← Back to blog

GDPR for dive resorts — the 5-minute compliance checklist

May 15, 2026 · ReefDesk Team · 2 min read

If you accept bookings from EU residents — even occasionally — GDPR applies to you. The good news: for a typical dive resort, compliance is mostly about being explicit and tidy with the data you already collect.

What data dive resorts typically store

Health and financial data are special categories with stricter rules.

The 5-minute checklist

  1. Privacy policy — written, visible from the footer of every page, listing every data category you store.
  2. Consent — explicit checkbox at booking time for marketing emails (pre-ticked is not valid consent).
  3. Right to access — be able to export a single guest's data within 30 days of a request.
  4. Right to erasure — be able to anonymise a guest while keeping accounting records intact.
  5. Audit trail — keep a log of who accessed or modified guest data, for 12+ months.

How ReefDesk helps

The Audit & GDPR tab in your settings gives you:

It won't replace a lawyer, but it will get you through 90% of practical EU compliance needs.

What ReefDesk doesn't do (yet)

Try ReefDesk free for 14 days

No credit card. Full feature access. Cancel any time.

Start free trial →