PII (personally identifiable information) is any data that can identify a specific person, such as names, passport numbers, emails, phone numbers and payment details. Hotels handle large volumes of PII and are accountable for protecting it.
Guest data flows through many systems, PMS, booking engine, channel manager, CRM, messaging tools, and each transfer is a point of exposure. Knowing which systems hold what data, and for how long, is the foundation of both security and privacy compliance.
Practical hygiene includes limiting staff access to what each role needs, avoiding exports of guest lists to spreadsheets and personal drives, and deleting data past its retention purpose. Breaches involving identity documents are especially damaging, legally and reputationally.
← sesion.org · All categories · Advisors · Blog · Glossary