Staying somewhere without being logged: hotels, rentals and guest wifi

Back to the blog
10 September 202612 min read

Introduction: three nights, forty traces

You arrive on a Tuesday evening at a hotel in a provincial town. The booking was made three weeks earlier on a platform, with your bank card stored, a confirmation email and two marketing follow-ups. At reception, you are asked for your ID — the desk clerk scans it, without comment. You are handed a keycard and a wifi password. You go up, switch on the smart TV, connect to the network, and order a meal through an app.

In forty minutes, your stay has produced: a named registration form that can be passed to the authorities, a digital image of your ID card stored who knows where, a bank card pre-authorisation, a time-stamped door-by-door record of keycard use, a MAC address linked to your name in the captive portal's logs, and an advertising identifier woken up by the TV in the room.

Man browsing on an open laptop showing a search engine, cup of coffee on the table

None of this is unlawful in itself. Several items are actually mandatory. But very few travellers know which ones — and it is precisely that ignorance that lets the less scrupulous establishments ask for a great deal more. This guide separates legal obligation from tolerated practice and outright abuse.


What your host is genuinely entitled to demand

The individual police form: who it applies to

Article R. 611-42 of the French Code on the entry and residence of foreign nationals and on the right of asylum requires hotels, campsites, holiday villages and professional short-term landlords to have guests fill in an individual police form — but only foreign travellers. A French national is under no legal obligation to complete it.

The form records surname, first names, date and place of birth, nationality, home address, and the arrival and expected departure dates. It is kept for six months and made available to the police and gendarmerie.

In practice, many establishments have everyone fill in the form, purely for simplicity. You can refuse if you are French, but the balance of power at 10 p.m. at the front desk is what it is.

Your ID: showing it yes, photocopying it no

This is the most widely misunderstood point. No legal text requires a hotelier or a landlord to keep a copy of your ID card or passport. The CNIL has been consistent on this: collecting a copy of an identity document must meet a specific need, and simply booking a room is not one.

In concrete terms:

RequestBasisYour room for manoeuvre
Showing your ID documentIdentity check, permittedAccept, hand it over yourself
Scanning or photocopying the documentNo general legal basisRefusal is legitimate
Emailing a copy before arrivalCommon practice with rentalsRefuse, or send a redacted copy
Card pre-authorisation as a depositContractual, permittedAccept, check the amount

If you do agree to send a copy anyway — some landlords will not confirm a booking without one — never hand over the raw image. Black out the document number with a marker and write across it by hand something like "copy given to [landlord's name] on [date], single use: booking". A customisable rubber stamp does the job very well and discourages any reuse. The CNIL explicitly recommends this kind of watermarking.

The face photo on arrival

Some hotel chains are trialling kiosk check-in with facial recognition. The European regulation on artificial intelligence, applicable in stages since 2025, places strict limits on biometric identification. Remember one simple rule: biometrics rest on explicit consent and must always offer a non-biometric alternative. A staffed desk has to remain available. Ask for it.


The property's wifi: the weak link

The captive portal is no minor detail

That page which opens automatically and asks for your name, your email, sometimes your room number or your phone number is called a captive portal. It serves two purposes: to comply with the connection-data retention obligations that fall on internet access providers, and to feed a marketing database.

What the portal typically records:

  • Your device's MAC address (a unique hardware identifier)
  • A timestamp for every session
  • Resolved domain names, depending on the configuration
  • The link to your name and room number

In other words, on a hotel network your activity is not anonymous: it is named by design. Two habits are enough to break that link.

First habit: randomised MAC addresses. iOS and Android have enabled this by default for several versions now ("Private Address", "Randomised Wi-Fi"), but the option is sometimes turned off on a per-network basis. Check it before you connect, not afterwards. On computers, Windows 11 and macOS offer the equivalent in the network properties.

Second habit: encrypt everything that leaves the device. A serious VPN — paid, no-logs, audited by an independent third party — makes the content of your traffic unintelligible to whoever runs the network. It does not make you anonymous towards the sites you visit, but it neutralises the local observer, which is the real risk here.

Person in a hoodie typing on a laptop in the dark, face not visible

The fake network that borrows the hotel's name

The most commonplace attack in hospitality is nothing sophisticated: a small box placed in a room broadcasts a network called "Hotel_Guest_Free", identical to the real one. Devices connect to it on their own if they have already saved it. ANSSI and CERT-FR regularly flag this scenario in their advice to business travellers.

Three defences, one sentence each:

  1. Ask reception for the exact name of the official network, and delete from your phone every hotel network saved during previous stays.
  2. Prefer tethering from your own mobile plan: a travel 4G router with a local prepaid SIM costs less than one night's accommodation and makes you independent of the venue's network.
  3. On the self-service computers in the lobby, never type a password — treat those machines as publicly compromised.

The property itself: cameras, locks and chatty devices

What a landlord may install, and what is prohibited

In a holiday rental, the French rule is clear: capturing images or sound inside the rented property is prohibited. Article 226-1 of the Criminal Code punishes with one year's imprisonment and a €45,000 fine anyone who invades another person's privacy by recording, without their consent, words or images in a private place. A rented room is a private place for the duration of the stay.

The major platforms have in fact tightened their own rules: since 2024, Airbnb has banned all surveillance cameras inside properties, including indoor common areas, and requires outdoor devices and noise monitors to be disclosed.

Still tolerated, subject to disclosure and information requirements:

DeviceStatusWhat to check
Outdoor camera pointed at the entranceAllowed if disclosedMust not film indoors
Video doorbellAllowed if disclosedField of view, retention period
Sound-level monitorAllowed if disclosedMust not record conversations
Indoor camera, even "switched off"ProhibitedReport it and leave
Smart lockAllowedAccess log, and who benefits from it

Spotting a camera in ten minutes

This is not paranoia: reports exist, and the devices involved are sold openly. The method is straightforward and is done on arrival, suitcase still shut.

  • Map the objects pointed at the bed or the shower: smoke detector, alarm clock, power strip, USB charger, decorative plant, mirror, speaker, air vent. A lens needs a line of sight.
  • Turn off the light and sweep the room with your phone's torch: most optics send back a sharp, pinpoint reflection.
  • Check the mirrors: place a fingernail against the surface. On a normal mirror, a gap separates the nail from its reflection. On a one-way mirror, they touch.
  • List the devices on the network: a network-scanning app on your smartphone reveals the objects connected to the property's wifi and their manufacturers.
  • Run a camera lens detector over the sensitive areas if you travel often or for professional reasons: these little red-LED-and-filter gadgets cost around twenty euros and save time.

If you find an indoor device: photograph it in place, do not dismantle it, contact the platform immediately and, depending on the seriousness, file a complaint. Evidence matters more than the satisfaction of having unplugged it.

The TV in the room

Hotel smart TVs often run a management system that greets you by name and logs what you watch. Some models use ACR (automatic content recognition), which samples the displayed image to identify what is playing — including from an external source.

Practical consequence: do not connect your personal streaming accounts to the TV in the room. If you do, sign out of them explicitly before you leave, from the account settings rather than from the TV. And to watch something in decent conditions, a wired headset plugged into your own device solves the problem without exposing anything.


Shrinking the footprint from the moment you book

Close-up of the keyboard and trackpad of a black laptop on a dark table

The best work is done before departure, while you still have a choice.

Compartmentalise your identifiers

Create an email address dedicated to travel, separate from your main inbox. It will receive the confirmations, the marketing follow-ups, the satisfaction surveys and, the day the hotelier suffers a data breach — the sector has had some spectacular ones — it is that address which will end up in the databases sold on, not your main one.

The same logic applies to your phone. An establishment asks for a number to warn you that your room is late or to send you an access code: there is no reason for that number to be the one your bank and your family know. A secondary number, or the use of a service that sends SMS without exposing your personal line, is more than enough for these one-off exchanges — and it puts an end to any later SMS campaigns.

Paying without telling your life story

Payment is the strongest thread between your stay and your civil identity. A few options, depending on the level you want:

  • Single-use virtual card, offered by most French banks: the merchant receives a number that only works for that one transaction.
  • A dedicated secondary account for travel spending, topped up as needed.
  • Cash during the stay for extras (bar, restaurant, parking), which avoids adding itemised lines to your statement.

A deposit is still almost always taken via a card pre-authorisation: that is contractual and legitimate. Simply check the stated amount and the release date.

The loyalty programme, that great collector

Hotel loyalty programmes are, by their very nature, profiling systems: dates, destinations, travel companions, preferences, spending habits, all kept for years. Nothing stops you from taking advantage of them, but read the stated purpose and exercise your right to object to marketing profiling — it is provided for by Articles 21 and 22 of the GDPR, and a simple written request is enough.


After the stay: what remains and how to erase it

Retention periods

DataUsual retentionBasis
Police form (foreign nationals)6 monthsCESEDA
Invoices and accounting records10 yearsCommercial Code
Wifi connection logs1 yearTelecoms obligations
Outdoor video surveillance footageGenerally 30 days maximumCNIL recommendation
Customer / marketing file3 years after last contactCNIL recommendation
Copy of ID documentNo solid legal basisHave it deleted

An erasure request that works

Write to the data controller — the establishment, not the platform — by email, with an explicit subject line. A short, effective template:

Subject: Access and erasure request (Articles 15 and 17 of the GDPR)

Dear Sir or Madam, I stayed at your establishment from [date] to [date], booking no. [reference]. I ask you to tell me all the personal data concerning me that you hold, its purpose and its retention period. I also request the erasure of any copy of my identity document, as well as the deletion of my contact details from your marketing files. You have one month in which to reply.

If there is no reply after a month, filing an online complaint with the CNIL takes five minutes and often triggers a reaction all by itself.

Don't narrate the trip live

One last point, the simplest and the most neglected: posting your holiday photos in real time amounts to announcing publicly that your home is empty, with precise geolocation. Postpone the posts until you are back. And if you leave cameras behind in the property, the habit of using a lockable storage case for documents and memory cards beats a bedroom drawer.


Summary: the five-minute routine

On arrival, in this order:

  1. Refuse the ID scan, agree to show the document.
  2. Ask for the exact name of the wifi network and check that MAC randomisation is on.
  3. Turn on the VPN before any other app.
  4. Walk round the room with the torch on and the lights off.
  5. Do not connect any personal account to the TV.

On departure:

  1. Sign out of every account used on any of the property's equipment.
  2. Forget the wifi network in your devices' settings.
  3. Check that the deposit is released within a fortnight.
  4. Send the erasure request, if needed.

A stay will never become invisible again: the law imposes a degree of traceability, and that is accepted. The realistic goal lies elsewhere — making sure that what is kept is the bare minimum, held by the bare minimum of people, for strictly the period foreseen. That is already a considerable difference from the default situation.

#Vie privée#Anonymat#Confidentialité#Cas d'usage#RGPD#Sécurité

On the same topic

// Anonymous SMS · Hidden number · To France

Envoyez votre message, gardez l'anonymat

Votre numéro reste masqué, aucune inscription, aucune trace. Rédigez, confirmez, et votre SMS part de façon totalement anonyme.

Envoyer un SMS anonyme