"Guest registration system" gets used loosely in the short-let world — sometimes it means a property management system's check-in module, sometimes an ID-verification app, sometimes just a spreadsheet. Before choosing one, it's worth being precise about what you're actually required to keep, because the legal duty behind it is older, stricter, and less well known than most of what gets written about short-let compliance.
The 1972 law most hosts have never heard of
The Immigration (Hotel Records) Order 1972 applies to "any hotel or other premises, whether furnished or unfurnished, where lodging or sleeping accommodation is provided for reward." That wording is broad by design — it isn't limited to premises that call themselves a hotel, and industry guidance on short-let compliance treats it as applying to short-stay lets and B&Bs, not just traditional hotels. If you let a property for money and someone sleeps there for a night or more, it's the kind of arrangement this Order was written to cover.
It's not a new or theoretical rule. It's been in force since 1973, and it's still cited today — a failure to comply can mean an unlimited fine and up to six months' imprisonment per breach. It simply isn't well known, because it predates Airbnb by four decades and nobody rewrote the short-let compliance conversation around it when the industry took off.
What you're actually required to record
For every guest aged 16 or over staying at the property, the keeper of the premises must keep a written record of:
- Full name and nationality, given by the guest on arrival.
- Next destination, given by the guest before they leave.
- For non-British, non-Irish guests (in practice, anyone who isn't a British, Irish or Commonwealth citizen): the number of their passport or other identity/registration document, and where it was issued.
Guests are themselves obliged to provide this information on request — the Order places a duty on the guest as well as the host. The record has to be kept in writing for at least 12 months, and made available for inspection by police or another authorised officer if asked. A paper book satisfies this. So does a spreadsheet, a database, or a field inside a check-in app — the format isn't specified, only that it exists, is accurate, and survives the full 12 months.
Paper register vs digital guest registration system
A physical guest book, kept accurately and stored for 12 months, is fully compliant. For a single property with a handful of bookings a month, that's a genuinely reasonable way to meet the requirement — there's no rule that says it has to be digital. Where it breaks down is scale and retrieval: if a police request ever asks "who was staying on the night of the 14th, across your three properties," searching handwritten entries is slow, and a book left in one property doesn't help you answer for the other two.
| Paper guest book | Digital guest registration system | |
|---|---|---|
| Meets the 1972 Order | Yes, if kept accurately for 12 months | Yes, if it's configured to retain records that long |
| Cost | Effectively free | Usually a small monthly cost, or bundled into a check-in/PMS tool |
| Search across properties | Manual, one book per property | Instant, across every property in the account |
| Guest fills it in themselves | Rare — usually the host transcribes it | Often self-service, as part of check-in |
| Risk of a gap | Depends entirely on the host remembering | Lower if it's built into a check-in flow guests already complete |
| GDPR handling | Whatever the host arranges — easy to over-retain by accident | Can be built to auto-expire data on a set schedule |
| Best for | One property, low volume, hands-on host | Multiple properties, higher turnover, less host time available |
What a good digital system actually needs to do
Not every "guest registration" or ID-verification tool marketed to short-let hosts is actually built around the 1972 Order's specific requirements. Before choosing one, check it against these four things:
- It captures the right fields. Name, nationality and next destination for every guest 16+; passport/ID number and place of issue for non-British/Irish/Commonwealth guests. A tool that only checks "is this a real ID" without recording nationality and next destination isn't capturing what the Order asks for.
- It retains records for 12 months, not less. This is the one hosts most often get wrong, because it cuts against the instinct — and good GDPR practice — to delete guest documents quickly. See the section below on why these two things can pull in different directions.
- It's searchable and exportable in case of a genuine police request, ideally across every property you manage from one place.
- It doesn't add friction guests won't complete. A registration step guests abandon halfway through isn't compliant, it's just an unfinished form. Collection works best when it's folded into a check-in step guests are already doing — not a separate form they have to be chased to fill in.
Don't confuse this with England's short-term let register
This is where most of the confusion online comes from, because two very different things are both called "registration" in the same breath. The 1972 Order is about recording who stayed at your property — it already applies, UK-wide, today. England's planned short-term let registration scheme is a completely separate thing: it's about registering the property itself on a national database before it can legally be let, alongside evidence of things like fire and gas safety compliance.
As of September 2026, that property-registration scheme is not yet live. Ministers have pointed to a full national rollout by March 2027, after the original 2024 and "Spring 2026" targets both slipped. If you host in England, you'll likely need to deal with both obligations eventually — but they're on different timelines, cover different things, and satisfying one doesn't satisfy the other. Guest registration under the 1972 Order is the one that already applies and carries a criminal penalty for non-compliance today.
Scotland: licensing is a separate obligation
Scotland has its own, additional layer: since 1 October 2023 (existing hosts) every short-term let in Scotland has needed a licence from the local council, and operating without one is a criminal offence carrying fines of up to £2,500. That's a property-level licensing scheme, similar in spirit to England's forthcoming register but already in force. It runs alongside — not instead of — the UK-wide 1972 Order's guest-recording duty, which applies in Scotland exactly as it does in England and Wales. A Scottish host who has their STL licence sorted still needs a guest register.
Guest data and GDPR
Here's the genuine tension in this topic: UK GDPR pushes toward collecting only what you need and deleting it as soon as you don't need it anymore, while the 1972 Order requires keeping specific guest details, including ID numbers for some guests, for a minimum of 12 months. Both are real legal obligations, and they don't contradict each other — the Order effectively sets your lawful, necessary retention period for that specific record, which is exactly the kind of documented basis the ICO expects you to have before holding personal data for any length of time.
Where hosts can go wrong is applying a GDPR-driven "delete quickly" instinct to every piece of guest data, including the specific register entry the 1972 Order requires you to keep. It's worth being deliberate here: an ID-verification step you use to confirm who's checking in can reasonably delete the document image quickly once it's served its purpose, while the separate written register entry — name, nationality, next destination, and the ID number where required — needs to survive the full 12 months. They're two different pieces of data with two different jobs and, potentially, two different retention clocks.
So what should you actually use?
If you run one property and don't mind a notebook, a properly kept paper register is genuinely compliant and costs nothing — don't let anyone tell you otherwise. The case for going digital gets stronger once you're managing more than one property, letting to a meaningful share of non-British guests (where the extra ID-number field applies), or you already know a paper system would realistically get forgotten on a busy changeover day.
If you already run a WhatsApp self check-in flow — or you're weighing one against a key lock box — it's worth checking exactly what it does with the ID and nationality details it collects at that verification step, and for how long. A check-in flow that confirms who's arriving before releasing a door code is doing genuinely useful verification work, but if it deletes the document quickly afterwards for GDPR reasons (a sensible default for the ID image itself), that alone won't satisfy the 1972 Order's 12-month written-record duty. The practical fix is simple: keep the two obligations separate in your head, and make sure whatever you use for the door-code side is paired with a basic register — even a one-line-per-guest spreadsheet — that's actually kept for the full year.
The law behind "guest registration" is older and stricter than most of what gets written about short-let compliance. It doesn't require a specific product — it requires that somewhere, for every guest, for twelve months, the right details actually exist.
For the practical side of getting guests through the door in the first place — codes, house rules, and the message flow itself — see our free Airbnb self check-in message templates and how to send Airbnb door codes automatically. If guest questions before arrival are also eating your evenings, an AI receptionist can field those around the clock so check-in isn't the only thing you've had to automate.