app.paycamp.co.uk/dashboard/compliance — Harbourside Marina
    Harbourside Marina
    All Current
    Compliant

    68

    Expiring Soon

    4

    Documents

    142

    Overdue

    0

    BSS Certificate — Kingfisher
    Dec 2026
    Insurance — Blue Heron
    Sep 2026
    Safety Inspection — Pontoon B
    Apr 2026
    Fire Extinguisher Check
    Nov 2026
    Compliance

    GDPR Guide for Caravan and Holiday Park Operators

    Stay compliant with data protection regulations when handling guest information.

    By Mary Lowry-Martin

    Co-Founder, PayCamp

    December 29, 2025 · Updated June 14, 2026
    8 min read
    🛡️
    1

    GDPR for Holiday Parks: Your Comprehensive Compliance Guide

    Navigate the essentials of data protection to keep your park compliant and your guests' information secure.

    2

    GDPR Compliance Guide for Site Operators

    Data protection is not optional. Since GDPR came into force, outdoor accommodation operators must handle guest data responsibly or face fines up to £17.5 million or 4% of turnover. Here is your complete compliance guide.

    Key Takeaways

    Understand Your Obligations

    Familiarise yourself with GDPR principles and legal bases for processing data to avoid common pitfalls.

    Protect Guest Data

    Implement robust measures for collecting, storing, and retaining guest information, including special categories.

    Ensure Transparency

    Maintain clear privacy notices and manage consent effectively to build trust with your guests.

    Prepare for Incidents

    Establish clear procedures for subject access requests and data breaches to respond efficiently and compliantly.

    Understanding Your Obligations

    Key GDPR Principles

    Principle What It Means for You
    Lawfulness Valid legal basis for processing
    Purpose limitation Only use data for stated purposes
    Data minimisation Collect only what you need
    Accuracy Keep records up to date
    Storage limitation Delete when no longer needed
    Security Protect against breaches
    Accountability Demonstrate compliance

    Legal Bases for Processing

    Legal Basis When to Use
    Contract Booking management, payments
    Legitimate interest Marketing to existing customers
    Consent Newsletter signup, third-party sharing
    Legal obligation Financial records, licensing requirements

    Data You Collect

    Typical Guest Data

    Data Type Purpose Retention Period
    Name, address Booking, contact 6 years (accounting)
    Email, phone Communication Until unsubscribe + 2 years
    Payment details Processing transactions Tokenised only
    Vehicle registration Site security Duration of stay + 30 days
    ID/passport Legal requirement (some cases) Duration of stay only

    Special Category Data

    Extra protection required for:

    • Health information (accessibility needs)
    • Dietary requirements (allergies)
    • Religious observance (facilities)

    Privacy Notice Requirements

    What to Include

    Your privacy notice must explain:

    • Who you are (data controller details)
    • What data you collect and why
    • Legal basis for processing
    • Who you share data with
    • How long you keep data
    • Guest rights and how to exercise them
    • How to complain

    Where to Display

    Location Format
    Website footer Link to full policy
    Booking confirmation Summary + link
    Reception desk Printed notice
    Booking form Checkbox acknowledgement
    💡

    Pro Tip: Regularly review and update your privacy policy, especially as your services or data processing activities evolve, to ensure it remains accurate and compliant.

    Valid Consent Requirements

    Consent must be:

    • Freely given (not bundled with T&Cs)
    • Specific (clear what they agree to)
    • Informed (understand consequences)
    • Unambiguous (positive opt-in)
    • Withdrawable (easy to unsubscribe)

    Pre-Ticked Boxes

    Never use pre-ticked consent boxes:

    • Marketing communications: Opt-in required
    • Third-party sharing: Explicit consent
    • Cookies (non-essential): Active consent

    Subject Access Requests

    Responding to SARs

    When guests request their data:

    1

    Response Time

    Respond within 1 month (extendable to 3 in complex cases).

    2

    Format

    Deliver electronically if requested electronically.

    3

    Cost

    Free of charge (unless the request is manifestly unfounded or excessive).

    4

    Verification

    Confirm identity before releasing any data.

    What to Provide

    • All personal data you hold
    • Processing purposes
    • Recipients of data
    • Retention periods
    • Source of data (if not from them)

    Data Breach Procedures

    Breach Response Timeline

    Action Deadline
    Identify breach Immediate
    Assess severity Within hours
    Notify ICO (if high risk) 72 hours
    Notify affected individuals Without undue delay
    Document breach Ongoing

    Breach Documentation

    Record for every breach:

    • Nature of breach
    • Categories of data affected
    • Number of individuals
    • Likely consequences
    • Measures taken

    Third-Party Processors

    Common Processors

    Processor Data Shared Agreement Required
    Booking systems Guest details Data Processing Agreement
    Payment providers Card details PCI DSS compliance
    Email marketing Email addresses DPA required
    Cloud storage All uploaded data DPA required

    Data Processing Agreement Essentials

    Every processor agreement must include:

    • Processing only on your instructions
    • Staff confidentiality obligations
    • Security measures
    • Sub-processor restrictions
    • Assistance with rights requests
    • Data return/deletion at end

    Marketing Compliance

    Direct Marketing Rules

    Channel Consent Required?
    Email to existing customers Soft opt-in acceptable
    Email to new contacts Explicit consent
    SMS/text Explicit consent
    Post Legitimate interest (with opt-out)
    Phone Check TPS, offer opt-out
    🤔

    Did You Know? The "soft opt-in" for email marketing to existing customers is a specific carve-out under PECR (Privacy and Electronic Communications Regulations), which works alongside GDPR.

    Soft Opt-In Conditions

    Can email existing customers if:

    • Obtained details during sale/negotiation
    • Marketing similar products/services
    • Given opportunity to opt-out at collection
    • Every message includes unsubscribe

    Staff Training

    Training Requirements

    Topic Frequency
    GDPR awareness Induction + annual
    Data handling Induction
    Breach recognition Annual
    Rights requests As needed

    Documentation Requirements

    Records to Maintain

    Document Purpose
    Privacy policy Public transparency
    Records of processing Accountability
    Consent records Evidence of valid consent
    Data retention schedule Storage limitation
    Breach log Compliance demonstration
    Training records Staff accountability

    ---

    Ready to simplify your GDPR compliance?

    Manage guest data securely, automate retention policies, and maintain compliance documentation with PayCamp's GDPR-compliant platform.

    • Automate data retention based on your policies.
    • Securely manage guest consent preferences.
    • Simplify responses to Subject Access Requests.
    Compliance — PayCampTry it

    2

    Valid

    1

    Expiring

    2

    Expired

    AssetStatus
    Narrowboat RosieValid
    Cruiser Blue HeronExpiring
    Barge KingfisherExpired
    Plot 14 – StaticValid
    Plot 7 – LodgeExpired
    Example: Compliance dashboard in PayCamp
    GDPR
    data protection
    legal

    Found this helpful?

    Share it with fellow site operators

    Explore Our Campsite Demo

    See how holiday parks and campsites manage bookings, pitches, and guests effortlessly.

    Ready to See It in Action?

    Take the 2-minute guided tour or start your free 14-day trial — no credit card required.