Operations

Asking guests for reviews under GDPR, without getting it wrong

Most advice on collecting reviews was written for the United States. If you operate in the EU or the UK, the email you were told to send is a regulated one.

Justin Ciappara

Co-founder, Revify11 min read

In the EU and the UK, an email asking a guest to review you is direct marketing. It is usually lawful to send, but on a specific basis and with specific conditions attached, and the conditions are the part that most review collection advice, written for a market without these rules, simply does not mention.

The short version: you can normally email your own past guests under the soft opt-in, provided you took the address in the course of a sale, gave them a way to refuse then, and give them one in every message since. If any of those three is missing, you need consent instead.

Is a review request marketing?

There is a tempting argument that a review request is a service message about a completed stay rather than marketing, and it is not one to rely on. The message promotes the business, it is sent to build a public asset, and regulators have taken a broad view of what counts as direct marketing for years. The UK Information Commissioner’s guidance on direct marketing and the electronic communications rules is the clearest statement of that position in English, and the EU position under the ePrivacy rules is materially the same.

Assume it is marketing. The rules are not onerous once you have set them up, and the alternative is arguing the point after a complaint.

The lawful basis, in plain terms

Two separate things have to be right, and conflating them is the usual source of confusion.

  1. A lawful basis under GDPR for processing the personal data. For review requests to past guests this is normally legitimate interests, and it requires you to have actually weighed your interest against the guest’s reasonable expectations, and to have written that down.
  2. Permission to send an electronic marketing message.This comes from the ePrivacy rules, not GDPR, and it is where consent or the soft opt-in lives. A legitimate interests assessment does not get you past this second requirement.

Soft opt-in, and its limits

The soft opt-in is the provision that makes ordinary review collection workable. It applies where all of the following are true:

Soft opt-in conditions, and what each means for a hotel or restaurant
ConditionIn practice
The address was obtained in the course of a sale or negotiations for oneA booking, a stay, an enquiry that led to one. Not a competition entry, not a Wi-Fi sign-in, not a scraped list
You are marketing your own similar products or servicesYour own property. Not a sister hotel under a different brand, and not a partner
An opt out was offered when the address was collectedA clear line at booking, not buried in terms
An opt out is offered in every messageA working unsubscribe in the review request itself

Three limits are worth stating plainly. Soft opt-in covers your own guests, so a list bought or inherited is out. It covers your own property, so a group cannot email one property’s guests about another without consent. And it does not survive an opt out: once somebody has said no, the basis is gone permanently, not until the next campaign.

Six rules that keep it clean

  • Ask once. One request, one optional reminder at most. A third message is where a mild irritation becomes a complaint.
  • Put a real unsubscribe in it. One click, working, and honoured immediately rather than at the end of a cycle.
  • Keep a record of where each address came from. The question after a complaint is always “how did you get this address”, and the answer needs to be in a system rather than in somebody’s memory.
  • Set a retention period and automate it. Whatever you choose, be able to state it and show it happening.
  • Do not segment by expected sentiment. Sending the request only to guests you believe are happy is review gating, it breaches the platforms’ own policies, and it is the practice most likely to get a listing penalised.
  • Do not incentivise. Google prohibits incentivised reviews. A discount for a review risks the listing, whatever the privacy position.
A guest's hands at a hotel reception desk at checkout.
A card on the desk is a review request with no personal data attached to it at all.

The mistakes that cause complaints

In practice, complaints come from a short list, and none of them are subtle legal questions.

  • Using the booking platform’s guest address for your own marketing. Addresses provided through an OTA come with contractual limits on use, and those limits are usually narrower than the law. This is a contract problem before it is a privacy one.
  • Wi-Fi captive portal addresses. Collected for network access, not in the course of a sale. Soft opt-in does not cover them.
  • The unsubscribe that does not work. More complaints come from this than from the original message, every time.
  • Asking again next year. A guest from three years ago who has not been back is no longer somebody with a reasonable expectation of hearing from you.

The methods with no data problem at all

The best answer to most of this is to collect reviews without collecting anything. A card with a QR code at checkout, a line on the folio, a printed prompt on the table, a link in a message the guest initiated: none of these involve processing an email address for marketing, so none of them raise any of the above.

They also tend to work better, because the request arrives at the moment the guest is still in the experience rather than two days after they got home. The mechanics are in how to get more Google reviews, and the same logic applies to displaying what you collect, which is covered in displaying Google reviews on your website.

Common questions

Do you need consent to email a guest asking for a review?

Not always. In the EU and the UK a review request to an existing customer can often rely on the soft opt-in for electronic marketing, provided you collected the address during a sale or negotiation, you offered an opt out at that point, and every message since has offered one too. Where those conditions are not met, you need consent.

Is asking for a review considered direct marketing under GDPR?

Usually yes. Regulators have consistently treated messages that promote a business, including invitations to review it, as direct marketing rather than service messages. Treating it as marketing and applying the marketing rules is the safe reading.

Can you offer a discount in exchange for a review?

You can offer an incentive to leave a review, but not an incentive to leave a positive one, and the major platforms have their own rules that are stricter than the law. Google prohibits incentivised reviews outright, so the safest position for a hospitality business is not to offer anything.

How long can you keep a guest's email address for review requests?

Only as long as you need it for the purpose you collected it for, and you have to be able to say what that period is. A defined retention rule, applied automatically, is the part most small operators never set up and the part a regulator asks about first.

See your own reviews this way

Every platform in one inbox, the themes pulled out for you, and a reply drafted in your voice waiting for approval.

Start free for 14 days

14 days · No card required · Cancel anytime