Running a holiday let or B&B feels like a hospitality business. In cybersecurity terms, you’re actually running a small data processing operation — collecting personal data from guests, taking payments, managing booking platform accounts, and providing internet access to strangers. Each of those activities comes with risks that most accommodation owners haven’t seriously considered.
This isn’t about being paranoid. It’s about knowing which specific problems you’re actually exposed to, so you can deal with the real ones and not spend energy worrying about the imaginary ones.
You’re probably a data controller — whether you know it or not
If you collect guest names, email addresses, phone numbers, or payment details, you are handling personal data under UK GDPR. That makes you a data controller, which means you have obligations under the ICO’s requirements.
The practical trigger for most holiday let owners is ICO registration. If you’re processing personal data for commercial purposes, you almost certainly need to pay the ICO’s data protection fee — £40 per year for micro-businesses. It’s not a huge sum, but plenty of small accommodation providers don’t know they need to register. The ICO’s enforcement approach has broadened to include smaller businesses, and “I didn’t know” isn’t a defence.
Beyond registration, UK GDPR requires that you don’t keep guest data longer than necessary, that you have a lawful basis for processing it (legitimate interest or contract usually covers booking data), and that you can respond to a subject access request if a guest asks what you hold about them.
The Wi-Fi problem most hosts ignore
Providing guest Wi-Fi means you’re operating what’s essentially a small internet service provider within your property. Whatever your guests do on that connection could create problems — particularly if you’re running an unrestricted flat network with no isolation.
The minimum you should be doing is separating your networks. Your personal devices, your booking system laptop, and your smart property devices should never be on the same network as guest Wi-Fi. A guest network isolated from your internal network (most modern routers support this as a standard feature) means that if a guest’s device is compromised, or if a guest tries to do something they shouldn’t, it doesn’t touch your own systems.
Router security matters too. Change the default admin credentials — your router came with a username of “admin” and a password of “admin” or something similar, and that combination is publicly known. Enable WPA3 if your router supports it. Keep the firmware updated. These aren’t technical steps that require expertise; they take about fifteen minutes once you know they’re needed.
Booking platform account security
Your Airbnb, Booking.com, or VRBO account is genuinely attractive to fraudsters. There’s a well-documented fraud pattern where criminals compromise host accounts and redirect guest payments, or change payout bank details so deposits flow to them instead of you. Accounts that have been taken over have also been used to scam guests out of deposits for properties they’ll never be able to access.
Enable two-factor authentication on every booking platform account you use. This is non-negotiable. Set it up now if you haven’t. Some platforms make 2FA optional — treat it as mandatory. Check your notification settings so you’re alerted to any login from a new device or location.
Clone listing scams are worth knowing about too. Fraudsters copy your listing and post it on other platforms at a lower price, taking deposits from guests who end up with nothing and often directing their complaints to you. Monitoring for your property address appearing on platforms you haven’t listed with is worth doing periodically.
Direct payments and card security
If you take direct bookings with card payment via your own website, you’re in scope for PCI DSS — the Payment Card Industry Data Security Standard. The short version: don’t store card details yourself, use a reputable payment processor (Stripe, Square, or SagePay are common choices for small accommodation providers), and never let guests email card numbers to you.
Bank transfer fraud is the more common risk for holiday lets. Guests may receive emails that appear to be from you but with different bank account details, particularly if your email account has been compromised. Always confirm bank details by phone if a guest queries them. Be alert to any last-minute changes to payment instructions — these are a red flag regardless of how convincing the email looks.
If something goes wrong
If personal data is breached — your laptop with guest records is stolen, for example, or your booking account is compromised and you lose access to guest details — you need to assess whether to report it to the ICO within 72 hours. The threshold for mandatory reporting is whether the breach is likely to result in a risk to individuals’ rights and freedoms.
A stolen laptop with guest names and phone numbers might not meet that threshold, depending on what else was on it. A breach involving payment card data, passport copies collected for security deposits, or medical information provided by guests (accessibility needs, for instance) is much more likely to require reporting. Document what happened either way.
The ICO’s primary interest is in organisations that have proper processes and respond appropriately when things go wrong — not in those with perfect security records.
Three things to do this week
Enable 2FA on all booking platform accounts. Separate your guest Wi-Fi network from your personal and business devices. Check whether you need to register with the ICO (the ICO’s website has a self-assessment tool). Those three steps cover the most common and most damaging risks for accommodation providers. Everything else is useful incremental improvement from there.