GDPR for Holiday Parks: Your Comprehensive Compliance Guide
Navigate the essentials of data protection to keep your park compliant and your guests' information secure.
GDPR Compliance Guide for Site Operators
Data protection is not optional. Since GDPR came into force, outdoor accommodation operators must handle guest data responsibly or face fines up to £17.5 million or 4% of turnover. Here is your complete compliance guide.
Key Takeaways
Understand Your Obligations
Familiarise yourself with GDPR principles and legal bases for processing data to avoid common pitfalls.
Protect Guest Data
Implement robust measures for collecting, storing, and retaining guest information, including special categories.
Ensure Transparency
Maintain clear privacy notices and manage consent effectively to build trust with your guests.
Prepare for Incidents
Establish clear procedures for subject access requests and data breaches to respond efficiently and compliantly.
Understanding Your Obligations
Key GDPR Principles
| Principle | What It Means for You |
|---|---|
| Lawfulness | Valid legal basis for processing |
| Purpose limitation | Only use data for stated purposes |
| Data minimisation | Collect only what you need |
| Accuracy | Keep records up to date |
| Storage limitation | Delete when no longer needed |
| Security | Protect against breaches |
| Accountability | Demonstrate compliance |
Legal Bases for Processing
| Legal Basis | When to Use |
|---|---|
| Contract | Booking management, payments |
| Legitimate interest | Marketing to existing customers |
| Consent | Newsletter signup, third-party sharing |
| Legal obligation | Financial records, licensing requirements |
Data You Collect
Typical Guest Data
| Data Type | Purpose | Retention Period |
|---|---|---|
| Name, address | Booking, contact | 6 years (accounting) |
| Email, phone | Communication | Until unsubscribe + 2 years |
| Payment details | Processing transactions | Tokenised only |
| Vehicle registration | Site security | Duration of stay + 30 days |
| ID/passport | Legal requirement (some cases) | Duration of stay only |
Special Category Data
Extra protection required for:
- Health information (accessibility needs)
- Dietary requirements (allergies)
- Religious observance (facilities)
Privacy Notice Requirements
What to Include
Your privacy notice must explain:
- Who you are (data controller details)
- What data you collect and why
- Legal basis for processing
- Who you share data with
- How long you keep data
- Guest rights and how to exercise them
- How to complain
Where to Display
| Location | Format |
|---|---|
| Website footer | Link to full policy |
| Booking confirmation | Summary + link |
| Reception desk | Printed notice |
| Booking form | Checkbox acknowledgement |
Pro Tip: Regularly review and update your privacy policy, especially as your services or data processing activities evolve, to ensure it remains accurate and compliant.
Consent Management
Valid Consent Requirements
Consent must be:
- Freely given (not bundled with T&Cs)
- Specific (clear what they agree to)
- Informed (understand consequences)
- Unambiguous (positive opt-in)
- Withdrawable (easy to unsubscribe)
Pre-Ticked Boxes
Never use pre-ticked consent boxes:
- Marketing communications: Opt-in required
- Third-party sharing: Explicit consent
- Cookies (non-essential): Active consent
Subject Access Requests
Responding to SARs
When guests request their data:
Response Time
Respond within 1 month (extendable to 3 in complex cases).
Format
Deliver electronically if requested electronically.
Cost
Free of charge (unless the request is manifestly unfounded or excessive).
Verification
Confirm identity before releasing any data.
What to Provide
- All personal data you hold
- Processing purposes
- Recipients of data
- Retention periods
- Source of data (if not from them)
Data Breach Procedures
Breach Response Timeline
| Action | Deadline |
|---|---|
| Identify breach | Immediate |
| Assess severity | Within hours |
| Notify ICO (if high risk) | 72 hours |
| Notify affected individuals | Without undue delay |
| Document breach | Ongoing |
Breach Documentation
Record for every breach:
- Nature of breach
- Categories of data affected
- Number of individuals
- Likely consequences
- Measures taken
Third-Party Processors
Common Processors
| Processor | Data Shared | Agreement Required |
|---|---|---|
| Booking systems | Guest details | Data Processing Agreement |
| Payment providers | Card details | PCI DSS compliance |
| Email marketing | Email addresses | DPA required |
| Cloud storage | All uploaded data | DPA required |
Data Processing Agreement Essentials
Every processor agreement must include:
- Processing only on your instructions
- Staff confidentiality obligations
- Security measures
- Sub-processor restrictions
- Assistance with rights requests
- Data return/deletion at end
Marketing Compliance
Direct Marketing Rules
| Channel | Consent Required? |
|---|---|
| Email to existing customers | Soft opt-in acceptable |
| Email to new contacts | Explicit consent |
| SMS/text | Explicit consent |
| Post | Legitimate interest (with opt-out) |
| Phone | Check TPS, offer opt-out |
Did You Know? The "soft opt-in" for email marketing to existing customers is a specific carve-out under PECR (Privacy and Electronic Communications Regulations), which works alongside GDPR.
Soft Opt-In Conditions
Can email existing customers if:
- Obtained details during sale/negotiation
- Marketing similar products/services
- Given opportunity to opt-out at collection
- Every message includes unsubscribe
Staff Training
Training Requirements
| Topic | Frequency |
|---|---|
| GDPR awareness | Induction + annual |
| Data handling | Induction |
| Breach recognition | Annual |
| Rights requests | As needed |
Documentation Requirements
Records to Maintain
| Document | Purpose |
|---|---|
| Privacy policy | Public transparency |
| Records of processing | Accountability |
| Consent records | Evidence of valid consent |
| Data retention schedule | Storage limitation |
| Breach log | Compliance demonstration |
| Training records | Staff accountability |
---
Ready to simplify your GDPR compliance?
Manage guest data securely, automate retention policies, and maintain compliance documentation with PayCamp's GDPR-compliant platform.
- Automate data retention based on your policies.
- Securely manage guest consent preferences.
- Simplify responses to Subject Access Requests.
2
Valid
1
Expiring
2
Expired
| Asset | Status |
|---|---|
| Narrowboat Rosie | Valid |
| Cruiser Blue Heron | Expiring |
| Barge Kingfisher | Expired |
| Plot 14 – Static | Valid |
| Plot 7 – Lodge | Expired |
Found this helpful?
Share it with fellow site operators
Explore Our Campsite Demo
See how holiday parks and campsites manage bookings, pitches, and guests effortlessly.