Become an expert hotel marketer with our free resources.
On May 25, 2018, the General Data Protection Regulation (GDPR) governing all European Union member countries come into effect. These new data privacy laws apply not just to businesses within the EU, but to any companies that process or handle private data of EU residents, regardless of the business location.
Steps Pegasus has taken to become GDPR compliant:
- Changed systems, contracts, privacy policies, and processes to comply with GDPR
- Trained employees on details and obligations of the regulations
- Built communication channels to inform clients of all GDPR updates and recommendations
- Rewrote our data protection agreement and privacy policies to comply with GDPR
GDPR Customer FAQ
Does my hotel need to be GDPR compliant?
Under GDPR, hotels that collect and manage private data (including, but not limited to, names, email addresses, credit card numbers, and IP addresses) from EU-based guests are defined as “Data Controllers” and subject to these regulations. As your CRS or website provider, Pegasus is defined as a “Data Processor” and is also subject to the regulations.
What steps should I take to become GDPR compliant?
We recommend that all hotels consider the following actions as part of their data protection efforts. Please note that the list is not exhaustive and that Pegasus cannot provide any legal advice on what specific actions are required of your hotel or organization to become GDPR compliant.
- Consult with your legal counsel to determine the extent of applicability of GDPR to your business. Larger organizations may require the appointment of a data protection officer to oversee compliance regulations.
- If you are a Pegasus customer, review and agree to Data Processing Addendum as part of the Master Services Agreement. This addendum names Pegasus as a data processor and is required for GDPR compliance.
- If you are using Pegasus products or services, please review the documentation on what changes will be made to our platforms and processes in order to be GDPR compliant. If you have not yet received documentation, please reach out to us at firstname.lastname@example.org for more information.