Search
Close this search box.

GDPR; travel companies must protect their most valuable asset

Data is often a travel company’s most valuable asset; without a list of existing and past customers, travel companies can’t generate repeat customer sales. With the new General Data Projection Regulation (GDPR) fast approaching, how companies acquire and manage data for clients and prospects will be the difference between success and failure.
heathrow

Data is often a travel company’s most valuable asset; without a list of existing and past customers, travel companies can’t generate repeat customer sales. With the new General Data Projection Regulation (GDPR) fast approaching, how companies acquire and manage data for clients and prospects will be the difference between success and failure. Contributor Rajeev Shaunak, Head of travel & tourism – MHA MacIntyre Hudson.

Travel businesses now have under 10 weeks to update their processes to demonstrate compliance with the new regulations. Failure to meet the 25 May deadline could result in penalties of up to €20 million or 4 percent of the company’s global annual turnover of the previous financial year, whichever is higher.

Many operators hold extensive marketing databases of personal information, collected through bookings, administration, and on and offline marketing activities. This comes direct from individuals, and via intermediaries such as travel agents and travel search websites. User profiling and online tracking tools such as cookies are also used to help better target marketing campaigns.

Travel businesses need to embrace the regulation and take the following steps to ensure they’re ready: Expand consent notices online and in brochures, explaining the option to opt out of future marketing, when data might be collected, and exactly how it could be used to meet the new requirement for ‘clear affirmative action’, and an end to pre-ticked boxes and bundled consents. Operators also need to consider how best to signpost their privacy notices.

Warn customers if data collected may be sent outside the European Economic Area (EEA), to Government Digital Service centres overseas for example, where data protection may not be as strong as within the EEA. Make customers aware of their right to demand full details of the information held on them, and unlike in the past, travel companies can no longer charge for providing this.

A company’s appointed data controller must notify privacy regulators and affected individuals in the event of certain data privacy breaches within 72 hours. Conduct a full data audit, and review data collection forms and privacy notices.

Demonstrate compliance to regulators on an ongoing basis and maintain records of data protection management. Details must include how long information is retaining for and consents held. Without consent companies may be expected to destroy information after the travel arrangements have been completed, provided there’s no contractual requirement for it.

Re-examine processes and systems used to deal with data subjects rights, including new rights in relation to erasure of data, data portability and use of profiling, along with supplier arrangements with third parties such as hoteliers and airlines. Time is ticking; if companies haven’t already begun reviewing their data processing procedures, they must start now, especially as they will soon have the challenges of the new Package Travel Directive to contend with too.

Read more

Latest News

Read More

Challenges and benefits of creating neuroinclusive workplaces

26 April 2024

Newsletter

Receive the latest HR news and strategic content

Please note, as per the GDPR Legislation, we need to ensure you are ‘Opted In’ to receive updates from ‘theHRDIRECTOR’. We will NEVER sell, rent, share or give away your data to third parties. We only use it to send information about our products and updates within the HR space To see our Privacy Policy – click here

Latest HR Jobs

The Bedford College GroupSalary £26 000 pa from depending on experience

London School of Hygiene amp Tropical Medicine 8211 DirectorateSalary £33 111 to £37 298 per annum inclusive

The purpose of the role will be to provide a comprehensive HR service for approximately 600 staff within the Trust 50 off Endeavour Children s

Working closely with the leadership team the interim Head of HR and OD will help lead the organisation through a period of change and lead

Read the latest digital issue of theHRDIRECTOR for FREE

Read the latest digital issue of theHRDIRECTOR for FREE