Customer rights

The main customer rights related risks in the hotel industry concern customer data privacy and accessibility for customers with disabilities.

Data privacy

Due to fast progress in digitalization and a strong increase in online bookings, hotels collect vast quantities of (confidential) customer data, including personal details, copies of passports and credit card numbers. These data increasingly stand in the focus of cybercriminals, seeking to steal or access data for various reasons, such as financial goals or to attack the reputation of a company. Hotels must ensure that customer data is stored safely and according to international guidelines, and inform their customers in the case of a data breach.


Accessibility for all customers is another main issue for hotels. Those most effected are people with disabilities or elderly people, for whom correct information about handicapped accessible infrastructure is a prerequisite for travel planning. Accessible hotel infrastructure may include barrier-free rooms, restrooms, and restaurants, as well as the availability of parking spaces for wheelchair users, specific markings for people with visual impairments or sign language for people with hearing impairments.

Customer safety

Furthermore, a lack of security or hygiene standards can lead to serious (mostly health-related) risks for customers, such as food poisoning or accidents. Tour operators should make sure that contracted hotels comply with hygiene and security standards and regularly assess the situation on-site.

Growing number of data breaches and malware attacks in the hotel industry

Various media report a growing number of data breaches in the hotel industry. In recent years, major hotel companies such as the Hilton, Hyatt, and most recently Marriott, have been victims of attacks with credit card targeting malware, exposing customer’s credit card details.

The Americans with Disabilities Act (ADA) came into force in 1990 and requires any place of public accommodation to provide “full and equal enjoyment of [its] goods, services, privileges, advantages or accommodations” to people with disabilities. 

Whereas 25 years ago, the implementation of the act mostly focused on the building of accessible facilities, today the focus lies on the digital space. Hotels and other businesses should have websites which are accessible for people with disabilities.

The article linked below highlights the most important issues to keep in mind to improve the accessibility of a business’ website:

  • Perceivable: The website should contain alternatives to any non-text content (i.e., large text, braille, sign language, etc.).
  • Operable: The website should be compatible with a user’s method for browsing a website. Examples include making sure your site can be operated with a keyboard, allowing users to pause certain sections if they need more time or ensuring pages are clearly labelled so that users can keep track of where they are on the website.
  • Understandable: The website’s language should be logical and functional.
  • Robust: The website should be compatible with a wide range of assistive technologies, such as alternative keyboards, text-to-speech software and screen magnifiers.
Taking action 300x190

Take action

Policy and process

  • Integrate accessibility and data privacy provisions in Supplier Code of Conduct to be signed by hotels.
  • Develop an effective data rights management strategy to ensure compliance with the General Data Protection Regulation (GDPR, EU) which came into force on 25th May 2018.

Supplier assessment

  • Work with hotels that are certified by a third-party provider for their accessibility.

Training and capacity building

  • Train sales staff on accessibility and data privacy (e.g. on GDPR compliance).

Sector collaboration

  • Get engaged in sector initiatives that aim to improve accessibility in tourism (e.g. Barrierefreie Schweiz in Switzerland).

Communication and reporting

  • Provide transparent and easily information to customers on the accessibility of the hotels offered. Consider the needs of various forms of disabilities (e.g. visually impaired, deaf, impaired mobility, wheelchair etc.).
  • Communicate transparently to customers how their personal data is used and with whom it is shared.

Responsible product development

  • Develop products that specifically take into account the needs of people with disabilities (including accessible hotels).

Find more information on potential measures to take on the "take action" site. 

Learn more

Find more information in the Resource Centre.