GUIDE
14-minute read
Last checked
3 October 2026
IN SHORT
Start with the rules your software has to handle: package travel information, ATOL Certificates and records, prices that include every compulsory fee and secure payments.
If you sell ATOL-protected flights or packages, an ATOL Certificate must go out as soon as a customer pays anything, and ATOL holders’ systems must keep records the CAA can see within 3 working days.
From 6 April 2027, two or more different types of travel service for the same trip, chosen and paid for separately in one visit to your shop or website or in one phone call, will form a package. Ask how your software will handle it.
Your software supplier will usually process your customers’ data for you, so you need a written contract that meets UK GDPR, and you stay responsible for choosing a safe supplier.
Test any system with your own real bookings, get the full cost in writing and check how you would take your data with you if you left.
Start with what your software has to do
In the UK, much of what the law asks of a travel business happens inside its systems: the information customers see before they book, the documents they get afterwards, the prices they are shown and the way their card details and personal data are handled. So before you compare features, be clear about how you sell:
Do you sell packages, and are you the organiser, the retailer or both?
Do you sell flights, and under whose ATOL?
Do you sell online, by phone, face to face or all three?
Which suppliers do you need, from airlines and bed banks to hotels you contract yourself?
Your answers decide which of the points below matter most. We make travel software ourselves, so we have an interest here. This guide sets out what the law and official guidance require, plus the practical questions we would ask, so you can use it to assess any supplier, including us.
Package travel information
If you sell packages, the Package Travel Regulations 2018 set out what customers must be told and when. Your software needs to produce:
Pre-contract information. Before booking, the customer must get the information in Schedule 1 that applies. That includes the main features of the trip and the total price, including taxes and all additional fees. It also covers any deposit and the other payment arrangements, plus general passport, visa and health information. It must all be clear, comprehensible and prominent.
The standard information form, using the form and wording set out in the regulations: Schedule 2 where hyperlinks can be used (such as on a website), Schedule 3 where they cannot or the sale is by phone and Schedule 4 for click-through packages (see below).
The contract or a confirmation of it, on a durable medium such as an email or PDF, when the contract is made or without undue delay afterwards. It must set out the full package, including the Schedule 1 information and the Schedule 5 information, such as the contact details of the insolvency protection provider and a contact point for help during the trip.
Travel documents in good time. Receipts, vouchers and tickets, with departure times, check-in deadlines and connections, must reach the customer in good time before departure.
Most of the information given before booking becomes part of the contract, and a customer does not have to pay fees they were not told about before booking. If there is a dispute about these duties, it is up to the organiser or retailer to show that it complied, so a system that keeps a dated record of what each customer was shown and sent is worth having.
Watch for click-through packages too. If a customer books with you online and your booking process passes their name, payment details and email address to another trader, and they book a different type of travel service with that trader within 24 hours of your booking being confirmed, the result is a package and your business is the organiser. Check any partner or cross-selling links in your booking flow with that in mind.
The April 2027 changes
From 6 April 2027, two or more different types of travel service for the same trip will form a package if one business lets the customer choose and pay for each separately in a single visit to, or contact with, its point of sale. A point of sale includes a shop, a website and a telephone service. Linked travel arrangements will no longer exist. The same changes remove regulation 28(2)(b), which made a trader who agreed to arrange a booking liable for errors made during the booking process. Regulation 28(2)(a) stays, so a trader is still liable for errors caused by technical defects in the booking system that are attributable to it.
The government’s explanatory memorandum counts updating IT systems among the one-off costs businesses will bear. Its guidance for businesses was last updated in July 2022, and the government says it will reissue it before the changes take effect. Ask any software supplier how its booking flows will handle the new rules, and whether the work is included in your price. Our Package Travel Regulations guide explains the rules in full.
ATOL
If you sell flight-inclusive packages, or flights that need ATOL protection, the ATOL rules reach right into your booking flow. Flight-only sales where a confirmed ticket is issued straight away can be exempt, but only on the CAA’s conditions. Where ATOL applies:
ATOL Certificates. A certificate must be issued as soon as the customer makes a first payment, and taking card details counts as payment. It must follow the CAA’s format exactly, using the right one of its four certificates: the Package (Single-contract), Package (Multi-contract), Flight-Only or Flight Inclusive Day Trip ATOL Certificate. It must carry no company branding and must name the business dealing with the customer as the issuer. If the details change more than 72 hours before departure, a new certificate is needed.
Information beside the price. As soon as a customer is invited to choose an ATOL-protected product, they must be told clearly, close to the price, that it is ATOL protected. Where they are known, they must also be shown the key flight details, such as the airline, airports and times, whether hold luggage and transfers are included and the price of any extra hold luggage or transfers they can add. The ATOL holder’s name and ATOL number must be shown before the booking is made.
Airline confirmation. Where flight details are shown, an ATOL holder must confirm the booking with the airline before, or as part of, taking the customer’s booking and payment. If that is impossible, it must do so as soon as possible afterwards at no extra cost to the customer.
Invoices and receipts. These must show the ATOL holder’s name and ATOL number and the CAA’s “Your Financial Protection” statement, and receipts must separate ATOL-protected money from the rest.
Records. An ATOL holder’s systems must produce certificates, record each certificate’s reference number against its booking, tell different types of sale apart, monitor bookings against licence limits and make records available to the CAA within 3 working days. Certificates and booking records must be kept for 12 months after the latest flight.
Ask a supplier to show you each of these working, including a certificate reissued after an amendment and the figures you report to the CAA each month or quarter. Our ATOL guide covers the wider rules.
Prices and selling online
Since 6 April 2025, the Digital Markets, Competition and Consumers Act 2024 has required the price in an advert or on a booking page to include every fee or charge a customer has to pay. The Competition and Markets Authority’s guidance says this covers booking, administration and processing fees, as well as local taxes and resort fees payable at a hotel, and it gives travel examples. It also says “from” prices must be realistic. The CMA can now fine businesses up to £300,000 or 10% of their global turnover, whichever is higher. Your software should let you build compulsory charges into the price at every stage, including search results.
Other rules your website has to follow:
Reviews. Publishing fake reviews, hiding that reviews were incentivised or showing reviews in a misleading way, such as suppressing negative ones, is banned. You must also take reasonable steps to prevent and remove fake reviews.
Pressure selling. Falsely claiming that a price or product is available only for a limited time is banned.
Card surcharges. You cannot charge a fee for paying with a consumer card.
Order buttons. For online sales outside packages, such as flight-only, accommodation-only or car hire, the button that places the order must say “order with obligation to pay” or something equally clear, and extras need the customer’s express consent rather than a pre-ticked box.
Card payments
Any business that takes card payments must meet the card industry’s data security standard, PCI DSS. It is an industry standard rather than law, and your acquirer decides how you show that you comply:
The simplest questionnaire, SAQ A, is for businesses that outsource all card handling to compliant providers and do not store, process or transmit card data on their own systems. Since 31 March 2025, a business using a payment form embedded in its own page can rely on confirmation from its compliant payment provider that the page is protected from script attacks.
Card details taken by staff are a different matter. Typing card numbers into a web-based terminal means handling card data yourself, which is unlikely to fit the simplest questionnaire, so check with your acquirer.
Card security codes must not be stored after a payment is authorised, even in call recordings.
Strong Customer Authentication applies to online card payments. Phone and mail order payments are outside it, and so are later payments taken under an agreed mandate, such as a balance, although setting up the mandate online needs authentication.
Our guide to taking payments explains these rules in more detail.
Data protection
Your software supplier will usually be a processor of your customers’ personal data, handling it on your instructions. That brings duties for you:
Choose carefully. You may only use a processor that gives sufficient guarantees about its security, and the regulator’s guidance says you should keep checking its compliance after you sign. You remain primarily responsible.
Get the contract right. It must be in writing and cover what UK GDPR requires, including acting only on your instructions, keeping data secure, using sub-processors only with your authorisation, helping you respond to people’s requests and deleting or returning all the data when the contract ends.
Know where your data goes. Ask where it is stored, processed and supported from. If a separate organisation outside the UK can access it, such as an overseas support company or contractor, that is a restricted transfer, which needs adequacy regulations, appropriate safeguards or an exception. The regulator’s own example is a UK travel company sending a family’s booking details to a hotel in Australia.
Plan for breaches. Unless a breach is unlikely to put people at risk, it must be reported to the regulator without undue delay and, where feasible, within 72 hours of becoming aware of it. Ask how quickly your supplier will tell you about one.
Two newer rules affect your website too. Since 5 February 2026, cookies used only to collect statistics about how visitors use your website, so you can improve it, can be set without consent if visitors get clear information and a simple, free way to object. The data must not be shared except to help make those improvements, and advertising and most other non-essential cookies still need consent. Since 19 June 2026, every business must have a way for people to complain about how their data is used, such as an online form, and must acknowledge complaints within 30 days.
Accessibility
No UK law sets a technical accessibility standard for private-sector websites. But the Equality Act 2010 applies to services provided through a website, and the duty to make reasonable adjustments is anticipatory: you must think about barriers before a disabled customer meets them. (In Northern Ireland, the Disability Discrimination Act 1995 applies instead.) The Equality and Human Rights Commission’s new code of practice for services, in force since 5 August 2026, uses the example of a business website with text embedded in images.
If you sell to consumers in the EU, the European Accessibility Act has applied to e-commerce services since 28 June 2025, and its definition of a service provider covers any business offering services to consumers in the EU. Microenterprises providing services, those with fewer than 10 staff and an annual turnover or balance sheet of no more than €2 million, are exempt. Ask a supplier which accessibility standard it builds to. For public sector websites, the government uses WCAG 2.2 AA.
Suppliers and content
Where your products come from shapes what your software has to connect to:
Flights. Global distribution systems hold schedules, availability and fares from many airlines. NDC is a data standard launched by IATA that lets airlines distribute their own offers to travel sellers. To issue tickets yourself you need IATA accreditation and ticketing authority from each airline, and businesses without it usually ticket through a consolidator.
Hotels. Bed banks are wholesalers that sell accommodation to the travel trade. Suppliers often require their own commercial agreement with you before you get live access, and certify the connection.
Your own contracts. If you contract rates directly with hotels or other providers, check that you can load and price them alongside live supplier content.
For each source, ask what is included, which suppliers need your own agreement or credentials, who pays any connection or per-booking fees and how cancellations and amendments work.
Being found in search
Your platform also affects how easily people find your website. Google’s own documentation says:
it indexes the mobile version of your site, so content that is missing on mobile is not indexed
its ranking systems use Core Web Vitals, which measure loading, responsiveness and visual stability, although good scores do not guarantee top rankings
pages built in the browser with JavaScript can wait in a queue to be rendered, and server-side rendering or pre-rendering is still a good idea
moving to a new platform with new web addresses needs permanent redirects from the old ones, and rankings can fluctuate for a while
there are no special optimisations needed for its AI features, and normal search best practice applies
content should add original value rather than repeat what is available elsewhere
That last point is worth bearing in mind if your pages rely on supplier descriptions that many other websites use too.
Questions to ask before you sign
Can you show us the whole process with our own recent bookings, including a tailor-made trip, a package with a flight, an amendment and a cancellation?
How does the system produce package information, standard information forms, confirmations and ATOL Certificates, and does it keep a record of what each customer was sent?
How will you handle the package travel changes on 6 April 2027, and will they cost extra?
What is the full cost, including set-up, monthly fees, per-booking or transaction charges, payment fees, supplier connection fees and training?
Which suppliers are included, and which need our own agreements?
Which payment providers do you support, and which PCI DSS questionnaire will we need to complete?
Where is our data stored, processed and supported from, and will you sign a processor contract that meets UK GDPR?
Do you hold Cyber Essentials, the government-backed minimum standard for cyber security, or another certification?
What support hours do you offer, including weekends and peak season, and how quickly do you respond?
What uptime do you commit to, and does planned maintenance count?
What are the minimum term, the notice period and the terms for price changes?
Who owns the domain, the website content and the customer data, and how do we export everything if we leave?
How will you move our data across from our current system?
Can we speak to UK travel businesses like ours that use the system?
Check your own position
This guide is general information, not legal advice. The rules that apply depend on what you sell and how, and they change, so check the official sources below and take advice on your own position before you sign a contract.
Sources
The official pages this guide draws on. Rules and fees change, so check the latest version.
The Package Travel and Linked Travel Arrangements Regulations 2018 (legislation.gov.uk)
The Package Travel and Linked Travel Arrangements (Amendment) Regulations 2026 (legislation.gov.uk)
Package holidays: guidance for businesses (GOV.UK)
ATOL Certificates (Civil Aviation Authority)
Official Record Series 3, the ATOL terms (Civil Aviation Authority)
Digital Markets, Competition and Consumers Act 2024, section 230 (legislation.gov.uk)
Digital Markets, Competition and Consumers Act 2024, Schedule 20 (legislation.gov.uk)
Price transparency, CMA209 (GOV.UK)
Fake reviews, CMA208 (GOV.UK)
The Consumer Contracts Regulations 2013, regulation 14 (legislation.gov.uk)
The Consumer Contracts Regulations 2013, regulation 40 (legislation.gov.uk)
The Consumer Rights (Payment Surcharges) Regulations 2012, regulation 6A (legislation.gov.uk)
Updates for merchants validating to SAQ A (PCI Security Standards Council)
New SAQ A eligibility criteria for e-commerce merchants (PCI Security Standards Council)
Strong Customer Authentication (FCA)
Payment Services and Electronic Money: our approach (FCA, PDF)
Responsibilities and liabilities for controllers using a processor (ICO)
Are we making a restricted transfer? (ICO)
The UK IDTA and the Addendum (ICO)
UK GDPR, Article 33 (legislation.gov.uk)
Data Protection Act 2018, section 164A (legislation.gov.uk)
The Privacy and Electronic Communications Regulations 2003, Schedule A1 (legislation.gov.uk)
Code of practice for services, public functions and associations (EHRC, GOV.UK)
Directive (EU) 2019/882, the European Accessibility Act (EUR-Lex)
Accessibility requirements for public sector websites and apps (GOV.UK)
Cyber Essentials (NCSC)
Mobile-first indexing best practices (Google Search Central)
Understanding page experience (Google Search Central)
JavaScript SEO basics (Google Search Central)
Site moves with URL changes (Google Search Central)
AI features and your website (Google Search Central)
Creating helpful, reliable, people-first content (Google Search Central)
QUESTIONS
Common questions
What should travel agency software do?
Beyond searching and booking, it should help you meet the rules: give package customers the information they must have, issue ATOL Certificates the moment a customer pays for an ATOL-protected booking, show prices that include every compulsory fee, take card payments securely and keep customer data safe.
Does my booking system need to issue ATOL Certificates?
If you sell flight-inclusive packages, or flights that need ATOL protection, a certificate must reach the customer as soon as they make a first payment, so your system or your ATOL holder’s must produce it at that point. An ATOL holder’s systems must also keep records it can make available to the CAA within 3 working days.
What changes for booking systems in April 2027?
From 6 April 2027, two or more different types of travel service for the same trip, chosen and paid for separately in a single visit to your shop or website or a single phone call, will form a package. Linked travel arrangements will no longer exist. Ask your supplier how its booking flows will handle this.
Is my software supplier responsible for data protection?
Partly. Your supplier will usually be a processor acting on your instructions, with its own legal duties. But you must choose a supplier that gives sufficient guarantees about security and have a written contract that meets UK GDPR. You should also keep checking its compliance, because you remain responsible for your customers’ data.
Do I need IATA accreditation to sell flights online?
No. Accreditation lets you issue tickets for the airlines that give you ticketing authority and settle through IATA’s Billing and Settlement Plan. Businesses without it usually ticket through a consolidator, and you can also sell flights as an agent for an ATOL holder.
HOW TRAVELGENIX HELPS
Travelgenix brings a bookable website, 200 connected suppliers, a wide range of payment providers and Travelify, our mid office, together on one travel tech platform, so your bookings run from one place.