Regulatory guide
SES Hospedajes: what Spain's guest registration law still requires in 2026, what it fines, and what Brussels is challenging
Spain's guest registration (SES Hospedajes) is still mandatory in 2026: data fields, 24-hour deadlines, fines up to 30,000 EUR and the status of case INFR(2026)4005.
If you operate hotels, short-term rentals, flex living or student housing in Spain, three overlapping stories are muddying your compliance picture in 2026: the Supreme Court ruling that annulled the NRUA rental registry in May, the infringement case Brussels opened against Spain in June over the traveller registration decree, and headlines that blend both into one. The practical fallout is visible every week: operators who stopped filing guest reports because they believe the duty fell with the NRUA, and operators who keep photocopying passports believing that counts as compliance. Both are wrong, and each mistake carries a different fine.
This guide separates the layers and works as a tracker for the international operator: what SES Hospedajes requires today, what non-compliance costs, what exactly case INFR(2026)4005 challenges, and which milestones come next. We will update it as the case moves.
What SES Hospedajes is and who must report in 2026
SES Hospedajes is the Spanish Interior Ministry's platform through which accommodation businesses file guest identity data, known in Spain as the parte de viajeros (the mandatory report of each guest's identity to law enforcement). The duty comes from Royal Decree 933/2021 and, after two extensions, has been fully enforceable through the electronic channel since 2 December 2024.
The short answer to the most repeated question: yes, guest registration is still mandatory in 2026. Neither the Supreme Court's NRUA ruling nor the Brussels case has suspended it. What the Court annulled on 21 May 2026 (judgment 620/2026) was the single rental registry, a different rule with a different purpose, which we map in the guide to Spain's seasonal rental rules after the ruling. And what Brussels opened is a procedure against the decree's design, not a suspension of its force. Until Spain repeals or amends the decree, the duty stands and so do the fines.
The obligation reaches anyone running accommodation as a business: hotels, hostels, tourist apartments and holiday lets, campsites, and operators of flex living or student residences whenever their model qualifies as lodging rather than a pure residential lease. The lodging-versus-lease boundary has nuances covered in the seasonal rental guide; the prudent operating rule for a professional operator with turnover of guests is to assume the duty applies and build the flow so compliance is frictionless.
What data you must file, by when, and how long you keep it
RD 933/2021 imposes three separate duties that are easy to conflate:
Report. Data goes to SES Hospedajes within a maximum of 24 hours, and the decree sets two triggers: formalising the booking or contract, and the start of the stay. For an operator with continuous check-ins this means wiring the report into the check-in flow itself, not batching it for an administrator at the end of the week.
Keep a register. Beyond reporting, you must maintain an internal documentary register of those operations and keep it for three years. Inspectors can demand it even if your reports are up to date.
Collect only what is required. The decree's annex lists more than 40 possible fields across operator, guest and transaction data: full name, ID document, nationality, date of birth, address, phone and email, family relationship when minors travel, and operation data that includes the means of payment. That last block, payment data, is precisely one of the elements Brussels considers disproportionate. Keep it in mind when designing forms: collecting more than required does not make you more compliant, it exposes you on the other flank, data protection.
SES Hospedajes does not cover all of Spain: Catalonia and the Basque Country run their own systems
A frequent error in multi-city portfolios: onboarding every asset onto SES Hospedajes and assuming the map is complete. It is not. In Catalonia guest reports go to the Mossos d'Esquadra (the regional police) and in the Basque Country to the Ertzaintza, each through its own channel. The underlying duty is the same; the destination and platform change. A portfolio with assets in Barcelona and Madrid needs two distinct reporting flows, and your operations software has to support both.
Photocopying guest IDs: the Spanish DPA says no
The sector's most widespread habit is also its most sanctionable. The AEPD, Spain's data protection authority, settled the question in a June 2025 informative note: photocopying or scanning a guest's ID document breaches the data minimisation principle (collecting only the data necessary for the purpose, article 5.1.c GDPR). The guest report requires specific fields to be transcribed, not an image of the full document, which contains more data than the law demands.
The financial risk here outweighs the guest report itself: GDPR infringements in this category can reach 4% of global annual turnover. For a branded hotel or flex operator, the reputational cost of a DPA resolution compounds the number. The fix is not going back to paper either: capture the required fields through digital identity verification, which validates the document without retaining unnecessary copies, and feed the report from there.
The Brussels case INFR(2026)4005: tracker
This is the layer that generates the most headlines and the least understanding. Status as of 21 July 2026:
4 June 2026. The European Commission opens infringement procedure INFR(2026)4005 against Spain with a letter of formal notice (the first formal stage: Brussels sets out why it considers a national rule breaches EU law and gives the member state a deadline to reply). The target is RD 933/2021: the Commission considers that the collection, transmission and retention duties it imposes on sector businesses breach Directive (EU) 2016/680 (the EU's data protection rules for the law enforcement field), challenging both the breadth of the data demanded and how long the authorities retain it.
5 June 2026. CEHAT, the Spanish hotel association, welcomes the case, recalling that the sector had warned since 2022 that the decree was operationally unworkable and at odds with EU law.
June 2026. The Interior Ministry suspends the Ministerial Order that was to implement RD 933/2021 until the procedure is resolved. The important nuance: what is suspended is the pending implementing regulation, not the decree in force. SES Hospedajes remains live and enforceable.
Next milestones. The standard window to reply to a formal notice is two months, placing Spain's answer around August 2026. If the reply does not satisfy the Commission, the next step is a reasoned opinion (the second stage, with a new deadline before a possible referral to the EU Court of Justice). Three outcomes are plausible: Spain amends the decree and trims the required data, the Commission closes the case after commitments, or the procedure escalates. Under any of the three, the payment-data block in the annex is the clearest candidate to shrink or disappear.
What it means for you today. Comply with the rule as it stands, and design your data flow so that cutting fields later is cheap. An operator who hard-wired all 40 fields into forms and contracts will rebuild them with every change; an operator who captures identity once and maps fields by configuration will not.
Fines: what non-compliance costs
The sanctioning regime for guest registration lives in Organic Law 4/2015 on citizen security. Missing the mandatory registers or omitting the reports is a serious infringement, fined between 601 and 30,000 euros. Formal irregularities (minor errors or delays in the books and reports) are minor infringements, fined 100 to 600 euros. Inspection campaigns are real, and sector press regularly reports fines at the top of the range against unregistered holiday lets.
For an operator with volume the true cost is not one fine, it is accumulated exposure: every unreported check-in is an omission. A flex operator with 40 units and average two-month stays generates around 240 check-ins a year; a year without reporting is a pool of infringements that a single inspection can surface. Against that, the cost of complying well is one integration: the data you already collect when verifying a guest and signing the contract is a superset of what the report requires.
An operating framework: check-in that complies without adding friction
The right design question for 2026 is not "how do I fill in the report" but "how many times do I ask the guest for the same data". A well-built onboarding flow resolves all four duties with a single capture:
- Digital identity verification at booking or before arrival: validate the document, extract the fields RD 933/2021 requires, discard the image (guest report and GDPR minimisation solved in one step).
- Contract or house terms signed electronically, pre-filled with the same data, nothing re-typed.
- The report filed with SES, Mossos or Ertzaintza inside the 24-hour window, per territory, from the system rather than from someone's to-do list.
- Payment tied to the same operation, from holding deposit to full stay, reconciled automatically through account-to-account rails, the model we develop in the open banking for real estate guide.
Evaluate any vendor against that pattern: a provider that only solves step 3 is a form, not a flow. At UrbanPay we work on exactly that onboarding flow (verify identity, sign and collect in one pass) with flex living and hotel operators across Europe; if you are redesigning check-in with the EU case on the horizon, tell us your setup and we will walk through it together on a call. Operators subject to Spanish AML duties will also want the adjacent map of obligated entities in real estate.