{"id":2705,"date":"2019-10-22T11:28:04","date_gmt":"2019-10-22T09:28:04","guid":{"rendered":"https:\/\/www.hotelinking.com\/en\/?p=2705"},"modified":"2026-03-11T09:23:24","modified_gmt":"2026-03-11T08:23:24","slug":"jorge-morell-terms-and-conditions-only-a-third-of-spanish-smes-have-properly-adapted-to-the-gdpr","status":"publish","type":"post","link":"https:\/\/www.hotelinking.com\/en\/blog\/interviews\/jorge-morell-terms-and-conditions-only-a-third-of-spanish-smes-have-properly-adapted-to-the-gdpr\/","title":{"rendered":"Jorge Morell (T\u00e9rminos y condiciones): &#8220;Only a third of spanish SME&#8217;s have properly adapted to the GDPR.&#8221;"},"content":{"rendered":"\r\n<p>He also founded <a href=\"https:\/\/legaltechies.es\/\" target=\"_blank\" rel=\"noreferrer noopener\">Legaltechies<\/a>, one of Spain\u2019s first consultancy firms specialising in the study and implementation of legal tech, which drafted the first <a href=\"https:\/\/terminosycondiciones.es\/2016\/07\/20\/legaltech-espana-mucho\/\" target=\"_blank\" rel=\"noreferrer noopener\">map on Spanish legal tech<\/a>. In 2017, he helped to organise Spain\u2019s first legal tech conference. He also created <a href=\"https:\/\/terminosycondiciones.es\/2017\/10\/12\/publicamos-jade-gestor-clientes-codigo-abierto-abogados\/\" target=\"_blank\" rel=\"noreferrer noopener\">Jade<\/a>, which was one of the first open source legal tech projects worldwide. Currently, besides participating in other forms of media and publications, he writes and collaborates in Abogac\u00eda Espa\u00f1ola\u2019s <a href=\"https:\/\/www.abogacia.es\/publicaciones\/blogs\/blog-de-innovacion-legal\/\" target=\"_blank\" rel=\"noreferrer noopener\" data-type=\"URL\" data-id=\"https:\/\/www.abogacia.es\/publicaciones\/blogs\/blog-de-innovacion-legal\/\">blog on legal innovation<\/a>.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\"><strong>What has the implementation of GDPR been like in the hotel industry? How does this compare to its general implementation?<\/strong><\/h2>\r\n\r\n\r\n\r\n<p>In general, <a href=\"https:\/\/www.pymesyautonomos.com\/legalidad\/dos-cada-tres-empresas-no-cumplen-rgpd\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>only one third<\/strong><\/a><strong> of Spanish SMEs have properly adapted<\/strong> to the new <a href=\"https:\/\/www.hotelinking.com\/docs\/whitepaperRGPD-en.pdf\" target=\"_blank\" rel=\"noreferrer noopener\" data-type=\"URL\" data-id=\"https:\/\/www.hotelinking.com\/docs\/whitepaperRGPD-en.pdf\">GDPR<\/a> regulations. In fact, <strong>only <\/strong><a href=\"https:\/\/www.eleconomista.es\/legislacion\/noticias\/10055808\/08\/19\/Solo-el-14-de-las-paginas-que-visitan-los-espanoles-ha-adaptado-sus-cookies-al-RGPD.html\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>14% of the websites<\/strong><\/a><strong> visited by Spanish browsers comply with regulations on cookies<\/strong> found in the new General Data Protection Regulation laws.<br \/><br \/>We don\u2019t have specific data for the hotel industry, but it would make sense for it to have similar numbers.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\"><strong>What has been the main change as a result of GDPR?<\/strong><\/h2>\r\n\r\n\r\n\r\n<p>Undoubtedly, the main change entailed by the <a href=\"https:\/\/www.hotelinking.com\/en\/updates\/what-is-gdpr-know-all-about-the-general-data-protection-regulation\/\" target=\"_blank\" rel=\"noreferrer noopener\" data-type=\"URL\" data-id=\"https:\/\/www.hotelinking.com\/en\/updates\/what-is-gdpr-know-all-about-the-general-data-protection-regulation\/\">General Data Protection Regulation<\/a> is that t<strong>he data manager, besides adhering to the law, needs to also demonstrate that he\/she adheres to it.<\/strong> Besides this, there are also other changes such as the disappearance of tacit consent, the emergence of a data protection delegate and the ways of managing security breaches, amongst others.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\"><strong>Do you think the information of users\/clients have been used responsibly?<\/strong><\/h2>\r\n\r\n\r\n\r\n<p>In general yes, but <strong>some services that are highly specialised in the management of personal data,<\/strong> such as Facebook, <strong>have been massively exploiting these data<\/strong> in a way that benefits their business model and harms their users.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\"><strong>Are hotel establishments up-to-date with regards to the latest data protection regulations?<\/strong><\/h2>\r\n\r\n\r\n\r\n<p>Most of them are, yes. They are making efforts to properly adapt to the new regulations, at least. In any case, <strong>there is still lots of room for improvement in certain areas<\/strong> (e.g. managing cookies or sending commercial communications).<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\"><strong>In which ways does a hotel need to adapt to the GDPR? What is the first thing that an accommodation establishment needs to do?<\/strong><\/h2>\r\n\r\n\r\n\r\n<p>The first thing that a hotel needs to consider is where they get their personal data from. For example, they may gather their information from their guests, social media platforms, websites or news bulletins.<\/p>\r\n\r\n\r\n\r\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\r\n<p>Once they are sure of the origin and type of the personal data that they collect, it will be much easier to start adapting to the corresponding regulations<\/p>\r\n<\/blockquote>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\"><strong>Do you have any recommendations for hotel owners with regards to data protection?<\/strong><\/h2>\r\n\r\n\r\n\r\n<p><strong>They should take note of their guests\u2019 country of origin;<\/strong> many of the guests at the hotel won\u2019t be Spanish citizens, in which case the hotel will need to translate the data protection information into languages other than Spanish. <strong>The hotel must therefore be clear and transparent about its use of personal information<\/strong> in as many languages as required by its guests.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\"><strong>What are the legal sanctions for non-compliance with these regulations?<\/strong><\/h2>\r\n\r\n\r\n\r\n<p>One of the biggest changes introduced by the General Data Protection Regulation relates to economic sanctions, which now reach <strong>20 million euros or 4% of the company\u2019s annual turnover,<\/strong> depending on the case and severity of the sanction. <br \/><br \/>In any case, warnings are now issued when the data manager breaches the regulations for the first time. This isn\u2019t serious a serious offence, with appropriate measures duly applied to rectify the situation. When they receive a warning, the hotel has to address the non-compliance but is not faced with economic sanctions.<br \/><br \/>In order for this warning to be invoked, please note that the hotel must have made the required effort to properly adapt to the regulation, at the very least.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\"><strong>How can a hotel guarantee the security of its guests\u2019 data?<\/strong><\/h2>\r\n\r\n\r\n\r\n<p>They could <strong>adopt the security measures recommended by data protection agencies,<\/strong> for example. These measures may include anonymising or encoding the data bases that they have created. In other words, this means that the personal information will be stored in a \u201ccage\u201d that can only be accessed by the hotel.<\/p>\r\n\r\n\r\n\r\n<h2 class=\"wp-block-heading\">In the era of digitalisation in which we are currently living, can data management be intelligent and ethical at the same time?<\/h2>\r\n\r\n\r\n\r\n<p>Indeed it is possible, and this should be the way forward. However, this is far from easy and requires aligning regulatory compliance with the company\u2019s business plan. In order to do this, <strong>it would be hugely useful to have a broad knowledge of the applicable regulations and the business sector in which the company operates. <\/strong><\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>Jorge Morell Ramos is the founder of the consultancy firm on technological law and legal tech, T\u00e9rminos y Condiciones. He has been providing legal services regarding technological law for the last 10 years, in both the public and private sectors. <\/p>\n","protected":false},"author":13,"featured_media":12132,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[48],"tags":[9,11,12],"class_list":["post-2705","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-interviews","tag-data-protection","tag-database","tag-gdpr"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.hotelinking.com\/en\/wp-json\/wp\/v2\/posts\/2705","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hotelinking.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hotelinking.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hotelinking.com\/en\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hotelinking.com\/en\/wp-json\/wp\/v2\/comments?post=2705"}],"version-history":[{"count":4,"href":"https:\/\/www.hotelinking.com\/en\/wp-json\/wp\/v2\/posts\/2705\/revisions"}],"predecessor-version":[{"id":14744,"href":"https:\/\/www.hotelinking.com\/en\/wp-json\/wp\/v2\/posts\/2705\/revisions\/14744"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hotelinking.com\/en\/wp-json\/wp\/v2\/media\/12132"}],"wp:attachment":[{"href":"https:\/\/www.hotelinking.com\/en\/wp-json\/wp\/v2\/media?parent=2705"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hotelinking.com\/en\/wp-json\/wp\/v2\/categories?post=2705"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hotelinking.com\/en\/wp-json\/wp\/v2\/tags?post=2705"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}