Can a company put a customer on an undesirable persons list after they publish a critical review of its services? This is a question that many entrepreneurs and consumers have been asking themselves in recent weeks, triggered by the high-profile case of one Polish hotel. The answer requires looking at several independent legal regimes simultaneously – and taking into account that neither party to such a dispute is automatically in the right.
What is a customer blacklist in practice, versus in the eyes of the law?
In practice, it is often nothing formalized, such as a note in a booking system or just a verbal instruction passed to the reception shift, which is enough to ensure a customer is no longer welcome. The reasons can be clear-cut, such as theft or aggression towards staff, but just as often they are subjective, such as a dispute over a bill, a conflict with service personnel, and sometimes… simply an inconvenient review online.
The problem affects not only hotel services. It also occurs on the internet, for example in shops looking for ways to deal with customers who, in their view, abuse the right of withdrawal, return damaged goods, and expect a refund.
From a legal perspective, however, this is not just an ordinary office memo; it is a set of personal data. This means that its existence, purpose, and storage period are subject to exactly the same rigours as any other data processing within a company. What looks like a simple precautionary measure to a manager is, under data protection regulations, an operation requiring a separate legal basis and a clear time limit.
Three legal regimes to bear in mind simultaneously
The GDPR does not recognize the concept of storing data “just in case”. In accordance with the principles of purpose limitation and storage limitation (Article 5(1)(b) and (e) of the GDPR), data can only be processed for as long as a specific, current purpose exists, and the basis for the entry is usually the legitimate interest of the controller (Article 6(1)(f) of the GDPR). This interest must, however, realistically outweigh the rights of the data subject – the mere fact of a conflict with a customer is not enough. Consumer law operates separately. Freedom of contract (Article 353¹ of the Civil Code) does not mean arbitrary freedom in refusing service, so a refusal without a specific justification previously outlined in the terms and conditions carries the risk of allegations of consumer rights violations, and in extreme cases, even discrimination.
Another layer is personal rights, meaning the relationship between the consumer’s right to criticism and the entrepreneur’s right to protection of good name, protected under Articles 23 and 24 of the Civil Code in conjunction with Article 43 of the Civil Code, applied mutatis mutandis to legal persons. A company may defend its reputation, but substantive criticism falling within the limits of permissible service evaluation does not constitute an unlawful violation of personal rights, even if it is inconvenient for the company.
On top of all this comes a thread that is only just emerging: automation. An increasing number of companies support the management of problematic customer registries with scoring systems that flag accounts as risky based on the number of complaints or behavioral patterns. If such a decision is made fully automatically and produces a tangible legal effect for the customer, Article 22 of the GDPR comes into play, limiting the permissibility of such decisions and requiring human intervention. The AI Act itself does not classify the maintenance of a customer list as a high-risk system, but if tools that systematically assess the behavior of natural persons are used to create it, it is worth checking already at the implementation stage whether it approaches a category subject to additional transparency obligations.

Where lies the risk, and where the real benefit?
The registry of undesirable persons itself is not prohibited and is often fully justified, because the protection of staff, property, and other customers is a legitimate interest of the entrepreneur. Trouble begins only when it is run without clear rules. Most often, companies fail to define the purpose and retention period of data, treat criticism or a complaint as an automatic basis for an entry without determining whether a breach of rules actually occurred, extend the ban to third parties who were not party to the dispute, or stop at vague regulatory provisions instead of a closed catalogue of refusal grounds. A well-designed registry has a clear purpose, a specific catalogue of events, and a defined data retention period; only then does it become an effective tool for protecting the business rather than a source of additional risk.
When theory meets practice: The Hotel Gołębiewski case
A good, recent example is the high-profile case of Hotel Gołębiewski and Szymon Nyczke, a YouTuber known as Książulo. It all started with an ordinary consumer dispute. Faulty air conditioning in a newly opened suite costing nearly PLN 5,000 per night, bedroom temperatures reaching over 32 degrees Celsius, and yellow water with sediment. Gołębiewski Holding admitted that such a situation should not have happened and honored the complaint by refunding the stay, while the Office of Competition and Consumer Protection (UOKiK) directly referred to the case on Instagram, pointing to Książulo’s stance as an example of enforcing consumer rights.
A few days later, the matter took a completely different turn. A letter was sent to the network’s facility directors indicating that Książulo and accompanying persons had been entered onto the list of undesirable guests, covering accommodation, restaurants, and water parks. Upon attempting to make a reservation, reception refused, citing a violation of the facility’s rules without specifying what that violation was supposed to be. The ban was lifted the same day following intervention by the management and the network’s owner, Jarosław Gołębiewski, and the chain has yet to publicly present a detailed stance on the list itself.
It is hard to find a better illustration of the mistakes described above. The lack of a clear purpose and retention period for the entry, treating a critical material as an event justifying a ban without establishing whether the regulations were actually breached, and extending the ban to accompanying persons who were not party to any dispute. However, the case is not exclusively unfavorable to the hotel. Jarosław Gołębiewski assessed Książulo’s material as harmful, and the creator himself emphasized that he did not wish to wage a campaign against the hotel – which clearly shows that justified consumer criticism and the protection of an entrepreneur’s good name are two independent threads requiring separate legal assessment. They cannot be resolved with a single hasty entry on a list.
Practical conclusions
Maintaining a registry of undesirable persons is not inherently impermissible, but it requires meeting several conditions simultaneously. There must be a specific event forming the basis of the entry, a clearly defined purpose and retention period for the data, restriction of the entry solely to the person actually involved in the event, and a precise catalogue of service refusal grounds in the terms and conditions rather than vague reservations. The Hotel Gołębiewski case clearly demonstrates how quickly a lack of such rules can turn a simple consumer dispute into a legal issue encompassing the GDPR, consumer rights, and personal rights all at once. It is worth checking this in advance, rather than only when the topic hits the media – especially where automated customer profiling by scoring systems is involved, which additionally requires evaluation under Article 22 of the GDPR and the AI Act.
If you run a service company and wonder whether your terms and conditions and internal procedures comply with the GDPR and consumer law, contact us. We will help you verify it.
