In-room TV security and GDPR: what your supplier must guarantee

What data the in-room TV actually processes
The guest's name for the welcome message, language, room number, charges generated, aggregated viewing history, and temporary OTT credentials entered by the guest. No other data is needed: if a supplier asks for more, request the reason in writing.
Deletion at check-out: the non-negotiable requirement
On the check-out event received from the PMS, the system must wipe OTT logins, viewing history, preferences and messages. This is the measure that prevents the most common type of breach: the next guest finding the previous one's Netflix account still logged in.
Roles and contracts (Article 28 GDPR)
The hospitality property is the data controller; the IPTV supplier is the processor and must be appointed under a written contract specifying purpose, categories of data, security measures, sub-processors and deletion timeframes. Without this document, the property is exposed in the event of an inspection.
Minimum technical measures
TLS encryption of communications between the box, server and back office; strong authentication on the back office with differentiated roles; network segmentation between the TV service, guests and administration; signed firmware updates; access logs retained and monitored; encrypted server backups.
NIS2 and hotel chains
Larger hotel chains increasingly fall within the scope of NIS2 and must document the security of their supply chain. The IPTV supplier should be asked for: a vulnerability management policy, stated patching timeframes, an incident contact, and a notification procedure within 24/72 hours.
What to ask during a tender
1) A signed DPA. 2) A list of sub-processors and countries of processing. 3) A description of the check-out wipe process. 4) Log retention periods. 5) The most recent penetration test or vulnerability assessment. 6) Security incident response SLA. These are six questions that separate a professional supplier from an improvised integrator.
Frequently asked questions
Does the in-room TV require the guest's consent?+
Essential functions (channels, information, requested services) rely on contract and legitimate interest. Consent is required for profiling and personalised promotional communications, with the option to decline without losing the service.
How long is viewing data retained?+
For the minimum time necessary. In practice, identifying data is deleted at check-out and only aggregated, anonymous statistics remain, used for service management purposes.
Who is liable in the event of a data breach?+
The property, as controller, notifies the supervisory authority; the supplier, as processor, must inform it without undue delay and provide support. All of this must be set out in the DPA signed before go-live.
Is a guest's Netflix login safe?+
Yes, if the system correctly wipes it at check-out: OTT sessions are temporary and are not retained by the hotel system.
