Your Holiday Costs More Than You Think
Let us go through it step by step.
Tickets
When you book a plane ticket — the data enters the global booking system. Amadeus, Sabre, Travelport — three companies that process almost all plane tickets in the world. Your name, passport, route, seat on the plane, meal preferences, flight history — all of this is in their databases. This data is transmitted to the airline, the airport, the border services of the countries you fly through, insurance companies, advertising networks. The US requires the transmission of passenger data 72 hours before departure — including citizens of third countries who are simply flying through American airspace. What to do: Book directly through the airline’s website — fewer intermediaries receive the data. Avoid intermediary sites like Skyscanner and Kayak for the final booking — use them only to search for the price.
Hotel
When booking a hotel through Booking or Airbnb — your data goes not only to the hotel. It goes to the intermediary site itself, its advertising partners, the payment system, the insurer, the hotel’s reputation-management system. Booking stores the history of all your bookings. The algorithm knows when you usually travel, which hotels you choose, how much you spend, who you go with. This data is used for dynamic pricing — you may be shown a higher price than a new user. What to do: After you have found a hotel through the intermediary site — go directly to the hotel’s website and book there. Usually the price is the same or lower. The data goes only to the hotel — without an intermediary. Use a virtual card for payment if your bank offers that possibility.
Car rental
Modern rental cars are mobile data-collection devices. A GPS tracker records every route. Telematics records speed, braking, driving style. Some companies transmit this data to insurers and advertising networks. On returning the car, the company has the full history of your movements for the entire rental period. Where you drove, where you stopped, at what time. What to do: Read the rental agreement — especially the section on GPS and telematics. You have the right to request what data is collected and to whom it is transmitted. In the EU this is a right under GDPR. Book through the company’s official website — not through an intermediary site. Pay by card rather than linking a card to the company’s app.
Insurance
Insurance companies buy data from brokers to assess risk. Your age, travel history, countries you have visited, even activity on social networks — all of this affects the cost of the policy. Some travel insurance policies require access to medical data or physical-activity data through an app. This is voluntary — but presented as a condition for getting a discount. What to do: Do not install the insurance company’s app if it is not mandatory. Request the policy through the website or by phone. Read the section on transferring data to third parties.
Public WiFi in airports and hotels
This is the most obvious threat that everyone knows about but no one takes seriously. Public WiFi can be eavesdropped on. Not necessarily by malicious actors — the WiFi provider itself sees all unencrypted traffic. Airport networks often belong to advertising companies that collect data about visited sites. What to do: Turn on a VPN before connecting to any public network. Do not log into your bank, email or any sensitive services without a VPN. If a VPN is unavailable — use mobile internet instead of public WiFi.
Passport data
When checking in at a hotel you hand over your passport. It is scanned or photographed. This data is stored — sometimes for years, sometimes without proper protection. In the EU hotels are obliged to register guests for tax and police purposes. But storing a passport scan longer than necessary is a GDPR violation. What to do: After check-in you have the right to ask how your data is stored and for how long. It sounds strange at the reception desk — but it is your lawful right.
Social networks during the trip
Every post with a geotag is data about your location in real time. Algorithms record the country, city, type of place. This enriches your profile. Holiday photographs contain metadata — GPS coordinates, time of shooting, camera model. Even if you do not indicate the geolocation in the post — the metadata in the photo file may contain it. What to do: Turn off geolocation in the camera settings before the trip. Publish photos after returning — not in real time. Privacy settings on social networks — friends only, not public.
Payment cards
Every transaction abroad is recorded — place, time, amount, category. The bank builds a profile of your spending. This data may be transmitted to analytics platforms. What to do: Use a separate card for travel with a limited balance. Revolut, Wise or their equivalents — less data with your main bank. Virtual cards for online bookings — a one-time number for each transaction.
The main thing to understand
Every booking is not merely a transaction. It is a data-collection point that enriches your digital profile. The airline, the hotel, the insurer, the car rental, the intermediary site — each receives a piece of information about you. Together these pieces add up to a detailed picture — who you are, where you are going, with whom, how much you spend, what lifestyle you lead. You cannot fully avoid transmitting data when travelling. But you can minimise the number of intermediaries who receive this data. Book directly. Pay with a virtual card. Turn on a VPN on public networks. Publish photos after returning. This takes a few minutes of extra attention. But the data about your trip stays yours. All the best and good luck in your travels. Take care of yourself.