Data Privacy 101: Understanding Wyndham’s EU–U.S. Data Privacy Framework Commitments
Protecting your personal information should feel effortless when you travel. That’s why understanding Wyndham’s EU–U.S. Data Privacy Framework commitments matters—especially if you’re a TRYP by Wyndham Aruba guest. These commitments, backed by United States Federal Trade Commission (FTC) oversight, outline how cross-border data is handled and the clear paths you have to ask questions, exercise rights, and resolve concerns.
In this guide, you’ll learn what the EU–U.S. Data Privacy Framework (DPF) is, what Wyndham has committed to, how those promises protect you, and the practical steps you can take to manage your privacy.
What is the EU–U.S. Data Privacy Framework?
The EU–U.S. Data Privacy Framework is a program administered by the U.S. Department of Commerce that establishes rules for transferring personal data from Europe to the United States. At a high level, it’s designed to ensure organizations receiving data in the U.S. protect it in line with defined Principles and provide people with accessible ways to raise and resolve privacy concerns.
Wyndham complies with the EU–U.S. Data Privacy Framework, the UK Extension to the EU–U.S. DPF, and the Swiss–U.S. DPF. Wyndham has certified that it adheres to the applicable Principles for personal data received from the European Union, the United Kingdom, and Switzerland. If there is any conflict between Wyndham’s Privacy Notice and the DPF Principles, the Principles govern.
- Learn more and view Wyndham’s certification: https://www.dataprivacyframework.gov/
Wyndham’s EU–U.S. Data Privacy Framework commitments at a glance
Wyndham’s commitments under the DPF translate into concrete protections and clear accountability:
- Certification and adherence to Principles: Wyndham has certified adherence to the EU–U.S. DPF Principles (including the UK Extension) and the Swiss–U.S. DPF Principles.
- FTC oversight: Wyndham’s EU–U.S. DPF commitments are subject to the investigatory and enforcement powers of the United States Federal Trade Commission (FTC).
- Cooperation with regulators: For unresolved complaints concerning personal data received under the DPFs, Wyndham commits to cooperate and comply with the advice of EU data protection authorities (DPAs), the UK Information Commissioner’s Office (ICO), and the Swiss Federal Data Protection and Information Commissioner (FDPIC).
- Accountability for onward transfers: When Wyndham shares your personal information with third parties working on its behalf, it may be liable under the DPF if those parties fail to meet applicable obligations, unless Wyndham demonstrates it is not responsible for the event giving rise to the damage.
- Independent recourse and arbitration: In certain circumstances, you have the right to invoke binding arbitration to resolve complaints not addressed by other means, as described in Annex I of the EU–U.S. DPF.
What these commitments mean for you
| Commitment | What it means for you |
|---|---|
| Adherence to DPF Principles | Your data transferred under the DPF is handled according to defined standards that govern collection, use, sharing, and access rights. |
| FTC oversight | There’s real accountability: a U.S. regulator can investigate and enforce Wyndham’s compliance with DPF obligations. |
| Cooperation with DPAs/ICO/FDPIC | You can seek help from European, UK, or Swiss authorities if a DPF-related concern is not resolved directly with Wyndham. |
| Onward transfer accountability | Vendors acting on Wyndham’s behalf must protect your data appropriately; Wyndham may be held responsible if they don’t, subject to DPF rules. |
| Binding arbitration option | A last-resort mechanism exists to resolve certain disputes that remain unresolved after other channels. |
How Wyndham protects your information more broadly
Beyond the DPF, Wyndham’s Privacy Notice outlines additional safeguards and choices that apply to guests, including those at TRYP by Wyndham Aruba:
- Information safeguards: Wyndham implements reasonable and appropriate physical, technical, and administrative measures to protect personal information from loss, misuse, unauthorized access or disclosure, alteration, and destruction. No security system is 100% secure.
- Retention: Personal information is kept only as long as needed to fulfill stated purposes, unless a longer period is required or permitted by law or legal process.
- Minors: Wyndham does not knowingly collect or process personal information from individuals under 18, and its Services are not directed to minors.
- Sensitive Personal Information: Wyndham does not use Sensitive Personal Information to infer characteristics about you and processes such data only for purposes permitted under applicable law.
- Automated decision-making: Wyndham does not perform automated decision-making or profiling that produces legal or similarly significant effects concerning guests.
- Global data transfers: Wyndham may transfer personal information to selected third parties outside your country and uses appropriate safeguards (e.g., adequacy decisions or model clauses), as applicable.
Your privacy choices and rights with Wyndham
Wyndham provides multiple ways to exercise privacy rights and control how your information is used.
Access, correction, deletion, objection, portability, and appeal
- Right to Know/Access: You can request access to your personal information. Under Wyndham’s Privacy Notice, you may submit Right to Know requests up to twice within any 12-month period.
- Correction: You can request correction of inaccurate or incomplete personal data.
- Erasure/Deletion: You can request deletion of your personal information; Wyndham will assess your request and determine whether deletion is permitted (e.g., no applicable legal exception applies).
- Processing objection: You may object to processing; Wyndham will assess whether it has legal or other justification for continued processing.
- Data portability/transfers: You may request your information in a portable format or direct Wyndham to transfer it to another company.
- Right to non-discrimination: Wyndham will not discriminate against you for exercising your privacy rights, as provided by applicable law.
- Right to appeal: If a request is denied, you can submit an appeal using the contact details below.
How to submit a privacy request (verification details)
When submitting a request, be prepared to provide verification details that match information on file:
- Email address
- First and last name
- Valid residential address
- Phone number
- Wyndham Rewards number (if applicable)
Contact Wyndham to submit requests:
- Email: privacy@wyndham.com
- Toll-free phone: 1-866-554-1236
Authorized agents
You may designate an authorized agent to act on your behalf by sending a written and signed authorization letter with both your and your agent’s contact details to:
- Wyndham Hotels & Resorts, Inc., 22 Sylvan Way, Parsippany, NJ 07054, Attn: Legal Privacy
Managing data sharing, marketing, and cookies
- Opt out of sale or sharing of personal information: Submit a request using Wyndham’s online form titled “Do Not Sell or Share My Personal Information” or call 1-866-554-1236.
- Marketing communications: Stop marketing emails or texts at any time by clicking the unsubscribe link in the message or by contacting privacy@wyndham.com or 1-866-554-1236.
- Cookies and tracking controls: Adjust cookie preferences at any time using the Cookie Consent tool in the footer of Wyndham websites.
- Global Privacy Control (GPC): When you visit the website, Wyndham honors supported opt-out preference signals and applies them to the device and browser you are using.
- Do Not Track (DNT): Wyndham does not currently respond to browser DNT signals.
With whom Wyndham may share your personal information
In accordance with its Privacy Notice and applicable law, Wyndham may disclose personal information to:
- Affiliates
- External service providers that perform functions such as payment processing, IT hosting, or customer service
- Business partners when necessary to fulfill or market services you request
Subject to your preferences (which may include consent), Wyndham may also license, sell, or otherwise share personal information with selected third parties for compensation for their or Wyndham’s business purposes. Once shared, that information may become subject to the third party’s privacy practices.
Quick answers for featured snippets
- Who oversees Wyndham’s EU–U.S. Data Privacy Framework commitments? The United States Federal Trade Commission (FTC).
- What if my DPF-related complaint isn’t resolved? You may seek assistance from EU DPAs, the UK ICO, or the Swiss FDPIC; in certain circumstances, you can invoke binding arbitration as described in Annex I of the EU–U.S. DPF.
- How many times can I make a Right to Know request? Up to twice within any 12-month period.
- Where can I view Wyndham’s DPF certification? https://www.dataprivacyframework.gov/
- How do I contact Wyndham about privacy? Email privacy@wyndham.com or call 1-866-554-1236.
Practical takeaways and tips
Use these steps to make the most of Wyndham’s privacy protections and your choices:
- Start with the Privacy Notice: For a full overview of practices and policies, review the TRYP by Wyndham Aruba Privacy Policy: https://tryparuba.com/privacy-policy
- Use the right channel for your request: For access, correction, deletion, portability, or objection, contact privacy@wyndham.com or 1-866-554-1236.
- Include verification details: Provide the email, full name, residential address, phone number, and (if applicable) your Wyndham Rewards number that match what Wyndham has on file.
- Set your cookie preferences: Use the Cookie Consent tool in the website footer to adjust analytics and advertising cookies.
- Leverage opt-out signals: If you use Global Privacy Control, Wyndham will honor supported opt-out preference signals for your current browser and device.
- Manage marketing easily: Unsubscribe via any marketing message or contact the privacy team to adjust your preferences.
- Know your frequency limits: Plan your Right to Know requests—up to two within a 12‑month period.
- Consider authorized agents when needed: If someone will act for you, send a signed authorization letter to Wyndham’s Legal Privacy address.
- Escalate thoughtfully: If a DPF-related concern remains unresolved, contact the appropriate DPA/ICO/FDPIC; binding arbitration may be available in certain cases.
- Safeguard minors’ data: Wyndham’s Services are not directed to individuals under 18; avoid submitting minors’ personal information.
Conclusion: Your data, your choices—backed by clear commitments
Wyndham’s EU–U.S. Data Privacy Framework commitments—certification to DPF Principles, FTC oversight, cooperation with European, UK, and Swiss regulators, onward transfer accountability, and an arbitration backstop—add a strong layer of protection for TRYP by Wyndham Aruba guests. Coupled with practical rights and easy-to-use controls, you have clear ways to access, manage, and safeguard your information.
Have questions or ready to make a request?
- Read the full Privacy Policy: https://tryparuba.com/privacy-policy
- Email: privacy@wyndham.com
- Call: 1-866-554-1236
Take control of your privacy today—review your settings, submit a request if needed, and travel with confidence.