GDPR-Compliant Marketing for Tour Operators (Without Asking for Email)
European tourists are increasingly anonymous, and asking a person on holiday for an email gets you a fake address. Here is what tour operators are legally allowed to do under GDPR — and the modern ways to reach customers without ever holding personal data.
A tour operator stops a traveller on the way back to their hotel and asks for an email address. A few years ago, that was marketing. In 2026, under the GDPR and related ePrivacy rules, it is rarely the right move — both for legal reasons and because the traveller, on holiday, is unlikely to give a real address anyway.
This guide is for European tour operators and any operator serving European travellers. It walks through what GDPR practically requires, what the consent rules look like in 2026, and the modern ways to keep a relationship with a traveller that don't require holding their personal data at all.
This is a practical operational guide, not legal advice. If you handle meaningful volumes of personal data, speak to a privacy professional.
The short version
- You need explicit, opt-in consent to send marketing email to a traveller.
- "They booked a tour, so they want my newsletter" is not consent.
- A pre-ticked checkbox is not consent.
- An email collected for a transactional purpose, like sending a ticket, cannot be reused for marketing without separate consent.
- Anonymous, opted-in mobile-wallet passes do not collect personal data, and are GDPR-aligned by design.
What GDPR treats as personal data
Anything that identifies a person, alone or in combination: name, email, phone, IP address, device ID, even a photo of their face. The threshold is broad. A "where they're from" signal alone is not personal data; the same signal paired with a meeting-point check-in time may be.
Transactional vs marketing
You can collect an email to send a booking confirmation — that is a transactional purpose. It does not give you the right to send the same person a "weekend offers" email next month. Marketing consent has to be collected separately, at the point of booking, with a clear and uncoerced opt-in.
In practice this means that even when you have an email address, you often cannot legally use it for marketing.
Five GDPR-aligned ways to reach travellers
1. Wallet passes
A traveller who saves your card to Apple Wallet or Google Wallet has actively opted in to receive updates from that specific card. They never give you their email. Apple and Google handle the device side anonymously. You can change the price, time, or text from your dashboard, and their phone updates within seconds. This is the cleanest customer-comms channel available to tour operators today.
2. Geo-triggered wallet notifications
When a traveller is near your meeting point, their phone can surface your card. This is a local OS feature; no personal data leaves the device for you.
3. WhatsApp Business with explicit opt-in
Travellers can opt in to receive WhatsApp messages from your business. WhatsApp handles much of the consent infrastructure. Best used for confirmations and friendly follow-ups, not for blast campaigns.
4. Email with double opt-in
Email still works, but only with a real, double opt-in. The traveller signs up, receives a confirmation email, clicks the link. Now you can email them. The list is smaller. It is also infinitely more defensible.
5. Anonymous aggregate analytics
You can measure aggregate behaviour — scans, saves, bookings per poster, per language, per time of day — without ever identifying an individual. GDPR is fine with this. A lot of useful business analysis lives in this layer.
What is no longer comfortable territory
- Buying email lists.
- Scraping reviews to email named travellers.
- Treating a previous booking as a "soft" basis for marketing email.
- Sharing customer email with partner businesses for cross-marketing.
- Tracking pixels in marketing email without consent.
The records you are expected to keep
If you do collect personal data, you should be able to show:
- What data you collected.
- When you collected it.
- What consent the person gave at that moment.
- The version of the privacy policy in effect.
- The exact wording presented at the point of collection.
This is why a casual paper list of emails at the meeting point creates more operational burden than marketing value. The compliance work to defend the list is usually larger than the return from using it.
The Tourist Scan posture
Tourist Scan is built around this constraint. The traveller scans a QR. A pass is saved to their wallet. No email collected. No name. No phone number. You can update the offer, send three native lock-screen notifications, and run a meeting-point check-in — all without storing personal data on the traveller. Our servers run in the EU.
For European operators, this resolves the GDPR question elegantly: the data you do not collect is data you do not need to defend.
Privacy as a marketing feature
We did not put "GDPR-aligned" on the home page because lawyers asked us to. We put it there because, in our experience, travellers notice. The generation of travellers raised on intrusive web ads is now booking holidays, and they tend to prefer the operators who don't ask, don't store, and don't share. Privacy has quietly become a small but real differentiator. See how we handle it.
Useful references
- UK Information Commissioner's Office (ICO) guidance on consent and marketing: ico.org.uk
- European Data Protection Board (EDPB): edpb.europa.eu