VenusLab

Self check-in and automated arrivals: what Italian law allows

Automation by Pasquale Ascione 11 min read

Automating check-in has become one of the most sought-after levers for containing staff costs and simplifying the running of accommodation businesses, both hotels and non-hotel properties. At the same time, it is one of the areas in which the legal framework has generated most uncertainty. After two years of ministerial interventions and conflicting court decisions, the Council of State ruling of November 2025 has fixed the boundaries within which self check-in can be considered lawful. Understanding where that boundary runs is now essential for any operator who wants to automate arrivals without exposing themselves to criminal liability.

The identification obligation: Article 109 TULPS

The governing provision is Article 109 of the Consolidated Law on Public Security (Testo Unico delle Leggi di Pubblica Sicurezza, Royal Decree no. 773 of 18 June 1931), which imposes two distinct duties on the operators of accommodation businesses: to give lodging exclusively to persons holding a valid identity document, and to report the particulars of those lodged to the public security authority, through the State Police’s Alloggiati Web portal.

The purpose of the rule is one of public order: to allow the police to hold an up-to-date picture of who is staying in accommodation, so as to prevent wanted or suspected persons finding refuge there. One frequently underestimated element concerns its scope: since 2018, by virtue of Article 19-bis of Decree-Law 113/2018 (converted into Law 132/2018), the obligation extends to landlords letting property on contracts of less than thirty days. Holiday homes, B&Bs, guest houses and short lets are therefore subject to the same regime as hotels, without distinction.

It is also worth remembering that non-compliance is not a mere administrative infringement: failing to report the particulars, or reporting them falsely, is a criminal offence punishable by up to three months’ detention or a fine of up to €206 for each unidentified guest.

The 2024 circular and the litigation that followed

The contested point never concerned the reporting obligation itself, but rather the methods by which one verifies that the person entering the property genuinely corresponds to the document produced. On this point the Chief of Police intervened with circular no. 38138 of 18 November 2024, addressed to all Prefects and Chief Constables. The circular — prompted by the intensification of short lets ahead of the Jubilee and by the sensitivity of the international climate — clarified that wholly remote check-in procedures, involving electronic transmission of a copy of the document and access to the premises by automated code or key box, do not satisfy the requirements of Article 109. Identification, according to the Ministry, must take place “de visu”, that is by verifying the correspondence between the person lodged and the photograph on the document.

The reaction from the non-hotel sector was immediate. The circular was challenged before the Regional Administrative Court (TAR) of Lazio, which by judgment no. 10210/2025 (May 2025) annulled it, holding that the requirement of in-person identification had been superseded by the simplification of procedures introduced in 2011, and that the available technologies now permitted verification at a distance.

The position of the Council of State

The Ministry of the Interior appealed, and the Council of State, by judgment no. 9101/2025 of Section III, filed on 21 November 2025, reversed the first-instance decision, settling the framework currently in force. There are three principles to take away.

First, the circular is interpretative in nature, not innovative: it does not introduce a new obligation, but restates a duty already provided for by the TULPS. It is not, therefore, a prescription that can be disapplied as excessive or as overtaken by events.

Second, self check-in without any control is unlawful: identification that goes no further than uploading a document and issuing an automated entry code does not satisfy the public-security rationale of the rule. Verification must establish the correspondence between the physical person entering and the document, with certainty as to place, time and visual confirmation.

Third — and this is the point of greatest practical significance — verification “de visu” does not necessarily mean the physical presence of the operator. The court expressly recognised that identification may also take place through dedicated video-link devices installed at the entrance to the property, provided they allow an effective and immediate ascertainment of identity. Self check-in, in other words, is not prohibited, but brought back within a procedure that guarantees recognition of the guest.

What this means in practice

The decisive criterion, in light of the ruling, is that verification must be contemporaneous with arrival: the identity check must take place at the moment the guest presents themselves at the property and, in any event, before access is granted — neither earlier nor later.

Accordingly, procedures based solely on sending a code in advance, or on the use of a key box with no visual confirmation, remain non-compliant, as does simply obtaining a copy of the document by messaging app or email: collecting the document is not the same as verifying who actually walks in.

Compliant, by contrast, are both in-person reception by the operator or their appointee, and real-time remote verification carried out by video call, digital video entryphone or equivalent tools allowing the guest’s face to be compared with the document before access is unlocked. The order of operations is decisive: identification first, then the code or the keys.

Remote recognition by webcam

A real-time video call, with the document held up to the camera, is currently the solution that best reconciles the demands of automation with those of security. It enables so-called hybrid check-in: the guest has a self-service experience, but identification takes place under the visual supervision of the operator or a member of staff, including from a remote workstation.

This approach has a further advantage on the data protection front. Where the comparison between face and document is carried out by a human operator, no processing of biometric data in the technical sense arises: the Italian Data Protection Authority (Garante) had already clarified this in a preliminary review of 26 July 2017, specifying that data acquired by webcam does not constitute biometric data provided the identity check is performed by an operator and not automated by software. It should be noted that more recent case law (Court of Cassation, order no. 12967/2024) has taken a stricter reading in cases where software analyses the images in any event, even where the final outcome is reviewed by a person. The position changes appreciably once recognition is entrusted to software.

Recognition by artificial intelligence

A number of vendors offer systems that automatically compare, by algorithm, the guest’s face captured in real time against the photograph on the document, often coupled with liveness detection checks to confirm the person is genuinely present. These are efficient solutions, but they change the applicable legal regime and require prior analysis on two fronts.

Under the European Artificial Intelligence Regulation (AI Act, Reg. (EU) 2024/1689), the use of such systems does not fall among the prohibited practices. The prohibition in the Regulation concerns remote biometric identification for law-enforcement purposes in public spaces, whereas “one-to-one” biometric verification — aimed at confirming that a person is who they claim to be in order to access a service or premises — is expressly excluded from that prohibition. Comparing face against document at check-in falls within this permitted category.

Under the General Data Protection Regulation (GDPR), however, one enters the processing of biometric data, which belongs to the special categories of data and enjoys reinforced protection. The moment an algorithm extracts the geometric features of a face and converts them into a comparable mathematical template, the processing is prohibited as a rule, save where specific conditions for lawfulness are met. In practice, adopting an automated facial recognition system presupposes identifying an appropriate legal basis — in respect of which the guest’s mere consent has repeatedly proved fragile — carrying out a data protection impact assessment (DPIA), and adopting adequate security and retention safeguards. When choosing a vendor it is advisable to verify formally how these matters are handled, rather than relying on generic declarations of compliance: the Garante has already penalised businesses that relied on such declarations in the absence of the required conditions.

The obligations that do not change

Whatever arrival procedure is adopted, some obligations remain in every case. The report to Alloggiati Web must be made within 24 hours of arrival, reduced to 6 hours for stays of no more than one day, subject to prior authorisation from the competent police headquarters. Responsibility for identification remains with the operator, with the criminal consequences already noted. Finally, it should be borne in mind that numerous municipalities — including Florence, Rome and Milan — have regulated or prohibited the installation of key boxes on public land or on parts of buildings visible from the street, with administrative fines (up to €400 per device) and removal by the authorities; Florence in particular has gone further, banning their use on private property as well on public safety grounds. This is a separate matter from the TULPS regime, being one of planning and civic amenity, but it has a concrete impact on day-to-day operations.

What comes next

The framework of principles is now settled, but there is still no official list of technologies recognised as compliant: as things stand, no technical standard certifies which video-identification devices satisfy the statutory requirement. Trade associations are pressing for a technical working group with the Ministry to close this gap, and dedicated legislation on video-link systems cannot be ruled out. At European level, Regulation (EU) 2024/1028 on short-term rentals, applicable from 20 May 2026, concerns the segment of tourist lettings offered through online platforms (and not hotels in the strict sense) and does not affect how guests are identified — which remains a national competence — but it does introduce a harmonised system for registering accommodation and transmitting data, in addition to the existing obligations.

Conclusions

The direction set by the Council of State does not penalise automation; it relocates it within a precise perimeter. Everything repetitive — collecting data, handling documents, transmitting to Alloggiati Web — can and should be automated; identity verification, by contrast, requires an effective, real-time check attributable to the operator, who retains full responsibility for it. For accommodation businesses, hotel and non-hotel alike, compliance does not require a return to a permanent physical presence, but the design of a check-in flow in which technology supports recognition of the guest without ever wholly replacing it. Seen this way, self check-in does not disappear: it becomes an automated but identified procedure, capable of combining operational efficiency with public security.

Sources (statutory and institutional references)

  • Art. 109, Royal Decree no. 773 of 18 June 1931 – Consolidated Law on Public Security (TULPS).

  • Art. 19-bis, Decree-Law no. 113 of 4 October 2018, converted into Law no. 132 of 1 December 2018 – extension of the obligation to short lets.

  • Ministry of the Interior Decree of 7 January 2013 – procedures for reporting guests through the Alloggiati Web portal (State Police); art. 5 of Decree-Law no. 53 of 14 June 2019, converted into Law no. 77 of 8 August 2019 – the 6-hour deadline for stays of no more than 24 hours.

  • Chief of Police circular no. 38138 of 18 November 2024 – identification of guests in accommodation businesses.

  • TAR Lazio – Rome, Section I, judgment no. 10210/2025 (May 2025) – annulment of the circular, subsequently reversed on appeal.

  • Council of State, Section III, judgment no. 9101/2025, filed on 21 November 2025 – confirmation of “de visu” identification, permitted also by real-time video link. (Some databases show the case docket number — 05732 — rather than the judgment number; the official number is 9101/2025.)

  • Regulation (EU) 2016/679 (GDPR) – in particular arts. 4(14), 9 and 35 – and Legislative Decree 196/2003 (Italian Privacy Code), arts. 2-sexies and 2-septies.

  • Italian Data Protection Authority (Garante) – preliminary review of 26 July 2017 (webcam recognition) and decisions on biometric data.

  • Regulation (EU) 2024/1689 (AI Act) – distinction between remote biometric identification (prohibited for law enforcement) and biometric verification/authentication (excluded from the prohibition).

  • Regulation (EU) 2024/1028 of 11 April 2024 – collection and sharing of data on short-term rental accommodation services; applicable from 20 May 2026.


This article is for information only and does not constitute legal advice. Given how quickly this area is evolving, and the criminal and data protection issues involved, you are advised to check the instruments in their official versions and to consult a professional before adopting any particular check-in solution.