The European Commission has initiated formal infringement proceedings against Spain for the traveler registration system regulated in Royal Decree 933/2021, considering that the regulation could violate EU data protection legislation. The decision, communicated on June 4th through a letter of formal notice to the Spanish Government, represents significant support for the criticisms that various sectors of the tourism industry have been making for years.
Both the Spanish Confederation of Hotels and Tourist Accommodation (CEHAT) and the Business Federation of Territorial Associations of Spanish Travel Agencies (FETAVE), currently in the process of integrating with UNAV, have welcomed Brussels' action, understanding that it confirms the warnings they have been conveying about a regulation they consider disproportionate, difficult to apply, and contrary to fundamental principles of European Union Law.
The file, registered under case INFR(2026)4005, questions central aspects of the Spanish system for collecting and processing traveler information, which affects accommodation establishments, vehicle rental companies, travel agencies, and tourist intermediation platforms.
A controversy that has been ongoing since 2022
Since its approval, Royal Decree 933/2021 has faced strong opposition from the affected sectors. CEHAT maintains that the rule was designed without considering the actual operations of tourist accommodations and has generated an excessive administrative burden for companies, in addition to obliging them to store large volumes of sensitive customer information.
The hotel employers' association warns that the system requires storing data related to payment methods, financial transactions, and other personal information that significantly increases cybersecurity risks for companies.
For its part, FETAVE recalls that it was the only sectoral organization in Spanish tourism to file a formal complaint with the European Commission in January 2023, denouncing the incompatibility of the rule with EU legislation. Since then, the federation has maintained intense activity with European institutions to defend its position, including actions before the European Commission, the European Parliament, and the European Ombudsman.
Brussels questions the proportionality of the system
According to business organizations, the arguments now put forward by the European Commission substantially coincide with the objections that the sector has been raising in recent years.
Brussels considers that the Spanish model requires the collection of excessive categories of data, including payment information and certain location data, that the authorities' access to such information is not sufficiently limited to specific purposes and that the generalized retention of data for three years may be disproportionate.
The Commission also focuses on the European principle of data minimization, one of the pillars of EU data protection legislation, which requires that only information strictly necessary for the intended purpose be collected.
For CEHAT, these conclusions confirm that the Royal Decree presented serious structural deficiencies from its origin. For FETAVE, they validate the essential core of the complaint filed with Brussels more than three years ago.
The precedent of the Court of Justice of the European Union
The legal discussion on Royal Decree 933/2021 is also framed within a consolidated jurisprudential line of the Court of Justice of the European Union (CJEU), especially in relation to the transfer of passenger data in the field of air transport.
The rulings of the European court have established that the massive collection of personal information for security reasons must be limited to specific, justified, and proportionate cases, avoiding systems of generalized or indiscriminate surveillance of the population.
In the opinion of business organizations, the Spanish model departs from these criteria by requiring the systematic collection of information from millions of travelers regardless of whether or not there is a specific risk to public security.
What the letter of formal notice implies
The letter of formal notice constitutes the first formal phase of the infringement procedure provided for by the European Union when the Commission considers that a Member State may be failing to comply with Community law.
From this moment on, Spain has a period of two months to respond to the observations made by Brussels. If the Commission considers the explanations or measures adopted by the Government insufficient, it may move towards a second phase through a reasoned opinion and, subsequently, bring the case before the Court of Justice of the European Union.
Although the procedure is still in its initial phase, both CEHAT and FETAVE consider that the formal opening of the file already represents a milestone of great relevance, by placing Spanish regulations under unprecedented European legal scrutiny.
The sector calls for immediate changes
After learning of Brussels' decision, CEHAT has called for the repeal of Royal Decree 933/2021 and the opening of a dialogue table with all affected sectors to design a new system that allows effective collaboration with the State Security Forces and Corps while respecting citizens' privacy and community regulations.
In parallel, FETAVE and UNAV have requested the Ministry of the Interior to urgently suspend the application of the rule to travel agencies while the European procedure is developed. Likewise, they demand the halting of any regulatory development that maintains direct obligations for agencies and the creation of a specific working group with the sector.
Among their proposals is to review the system in accordance with the principles of proportionality, data minimization, and legal certainty, as well as to exclude travel agencies from certain obligations when they act solely as intermediaries, understanding that the required information is already collected by hotels and vehicle rental companies.
A call for dialogue
Both the hotel sector and travel agencies have wanted to emphasize that their criticisms of the regulations do not question the need to collaborate with the State Security Forces and Corps.
The business organizations agree in defending that citizen security constitutes a priority, but they maintain that the mechanisms used to achieve it must be compatible with fundamental rights, data protection, and the operational reality of tourism companies.
In this context, representatives of the sector consider that the European Commission's action opens an opportunity to rethink the current model and build a system that combines police effectiveness, legal certainty, and respect for European legislation.
"If the European Commission questions the pillars of RD 933/2021, the Ministry of the Interior must suspend its application to travel agencies and immediately review the regulation," said the president of FETAVE and UNAV, César Gutiérrez. Along similar lines, the president of CEHAT, Jorge Marichal, believes that the European investigation should serve to promote a profound reform that allows for the recovery of trust between the Administration and one of the strategic sectors of the Spanish economy.
This version has a tone more suited to a specialized economic or tourism media outlet, integrating the positions of CEHAT and FETAVE-UNAV without appearing to be the sum of two corporate press releases.