Brazil's LGPD for hotels: the practical owner's guide
LGPD (Brazil's General Data Protection Law) requires you to collect only necessary data, store it securely, have legal basis for each use, and respond to guests requesting their information. Real risk is a fine of up to 2% of revenue — but doing the basics right is normal operations.
By Denise Satoupdated on August 03, 20264 min read
LGPDdadosregulamentação
What does LGPD have to do with your small hotel?
LGPD (Law 13.709/2018) is Brazil's data protection law. It applies to every business that collects, stores, or processes personal information — and you, as a hotel owner, collect data every day: name, ID, phone, email, address of every guest. The law states that this data must be collected for a clear purpose, stored securely, retained for a defined time, and collected with explicit consent or legal basis.
What changed in practice is that you now have legal responsibility. LGPD provides for fines of up to 2% of revenue, capped at R$50 million per violation (article 52) — high numbers that sound scary. But for most small hotels, the actual fine is zero if you do the basics: minimize data collection, store it carefully, post a simple privacy notice, and let guests opt out of marketing contact.
What guest data can you collect?
Only what's necessary. The key rule is minimization: don't ask for CPF from everyone if only the accounting team needs a few; don't store children's data unnecessarily; don't capture security camera footage without notice. FNRH Digital, a legal requirement for Cadastur-registered accommodations, already structures part of this collection — name, ID, nationality, check-in and check-out dates.
Beyond that, you have three legal bases for each data point: contract (the guest wants to book, so you need email and phone), legal obligation (FNRH, FGTS, invoicing), and explicit consent (if you want to collect data for marketing, it's opt-in only). Don't bury "data will be collected via Google Analytics trackers or cameras" in fine print — clear on-screen notice is worth more than hidden contracts.
For how long should you keep data (and how do you delete it)?
Set a deadline: if it's to comply with FNRH, keep it as long as the law requires (consult your accountant). If it's for birthday greetings via WhatsApp, 12 months is reasonable — after that, delete. If it's backup, encrypt it. The trap is forgetting: configure automatic purge reminders — discarded data becomes zero risk.
Deletion means really deleting: it's not moving an old file to an "archives" folder; it's encrypting, shredding, or erasing with a tool that makes recovery impossible. If you use third parties (laundry service that copies guest CVs, vendors handling your data), make sure the supplier has a written commitment to deletion — that requirement is mandatory under LGPD.
What changes for WhatsApp and email marketing?
WhatsApp is transactional — notifying check-in, reception updates, or departure — based on contract execution, so it's allowed without prior consent. But marketing (promotion, discount for next visit) requires explicit opt-in: the guest clicks "I want to receive offers" or you collect the number with a clear question first.
Important: every marketing message must have an unsubscribe button ("To unsubscribe, reply STOP"). That mailing-list-without-unsubscribe approach some hotels use has become a legal trap. For email, the rule is identical — consent plus unsubscribe button on all messages. Confirm with your lawyer about exact templates; each jurisdiction has nuances.
What's the real fine risk?
High in theory, low in practice if you act. Fines target companies that leak millions of records, sell data, ignore subject-access requests, or lack basic security (shared front-desk passwords, email spreadsheets in public OneDrive). A 15-room small hotel that collects data, stores it securely, and respects opt-outs is unlikely to be targeted.
The real risk is operational: reputation. A guest who discovers their data was sold, exposed in a shared spreadsheet, or used for spam leaves a bad review. The LGPD fine might be zero, but your rating tanks. So the reason to do it right is simpler: data handled with care builds trust.
How to comply in 8 steps?
- Audit your data: List everything you collect (name, CPF, email, phone, photo, camera biometrics, Wi-Fi logs).
- Justify each collection: Keep only the minimum — if you collect CPF from everyone, ask yourself if it's really mandatory.
- Restrict access: Front desk sees guest data for current visitors; manager sees everything; housekeeping sees nothing.
- Strong passwords and encryption: Two-factor authentication for dashboard access, sensitive data encrypted.
- Set retention periods: "Guest data stays 12 months post-checkout; backups 6 months; then we delete."
- Privacy notice: Poster at reception or link on your website (plain language, no legal jargon — "Your data is collected for booking, FNRH, and service; we keep it for X time; you can request to see or delete it anytime").
- Channel for subject requests: Email, WhatsApp, or phone where guests can ask "I want my data" or "Delete my data."
- Vendor contracts: If you outsource cleaning, Wi-Fi, or other services accessing data, all must have a contract stating they'll use it only as agreed — confirm the final notice text with your lawyer.
Guest data handled securely and transparently builds trust — and ViaHotel is built with encrypted pre-check-in and automatic purging (LGPD by design). Less risk, less bureaucracy. Try 14 days free, no card required.