for your country, treat this as the duty category, not the rule text.
What the text actually says
where applicable, that the price was personalised on the basis of automated decision-makingArt. 6(1)(ea), inserted by Dir. (EU) 2019/2161
Source: 02011L0083-20220528 · verified 2026-08-21
Make the ONLINE BOOKING JOURNEY accessible — website, app, e-ticketing (NOT the building)eubindingEuropean Accessibility Act

The property's e-commerce service — the booking website and mobile app, the path from search through to a concluded reservation, and the confirmation and support that go with it — must meet the accessibility requirements in Annex I of the European Accessibility Act, as transposed nationally. This is a requirement about SOFTWARE AND INFORMATION, not about the premises.

Applies when: always :: Exempt only if the business is a microenterprise providing services — fewer than 10 persons employed AND annual turnover or balance-sheet total not exceeding EUR 2 million (Art. 3(23), Art. 4(5)). Headcount and turnover are not property attributes, so this register cannot decide it for you.
SCOPE TRAP — READ THIS. Article 2(2) lists the services the EAA covers, and accommodation is NOT one of them. Hotels are caught only through limb (f), "e-commerce services". The consequence is precise: the booking journey is in scope; the hotel's rooms, entrance, lift and bathrooms are NOT covered by this Directive. Physical accessibility is national building code — see eu.eaa.NOT-physical-accessibility and, for the Netherlands, nl.bbl.building-physical-accessibility.
Article 4(4) lets a Member State OPTIONALLY extend accessibility requirements to the built environment used by clients. That is a national election, not an EU-wide duty, and where a state has made it the duty is in national law.
A booking taken by telephone, by email or at the desk is not an e-commerce service and is not caught by this limb.
This is an EU Directive. It binds Member States, and the duty an operator can actually be prosecuted under is the national law transposing it — wording, thresholds and penalties vary by Member State. The national layer is where that lands; where this register has no national layer for your country, treat this as the duty category, not the rule text.
What the text actually says
(e) e-books and dedicated software; and (f) e-commerce services.Art. 2(2)(f) — the scope limb that catches accommodation
means services provided at a distance, through websites and mobile device-based services by electronic means and at the individual request of a consumer with a view to concluding a consumer contractArt. 3(30) — definition of 'e-commerce services'
Microenterprises providing services shall be exempt from complying with the accessibility requirements referred to in paragraph 3 of this ArticleArt. 4(5)
They shall apply those measures from 28 June 2025.Art. 31(2)
Source: 32019L0882 · verified 2026-08-21
Physical accessibility of the premises is NOT governed by the European Accessibility ActeuguidanceEuropean Accessibility Act

Nothing to do at EU level. This entry exists to close a gap rather than to impose a duty: step-free access, doorway widths, accessible rooms and bathrooms, lifts and signage are set by NATIONAL building regulation, and the European Accessibility Act does not require them. Look for the duty in this register's national layer for your country; where that layer is absent, this register does not answer the question and you must check the national building code yourself.

Applies when: always
Marked `guidance` deliberately: it is a statement about where a duty is NOT, and it must never be rendered as something the operator must do. It is in the register because an operator searching "accessibility" will otherwise read eu.eaa.booking-journey-accessibility as covering ramps and doorways, and act on a confidently wrong answer in the register's most visible category.
The two accessibility entries are deliberately kept apart, with different titles, different scope and different consequences. Do not merge them, and do not summarise them together.
This is an EU Directive. It binds Member States, and the duty an operator can actually be prosecuted under is the national law transposing it — wording, thresholds and penalties vary by Member State. The national layer is where that lands; where this register has no national layer for your country, treat this as the duty category, not the rule text.
What the text actually says
Member States may decide, in the light of national conditions, that the built environment used by clients of services covered by this Directive shall comply with the accessibility requirements set out in Annex IIIArt. 4(4) — permissive, not mandatory
Source: 32019L0882 · verified 2026-08-21
Get consent before setting non-essential cookies or trackers on the booking siteeubindingePrivacy Directive

Storing information on, or reading information from, a visitor's device is allowed only with that visitor's prior consent, given after clear and comprehensive information about the purposes. Strictly necessary storage — the session that carries a booking through checkout — is exempt. Analytics, advertising, remarketing pixels, chat widgets and A/B testing are not.

Applies when: always
The CONSOLIDATED text is cited on purpose. The original 2002 wording required only a right to refuse; the consent requirement was introduced in 2009. Citing CELEX 32002L0058 for this duty would link an operator to a source that does not state it.
The quality of consent — freely given, specific, informed, unambiguous, and as easy to withdraw as to give — is set by the GDPR, not by this Directive.
This is an EU Directive. It binds Member States, and the duty an operator can actually be prosecuted under is the national law transposing it — wording, thresholds and penalties vary by Member State. The national layer is where that lands; where this register has no national layer for your country, treat this as the duty category, not the rule text.
What the text actually says
Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consentArt. 5(3), as amended by Dir. 2009/136/EC
Source: 02002L0058-20091219 · verified 2026-08-21
Star ratings, classification claims and property descriptions must not misleadeubindingUnfair Commercial Practices Directive

Do not state or imply a star rating, classification, award or facility the property does not have, and do not present true information in a way that is likely to deceive. Where a star rating comes from a national or regional classification scheme, only that scheme's award may be presented as a classification; a self-assigned or marketing "star" must not be presented as one. The same rule catches photographs, room descriptions, "sea view", scarcity claims and discounted-rate announcements.

Applies when: always
Hotel star classification itself is NOT harmonised at EU level. Whether a scheme is compulsory, voluntary or absent is a national — and in Spain and Italy frequently a regional — question, and v1 does not cover the regional layer. This entry tells you the claim must be true; it does not tell you which scheme you must join.
This is an EU Directive. It binds Member States, and the duty an operator can actually be prosecuted under is the national law transposing it — wording, thresholds and penalties vary by Member State. The national layer is where that lands; where this register has no national layer for your country, treat this as the duty category, not the rule text.
What the text actually says
A commercial practice shall be regarded as misleading if it contains false information and is therefore untruthful or in any way, including overall presentation, deceives or is likely to deceive the average consumer, even if the information is factually correctArt. 6(1)
Source: 02005L0029-20220528 · verified 2026-08-21
Short-term rental: obtain a registration number and show it on every listingeubindingShort-Term Rental Regulation

Where the Member State (nationally, regionally or locally) has established a registration procedure for the area the unit is in, the host must declare to the online platform whether the unit is subject to that procedure and, if it is, supply the registration number. The number must be obtained by declaration to the competent authority before the unit is offered.

Applies when: is_str :: Only where the accommodation is a "unit" under Art. 3(1). Hotels and similar accommodation (NACE 55.1), hostels, and camping, RV and trailer parks (NACE 55.3) are EXCLUDED from the definition and this obligation does not apply to them.
Penalty for failing to display a registration number: cannot be determined — Regulation (EU) 2024/1028 does not set penalties for hosts. Recital 30 requires Member States to lay down penalties for infringements by ONLINE SHORT-TERM RENTAL PLATFORMS, and any host-facing penalty is created by national or local law. No figure can be stated at the EU layer, and a range would imply a jurisdiction that was never named.
REGISTRAR GAP — v1 identifies this duty and frequently CANNOT NAME THE BODY YOU REGISTER WITH. Article 4(1) allows the registration procedure to be established "at national, regional or local level", and in several Member States — the Netherlands among them — the scheme is run by the municipality under a local housing ordinance. The MUNICIPAL LAYER IS NOT IN THIS VERSION, so this register will often tell you that you must hold a registration number without being able to tell you where to get it. Check your municipality before you list.
SCOPE TRAP. This Regulation does NOT apply to hotels. Article 3(1)(a) removes "hotels and similar accommodation, including resort hotels, suite or apartment hotels and motels" (NACE 55.1) and hostels from the definition of "unit", and Article 3(1)(b) removes camping grounds, RV parks and trailer parks. A hotel shown this obligation is being given a wrong answer.
The boundary is not perfectly crisp and this register will not pretend it is. Art. 3(1)(a) excludes NACE 55.1 in full but within NACE 55.2 excludes only HOSTELS — so a serviced apartment or holiday let sitting in 55.2 that is not a hostel remains in scope. Aparthotels are a genuine borderline. If your format sits near that line, get it confirmed rather than inferring it from here.
The Regulation also does not displace local rules on whether you may let at all. Art. 2(2)(a) expressly preserves national, regional and local rules regulating access to the provision of short-term rental services — night caps, permit requirements and zoning survive it.
What the text actually says
hosts are required, when offering their short-term accommodation rental services via an online short-term rental platform, to declare to the online short-term rental platform whether the unit offered is subject to a registration procedure and, if it is, to provide the registration numberArt. 4(3)(h)
Any registration procedure established by a Member State, at national, regional or local level, for units located in its territory, shall comply with the provisions of this Chapter.Art. 4(1)
It shall apply from 20 May 2026.Art. 19
Source: 32024R1028 · verified 2026-08-21
Guests must be told when they are talking to an AI, not a personeubindingEU AI Act

An AI system intended to interact directly with people must be designed so those people are informed they are interacting with an AI — unless it is obvious to a reasonably well-informed, observant and circumspect person in the context. For a booking chatbot or concierge assistant, assume it is not obvious and disclose.

What you need in placeHave the disclosure visible at the point the guest starts interacting — first message on the chatbot, not buried in the privacy policy.
Applies when: ai_customer_facing :: Any AI that converses with guests directly — booking chatbot, concierge assistant, voice agent. The "unless it is obvious" exemption is narrower than it sounds and should not be relied on for a chatbot that answers in fluent prose.
READ THE DUTY-HOLDER. Article 50(1) is addressed to PROVIDERS, not deployers. If you bought the chatbot off the shelf, the design duty is your vendor's and your job is to verify they have met it. If you built it, or put your own name or trademark on it, you are the provider and it is yours. This register cannot tell which of those you are.
What the text actually says
AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspectArt. 50(1)
Ask your vendor
Confirm in writing how the system informs users they are talking to an AI, and where that disclosure appears. owed under Art. 50(1)
A compliant answer contains
  • The exact wording shown to the user, and at what point in the conversation
  • That it appears at or before the FIRST interaction, which is what Art. 50(5) requires
  • Whether it is served in the page markup or injected later by script — a disclosure that only exists after hydration is not reliably present
  • How it behaves on the surfaces we actually run: web widget, WhatsApp, voice, in-app
  • Whether we can alter or remove it in configuration, and what happens to your compliance position if we do
If they will not: Art. 50(1) is a DESIGN duty on the provider, so a vendor who cannot describe the mechanism has not built one. If the answer is that we control it in configuration, the duty has effectively been handed to us without being said out loud, and our configuration is now a compliance artefact.
Tell us whether you consider us the provider of this system, and why. commercial leverage — not a legal duty
If they will not: Not a legal duty on them, but the single most useful question you can ask. If the deployment is bespoke and runs under your name, Art. 3(3) may make YOU the provider — see eu.aiact.provider-status-if-commissioned — and every "your vendor owes this" in this register inverts. Ask early; the answer is cheap now and expensive later.
Source: 32024R1689 · verified 2026-08-23
Commission a bespoke AI system and run it as your own, and your vendor's duties become yourseubindingEU AI Act

A "provider" is anyone who develops an AI system — OR HAS ONE DEVELOPED — and puts it into service under their own name or trademark. Buy an off-the-shelf chatbot and use it, and you are a deployer. Commission one, or have a vendor build a bespoke assistant you run as your own, and you are the PROVIDER of that system. Every duty this register describes as "your vendor's" then belongs to you: the Art. 50(1) disclosure design, the Art. 50(2) marking of generated content, and, if the system is ever high-risk, the whole Chapter III conformity apparatus.

What you need in placeEstablish which role you hold in writing, because it decides which duties are yours. Put your own name on a system and the provider duties follow it.
Applies when: uses_ai :: Settle this before reading anything else in the AI Act chapter. It changes who owes almost every other duty.
THE TEST IS "HAD IT DEVELOPED", NOT "PAID FOR IT". Licensing a product other customers also use does not make you its provider, even white-labelled. Commissioning a build specific to you, which you put into service as yours, is the case the definition names. Between those sits a real grey zone — a heavily configured deployment of a shared product — and this register does not pretend to resolve it. Where the answer changes what you owe, get it in writing from counsel and keep the reasoning.
Article 25, which turns a deployer into a provider by branding or substantial modification, is limited to HIGH-RISK systems and does not reach a chatbot. The route that reaches a chatbot is the Art. 3(3) definition itself.
This is the most commercially consequential question in the chapter and the one most often answered by assumption. Hotels commission bespoke booking assistants routinely, then read "the duty is the provider's" as meaning it is somebody else's.
What the text actually says
that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademarkArt. 3(3)
using an AI system under its authority except where the AI system is used in the course of a personal non-professional activityArt. 3(4)
the supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purposeArt. 3(11)
Source: 32024R1689 · verified 2026-08-26
Machine-readable marking of AI-generated content — your vendor's duty, and what to demandeubindingEU AI Act

Providers of AI systems generating synthetic audio, image, video or text must ensure the output is marked in a machine-readable format and detectable as artificially generated or manipulated. This duty is the PROVIDER's. Use a third-party tool to produce marketing copy or imagery and the marking duty is that tool vendor's, not yours. What is yours is the consequence of publishing unmarked synthetic content, and the Art. 50(4) disclosure duty where that content is a deep fake. The action here is procurement, not engineering.

What you need in placeHave your vendor's written confirmation that outputs are marked machine-readable, and a way to check it. The marking duty is theirs; verifying it is your procurement.
Applies when: uses_ai :: Any generative tool used to produce published copy, imagery, audio or video — including general-purpose assistants used by the marketing team.
DO NOT READ THE ABSENCE OF A MARK AS PROOF OF ANYTHING. An image carrying no C2PA manifest is an image carrying no manifest. That is not evidence the image is synthetic, and not evidence it is authentic. Any finding built the other way round collapses on contact with the vendor.
Systems already on the market before 2 August 2026 have until 2 DECEMBER 2026 to comply with this paragraph. That grace period belongs to the PROVIDER. It is not a deadline a hotel can miss, and it is routinely mis-sold as one.
There is a carve-out where the AI performs an assistive function for standard editing or does not substantially alter the input data. Ordinary retouching sits inside it. That carve-out does more work than most summaries admit.
What the text actually says
Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulatedArt. 50(2)
Ask your vendor
State how your system marks generated output, and give us a way to verify a mark on a file we supply. owed under Art. 50(2)
A compliant answer contains
  • Which technique is used — C2PA / Content Credentials manifest, a SynthID-style watermark, a cryptographic signature, or metadata only
  • Whether the mark survives what we actually do to files: re-encoding, resizing, CDN transformation, screenshotting
  • A named tool or endpoint we can run against an output file to confirm the mark is present and valid
  • Which output types are marked and which are not — text is frequently unmarked even where images are
  • For systems on the market before 2 August 2026, the date they will meet Art. 50(2), which cannot be later than 2 December 2026
If they will not: Cannot name a technique: there is no mark. Names one but cannot give a verification path: you have no way to evidence compliance and neither have they. Metadata-only marking that your own CDN strips on upload is marking that does not survive your publishing pipeline.
Warrant in the contract that outputs supplied to us are marked, and that you will notify us if that changes. commercial leverage — not a legal duty
If they will not: Commercial leverage, not a legal duty — Art. 50(2) obliges them to mark, not to indemnify you. Worth having anyway, because the Art. 50(4) and reputational exposure of publishing unmarked synthetic content lands on you, not them.
Source: 32024R1689 · verified 2026-08-26
Publish AI-generated or materially altered imagery of your property, and you must disclose iteubindingEU AI Act

A deployer who generates or manipulates image, audio or video content constituting a deep fake must disclose that the content has been artificially generated or manipulated. A deep fake is content resembling existing persons, objects, places, entities or events that would falsely appear to a person to be authentic. A fully generated room, or a composite showing a view the room does not have, is squarely within it. Unlike Art. 50(1) and 50(2), this duty is the DEPLOYER's — it is yours, and it does not move to the tool vendor.

What you need in placeHave a disclosure on published imagery that is AI-generated or materially manipulated, and an inventory of which published assets that covers.
Applies when: uses_ai :: Any AI-generated or AI-composited imagery of the property, its rooms, its views or its surroundings used in marketing, OTA listings or the booking flow.
WHERE THE LINE ACTUALLY FALLS. Fully generated room imagery and composites showing a view the property does not have are the mischief the paragraph names. Sky replacement, object removal and colour grading are far more arguable and your vendor's counsel will call them assistive editing. This register does not claim the line is crisp; it claims you need an inventory to sit on either side of it.
THIS CANNOT BE ANSWERED BY SCANNING YOUR WEBSITE. Whether an image is generated, composited or merely retouched is not observable from the published file — absence of a provenance mark proves nothing either way. The only reliable source is your own production process: who made the asset, with what tool, and how much of it is real. That makes this an inventory question, not an audit finding.
The same paragraph separately covers AI-generated TEXT published to inform the public on matters of public interest. Hotel marketing copy is not that. Do not stretch it: a duty asserted where it does not apply discredits the ones that do.
Consumer law bites here independently and often harder. Imagery that materially misleads a guest about what they are booking is an unfair commercial practice under the UCPD whatever the AI Act says — see eu.ucpd.misleading-claims.
What the text actually says
Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulatedArt. 50(4)
Source: 32024R1689 · verified 2026-08-26
The disclosures must land at first interaction, and be accessibleeubindingEU AI Act

Every disclosure required by Art. 50(1), 50(3) and 50(4) must be given to the person concerned clearly and distinguishably, at the latest at the time of the first interaction or exposure, and must meet the applicable accessibility requirements. A disclosure buried in a privacy policy, or shown after the guest has already typed a message to the chatbot, does not discharge the duty.

What you need in placeHave each disclosure given at the FIRST interaction and in an accessible form — late or unreadable is not disclosed.
Applies when: ai_customer_facing or ai_biometric :: Applies to whichever of the Art. 50 disclosures you owe. It governs their delivery, not whether you owe them.
THIS IS THE PARAGRAPH A WEBSITE SCAN CAN ACTUALLY EVIDENCE. Whether a disclosure is present in served markup before the first interaction is directly observable from outside. Whether an image was generated, or whether staff received literacy training, is not. Weight findings accordingly.
"Accessible" carries the Union accessibility requirements, so a disclosure that is visual-only, or that a screen reader does not reach, is incomplete even when it is present and timely.
What the text actually says
The information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposureArt. 50(5)
Source: 32024R1689 · verified 2026-08-26
NL transposition of the European Accessibility Act — e-commerce gets NO transitional reliefnationalbindingImplementatiewet toegankelijkheidsvoorschriften

The Netherlands transposed Directive (EU) 2019/882 by amending the Warenwet, the Wet gelijke behandeling op grond van handicap of chronische ziekte, the Telecommunicatiewet, Book 6 of the Burgerlijk Wetboek and the Wet handhaving consumentenbescherming. The transitional article softens the landing for most services — pre-28 June 2025 service contracts may run to expiry, and existing products may keep being used — but article VIII(4) EXCLUDES e-commerce service providers from that relief. A Dutch hotel's booking website therefore had to be accessible from 28 June 2025 with no grace period.

Applies when: always :: Microenterprises providing services are exempt under Art. 4(5) of the Directive — fewer than 10 persons employed and turnover or balance-sheet total not over EUR 2 million. Headcount and turnover are not property attributes.
BOOKING JOURNEY, NOT THE BUILDING. This obligation is about the website, app and online booking flow. Physical accessibility of the premises is a completely separate Dutch rule with a different source — see nl.bbl.building-physical-accessibility. Do not conflate them.
This instrument is an AMENDING act (wijzigingswet): it inserts requirements into the Warenwet and Boek 6 BW rather than stating them itself. The operative text an enforcement authority will cite lives in the amended statutes. The transitional article quoted above is the exception — it is substantive and stands on its own.
What the text actually says
Dienstverleningscontracten die gesloten zijn vóór 28 juni 2025 kunnen ongewijzigd doorlopen totdat zij verstrijken, evenwel uiterlijk tot vijf jaar na die datum.Art. VIII lid 2
niet van toepassing op dienstverleners van e-handelsdiensten als bedoeld in artikel 2, tweede lid, onderdeel f, van de richtlijnArt. VIII lid 4
Source: BWBR0049571 · verified 2026-08-21
Short-term rental: display the municipal registration number on every listingnationalbindingHuisvestingswet 2014

Where the municipal council has designated a category of dwelling and an area in its huisvestingsverordening, it is prohibited to offer that dwelling for the form of tourist letting described in the ordinance without stating the dwelling's registration number in EVERY listing. The number is applied for by the person offering the dwelling. Publishing a listing without the number is separately prohibited.

Applies when: is_str :: Only bites where YOUR municipality has actually designated the category and the area in its huisvestingsverordening. Many have not. This register cannot tell you whether yours has.
Penalty for listing without a registration number: cannot be determined — Enforcement of the toeristische verhuur regime runs through municipal enforcement powers and the municipality's own ordinance, and the amounts are set locally. The MUNICIPAL LAYER IS NOT IN THIS VERSION. No figure is stated, and a national range would misrepresent a local decision.
REGISTRAR GAP, CONCRETELY. This is the Dutch answer to Regulation (EU) 2024/1028's registration duty, and it shows exactly why v1 often cannot name your registrar: the whole regime is switched on, scoped and operated BY THE MUNICIPALITY through its huisvestingsverordening. Whether you need a number, for which dwellings, in which streets, and where you apply are all municipal questions that this version does not answer. Check your gemeente before you list.
Article 23a is the DISPLAY duty. Separate municipal instruments commonly add a per-let notification duty (meldplicht), a night cap, and a permit for withdrawing a dwelling from the housing stock (onttrekkingsvergunning). Those are not covered here and are frequently the ones that actually stop a letting.
The source page carries the marker "Wijziging(en) zonder datum inwerkingtreding aanwezig" — amendments exist whose commencement date has not been set. Re-check before relying on the current wording.
What the text actually says
voor een in die verordening omschreven vorm van toeristische verhuur aan te bieden zonder het registratienummer van die woonruimte te vermelden bij iedere aanbieding van die woonruimte voor toeristische verhuurArt. 23a lid 1
Een registratienummer als bedoeld in het eerste lid, wordt aangevraagd door degene die een woonruimte aanbiedt voor toeristische verhuur.Art. 23a lid 2
Source: BWBR0035303 · verified 2026-08-21

BOOK — 5 obligations

Forming the contract.

There is no 14-day cooling-off right for a stay booked for a specific dateeubindingConsumer Rights Directive

Accommodation provided for a specific date or period is exempt from the distance contract right of withdrawal. The operator sets its own cancellation policy — but that policy must be disclosed before booking, and it is what the guest is held to. Do not tell a guest they have a statutory 14-day right; do not tell them no consumer protection applies either, because the terms remain reviewable for fairness.

Applies when: always
The exemption is conditional on the contract providing for a specific date or period of performance. An open-dated voucher or a gift stay with no fixed date is not obviously covered by it.
This is an EU Directive. It binds Member States, and the duty an operator can actually be prosecuted under is the national law transposing it — wording, thresholds and penalties vary by Member State. The national layer is where that lands; where this register has no national layer for your country, treat this as the duty category, not the rule text.
What the text actually says
the provision of accommodation other than for residential purpose, transport of goods, car rental services, catering or services related to leisure activities if the contract provides for a specific date or period of performanceArt. 16(1)(l)
Source: 02011L0083-20220528 · verified 2026-08-21
Deposit, prepayment and cancellation terms must survive an unfairness testeubindingUnfair Contract Terms Directive

Standard terms the guest did not individually negotiate are void if, contrary to good faith, they create a significant imbalance to the guest's detriment. The Annex names two patterns a hotel routinely writes: keeping the guest's deposit when the guest cancels without giving the guest an equivalent sum when the HOTEL cancels, and requiring a disproportionately high sum from a guest who fails to pay. Non-refundable rates are not automatically unfair — asymmetric ones are the exposure.

Applies when: always
The Annex is an indicative list, not a blacklist: a listed term is not automatically void, and an unlisted term is not automatically safe. Member States have gone further in places, so the national layer matters here.
This is an EU Directive. It binds Member States, and the duty an operator can actually be prosecuted under is the national law transposing it — wording, thresholds and penalties vary by Member State. The national layer is where that lands; where this register has no national layer for your country, treat this as the duty category, not the rule text.
What the text actually says
A contractual term which has not been individually negotiated shall be regarded as unfair if, contrary to the requirement of good faith, it causes a significant imbalance in the partiesArt. 3(1)
permitting the seller or supplier to retain sums paid by the consumer where the latter decides not to conclude or perform the contract, without providing for the consumer to receive compensation of an equivalent amount from the seller or supplier where the latter is the party cancelling the contractAnnex, point 1(d)
Source: 31993L0013 · verified 2026-08-21
Card payments taken online need strong customer authenticationeubindingPayment Services Directive (PSD2)

An electronic payment initiated by the payer through a remote channel must be authenticated with two independent elements from knowledge, possession and inherence, dynamically linked to the amount and the payee. In practice the operator's obligation is to route online card payments through a payment service provider that applies SCA, and to design the booking flow so authentication can complete rather than dropping the booking.

Applies when: always
Card details taken by telephone or by post and keyed by the hotel (MOTO) fall outside the scope of SCA, because the transaction is not initiated by the payer online. That is a real and commonly misunderstood distinction, and it is not a licence: a MOTO transaction carries the liability the SCA exemption removes from the issuer.
The detailed authentication rules and the exemptions — low value, recurring, trusted beneficiary, transaction risk analysis — are in Commission Delegated Regulation (EU) 2018/389 (CELEX 32018R0389), not in this Directive.
This is an EU Directive. It binds Member States, and the duty an operator can actually be prosecuted under is the national law transposing it — wording, thresholds and penalties vary by Member State. The national layer is where that lands; where this register has no national layer for your country, treat this as the duty category, not the rule text.
What the text actually says
Member States shall ensure that a payment service provider applies strong customer authentication where the payerArt. 97(1)
payment service providers apply strong customer authentication that includes elements which dynamically link the transaction to a specific amount and a specific payeeArt. 97(2)
Source: 32015L2366 · verified 2026-08-21
Disclose city or tourist tax before booking — the RATE is municipal and not in v1eubindingConsumer Rights Directive

Where a city, tourist or overnight tax is payable by the guest, it forms part of what the guest must be told before being bound. State that the tax applies, and state the amount or the basis on which it is calculated, in the pre-contract information rather than at check-out.

Applies when: always
Tourist tax rate: cannot be determined — There is no EU tourist tax rate. Tourist and overnight taxes are levied under national enabling law and set by the individual municipality. The MUNICIPAL LAYER IS NOT IN THIS VERSION, so this register can tell you that a disclosure duty exists and cannot tell you the number to disclose.
The DISCLOSURE duty is EU consumer law and is in scope. The rate, the exemptions (children, business stays, long stays), the collection mechanics and the filing deadline are municipal in most Member States and are NOT covered by v1. Check your municipality.
This is an EU Directive. It binds Member States, and the duty an operator can actually be prosecuted under is the national law transposing it — wording, thresholds and penalties vary by Member State. The national layer is where that lands; where this register has no national layer for your country, treat this as the duty category, not the rule text.
What the text actually says
the total price of the goods or services inclusive of taxesArt. 6(1)(e)
Source: 02011L0083-20220528 · verified 2026-08-21
Bundling a room with a transfer, tour or ticket can turn you into a package organisereubindingPackage Travel Directive

Selling accommodation together with at least one other travel service — airport transfer, car hire, excursion, event ticket sold as part of the stay — can make the sale a package or a linked travel arrangement. If it does, obligations attach that a hotel does not otherwise carry: prescribed pre-contract information, liability for performance of the whole package, and mandatory INSOLVENCY PROTECTION for the money taken. Decide deliberately whether your add-ons cross the line; do not discover it after the fact.

Applies when: always
Services that are an intrinsic part of accommodation — housekeeping, meals, the pool, in-house spa — do not count as a second travel service. The risk sits with add-ons sold at the point of booking, especially where a commission is earned on a third party's service.
This is an EU Directive. It binds Member States, and the duty an operator can actually be prosecuted under is the national law transposing it — wording, thresholds and penalties vary by Member State. The national layer is where that lands; where this register has no national layer for your country, treat this as the duty category, not the rule text.
What the text actually says
means at least two different types of travel services purchased for the purpose of the same trip or holiday, not constituting a package, resulting in the conclusion of separate contracts with the individual travel service providersArt. 3(5) — linked travel arrangement
Source: 32015L2302 · verified 2026-08-21

STAY — 23 obligations

Operating the property.

Guest registration: foreign guests complete and sign a registration form on arrivaleubindingSchengen Convention

Managers of establishments providing accommodation must ensure that non-national guests personally complete and sign a registration form and confirm their identity with a valid identity document. Completed forms are kept for, or forwarded to, the competent authorities. Accompanying spouses, accompanying minors and members of travel groups are excepted.

Applies when: always
MECHANICS ARE NOT IN v1. This is the Union-level source of the duty; what the register must contain, how long it is kept, whether it must be submitted electronically and to whom, and whether domestic guests are also covered are set by NATIONAL law and, in several states, by MUNICIPAL ordinance. See nl.sr438.night-register for the Netherlands.
Retaining identity-document data engages the GDPR. Copying or scanning passports is not authorised by this Article and is restricted or prohibited in several Member States — see eu.gdpr.retention-and-erasure.
What the text actually says
personally complete and sign registration forms and confirm their identity by producing a valid identity documentArt. 45(1)(a) CISA
the completed registration forms will be kept for the competent authorities or forwarded to them where such authorities deem this necessaryArt. 45(1)(b) CISA
Source: 42000A0922(02) · verified 2026-08-21
Fire safety in hotels — the EU instrument is a RECOMMENDATION and binds nobodyeuguidanceFire Safety in Hotels Recommendation

No directly binding EU duty exists. Council Recommendation 86/666/EEC sets out principles for fire precautions in existing hotels — reduce the risk of a fire starting, prevent the spread of flame and smoke, ensure all occupants can be evacuated safely, enable the emergency services to act — and invites Member States to legislate. The enforceable requirements (detection, compartmentation, escape routes, occupancy limits, use notifications) are in NATIONAL building and fire regulation.

Applies when: always
Fire safety is the category where an operator is most likely to assume EU harmonisation exists. It does not. If your country's national layer is not covered in this register, this entry is a POINTER, not an answer.
This instrument is a Recommendation and is NOT legally binding on anyone. It is listed because the duty category is real and is regulated nationally, not because this text imposes a requirement. Do not read it as one.
What the text actually says
to take all appropriate measures in so far as existing laws are not already sufficient to meet the requirements of this recommendationRecommendation, point (1)
Source: 31986H0666 · verified 2026-08-21
Food service: put HACCP-based procedures in place and keep them runningeubindingFood Hygiene Regulation

A food business operator — which includes a hotel kitchen, restaurant, bar, breakfast buffet or room service — must put in place, implement and maintain a permanent procedure based on HACCP principles: identify hazards, identify critical control points, set critical limits, monitor, correct, verify and keep records. A written plan that is not actually operated does not satisfy this.

Applies when: food_service or bar :: Any handling, preparation or service of food or drink, including a self-service breakfast buffet and in-room minibar restocking.
This is a Regulation and is directly applicable — unusually for this layer, the text above is the operative rule and not a transposition target. Registration of the establishment with the competent authority under Art. 6(2) is a separate national procedure.
What the text actually says
Food business operators shall put in place, implement and maintain a permanent procedure or procedures based on the HACCP principles.Art. 5(1)
Source: 32004R0852 · verified 2026-08-21
Allergen information must be given for unpackaged food — distinct from HACCPeubindingFood Information to Consumers Regulation

Where food is offered to the final consumer without prepackaging — a buffet, a plated restaurant dish, a bar snack — the 14 substances listed in Annex II must be declared. This is MANDATORY for non-prepacked food; only the MEANS of providing it (menu, notice, verbal on request with a written back-up) is left to national measures. Being able to answer "does this contain celery?" correctly is the duty.

Applies when: food_service or bar :: Any food or drink served to guests, prepacked or not.
Substances or products causing allergies or intolerances that must be declared: 14 substances — quoted: “the provision of the particulars specified in point (c) of Article 9(1) is mandatory”
COMMONLY MISSED, AND DISTINCT FROM HACCP. HACCP is about food safety process; this is about information given to the guest. A kitchen can hold a fully compliant HACCP plan and still breach this Regulation by not knowing what is in the dish. They are separate obligations with separate enforcement.
Article 44(1)(b) and 44(2) leave the MEANS of communication to national measures, so whether allergens must be on the menu, on a notice, or available on request varies by Member State. That specific point belongs to the national layer.
What the text actually says
Where foods are offered for sale to the final consumer or to mass caterers without prepackagingArt. 44(1)
the provision of the particulars specified in point (c) of Article 9(1) is mandatoryArt. 44(1)(a) — Art. 9(1)(c) is the allergen particular
Source: 32011R1169 · verified 2026-08-21
Playing music or television in guest rooms and public areas needs a licenceeubindingCopyright in the Information Society Directive

Authors hold the exclusive right to authorise communication of their works to the public. Transmitting a signal to television or radio sets in guest rooms, and playing recorded or broadcast music in a lobby, bar, restaurant, gym or spa, is such a communication and requires a licence from the relevant collecting societies — normally one for the authors' rights and a second for performers' and producers' related rights.

Applies when: always
Licence tariff: cannot be determined — Tariffs are set by national collecting societies, not by Union law, and vary by country, by room count and by the areas in which music is played. No figure can be stated at the EU layer.
That a hotel room counts as "the public" for this purpose is settled by CJEU case law (C-306/05 SGAE v Rafael Hoteles), not by the text of Article 3 itself. This register cites the Directive because the Directive is the operative source; the extension to hotel rooms is interpretation, and it is flagged as such rather than being written into the quote.
Merely installing a television without transmitting a signal is not, on the Court's reasoning, a communication to the public. The licence follows the signal.
This is an EU Directive. It binds Member States, and the duty an operator can actually be prosecuted under is the national law transposing it — wording, thresholds and penalties vary by Member State. The national layer is where that lands; where this register has no national layer for your country, treat this as the duty category, not the rule text.
What the text actually says
Member States shall provide authors with the exclusive right to authorise or prohibit any communication to the public of their works, by wire or wireless meansArt. 3(1)
Source: 32001L0029 · verified 2026-08-21
Legionella risk in the building's water system must be assessed and managedeubindingDrinking Water Directive

Member States must ensure a risk assessment of domestic distribution systems is carried out, and may focus Legionella monitoring on PRIORITY PREMISES — large non-household premises with many users, which is what a hotel is. Where a risk is found, remedial measures follow. The operator-facing duty (a written risk analysis, a control plan, temperature regimes, flushing of little-used outlets, sampling and a logbook) is created by the national transposition.

Applies when: always :: The duty attaches to the building's water system, not to the presence of a pool. A spa, whirlpool, decorative fountain, cooling tower or any little-used outlet raises the risk materially, but a hotel with none of those is still within scope.
Which premises are "priority premises" is expressly left to each Member State to identify, so whether YOUR property is inside the national scheme is a national question. The Netherlands, for example, brings every building with a `logiesfunctie` into scope regardless of size — see nl.drinkwater.legionella.
Swimming pool and spa water is regulated separately from drinking water in most Member States, under bathing-water rather than drinking-water rules. Do not assume one assessment covers both.
This is an EU Directive. It binds Member States, and the duty an operator can actually be prosecuted under is the national law transposing it — wording, thresholds and penalties vary by Member State. The national layer is where that lands; where this register has no national layer for your country, treat this as the duty category, not the rule text.
What the text actually says
Member States shall ensure that a risk assessment of domestic distribution systems is carried out.Art. 10(1)
In relation to Legionella or lead, Member States may decide to focus the monitoring referred to in point (b) of the first subparagraph on priority premises.Art. 10(1), final subparagraph
means large non-household premises with many users potentially exposed to water-related risks, in particular large premises for public use, as identified by Member StatesArt. 2(6) — 'priority premises'
Source: 32020L2184 · verified 2026-08-21
CCTV, door locks and guest data need a lawful basis and a privacy noticeeubindingGDPR

Personal data collected from guests — booking records, identity documents, CCTV footage, electronic door-lock logs, Wi-Fi and captive-portal data, loyalty profiles — must be processed lawfully, fairly and transparently, limited to what is necessary, and the guest must be told at the point of collection who is processing it, why, on what basis, for how long and what rights they have. CCTV needs signage at the point of entry to the monitored area, and cameras must not cover rooms, bathrooms or changing areas.

What you need in placeHave signage at the point of capture and a privacy notice covering the footage: purpose, lawful basis, retention, and who to contact.
Applies when: always
A statutory guest-registration duty is a lawful basis for the registration data it requires and for nothing beyond it. Retaining a scanned passport image because it is convenient is a separate processing operation needing its own basis, and several Member States restrict or prohibit copying identity documents outright.
What the text actually says
processed lawfully, fairly and in a transparent manner in relation to the data subjectArt. 5(1)(a)
adequate, relevant and limited to what is necessary in relation to the purposes for which they are processedArt. 5(1)(c)
Source: 32016R0679 · verified 2026-08-21
Ensure staff who operate or use your AI systems have sufficient AI literacyeubindingEU AI Act

If the property operates any AI system — a booking chatbot, dynamic pricing, a CV screener, guest sentiment analytics — it must take measures to ensure a sufficient level of AI literacy among staff and others dealing with the system on its behalf, taking into account their technical knowledge, experience and training, and the context the system is used in. This is a duty on DEPLOYERS, not only on the company that built the tool.

What you need in placeHave a record of AI-literacy measures for staff who use or are affected by these systems: who was trained, on what, and when.
Applies when: uses_ai :: Any AI system operated by or on behalf of the property. Buying the tool from a vendor does not move this duty to the vendor.
Most operators do not think of themselves as AI companies and so never look for this. It is the cheapest AI Act duty to discharge and the easiest to be caught without.
What the text actually says
Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staffArt. 4
Ask your vendor
Provide the training material, model limitations and failure modes we need to make our staff competent on this system. commercial leverage — not a legal duty
If they will not: Art. 4 binds YOU, not them — staff competence is not a duty a vendor can discharge on your behalf, and no article obliges them to help. But they hold what you would train anyone on, and a vendor who will not describe the system's limitations is telling you something about how it will behave when it fails.
Source: 32024R1689 · verified 2026-08-22
PROHIBITED: inferring staff emotions in the workplace with AIeubindingEU AI Act

Placing on the market, putting into service or using AI systems to infer the emotions of a natural person in the workplace is PROHIBITED, save where the system is intended for medical or safety reasons. This is a prohibition, not a requirement to manage — there is no compliance path that makes it permissible for staff-monitoring or performance purposes.

What you need in placeDo not deploy it. This is a prohibition, not a duty you can discharge with documentation — if such a system is running in a workplace or training context, withdraw it.
Applies when: uses_ai :: Applies to the workplace. Note the carve-out is narrow — medical or safety reasons only.
QUOTE CORRECTED 2026-08-26. The span read "intended to be installed or put into the market"; the source reads "intended to be put in place or into the market". A paraphrase inside quotation marks is the exact failure the span rule exists to catch, and it survived because the live citation test needs --run-network and is skipped by default.
Guest-facing emotion analytics is a different question from staff monitoring and is not covered by this prohibition limb — but may engage GDPR Art. 9 and the transparency duties. This register does not resolve that; take advice.
What the text actually says
the placing on the market, the putting into service for this specific purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasonsArt. 5(1)(f)
Source: 32024R1689 · verified 2026-08-22
AI used to hire or sift staff is HIGH-RISK — deployer duties apply to youeubindingEU AI Act

AI systems intended to be used for the recruitment or selection of natural persons — placing targeted job adverts, analysing and filtering applications, or evaluating candidates — are high-risk under Annex III. A property using such a system is a DEPLOYER and must, among other duties, use it in accordance with the provider's instructions, assign human oversight to people with the competence, training and authority to exercise it, monitor operation, and keep the automatically generated logs it controls.

What you need in placeHave the provider's Article 13 instructions for use, an assigned competent human overseer, and retained logs before the system screens a single applicant.
Applies when: ai_recruitment or ai_workforce :: Art. 26 binds the deployer of ANY high-risk system, so this covers both Annex III limbs: 4(a) recruitment and selection, and 4(b) allocating tasks, monitoring or evaluating staff, and decisions on promotion or termination. A guest-facing chatbot is not high-risk on either limb.
DATE CORRECTED 2026-08-26. This was carried as 2026-08-02. The Digital Omnibus on AI (in force 27 July 2026) postponed the Annex III high-risk obligations to 2 December 2027; Annex I moves to 2 August 2028. Article 50 transparency was NOT postponed and still applies from 2 August 2026 — the two are routinely confused, and the confusion runs both ways.
High-risk obligations under Art. 6(2) and Annex III have applied since 2 August 2026. The separate Art. 6(1) route — AI as a safety component of a regulated product — does not apply until 2 August 2027 and is unlikely to be relevant to accommodation.
What the text actually says
AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidatesAnnex III, 4(a)
Deployers of high-risk AI systems shall take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use accompanying the systemsArt. 26(1)
Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support.Art. 26(2)
Source: 32024R1689 · verified 2026-08-22
Tell your staff before you put a high-risk AI system to work on themeubindingEU AI Act

Before putting a high-risk AI system into service or use at the workplace, a deployer that is an employer must inform workers' representatives and the affected workers that they will be subject to its use. This is a duty owed to staff, and it sits alongside — not instead of — any information duty owed to candidates or guests.

What you need in placeHave a documented notice to affected workers and their representatives, issued BEFORE the system goes live — not on the day.
Applies when: ai_recruitment or ai_workforce :: Triggered by deploying ANY high-risk system at the workplace, not only a hiring tool.
What the text actually says
Before putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers' representatives and the affected workers that they will be subject to the use of the high-risk AI system.Art. 26(7)
Source: 32024R1689 · verified 2026-08-22
AI that allocates shifts, monitors or rates staff is HIGH-RISK tooeubindingEU AI Act

Annex III is not limited to hiring. An AI system used to allocate tasks based on individual behaviour or personal traits, to monitor or evaluate the performance and behaviour of staff, or to inform decisions on promotion or termination, is high-risk in its own right. Rota optimisation that scores individuals, and performance dashboards that rank them, are squarely within this limb — and it catches far more hotels than CV screening does.

What you need in placeHave the provider's instructions, a named human overseer with authority to override, and log retention running before rotas or evaluations depend on it.
Applies when: ai_workforce :: Task allocation, monitoring, performance evaluation, promotion or termination. Scheduling that merely fills shifts without scoring individuals is outside this limb.
DATE CORRECTED 2026-08-26. This was carried as 2026-08-02. The Digital Omnibus on AI (in force 27 July 2026) postponed the Annex III high-risk obligations to 2 December 2027; Annex I moves to 2 August 2028. Article 50 transparency was NOT postponed and still applies from 2 August 2026 — the two are routinely confused, and the confusion runs both ways.
This was missing from an earlier version of this register, which gated all high-risk duties on recruitment alone. An operator who does not screen CVs but does run performance analytics would have been told no high-risk obligations applied. They do.
What the text actually says
to make decisions affecting terms of work-related relationships, the promotion or termination of work-related contractual relationships, to allocate tasks based on individual behaviour or personal traits or characteristics or to monitor and evaluate the performance and behaviour of persons in such relationshipsAnnex III, 4(b)
Source: 32024R1689 · verified 2026-08-23
Tell people when a system is reading their face or inferring emotioneubindingEU AI Act

A deployer of an emotion recognition system or a biometric categorisation system must inform the people exposed to it that it is operating, and must process the personal data in accordance with the GDPR. Unlike Art. 50(1), this duty sits with the DEPLOYER — it is yours, not your vendor's.

What you need in placeHave the notice delivered to the people exposed to the system before they are exposed, plus the GDPR lawful basis that permits the processing at all.
Applies when: ai_biometric :: Emotion recognition or biometric categorisation.
CITATION CORRECTED 2026-08-26. This was carried as Art. 50(4) and is Art. 50(3). 50(4) is a different duty entirely — deep fakes and public-interest text — and is registered separately as eu.aiact.transparency-deepfake-imagery. The paragraphs bind different things, so the wrong number sends an operator to the wrong duty.
Facial check-in is probably NOT high-risk. Annex III 1(a) expressly excludes biometric VERIFICATION whose sole purpose is confirming a person is who they claim to be — which is exactly what matching a guest to their own booking does. Identifying people who have not presented themselves is a different thing. Emotion inference on STAFF is separately PROHIBITED outright — see eu.aiact.prohibited-emotion-recognition-workplace.
What the text actually says
Deployers of an emotion recognition system or a biometric categorisation system shall inform the natural persons exposed thereto of the operation of the system, and shall process the personal data in accordance with Regulations (EU) 2016/679Art. 50(3)
Source: 32024R1689 · verified 2026-08-23
Running a high-risk system: oversight, monitoring, and six months of logseubindingEU AI Act

A deployer of a high-risk AI system must use it in accordance with the instructions for use; assign human oversight to named people with the competence, training, authority and support to exercise it; ensure input data it controls is relevant and sufficiently representative; monitor operation and suspend use and inform the provider where the system presents a risk; and keep the logs the system generates automatically for at least six months. Where a decision affects a person, that person must be told a high-risk system is being used on them.

What you need in placeHave logs retained for at least six months, human oversight assigned to a competent person, and input data relevant to the intended purpose.
Applies when: ai_recruitment or ai_workforce :: The Annex III limbs a hotel realistically hits are 4(a) recruitment and selection and 4(b) task allocation, monitoring and evaluation. A guest-facing chatbot is high-risk on neither.
Minimum retention of automatically generated logs: 6 months — quoted: “keep the logs automatically generated by that high-risk AI system to the extent such logs ”
THE LOGS ARE ONLY YOURS IF YOU CAN GET THEM. Art. 26(6) binds you to retain logs "to the extent such logs are under their control", and a SaaS deployment routinely leaves them under the vendor's. Retention you cannot perform is not an excuse; it is a procurement failure you can still fix. See the vendor asks below.
DATE. Annex III high-risk obligations were postponed to 2 December 2027 by the Digital Omnibus (in force 27 July 2026). Article 50 transparency was not postponed. Do not let the delay of one become an assumption about the other.
Art. 26(9) does not create a new assessment — it requires you to USE the Art. 13 information to perform the GDPR Art. 35 DPIA you already owe. If your DPIA for an AI recruitment tool does not draw on the vendor's instructions for use, it was written without the inputs the Regulation assumes.
What the text actually says
take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use accompanying the systemsArt. 26(1)
assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary supportArt. 26(2)
keep the logs automatically generated by that high-risk AI system to the extent such logs are under their control, for a period appropriate to the intended purpose of the high-risk AI system, of at least six monthsArt. 26(6)
inform the natural persons that they are subject to the use of the high-risk AI systemArt. 26(11)
Ask your vendor
Supply the instructions for use for this system, complete to Article 13(3). owed under Art. 13
A compliant answer contains
  • 13(3)(a) — provider identity and contact details, and those of any authorised representative
  • 13(3)(b) — intended purpose; accuracy level WITH THE METRICS IT WAS TESTED AGAINST, robustness and cybersecurity per Art. 15; circumstances that degrade them; known risks; performance for the specific groups the system is used on; input data specification
  • 13(3)(c) — pre-determined changes to the system and its performance fixed at conformity assessment
  • 13(3)(d) — the human oversight measures under Art. 14, including the technical measures that help us interpret output
  • 13(3)(e) — computational and hardware requirements, expected lifetime, and required maintenance and software updates
  • 13(3)(f) — the mechanisms for collecting, storing and interpreting the logs
If they will not: A high-risk system is not lawfully on the market without these. A vendor who cannot produce them either does not have a conformity assessment, or does not accept the system is high-risk — and you need to know which, because if they are wrong you are operating a non-conforming system on your own staff.
Give us access to the automatically generated logs, and confirm retention meets six months. owed under Art. 26(6)
A compliant answer contains
  • How we export or retain the logs ourselves, not merely view them in your console
  • Your retention period, and what happens to logs if we terminate the contract
  • Confirmation the logs cover the events Art. 12 requires the system to record
  • The format, so the logs are readable without your product
If they will not: Art. 26(6) binds US to keep these for at least six months. If the logs sit only in your product and you delete them at 30 days, we cannot comply, and the breach is recorded against us rather than you.
Commit to a serious-incident notification path and the timescales you work to. owed under Art. 73
A compliant answer contains
  • A named contact and channel for notifying us, not a general support queue
  • Your reporting deadlines to market surveillance authorities: 15 days ordinarily, 2 days for widespread infringement or serious disruption of critical infrastructure, 10 days where a death is involved
  • That you will notify US on becoming aware, since our monitoring duty under Art. 26(5) depends on it
  • What you treat as a serious incident under Art. 3(49)
If they will not: Art. 73 puts the reporting duty on the provider, but the clock can start when the DEPLOYER becomes aware. Without a notification path in both directions the deadline can expire while each of you assumes the other is handling it.
Provide the EU declaration of conformity and CE marking evidence for this system. owed under Art. 47
A compliant answer contains
  • The declaration identifying this system and the version we are running
  • Which conformity assessment route was used
  • The harmonised standards or common specifications applied
If they will not: For an Annex III high-risk system this is the document that says it may lawfully be placed on the market at all. Its absence is not a paperwork gap.
Source: 32024R1689 · verified 2026-08-26
A rejected candidate can demand to know what the AI did in the decisioneubindingEU AI Act

Where you take a decision on the basis of output from an Annex III high-risk system, and that decision produces legal effects or similarly significantly affects the person adversely in their health, safety or fundamental rights, that person has the right to obtain from YOU — the deployer, not the vendor — clear and meaningful explanations of the role the AI system played in the decision procedure and the main elements of the decision taken. A rejected job applicant, or an employee refused a promotion where a scoring tool contributed, is exactly this person.

What you need in placeHave a route by which an affected person can get a meaningful explanation of a decision — and confirm your vendor can supply what that route needs.
Applies when: ai_recruitment or ai_workforce :: Annex III point 2 (critical infrastructure) is excluded from this right; the employment limbs at point 4 are not.
YOU CANNOT ANSWER THIS WITHOUT THE VENDOR, BUT YOU OWE IT ANYWAY. The explanation is due from you. If the system is a black box you licensed and the vendor will not describe how output is produced, you will be unable to discharge a duty that is nonetheless yours. That is a procurement problem to solve BEFORE deployment, which is why Art. 13(3)(b) requires the provider to describe the technical capability to explain output. Ask for it while you still have commercial leverage.
This sits alongside, not instead of, GDPR Art. 22 on automated decision-making and Art. 15(1)(h) on meaningful information about the logic involved. Where personal data is processed, expect both to be invoked in the same letter.
What the text actually says
shall have the right to obtain from the deployer clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision takenArt. 86(1)
Ask your vendor
Describe the technical capability of the system to explain its output, in terms we can put in front of an affected person. owed under Art. 13(3)(b)
A compliant answer contains
  • The technical capabilities of the system to provide information relevant to explaining its output
  • Which features or inputs drove an individual decision, retrievable for a named case after the fact
  • How long that per-decision explanation data is retained and how we export it
  • Any documented limits on explainability, stated plainly rather than implied
If they will not: Art. 86 makes the explanation OUR duty and Art. 13(3)(b) obliges the provider to describe this capability for a high-risk system. A vendor who cannot describe it is selling a system we cannot lawfully use for decisions about people.
Source: 32024R1689 · verified 2026-08-26
Facial check-in is prohibited processing unless you have explicit consent and a real alternativeeubindingGDPR

Matching a guest's face to their booking is the processing of biometric data for the purpose of uniquely identifying a natural person. Article 9(1) GDPR PROHIBITS that outright, and it becomes lawful only if one of the Article 9(2) exceptions applies. For a hotel the only realistic one is 9(2)(a) explicit consent. Consent is valid only if it is freely given, which means a guest who declines must be able to check in another way, just as quickly and without disadvantage. If facial check-in is the only route, or the alternative is a longer queue, the consent is not freely given and the processing has no lawful basis at all.

What you need in placeHave explicit consent captured and logged per guest, an equally quick non-biometric alternative, and a completed DPIA — all BEFORE go-live, not after.
Applies when: ai_biometric :: Any face-matching at check-in, in-room access or payment. Applies whether or not the system is "AI" — GDPR does not care how the match is computed.
THE AI ACT IS THE PERMISSIVE ONE HERE, AND THAT IS THE TRAP. Facial check-in is not a prohibited practice under Article 5, and Annex III 1(a) expressly carves biometric VERIFICATION out of the high-risk list where the sole purpose is confirming a person is who they claim to be. Read the AI Act alone and facial check-in looks permitted. GDPR Article 9(1) prohibits it by default. Both are true; the second is the one that stops the project.
DO NOT REACH FOR LEGITIMATE INTERESTS. Article 6 lawful bases do not unlock Article 9 special-category data — you need a 9(2) gateway as well as a 6(1) basis, and legitimate interests is not one of the gateways. "Necessary for the contract" is also not a 9(2) gateway, and a guest can plainly be checked in without their face.
A DPIA is required before you start. Article 35 requires one where processing is likely to result in high risk, and new-technology biometric identification of guests is the paradigm case. Doing the DPIA after go-live does not cure the defect — the obligation is prior.
The AI Act duty still applies on top: Article 50(3) requires you to inform people exposed to an emotion recognition or biometric categorisation system. Verification against a booking is arguably neither of those, but if you infer anything about the person beyond "is this the guest", you are into 50(3) and possibly Annex III 1(b) or 1(c) as well.
Employees are a harder case than guests, not an easier one. Consent from staff is rarely accepted as freely given because of the imbalance of power, so biometric time-and-attendance sits on much weaker ground than guest check-in does.
What the text actually says
the processing of genetic data, biometric data for the purpose of uniquely identifying a natural personArt. 9(1)
the data subject has given explicit consent to the processing of those personal data for one or more specified purposesArt. 9(2)(a)
Source: 32016R0679 · verified 2026-08-26
Night register: check ID on arrival and keep a continuous guest registernationalbindingWetboek van Strafrecht

Anyone whose business is providing overnight accommodation must, immediately on a guest's arrival, have a valid travel document or identity document produced, and must keep a CONTINUOUS register recording without delay the guest's name, place of residence and date of arrival, the nature of the document produced, and on departure the date of departure. Failing to do so is a criminal offence (overtreding), not an administrative one.

Applies when: always
Maximum fine (geldboete van de tweede categorie): cannot be determined — The consolidated text in force on 2026-08-21 states "de tweede categorie, EUR 3 350" in article 23(4) Sr, but the SAME page carries an editorial forward-note "[Red: Per 1 januari 2026: EUR 5.500.]" for a date that has already passed. The source contradicts itself and the operative amount cannot be determined from it. Confirm the current category-2 amount before relying on either figure.
Maximum custodial sentence: 1 month — quoted: “hechtenis van ten hoogste een maand”
THIS IS THE NATIONAL DUTY; THE MECHANICS ARE OFTEN MUNICIPAL. Article 438 fixes the minimum content of the register. Many gemeenten add requirements through the Algemene Plaatselijke Verordening — the format, an obligation to produce the register on demand, and in some places electronic submission. The MUNICIPAL LAYER IS NOT IN THIS VERSION.
Article 438 requires the document to be PRODUCED and its NATURE recorded. It does not authorise copying or scanning it. Retaining a passport image is a separate processing operation under the GDPR and the UAVG and needs its own justification.
The fine figure above is deliberately left indeterminate rather than rounded to a confident number. An unsourced or ambiguous penalty figure in a compliance register is precisely the failure the product exists to fix.
What the text actually says
Hij die er zijn beroep van maakt aan personen nachtverblijf te verschaffen wordt gestraft met hechtenis van ten hoogste een maand of geldboete van de tweede categorieArt. 438 lid 1 Sr
geen doorlopend register houdt of nalaat daarin onverwijld bij de aankomst van die persoon zijn naam, woonplaats en dag van aankomst aan te tekenen of te doen aantekenenArt. 438 lid 1 sub 2e Sr
Source: BWBR0001854 · verified 2026-08-21
PHYSICAL accessibility of the building — Bbl, not the Accessibility ActnationalbindingBesluit bouwwerken leefomgeving (Bbl)

A building must have spaces that are sufficiently accessible to persons with a functional impairment. For the use functions listed in table 4.183 this is satisfied by complying with the designated rules on an accessibility sector (toegankelijkheidssector): its presence, its floor area, which specific rooms it must contain, how it must be reached, permitted height differences and lift dimensions. Thresholds turn on the use function and the gross floor area.

Applies when: always :: Which rules bite depends on the gebruiksfunctie (logiesfunctie, bijeenkomstfunctie for a conference or restaurant area) and on gross floor area thresholds in table 4.183, plus whether the work is new build, renovation or existing stock. Floor area is not a PropertyAttributes field.
THIS IS THE OBLIGATION OPERATORS MEAN WHEN THEY SAY "ACCESSIBILITY". Ramps, doorway widths, accessible rooms and bathrooms, lifts and thresholds are HERE, in Dutch building regulation — not in the European Accessibility Act. The EAA covers the online booking journey and says nothing about the premises. Two obligations, two sources, two enforcement routes. See nl.eaa.toegankelijkheid-diensten and eu.eaa.booking-journey-accessibility.
The specific dimensions live in articles 4.184 to 4.190 and in table 4.183, which is a matrix keyed by use function. This entry establishes that the duty exists and where it is written down; it does not reproduce the matrix, and the matrix is what determines what you must actually build.
The Omgevingswet system also devolves real discretion to the municipality through the omgevingsplan and maatwerkvoorschriften. Local deviations are NOT covered in this version.
What the text actually says
Een bouwwerk heeft ruimten die voldoende toegankelijk zijn voor personen met een functiebeperking.Art. 4.183 lid 1 (aansturingsartikel)
Als voor een gebruiksfunctie in tabel 4.183 regels zijn aangewezen, wordt voor die gebruiksfunctie aan het eerste lid voldaan door naleving van die regels.Art. 4.183 lid 2
Source: BWBR0041297 · verified 2026-08-21
Fire safety: notify the municipality before using the building for accommodationnationalbindingBesluit bouwwerken leefomgeving (Bbl)

Using a building for a lodging function generally requires a prior use notification (gebruiksmelding) to the competent authority, with drawings and particulars about escape routes, occupancy and fire-safety installations. The paragraph applies to a use function only in so far as table 6.6 designates it, and the trigger is stated as a number of persons present rather than a number of rooms.

Applies when: always :: Table 6.6 keys the threshold to the gebruiksfunctie and to the number of PERSONS present, distinguishing a logiesfunctie in a logiesgebouw from another logiesfunctie. Room count is a proxy for occupancy, not the statutory test.
Occupancy threshold triggering a gebruiksmelding: cannot be determined — The value is held in a cell of table 6.6, keyed by gebruiksfunctie and read from the "aanwezigheid [personen]" column. A table cell cannot be quoted as an operative sentence, and reproducing a number lifted out of a matrix without its row and column headings is how a register misroutes a threshold to the wrong use function. Read row 7 (Logiesfunctie) of table 6.6 at the source URL.
The gebruiksmelding is a NOTIFICATION, not a permit — but using the building without having made it is an offence, and the authority may impose maatwerkvoorschriften in response. Do not treat it as a formality.
Fire-safety enforcement in practice sits with the municipality and the veiligheidsregio, and local policy on inspections and on what must accompany the notification is NOT covered in this version.
What the text actually says
De regels in deze paragraaf zijn op een gebruiksfunctie van toepassing voor zover deze in tabel 6.6 voor die gebruiksfunctie zijn aangewezen.Art. 6.6 (aansturingsartikel)
Source: BWBR0041297 · verified 2026-08-21
Food hygiene: breaching Regulation 852/2004 is a Dutch offence in its own rightnationalbindingWarenwetbesluit hygiëne van levensmiddelen

It is prohibited to act contrary to the specified articles of Regulation (EC) 852/2004 — including article 5, the HACCP obligation — and of Regulations 853/2004 and 854/2004 where relevant. In other words the EU hygiene rules are not merely directly applicable; the Warenwetbesluit makes breaching them a discrete enforceable prohibition under Dutch law, policed by the NVWA.

Applies when: food_service or bar :: Any preparation or service of food or drink, including a breakfast buffet and a minibar.
Allergen information is a DIFFERENT obligation with a different source and a different failure mode — see eu.food.allergen-information. A kitchen can hold a working HACCP plan and still breach the allergen rules.
What the text actually says
Het is verboden te handelen in strijd met de artikelen 3, 4, eerste, tweede en derde lid, 5, eerste lid, tweede lid, laatste alinea, en vierde lid, en 6, tweede lid en derde lid, onderdelen a en b, van verordening (EG) 852/2004Art. 2 lid 1
Source: BWBR0018823 · verified 2026-08-21
Serving alcohol requires a licence from the mayornationalbindingAlcoholwet

It is prohibited to operate a licensed-hospitality business (horecabedrijf) or an off-licence without a licence to that effect from the mayor. For a hotel this captures the bar, the restaurant, banqueting and in-room service of alcoholic drinks. The licence is tied to premises and to named managers, and it does not travel with a change of operator.

Applies when: bar or food_service :: The test is the serving of alcoholic drinks for consumption on the premises, not the presence of a room labelled "bar".
THE LICENCE IS ISSUED MUNICIPALLY. The duty is national; the application, the conditions attached, the fee and any local horeca policy (opening hours, terrace conditions, a Bibob integrity screening) sit with your gemeente and are NOT covered in this version.
A terrace is regulated separately again — terrace boundaries and hours are municipal, and this register names that gap rather than answering it.
What the text actually says
Het is verboden zonder daartoe strekkende vergunning van de burgemeester het horecabedrijf of slijtersbedrijf uit te oefenen.Art. 3 lid 1
Source: BWBR0002458 · verified 2026-08-21
Music and television in the hotel is a communication to the public and needs a licencenationalbindingAuteurswet

Performance or presentation of a work in public is a form of making the work public, which is reserved to the rightholder. Playing music in a lobby, bar, restaurant, gym or spa, and relaying a television or radio signal to guest rooms, therefore requires permission — in practice a licence from Buma/Stemra for authors' rights and from Sena for performers' and producers' related rights.

Applies when: always
Buma/Stemra and Sena tariff: cannot be determined — Tariffs are published by the collecting societies, not in the Auteurswet, and they vary by room count, by the areas in which music is played and by whether rooms carry television. The statute fixes the requirement to hold a licence and says nothing about the price.
Two separate licences are normally needed, from two separate organisations. Holding only one is a common and expensive mistake.
What the text actually says
Onder de openbaarmaking van een werk van letterkunde, wetenschap of kunst wordt mede verstaanArt. 12 lid 1
de voordracht, op- of uitvoering of voorstelling in het openbaar van het geheel of een gedeelte van het werkArt. 12 lid 1 sub 4
Source: BWBR0001886 · verified 2026-08-21
Legionella: a written risk analysis and control plan is required for lodging buildingsnationalbindingDrinkwaterbesluit

Chapter 4 of the Drinkwaterbesluit applies to the owner of a collective water supply or collective pipe network serving taps in, among others, a building with a lodging function (logiesfunctie), a dwelling function providing commercial overnight accommodation to more than five persons, and a bathing establishment. Those owners must carry out a legionella risk analysis, draw up and execute a control plan, keep a logbook, sample at the prescribed frequency, and inform the inspector and take measures when limits are exceeded.

Applies when: always :: Scope follows the BUILDING's use function, not the presence of a pool. Recreational accommodation (recreatieverblijven), allotment cabins and buildings used only by on-site staff are excluded by art. 35 lid 1 onder c sub 1. A pool brings the separate badinrichting limb into play as well.
Occupancy threshold for a dwelling-function property (woonfunctie): 5 persons — quoted: “waar bedrijfsmatig nachtverblijf wordt verleend aan meer dan vijf personen”
SIZE IS NOT THE TEST FOR A HOTEL. A building with a logiesfunctie is in scope regardless of how small it is; the "more than five persons" threshold applies to the WOONFUNCTIE limb, which is the one a house or apartment let commercially falls under. Reading the threshold across to a hotel would wrongly exempt small hotels.
A swimming pool or spa brings the badinrichting limb of article 35 into play in addition. It is not a substitute for the lodging-function duty and does not replace the drinking-water risk analysis.
What the text actually says
Dit hoofdstuk is van toepassing op de eigenaar van een collectieve watervoorziening of collectief leidingnetArt. 35 lid 1
met uitzondering van recreatieverblijven, huisjes op volkstuincomplexen en gebouwen waar uitsluitend wordt overnacht door personen die ter plaatse werkzaam zijnArt. 35 lid 1 onder c sub 1
waar bedrijfsmatig nachtverblijf wordt verleend aan meer dan vijf personenArt. 35 lid 1 onder c sub 2
Source: BWBR0030111 · verified 2026-08-21

POST-STAY — 7 obligations

After the guest leaves.

Delete guest data when the purpose it was collected for has endedeubindingGDPR

Personal data may be kept in identifiable form only for as long as is necessary for the purpose it was collected for. Set and actually apply a retention period per category — booking records, CCTV, door-lock logs, marketing consents — and delete or anonymise on schedule. Where a guest asks for erasure and no other basis to keep the data applies, erase it. "We keep everything" is not a retention policy.

What you need in placeHave a documented retention schedule per data category, and a deletion mechanism that actually runs rather than a policy that describes one.
Applies when: always
Retention period for guest records: cannot be determined — The GDPR sets no period. The retention floor for any given category is fixed by OTHER law — tax and invoicing rules, the national guest-registration statute, employment law — and those periods are national. This register will not invent a number that the source does not contain.
Retention periods collide. The tax rule says keep the invoice; the guest-register rule says keep the form; the GDPR says do not keep either longer than necessary. Resolving that collision is national-layer work and, for the register mechanics, sometimes municipal.
What the text actually says
kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processedArt. 5(1)(e)
Source: 32016R0679 · verified 2026-08-21
Issue a compliant VAT invoice for business stayseubindingVAT Directive

A taxable person must ensure an invoice is issued for supplies made to another taxable person or to a non-taxable legal person, and for payments on account received before such a supply. In accommodation that means corporate bookings, company-paid stays and prepaid deposits from business customers. The invoice must carry the particulars the Directive prescribes, and the issuing and storage rules are then set nationally.

Applies when: always
VAT rate on accommodation: cannot be determined — Set by each Member State within the limits of the VAT Directive, and several states have changed the accommodation rate recently. It is a national-layer figure and is not asserted here.
Whether a simplified invoice or a receipt suffices for a private guest, and the thresholds for it, are national elections under Arts. 220a and 238.
This is an EU Directive. It binds Member States, and the duty an operator can actually be prosecuted under is the national law transposing it — wording, thresholds and penalties vary by Member State. The national layer is where that lands; where this register has no national layer for your country, treat this as the duty category, not the rule text.
What the text actually says
Every taxable person shall ensure that, in respect of the following, an invoice is issuedArt. 220
supplies of goods or services which he has made to another taxable person or to a non-taxable legal personArt. 220(1)
Source: 32006L0112 · verified 2026-08-21
DAC7: the PLATFORM reports your rental income to the tax authority — you do noteubindingDAC7

Reporting platform operators must run due-diligence procedures on their sellers and report them annually to a Member State tax authority, which then exchanges the data automatically across the Union. The host's own position is consequential rather than procedural: identity, address, tax identification number, property address and the consideration credited each quarter are collected and reported, so income declared to the tax authority must match what the platform has already told it. Expect the platform's data requests and answer them accurately.

Applies when: always
Platform reporting deadline: 31 January of the year following the reportable period — quoted: “no later than 31 January of the year following the calendar year in which the Seller is id”
DIRECTION OF THE DUTY MATTERS. DAC7 obliges PLATFORM OPERATORS, not hosts. A register that tells an operator "you must file a DAC7 report" is wrong. What a host must do is supply accurate information when the platform asks — a platform is required to close or withhold payment on accounts that do not respond — and declare the income consistently.
This reaches hotels too, not only short-term rentals: "rental of immovable property" is a relevant activity, and a hotel selling rooms through an online platform is a seller for these purposes. Unlike Reg. (EU) 2024/1028, DAC7 has no hotel exclusion.
This is an EU Directive. It binds Member States, and the duty an operator can actually be prosecuted under is the national law transposing it — wording, thresholds and penalties vary by Member State. The national layer is where that lands; where this register has no national layer for your country, treat this as the duty category, not the rule text.
What the text actually says
Each Member State shall take the necessary measures to require Reporting Platform Operators to carry out the due diligence procedures and fulfil reporting requirements laid down in Sections II and III of Annex V.Art. 8ac(1), inserted into Dir. 2011/16/EU
no later than 31 January of the year following the calendar year in which the Seller is identified as a Reportable SellerAnnex V, Section III, paragraph A(1)
Source: 32021L0514 · verified 2026-08-21
Tell guests which ADR body covers you — the EU ODR platform NO LONGER EXISTSeubindingADR Directive

Where the operator is committed to, or required to use, an alternative dispute resolution entity, it must tell consumers which entity or entities those are and give the entity's website address, clearly and accessibly on its own website and in its terms and conditions. Where a complaint cannot be settled directly, the consumer must be told on paper or another durable medium whether the operator will use ADR to resolve it.

Applies when: always
REMOVE THE ODR LINK FROM YOUR SITE. Many hotel websites still carry the mandatory link to the European Online Dispute Resolution platform. That duty is GONE: Regulation (EU) No 524/2013 was repealed with effect from 20 July 2025 by Regulation (EU) 2024/3228, complaint submission stopped on 20 March 2025 and the platform has been discontinued. A live link to a dead platform is itself misleading information about redress.
Whether participation in ADR is voluntary or compulsory for accommodation, and which body is competent, is set nationally. This entry establishes the INFORMATION duty, not membership of any particular scheme.
This is an EU Directive. It binds Member States, and the duty an operator can actually be prosecuted under is the national law transposing it — wording, thresholds and penalties vary by Member State. The national layer is where that lands; where this register has no national layer for your country, treat this as the duty category, not the rule text.
What the text actually says
Member States shall ensure that traders established on their territories inform consumers about the ADR entity or ADR entities by which those traders are coveredArt. 13(1)
shall be provided in a clear, comprehensible and easily accessible way on the tradersArt. 13(2)
Source: 32013L0011 · verified 2026-08-21
Guest reviews: no fakes, no cherry-picking, and verify that reviewers actually stayedeubindingUnfair Commercial Practices Directive

If the property states or implies that the reviews it displays come from guests who actually stayed, it must take reasonable and proportionate steps to check that they did. Submitting, commissioning or incentivising false reviews, and misrepresenting reviews — including by publishing only the positive ones while implying the set is complete — are prohibited in all circumstances, with no need to prove that any consumer was actually harmed.

Applies when: always
These are Annex I practices — unfair in ALL circumstances. Unlike a general misleading-practice claim, no assessment of effect on the average consumer is needed, which makes them unusually cheap to enforce.
The CONSOLIDATED CELEX is cited because points 23b and 23c were inserted by the Omnibus Directive in 2019. The original CELEX 32005L0029 does not contain them.
This is an EU Directive. It binds Member States, and the duty an operator can actually be prosecuted under is the national law transposing it — wording, thresholds and penalties vary by Member State. The national layer is where that lands; where this register has no national layer for your country, treat this as the duty category, not the rule text.
What the text actually says
Stating that reviews of a product are submitted by consumers who have actually used or purchased the product without taking reasonable and proportionate steps to check that they originate from such consumers.Annex I, point 23b
Submitting or commissioning another legal or natural person to submit false consumer reviews or endorsements, or misrepresenting consumer reviews or social endorsements, in order to promote products.Annex I, point 23c
Source: 02005L0029-20220528 · verified 2026-08-21
Tourist tax: the municipality MAY levy it, and may recover it from you as the hostnationalbindingGemeentewet

Municipalities are empowered — not required — to levy a tourist tax in respect of overnight stays by persons not registered as residents at an address in that municipality. Where the tax is levied on the person PROVIDING the opportunity to stay, that person is entitled to pass it on to the guest whose stay gives rise to it. In practice the operator collects and remits, under a municipal ordinance.

Applies when: always
Tourist tax rate: cannot be determined — Article 224 confers a POWER and sets no rate. Every element an operator actually needs — whether the tax exists at all in this municipality, the rate, whether it is per person per night or a percentage of turnover, the exemptions, and the filing deadline — is set in the municipal belastingverordening. The MUNICIPAL LAYER IS NOT IN THIS VERSION.
The single word "kan" is doing a lot of work here, and this is exactly the shape of the v1 municipal gap. National law says the tax MAY exist and that you may pass it on. Whether it does exist, at what rate, and when you must remit are decisions your gemeente makes. Check your municipality's belastingverordening.
What the text actually says
kan een toeristenbelasting worden gehevenArt. 224 lid 1 — enabling, not mandatory
Voor zover de belasting wordt geheven van degene die gelegenheid tot verblijf biedt, is deze bevoegd de belasting als zodanig te verhalen op degene ter zake van wiens verblijf de belasting verschuldigd wordt.Art. 224 lid 2
Source: BWBR0005416 · verified 2026-08-21
VAT invoices must carry the prescribed particularsnationalbindingWet op de omzetbelasting 1968

An invoice must state the prescribed particulars: the date of issue, a sequential number from one or more series that uniquely identifies it, the VAT identification number under which the supply was made, the customer's VAT identification number where relevant, and the further items listed in the article. A periodic invoice may cover several supplies provided the period is no longer than one calendar month, and self-billing by the customer is permitted only where agreed in advance and subject to an acceptance procedure.

Applies when: always
VAT rate on accommodation (logies): cannot be determined — The reduced-rate categories are in Tabel I bij de Wet op de omzetbelasting 1968, which wetten.overheid.nl publishes as a SEPARATE ANNEX that is not returned with the article text at the cited URL. The rate applicable to accommodation could not be read from the source retrieved on 2026-08-21 and is therefore not asserted. Confirm the current rate with the Belastingdienst or in Tabel I directly.
Maximum period covered by a periodic invoice: 1 calendar month — quoted: “mits de periode waarop de factuur betrekking heeft niet langer is dan een kalendermaand”
The accommodation VAT rate is deliberately left unstated. It is the number operators most want and it moved recently in the Netherlands; guessing it, or carrying forward a remembered figure, is exactly the unsourced-number failure this register is built to avoid.
What the text actually says
Op de factuur zijn de volgende vermeldingen verplichtArt. 35a lid 1
Voor verscheidene afzonderlijke leveringen of diensten kan een periodieke factuur worden opgemaakt, mits de periode waarop de factuur betrekking heeft niet langer is dan een kalendermaand.Art. 35 lid 1
Source: BWBR0002629 · verified 2026-08-21