The best guest registration system for UK holiday lets in 2026 (and the law most hosts don't know about)

Most Airbnb and holiday-let hosts have never heard of the Immigration (Hotel Records) Order 1972 — a law that's been quietly in force since 1973 and still applies to short-term lets today. It requires you to keep a written record of who stayed at your property, for at least 12 months. Here's exactly what it requires, how it's different from the licensing and registration schemes hosts have heard of, and what to actually look for in a guest registration system.

"Guest registration system" gets used loosely in the short-let world — sometimes it means a property management system's check-in module, sometimes an ID-verification app, sometimes just a spreadsheet. Before choosing one, it's worth being precise about what you're actually required to keep, because the legal duty behind it is older, stricter, and less well known than most of what gets written about short-let compliance.

The 1972 law most hosts have never heard of

The Immigration (Hotel Records) Order 1972 applies to "any hotel or other premises, whether furnished or unfurnished, where lodging or sleeping accommodation is provided for reward." That wording is broad by design — it isn't limited to premises that call themselves a hotel, and industry guidance on short-let compliance treats it as applying to short-stay lets and B&Bs, not just traditional hotels. If you let a property for money and someone sleeps there for a night or more, it's the kind of arrangement this Order was written to cover.

It's not a new or theoretical rule. It's been in force since 1973, and it's still cited today — a failure to comply can mean an unlimited fine and up to six months' imprisonment per breach. It simply isn't well known, because it predates Airbnb by four decades and nobody rewrote the short-let compliance conversation around it when the industry took off.

What you're actually required to record

For every guest aged 16 or over staying at the property, the keeper of the premises must keep a written record of:

  • Full name and nationality, given by the guest on arrival.
  • Next destination, given by the guest before they leave.
  • For non-British, non-Irish guests (in practice, anyone who isn't a British, Irish or Commonwealth citizen): the number of their passport or other identity/registration document, and where it was issued.

Guests are themselves obliged to provide this information on request — the Order places a duty on the guest as well as the host. The record has to be kept in writing for at least 12 months, and made available for inspection by police or another authorised officer if asked. A paper book satisfies this. So does a spreadsheet, a database, or a field inside a check-in app — the format isn't specified, only that it exists, is accurate, and survives the full 12 months.

The bit hosts miss This isn't optional "best practice" advice — it's a standing legal duty that applies to holiday lets right now, independently of any licensing scheme, property registration database, or platform's own ID-check feature. Whatever system you choose, it has to actually satisfy this on its own terms.

Paper register vs digital guest registration system

A physical guest book, kept accurately and stored for 12 months, is fully compliant. For a single property with a handful of bookings a month, that's a genuinely reasonable way to meet the requirement — there's no rule that says it has to be digital. Where it breaks down is scale and retrieval: if a police request ever asks "who was staying on the night of the 14th, across your three properties," searching handwritten entries is slow, and a book left in one property doesn't help you answer for the other two.

 Paper guest bookDigital guest registration system
Meets the 1972 OrderYes, if kept accurately for 12 monthsYes, if it's configured to retain records that long
CostEffectively freeUsually a small monthly cost, or bundled into a check-in/PMS tool
Search across propertiesManual, one book per propertyInstant, across every property in the account
Guest fills it in themselvesRare — usually the host transcribes itOften self-service, as part of check-in
Risk of a gapDepends entirely on the host rememberingLower if it's built into a check-in flow guests already complete
GDPR handlingWhatever the host arranges — easy to over-retain by accidentCan be built to auto-expire data on a set schedule
Best forOne property, low volume, hands-on hostMultiple properties, higher turnover, less host time available

What a good digital system actually needs to do

Not every "guest registration" or ID-verification tool marketed to short-let hosts is actually built around the 1972 Order's specific requirements. Before choosing one, check it against these four things:

  • It captures the right fields. Name, nationality and next destination for every guest 16+; passport/ID number and place of issue for non-British/Irish/Commonwealth guests. A tool that only checks "is this a real ID" without recording nationality and next destination isn't capturing what the Order asks for.
  • It retains records for 12 months, not less. This is the one hosts most often get wrong, because it cuts against the instinct — and good GDPR practice — to delete guest documents quickly. See the section below on why these two things can pull in different directions.
  • It's searchable and exportable in case of a genuine police request, ideally across every property you manage from one place.
  • It doesn't add friction guests won't complete. A registration step guests abandon halfway through isn't compliant, it's just an unfinished form. Collection works best when it's folded into a check-in step guests are already doing — not a separate form they have to be chased to fill in.

Don't confuse this with England's short-term let register

This is where most of the confusion online comes from, because two very different things are both called "registration" in the same breath. The 1972 Order is about recording who stayed at your property — it already applies, UK-wide, today. England's planned short-term let registration scheme is a completely separate thing: it's about registering the property itself on a national database before it can legally be let, alongside evidence of things like fire and gas safety compliance.

As of September 2026, that property-registration scheme is not yet live. Ministers have pointed to a full national rollout by March 2027, after the original 2024 and "Spring 2026" targets both slipped. If you host in England, you'll likely need to deal with both obligations eventually — but they're on different timelines, cover different things, and satisfying one doesn't satisfy the other. Guest registration under the 1972 Order is the one that already applies and carries a criminal penalty for non-compliance today.

Scotland: licensing is a separate obligation

Scotland has its own, additional layer: since 1 October 2023 (existing hosts) every short-term let in Scotland has needed a licence from the local council, and operating without one is a criminal offence carrying fines of up to £2,500. That's a property-level licensing scheme, similar in spirit to England's forthcoming register but already in force. It runs alongside — not instead of — the UK-wide 1972 Order's guest-recording duty, which applies in Scotland exactly as it does in England and Wales. A Scottish host who has their STL licence sorted still needs a guest register.

Guest data and GDPR

Here's the genuine tension in this topic: UK GDPR pushes toward collecting only what you need and deleting it as soon as you don't need it anymore, while the 1972 Order requires keeping specific guest details, including ID numbers for some guests, for a minimum of 12 months. Both are real legal obligations, and they don't contradict each other — the Order effectively sets your lawful, necessary retention period for that specific record, which is exactly the kind of documented basis the ICO expects you to have before holding personal data for any length of time.

Where hosts can go wrong is applying a GDPR-driven "delete quickly" instinct to every piece of guest data, including the specific register entry the 1972 Order requires you to keep. It's worth being deliberate here: an ID-verification step you use to confirm who's checking in can reasonably delete the document image quickly once it's served its purpose, while the separate written register entry — name, nationality, next destination, and the ID number where required — needs to survive the full 12 months. They're two different pieces of data with two different jobs and, potentially, two different retention clocks.

So what should you actually use?

If you run one property and don't mind a notebook, a properly kept paper register is genuinely compliant and costs nothing — don't let anyone tell you otherwise. The case for going digital gets stronger once you're managing more than one property, letting to a meaningful share of non-British guests (where the extra ID-number field applies), or you already know a paper system would realistically get forgotten on a busy changeover day.

If you already run a WhatsApp self check-in flow — or you're weighing one against a key lock box — it's worth checking exactly what it does with the ID and nationality details it collects at that verification step, and for how long. A check-in flow that confirms who's arriving before releasing a door code is doing genuinely useful verification work, but if it deletes the document quickly afterwards for GDPR reasons (a sensible default for the ID image itself), that alone won't satisfy the 1972 Order's 12-month written-record duty. The practical fix is simple: keep the two obligations separate in your head, and make sure whatever you use for the door-code side is paired with a basic register — even a one-line-per-guest spreadsheet — that's actually kept for the full year.

The law behind "guest registration" is older and stricter than most of what gets written about short-let compliance. It doesn't require a specific product — it requires that somewhere, for every guest, for twelve months, the right details actually exist.

For the practical side of getting guests through the door in the first place — codes, house rules, and the message flow itself — see our free Airbnb self check-in message templates and how to send Airbnb door codes automatically. If guest questions before arrival are also eating your evenings, an AI receptionist can field those around the clock so check-in isn't the only thing you've had to automate.

Mohsan Abasi

Founder, Pivot Bureau

Mohsan builds done-for-you AI assistants and self check-in automation for UK short-let hosts and small businesses — WhatsApp self check-in, AI receptionists and AI-ready websites. Connect on LinkedIn.

FAQ

Do UK holiday lets legally have to keep a guest register?

Yes. The Immigration (Hotel Records) Order 1972 applies to "any hotel or other premises... where lodging or sleeping accommodation is provided for reward" — a definition wide enough to cover short-term lets and holiday cottages, not just hotels and B&Bs. It's a genuinely obscure piece of law that most hosts have never been told about, but it's still in force.

What information am I required to record about each guest?

For every guest aged 16 or over: their name and nationality on arrival, and their next destination before they leave. For guests who are not British, Irish or Commonwealth citizens, you must also record their passport or ID document number and where it was issued. This has to be a written record — a paper book or a digital equivalent both satisfy the requirement.

How long do I have to keep guest registration records?

At least 12 months, and the record has to be available for inspection by police or another authorised officer on request. This is longer than many hosts assume, and longer than some automated ID-verification tools retain guest documents by default — worth checking against whatever system you use.

Is this the same as England's new short-term let registration scheme?

No, and confusing the two is a common mistake. The 1972 Order is about recording who stayed at your property, and it already applies UK-wide today. England's separate registration scheme is about registering the property itself with a national database before it can be let — it is not yet live as of September 2026, with ministers pointing to a full rollout by March 2027. You may end up dealing with both, but they are different obligations on different timelines.

Does a WhatsApp self check-in ID check count as my legal guest register?

It can cover the collection step, but check the retention period. Some self check-in tools verify guest ID before releasing a door code and then delete it quickly afterwards for GDPR data-minimisation — which is good privacy practice, but if it deletes inside 12 months it doesn't, on its own, satisfy the 1972 Order's retention duty. You need a separate written record (even a simple spreadsheet row per guest) that survives the full 12 months, alongside whatever ID-verification tool you use for the actual check-in.

See WhatsApp self check-in for your property

Tell us how guests currently check in and we'll show you exactly what automating it would look like — including an honest answer on what it does and doesn't cover for your legal guest-record duty.

See WhatsApp Self Check-In Book a free 30-min call