Seville: A system that obliges hotels, online platforms and car-rental firms to harvest the personal details of their customers and feed them into a central government register has put Spain on the wrong side of the European Union’s data-protection rules. In its June infringements package the Commission opened a procedure against Madrid, sending a letter of formal notice over what it considers an excessive collection of personal data under the directive that governs how law-enforcement authorities may process information.
The directive at issue is the less famous sibling of the bloc’s general data-protection regime, written specifically for the police and judicial sphere. It permits authorities to process personal data for fighting crime, but it insists that what is gathered be necessary and proportionate to that aim rather than swept up indiscriminately. The Commission’s objection is that the Spanish scheme fails that test, requiring accommodation providers, platforms and rental companies to collect, retain and transmit a sweep of traveller data that, in its assessment, goes well beyond what tackling crime can justify.
The breadth of the datasets is what draws the Commission’s eye. The obligation extends to a wide variety of categories, including payment information and even GPS data, the kind of granular detail that can reconstruct not just who a traveller is but where they went and how they paid along the way. A register that aggregates that material across millions of journeys becomes a powerful surveillance resource, and the principle the directive defends is that such power must be matched by a demonstrable and bounded need rather than collected because the technology makes it easy.
A letter of formal notice is the opening move in an infringement procedure, an invitation to the government to explain itself before the dispute escalates. Spain now has a window to respond, to justify the scheme on security grounds or to narrow the categories of data it demands. Many infringement cases end at this stage, with the member state quietly adjusting its rules to meet the Commission’s concerns, and the formal notice is as much a prompt to negotiate as a threat to litigate.
The case sits within a larger European argument about the limits of data collection in the name of security. Governments across the bloc have reached for ever-wider registers of travel, payment and movement data, arguing that modern policing requires modern visibility, while data-protection authorities and civil-liberties groups counter that proportionality is not a technicality to be waved aside whenever a security rationale is invoked. The traveller-data scheme is a clean illustration of that tension, pitting a state’s appetite for information against a directive built to keep that appetite in check.
How Spain responds will shape more than its own register. A government that trims the scheme to the data genuinely needed sets a marker for how far the directive’s proportionality requirement bites in practice. One that defends the system in full invites a confrontation that could eventually reach the Court of Justice and clarify, for every member state building similar databases, exactly where the line between legitimate security and excessive surveillance is drawn. For now the notice has been served, and the burden rests with Madrid to show that its hunger for traveller data can be squared with the rights the directive protects.




