Hotel Privacy Policy Disclosures Should Match Every Booking Channel. Most Don’t.

A conceptual network diagram made of red and blue strings connected by pins on a white background, symbolizing social capital and business networking.

Every reservation ends with the hotel holding guest personal information; what changes is how that information reached the hotel, and why that origin matters for the hotel’s own privacy obligations

A hotel’s privacy policy obligations shift with every booking channel, yet almost every policy in circulation still describes guest data as if it all arrived the same way. This is not a story about artificial intelligence or a new wave of regulation โ€” it is about a structural mismatch that already exists inside most hotels’ compliance documents, between how reservations are actually acquired and how the resulting data is disclosed to guests. A booking made through an OTA, a GDS, a corporate travel agent, or a group organizer carries a different consent trail, a different retention justification, and in several jurisdictions, a different enforcement exposure. For a GM signing off on a privacy policy, a DOSM negotiating a group contract, or a revenue manager choosing which channels to push, the distinction is not academic: regulators in 2025 fined businesses specifically for treating distinct third-party data flows as one undifferentiated category, and hotels run more distinct third-party data flows than almost any other consumer business.

1. Direct bookings: the baseline the rest gets measured against


A direct booking โ€” through the hotel’s own website, call center, or front desk โ€” is the only channel where the hotel is the sole collector of guest data from the first point of contact. There is no intermediary consent chain to reconstruct, no second party’s privacy notice to reconcile with the hotel’s own, and no ambiguity about who the data controller is. The guest fills in a name, contact details, payment information, and stay preferences directly into a system the hotel owns or licenses, and sees the hotel’s own privacy policy before doing so.

That clarity comes with a commercial premium attached to it. SiteMinder’s analysis of more than 125 million reservations across roughly 44,500 hotels found that hotel websites generated an average booking value of $516 in 2025, ahead of wholesalers ($445), global distribution systems ($392), and OTAs ($312).

ChannelAverage booking value, 2025
Hotel website (direct)$516
Wholesaler$445
Global distribution system (GDS)$392
OTA$312

Source: SiteMinder, “Hotel Booking Trends,” 2025/2026 edition, based on 125+ million reservations across ~44,500 hotels.

The direct channel also carries the fewest data-sharing agreements to maintain โ€” typically just a payment processor and a booking-engine vendor, both acting as processors under a data processing agreement rather than as independent controllers. The commercial argument for growing this channel is well established; the compliance argument is less discussed but just as real: every reservation shifted from an OTA to the hotel’s own site is one fewer third-party data-sharing relationship the privacy policy has to account for.

What deserves attention here is not the mechanism, which is simple, but the temptation to treat this simplicity as evidence that the whole privacy policy is fine. A clean direct channel does not offset a poorly disclosed OTA or loyalty-partner relationship elsewhere in the same document โ€” regulators evaluate each data flow, not the average.

2. OTAs: the channel with the most guests and the most ambiguity


Online travel agencies operate under two distinct financial models, and the model determines the shape of the data flow. In the agency model, the OTA passes the booking to the hotel and the hotel bills the guest directly, meaning full payment and contact data must reach the hotel to complete the transaction. In the merchant model, the OTA is the merchant of record and charges the guest itself, but the hotel still receives the personal data โ€” name, contact details, arrival information, special requests โ€” needed to service the stay, even though it never touches the payment. Booking Holdings’ FY2025 annual filing shows this mix shifting: merchant revenues grew 25.5% year-over-year to $17.8 billion while agency revenues declined 6.5% to $8.0 billion, continuing what the filing describes as an ongoing shift from agency to merchant revenue at Booking.com.

Globally, OTAs are projected to have generated $408 billion in gross bookings in 2025, about one in four travel dollars worldwide, with lodging remaining the segment where intermediaries hold the strongest position relative to airlines or cruise. That scale is precisely what makes the OTA relationship the one most hotels get wrong in their privacy documentation: a property working with even a modest number of OTA partners is running that many separate third-party data pipelines, each governed by a different set of terms, and most hotel privacy policies collapse all of them into a single line โ€” “our online travel agency partners.”

That shortcut is what regulators have started to test, just not yet against a hotel by name. The California Privacy Protection Agency’s first contested enforcement actions in 2025 turned on exactly this pattern: businesses describing third-party data sharing in generic terms rather than specific, verifiable disclosures.

BusinessFineDate
American Honda Motor Co.$632,500March 2025
Todd Snyder, Inc.$345,178May 2025
Tractor Supply Company$1.35 millionSeptember 2025

Source: California Privacy Protection Agency, enforcement announcements, 2025.

None of these are hospitality cases, and no equivalent action against a hotel or OTA has been made public as of this writing โ€” that gap should be stated plainly rather than implied away. But the CPPA’s stated priorities (honoring opt-out requests, data minimization, verifiable third-party disclosures) apply with equal force to a hotel’s relationship with Booking.com, Expedia, Agoda, or Trip.com, and there is no structural reason the hospitality sector is exempt from the same scrutiny. Whether or when that scrutiny arrives is genuinely unresolved; what’s already true is that the disclosure gap exists today, independent of enforcement timing.

3. GDS and corporate travel management: the quiet channel with the deepest data


Global Distribution Systems โ€” Amadeus, Sabre, and Travelport โ€” were built to move airline inventory, and the Passenger Name Record they created for that purpose has since become the standard data structure across hotel, car, and rail bookings as well. A PNR consolidates a traveler’s itinerary, contact information, and payment details into a single record, and because corporate and agent-mediated bookings often touch more than one back-end system, the same reservation can generate multiple linked PNRs that must stay synchronized across the GDS, the airline or hotel’s own reservation system, and the travel management company’s platform.

The commercial line this touches is different from the OTA relationship. GDS access typically costs hotels a flat transaction or segment fee rather than a percentage commission, so the P&L impact shows up as a system cost rather than an acquisition cost. The privacy impact is arguably larger than the financial one: corporate travel bookings frequently carry a contracting party โ€” the traveler’s employer โ€” that is distinct from the data subject, raising a lawful-basis question GDPR doesn’t answer cleanly (whose consent governs a booking made by a travel manager on behalf of an employee who never saw a privacy notice), and international corporate travel can pull in passport or national ID data that a typical leisure booking would not. A hotel receiving reservations through a GDS is, in practice, one step removed from the guest and one or two steps removed from whichever TMC or corporate booking tool originated the transaction โ€” which makes it harder, not easier, to state in a privacy policy exactly where the data came from.

What’s worth watching is the layer now building on top of GDS data rather than replacing it: corporate travel platforms are increasingly pulling PNR data at the point of booking to automate expense and policy compliance workflows, adding yet another party that touches the same record before it reaches the hotel. Evidence on how this changes hotel-side obligations specifically is still too early to characterize with confidence.

4. Traditional travel agents and tour operators: data arriving pre-packaged


Leisure travel agents and tour operators frequently collect more data upfront than a single-room reservation requires โ€” full traveler manifests for package tours, dietary or health notes for organized excursions, sometimes passport and visa details bundled with the booking file โ€” and transmit that file to the hotel through channels that are often less structured than an API: an extranet upload, an email, occasionally still a fax. The hotel receives the file largely as-is.

This is where the data-minimization principle common to GDPR, CCPA, and PIPL alike gets tested in practice rather than in policy language. If an agent forwards a complete package manifest including details the hotel doesn’t need to fulfil the room booking, retaining that surplus data indefinitely is difficult to justify under any of the three regimes’ “reasonably necessary” or “adequate, relevant and limited” standards. That review step โ€” someone deciding what from an inbound agent file the hotel actually needs to keep โ€” is a process cost with no clean equivalent in the OTA or direct channels, where the data arriving is closer to the minimum required by design.

No named primary source publishes a current, quantified figure for personal-data volumes moving through traditional agent and tour-operator channels specifically, so this section rests on the regulatory principle rather than a statistic โ€” and that absence of data is itself informative: manual, file-based channels are the ones least likely to show up in any distribution research precisely because they are the least instrumented, which is also why they are where minimization failures are hardest to detect.

5. Group and MICE organizers: one contract, many data subjects the hotel never spoke to


A meeting, conference, or wedding block is negotiated between the organizer and the hotel’s sales team, and the result is a rooming list โ€” sometimes dozens, sometimes hundreds of individual names, often with accessibility or dietary information attached, occasionally with payment authorization details for a master account. Every individual on that list becomes a data subject in the hotel’s systems without having interacted with the hotel or seen its privacy policy at any point.

This is a genuinely different legal situation from every other channel in this article, because the hotel’s own privacy notice cannot realistically be the mechanism through which those guests learned how their data would be used โ€” the organizer’s notice, if one exists, is doing that job instead. The commercial consequence sits less on a revenue line and more on contract risk: a single group contract can transfer hundreds of guest profiles in one file, and the exposure scales with every block a sales team books, independent of room revenue.

Some operators have started addressing this directly in group sales paperwork, adding warranties requiring the organizer to confirm attendees were notified before a rooming list is transmitted. That practice is not yet standard, and whether it becomes a fixture of group-sales contracts industry-wide, rather than a policy adopted by a handful of larger operators, is still an open question.

6. Loyalty programs, co-brand cards, and travel partners: data that keeps moving after checkout


A hotel loyalty program is designed to extend the guest relationship past checkout, and the data flow follows that design. Marriott’s own annual report describes its Loyalty Program as encompassing points earned through direct stays as well as “purchases with co-branded credit cards and our Loyalty Program partners” โ€” meaning transaction signals from card issuers such as Amex and Chase, and point-transfer activity with airline and other travel partners, continue to move between the hotel group and named financial and travel companies long after the stay itself has ended.

This is a retention and disclosure-scope question rather than an acquisition-cost one. The hotel group is simultaneously a recipient of spending signals from card issuers and a discloser of stay history to partners for point-crediting purposes, and most loyalty privacy policies describe this in categorical terms โ€” “our co-brand card issuers,” “our participating partners” โ€” rather than by name, which is the same specificity gap regulators have already penalized in non-hospitality cases. Loyalty and central reservation databases also represent, by a wide margin, the largest historical store of guest personal data a hotel group holds, aggregating years of stays across every brand in a portfolio. The Marriott/Starwood breach remains the reference point for what that concentration means as a liability: roughly 339 million guest records exposed globally, an initial UK ICO penalty notice of ยฃ99.2 million later reduced to a final ยฃ18.4 million once mitigating factors were weighed. That case predates this article’s stated data window by several years and should be read as standing precedent, not a current figure โ€” but the underlying structure it illustrates, a single loyalty database as the largest concentration of risk, hasn’t changed.

7. The AI-agent booking channel: a new source with no settled disclosure category yet


In 2026, Google extended its Universal Commerce Protocol โ€” an open standard letting AI agents discover, price, and complete purchases on a consumer’s behalf โ€” to hotel bookings, following its initial January 2026 launch for retail, as reported by Skift. Comparable agentic-commerce work from other AI platforms points the same direction: a guest’s assistant searches, selects, and finalizes a hotel reservation without the guest visiting the hotel’s website or an OTA page, transmitting identity, payment credential, and preference data to the hotel or its booking engine programmatically.

No commercial line item exists yet for this channel, and that absence is itself the relevant fact for a revenue manager: it isn’t clear whether an agent-originated booking should be reconciled like a direct booking, an OTA-referred one, or something priced entirely differently, because the take-rate structures are still being negotiated between platforms and hotel groups. The privacy question, however, already exists regardless of how that commercial question resolves. Current compliance guidance for 2026 treats an AI agent as a data processor and the organization deploying it โ€” in this case, whichever party configured the agent to transact, which may be the hotel, the platform, or a distribution intermediary โ€” as the controller retaining full accountability, including the ability to demonstrate what data the agent accessed and on what basis. Most hotel privacy policies describe how “you” provide information to the hotel; none yet describe how an autonomous system provides it on a guest’s behalf.

Several national data protection authorities, including France’s CNIL, Germany’s DSK, and Italy’s Garante, have already opened inquiries into AI agent deployments in commercial settings generally. None of these inquiries are hospitality-specific yet, but a hotel adopting agent-checkout integrations is, by that act, stepping into the same regulatory perimeter. How this settles โ€” what disclosure an agent-mediated booking requires, and who is responsible for providing it โ€” is not something the evidence today can resolve, and this article won’t pretend otherwise.

8. Building the channel-based privacy inventory


The pattern across every channel above is the same one stated at the outset: the hotel ends up holding the data regardless of source, but the origin determines what has to be disclosed, to whom, and how defensible that disclosure is if a regulator asks. Of the six sources examined here, four warrant the closest attention right now โ€” OTAs and loyalty/co-brand partners, because of their scale and the specificity gap regulators are actively penalizing elsewhere; group and MICE bookings, because of the consent gap built into how rooming lists are collected; and AI-agent bookings, because no disclosure convention exists for them yet at all. Direct bookings and GDS-routed corporate travel carry real considerations of their own, but neither currently sits inside active enforcement attention the way the other four do.

None of this resolves into a single fix, because the six channels don’t share a single mechanism. What they share is the requirement that a hotel’s privacy policy name them individually rather than absorb them into a generic “third-party booking partners” clause โ€” the same shortcut regulators have already shown they will not accept from businesses outside hospitality, and have no evident reason to accept from businesses inside it.


Data Source