In September 2024 the Comissão Nacional de Proteção de Dados published a technical clarification on hospitality messaging that most independent hoteliers still have not properly digested. It did not change the law — the law is still the GDPR and the Portuguese implementation Lei 58/2019 — but it clarified how the CNPD reads three specific areas that matter to any property sending pre-arrival messages, WhatsApp templates or post-stay review requests. This piece walks through what actually changed, what the practical audit now looks like, and how Talk with Guest handles each requirement out of the box. Nothing here is legal advice for your specific property. Talk to your DPO. But this is what we tell every operator asking us the same question over WhatsApp on a Sunday evening.
Change one: WhatsApp templates and the boundary of transactional messaging
Before September 2024 the practical assumption in most Portuguese hotels was that any WhatsApp message related to a confirmed reservation counted as transactional and did not require explicit marketing consent. The CNPD clarification tightened the definition of "transactional". A message strictly required to fulfil the reservation — arrival instructions, room number, check-in time — is still transactional. A message that offers an ancillary service, even one closely related to the stay, requires either explicit consent captured at booking or a legitimate-interest assessment (LIA) documented in writing before the message is sent.
In practice this means the airport-transfer offer, the breakfast attach and the room-upgrade nudge — the three levers we discuss in the RevPAR article — now sit in a slightly different category from the address confirmation. You can still send them. You just need the paperwork behind them. Talkguest handles this in two ways: the booking engine captures a clear opt-in with granular categories at the moment the guest confirms the reservation, and every WhatsApp template in the message library is tagged as "transactional", "legitimate-interest" or "marketing", with a stored LIA for each legitimate-interest template.
- Every guest profile records the consent state per channel and per purpose.
- Every WhatsApp template has a stored classification and a version history.
- The consent audit view lets a DPO reconstruct why a given message was sent, three years later, in under a minute.
Change two: retention periods on messaging archives
The 2024 clarification also addressed how long a property may retain WhatsApp and email conversation archives after checkout. The previous default was three years, which most hoteliers applied to almost everything by inertia. The clarification is more nuanced. Reservation records tied to a factura remain governed by tax law and are held for ten years. Guest communication archives that are not part of the tax record now have a shorter default retention: eighteen months for transactional archives, twelve months for legitimate-interest archives, and a hard six-month cap on marketing archives unless the guest has explicitly consented to a longer retention.
This is the change most properties are technically non-compliant with today, because their inbox tool is a shared email account that never deletes anything. On Talkguest, the messaging module runs a retention scheduler that automatically deletes conversation content beyond its retention window, with the reservation metadata preserved. The archive view remains searchable within the retention window and returns a "retention expired, content deleted" placeholder outside it. This is the state the CNPD expects to see if it audits your property, and it is the state most hoteliers cannot produce today.
The audit question is never "did you follow the rules". The audit question is "can you prove, in a specific case, what data you held about a guest, why you held it, and when you deleted it." Most independents cannot answer that today. The tooling that can answer it is now table stakes.
Change three: cross-border transfers and the WhatsApp Business API
The third change is the one that caused the most anxiety among the Talkguest customer base. WhatsApp Business Solution Providers route messages through Meta infrastructure, which is now considered adequate under the EU-US Data Privacy Framework as of July 2023, but the CNPD emphasised in the 2024 clarification that Portuguese controllers must still document the transfer in their record of processing activities (ROPA), name the specific BSP, and confirm that the BSP has signed the standard contractual clauses (SCCs) as a processor.
This is administrative work but it is real. If you are a Portuguese hotel using a BSP for WhatsApp messaging today, your DPO must be able to produce a signed Data Processing Agreement with the BSP, and the ROPA entry must name the BSP explicitly. Talkguest publishes a template ROPA entry for every property on the platform in the compliance dashboard, and we hold the master DPA with our BSP on behalf of all customer properties. That means a single DPO can be up to date on this compliance requirement in under fifteen minutes per property.
What a compliant audit looks like in 2027
The CNPD publishes annual audit statistics. The 2026 report showed a 42 percent increase in hospitality-sector inspections compared to 2023, driven partly by guest complaints about post-stay marketing messages. If your property is inspected — either through a routine audit or through a subject access request that goes wrong — the inspector will want to see six specific artefacts, and Talkguest generates all six.
- The current privacy notice on your booking engine and its version history.
- The consent-capture flow at booking, with per-purpose granularity.
- The record of processing activities (ROPA) for each processing purpose.
- The Data Processing Agreements with every subprocessor, including the BSP and the PSP.
- The retention policy and evidence of automated enforcement.
- The subject-access-request response log, showing average response time under thirty days.
The subject access request workflow
A subject access request now must be answered in under thirty calendar days, and the CNPD explicitly stated in the 2024 note that a "we cannot find the data" answer is not acceptable if the controller was required to hold that data under its own retention policy. Talkguest ships a subject-access-request view: enter the guest email or reservation number, generate a machine-readable JSON export and a human-readable PDF, send it to the guest through the platform. The whole cycle runs in under ten minutes for a straightforward request and is logged in the compliance dashboard for future audit.
What operators should do this quarter
If you take one action from this article, review your consent-capture flow at booking. Most independent hotels are still using a single "I accept the privacy policy" checkbox, which is not sufficient under the 2024 clarification for anything beyond transactional messaging. You need at least three checkboxes: transactional communications required to fulfil the reservation, service-related messages including offers about your own services, and marketing communications about future stays. Wire each checkbox to a stored consent state in your platform. Talkguest does this by default, and the migration hub imports historical consent flags from every mainstream booking engine.
If you take two actions, the second one is to publish or update your privacy notice with a clear statement of retention periods per data category. The CNPD has been publishing example notices for the hospitality sector since 2022; ours is available at /legal/privacy and is available as a template on request through /contact.
If you want a full compliance walk-through against your current setup, our legal team runs a monthly compliance clinic for Talkguest customers where we look at three properties in depth. Ask for access at /get-access and mention the clinic in the notes field.
