Spain SES Hospedajes & RD 933/2021: Complete Automation Guide for Hosts
How Spain's Real Decreto 933/2021 works in practice: the traveller and payment data you must capture, what the 24-hour SES Hospedajes window is measured from, and the five operational gaps where compliance actually fails.

What Real Decreto 933/2021 actually requires
Spain's Real Decreto 933/2021 replaced the older lodging-register rules with a single documentary-registration duty covering accommodation providers and vehicle rental companies. For short-term rental operators the practical effect is narrow but unforgiving: for every stay you collect a defined set of traveller and booking data, you keep it, and you transmit it to the Ministry of the Interior through the SES Hospedajes platform.
It applies whether you manage one flat or two hundred, whether you let through Airbnb, Booking.com or directly, and whether or not you ever meet the guest. Peninsular Spain, the Balearics and the Canaries are all in scope. Delegating check-in to a co-host, a concierge company or a smart lock does not move the obligation β it stays with the operator registered as the accommodation provider.
The data you have to capture
Two blocks, and most people only plan for the first.
Traveller identity. Full name and surnames, sex, document type and number (DNI, NIE or passport), date of birth, nationality, and for minors the relationship to the accompanying adult. Every traveller counts, not only the person who made the booking.
The stay and the transaction. Property reference, check-in and check-out, number of travellers, and details of how the booking was paid, including the payment method and its associated identifier.
That second block is what catches operators who built their process around scanning a passport at the door. Payment data lives in the OTA dashboard or the PMS, never on the guest's ID, so a check-in flow that only reads documents is structurally incomplete no matter how well it runs.
"Within 24 hours" is measured from something specific
The transmission window runs from the start of the stay β not from when you got round to it, and not from when the guest finally answered your message. For a 2 a.m. self-check-in on a Saturday, the clock is already running while nobody is awake to type anything into a portal.
This is why the deadline is an operational problem rather than a legal one. The rule itself is simple. Meeting it manually, for every stay, across every property, without exception, is the part that fails.
Where compliance actually breaks
Very few operators fail because they did not know the duty existed. They fail in one of five ways.
Transcription. Someone reads a passport and types it into a form. Surnames get interchanged, an NIE check letter is mistyped, a date arrives in the wrong order. The record transmits successfully and is still wrong.
Partial groups. The booker's details are captured; the three people who arrived with them are not. Rejections here are common, and they tend to surface after the window has already closed.
Minors. The relationship field is not optional and no document scanner can infer it. It has to be asked explicitly, and asked in a way a parent will actually complete.
Late and unattended arrivals. Self-check-in removes the moment at which a human would have collected anything. Unless the flow captures the data before arrival, there is no natural point at which it happens at all.
Credentials. Access to the platform depends on the operator being registered and holding working credentials. Expired or unshared credentials mean data that was collected correctly and never sent β which, from the authority's side, looks identical to never having collected it.
What automation is actually for
The value is not that software types faster. It is that the data is captured before the stay begins, validated at the point of entry, and transmitted without depending on anyone remembering.
A workable flow looks like this. The guest receives a check-in link when the booking is confirmed. Every traveller in the party completes their own record, not just the booker. Documents are scanned on the guest's own device, with fields read from the machine-readable zone rather than retyped. DNI and NIE check digits are validated immediately, so an error is corrected by the guest while they are still in the flow rather than by you after a rejection. Minors are routed to a guardian attestation instead of a document upload. Booking and payment references are pulled from the reservation record automatically. Transmission is scheduled against check-in, and every submission returns an acknowledgement you can retrieve later.
That last part matters more than it sounds. A compliance process you cannot evidence afterwards is not worth much more than one you never ran.
Before you rely on any specific number
Field lists, deadlines and penalty bands under this regime have been amended and deferred more than once since the decree was published, and enforcement practice varies between regions. Treat everything above as the shape of the obligation rather than as a citation. Confirm the current text and current figures against the official decree or with an adviser before making any decision that depends on them β particularly anything involving fines.