In almost every situation, a hotel cannot give out guest information to someone who asks. Front desk staff are not supposed to confirm whether you are checked in, share your room number, or disclose your dates of stay, your bill, or your contact details to outside parties. That confidentiality is the default, and it bends only in narrow circumstances: your own consent, a valid warrant or subpoena, or a genuine emergency. The bigger surprise for most travelers is what happens outside those front-desk conversations, where hotels and booking platforms share guest data with advertising partners as a matter of routine.
What Counts as Guest Information
Every hotel keeps a detailed record for each guest, usually called a folio. It holds your name, home address, phone number, email, room number, check-in and check-out dates, and confirmation number. It also captures every charge you make during the stay: restaurant and bar tabs, room service, spa, parking, minibar, laundry, your daily rate, taxes, resort fees, and the card used to settle the bill.
Loyalty program members have far more on file. Major chains record travel companions and their relationship to you, dietary restrictions, room preferences, hobbies, anniversaries and other significant dates, and a running history of stays and purchases across every property in the brand.1Marriott Group. Global Privacy Statement All of that is “guest information,” and all of it is subject to the same confidentiality duty.
The Default Rule Is Confidentiality
The duty to protect guest information comes from common law principles governing innkeepers that long predate modern privacy statutes. Under those principles, a hotel owes each guest a duty of care that includes safeguarding personal information from unauthorized disclosure. Most hotels put that duty into a written privacy policy, but the obligation exists whether or not the policy does.
In practical terms, a front desk employee is not allowed to confirm to a caller whether you are staying there, give out your room number, or share your checkout date. A staff member who casually confirms a guest’s presence to the wrong person exposes the hotel to liability for invasion of privacy. The protection extends to every category of data the hotel holds, from billing records to security footage of common areas.
Requests From Spouses, Family, and Private Parties
Private individuals have no automatic right to any of this information. A hotel should refuse to confirm whether you are a guest, share your room number, or disclose your dates of stay to anyone who asks, whether that person is a spouse, an employer, a private investigator, or a concerned relative. Disclosing without your explicit consent creates legal exposure for the hotel.
In civil cases, including divorce and personal injury matters, a private attorney can obtain guest records only through a court-ordered subpoena. The hotel must comply with a valid subpoena but should push back on informal requests, even from lawyers. Hotels that voluntarily hand over records without legal process risk liability for invasion of privacy, whatever the requester’s relationship to the guest.
If You Are Fleeing Domestic Violence
The confidentiality rule carries special weight when a guest is hiding from an abuser or stalker. The Department of Justice has recommended that private companies review their procedures around confidentiality to avoid inadvertently disclosing information that could put victims and their families at risk.2Office of Justice Programs. Confidentiality of Domestic Violence Victims Addresses Most states also run Address Confidentiality Programs that give survivors of domestic violence, stalking, and sexual assault a substitute address to use with businesses. If you are in this situation, tell the hotel directly that no information about your stay should be shared with anyone, and ask whether you can register under an alias.
When Police Can Get Guest Records
Law enforcement gets more access than a private person, but not automatic access. In City of Los Angeles v. Patel, the Supreme Court struck down a Los Angeles ordinance that had required hotels to hand over guest registries to police on demand, with criminal penalties for refusing. The Court held the ordinance violated the Fourth Amendment because it gave hotels no opportunity to challenge the demand before complying.3Justia U.S. Supreme Court Center. Los Angeles v. Patel, 576 U.S. 409 (2015)
The upshot is straightforward. An officer can ask to see a hotel’s guest records, and the hotel can say no. To compel disclosure, the officer needs a search warrant issued by a judge or a subpoena the hotel can contest before a neutral decision-maker. Officers can also obtain an ex parte warrant for surprise inspections, or guard the records while seeking judicial approval if they suspect the hotel might alter them.3Justia U.S. Supreme Court Center. Los Angeles v. Patel, 576 U.S. 409 (2015)
The one exception is exigent circumstances. Courts let police skip the warrant requirement when waiting would create serious and immediate consequences: a life is in danger, a suspect is about to flee, or critical evidence is being destroyed. The bar is high. Police must show the threat was real, immediate, and likely to materialize before a warrant could be obtained, and courts routinely suppress evidence obtained on weak exigent-circumstances claims.
Police Searches of the Room Itself
Records and rooms are governed by different rules, and the room gets even stronger protection. In Stoner v. California, the Supreme Court held that a hotel guest has the same Fourth Amendment rights inside a rented room as a person has at home. A clerk or manager cannot consent to a police search of your room on your behalf.4Legal Information Institute. Consent Searches
Police need your own consent, a warrant, or a recognized exception like exigent circumstances to enter and search. The fact that the hotel owns the building does not change that. If officers search your room based solely on a manager’s permission, anything they find can be challenged and potentially suppressed.
Genuine Emergencies
Medical and safety emergencies create a narrow exception to confidentiality. When someone’s life or physical safety is at immediate risk, a hotel can share what first responders need to help. If a guest has a medical crisis, staff can tell paramedics the room number and relay known medical details. Federal guidance under HIPAA confirms that health care providers may share patient information as necessary to prevent or lessen a serious and imminent threat to a person or the public.5U.S. Department of Health and Human Services. HIPAA Privacy in Emergency Situations – Bulletin
During evacuations for fires and similar threats, hotels routinely share occupancy information with fire departments to account for everyone in the building. Local fire codes in many jurisdictions require hotels to maintain that information in an accessible format for exactly that purpose. The limit is proportionality: the hotel should share only what the emergency requires. Telling firefighters which rooms are occupied is appropriate; handing over a full guest registry with home addresses and card numbers is not.
The Sharing That Happens Without Anyone Asking
Most disclosure of guest information does not happen at the front desk. It happens through marketing partnerships and booking platforms, in ways travelers rarely think about.
Major hotel chains share guest data with advertising partners, including social media platforms, ad networks, and data brokers. Marriott’s privacy statement lists Meta, Google, Pinterest, Snap, and several other advertising companies as recipients of guest personal data for targeted marketing.1Marriott Group. Global Privacy Statement If you booked through an online travel agency, that platform is sharing separately. Expedia, for example, discloses advertising identifiers, hashed email addresses, approximate location, and trip details to advertising intermediaries and social media companies.6Expedia Group. Third-Party Data Sharing – Controllers and Joint Controllers
None of this requires a warrant or a subpoena. It runs automatically under the privacy policies you agreed to when you booked, and the hotel and the booking platform act as independent controllers, each sharing under its own terms.
Using State Law to Limit That Sharing
Federal law does not include a comprehensive consumer privacy statute, but a growing number of states have their own. As of 2026, twenty states have enacted comprehensive consumer privacy laws, and several give you real tools to control what hotels do with your data.
California’s Consumer Privacy Act is the most established. If you live in California and the hotel meets the law’s revenue or data-volume thresholds, you have the right to know what personal information the hotel has collected about you, request that it be deleted, and opt out of the sale or sharing of that data for targeted advertising. Once you opt out, the business cannot sell or share your information again unless you later reauthorize it, and must wait at least 12 months before even asking you to opt back in.7Office of the California Attorney General. California Consumer Privacy Act (CCPA)
Colorado, Connecticut, Virginia, Texas, and other states offer comparable rights with varying details. If you live in one of these states, look for a “Do Not Sell or Share My Personal Information” link on the hotel’s website. Major chains are required to honor those requests, and compliance usually runs through an online form or a toll-free number.
If a Hotel Disclosed Your Information
Start by documenting what happened: what was shared, with whom, and how you found out. Then file a formal complaint with the hotel’s management and, for a chain, the corporate privacy team. Large chains have dedicated privacy staff, and a written complaint referencing potential regulatory exposure often gets a faster response than a general customer service call.
For a more formal path, report the incident to your state’s attorney general, which is the agency that enforces consumer privacy laws in most states. In states with a comprehensive privacy law, the attorney general’s office can investigate and impose fines that range from $2,500 to $7,500 or more per violation, depending on the state and whether the violation was intentional.
If the disclosure caused real harm, such as a stalker locating you, identity theft, or financial losses, you may have grounds for a civil lawsuit. The usual claims are invasion of privacy and negligence, and you would need to show that the hotel owed you a duty of confidentiality, breached it, and caused you actual damages. Juries have awarded significant sums in invasion of privacy cases involving hotel guests when the facts support it. A lawyer who handles privacy or personal injury litigation can tell you whether your situation is worth pursuing.