GDPR for dive resorts — the 5-minute compliance checklist
If you accept bookings from EU residents — even occasionally — GDPR applies to you. The good news: for a typical dive resort, compliance is mostly about being explicit and tidy with the data you already collect.
What data dive resorts typically store
- Personal data: name, email, phone, date of birth, address
- Health data (special category): allergies, dive medical declarations
- Certification data: PADI/SSI level, dive log
- Financial data: card last 4, invoice address, payment status
- Marketing data: newsletter opt-in, source attribution
Health and financial data are special categories with stricter rules.
The 5-minute checklist
- Privacy policy — written, visible from the footer of every page, listing every data category you store.
- Consent — explicit checkbox at booking time for marketing emails (pre-ticked is not valid consent).
- Right to access — be able to export a single guest's data within 30 days of a request.
- Right to erasure — be able to anonymise a guest while keeping accounting records intact.
- Audit trail — keep a log of who accessed or modified guest data, for 12+ months.
How ReefDesk helps
The Audit & GDPR tab in your settings gives you:
- One-click ZIP export of your full tenant database (Article 20)
- Per-guest JSON export for access requests (Article 15)
- One-click anonymisation that scrubs PII while keeping invoices intact (Article 17)
- A full audit trail of every login, user change, and GDPR action — searchable by user, action or entity
It won't replace a lawyer, but it will get you through 90% of practical EU compliance needs.
What ReefDesk doesn't do (yet)
- Cookie consent on your own website — that's on you (and we'll ship a free widget soon)
- Data Processing Agreement — sign one with us via legal@reefdesk.io
- Marketing consent collection on third-party booking sites — Booking.com, Agoda etc. handle their own consent
Try ReefDesk free for 14 days
No credit card. Full feature access. Cancel any time.
Start free trial →