Reviewed on 7 August 2026.
Important: This guide gives general information, not legal or tax advice. Hotels should review their own duties, systems, and procedures with a qualified German tax adviser.
Hotel accounting data rarely stays in one place. Reservations create invoices, payments, refunds, deposits, and accounting exports. The PMS may exchange data with sales, payment, document, and accounting platforms. Germany’s GoBD can affect this whole chain.
GoBD is the German abbreviation for principles on digital records and data access. It is not a product certificate. The rules examine people, source documents, systems, interfaces, controls, and exports. They also examine permissions and written procedures.

This image appeared in HotelFriend’s original 2021 article. It does not prove that any product or process meets the GoBD.
What GoBD is and who it applies to
The GoBD explain the tax authority’s view of duties for digital records. Legal foundations include the Abgabenordnung. The Commercial Code and VAT Act may also apply. Precise duties depend on the business, transaction, and legal obligation.
The taxpayer remains responsible for proper records. This remains true when a hotel uses cloud software, a data centre, or a tax adviser. A vendor can supply useful controls, but outsourcing does not transfer the hotel’s legal responsibility.
Which BMF guidance applies in 2026?
The base text is the Federal Ministry of Finance letter dated 28 November 2019. It applied to tax periods beginning after 31 December 2019. The Ministry amended that text on 11 March 2024, with effect from 1 April 2024.
A second amendment followed on 14 July 2025 and took immediate effect. It addressed several legal changes. One reason was mandatory e-invoicing for certain domestic business transactions from 1 January 2025.
On 7 August 2026, the BMF index still listed July 2025 as the second amendment. Current work needs the 2019 text plus both amendments. Check for later guidance after this article’s review date.
The primary references are the official GoBD text and the 14 July 2025 amendment.
Traceability, auditability, and complete records
The GoBD list several connected principles. Records must be traceable and open to review. Relevant transactions must be complete, accurate, timely, and ordered. Record individual items when the underlying rules require it. These standards apply throughout each retention period.
Traceability works in both directions. An auditor should be able to move from a source document through entries and accounts to a tax return. The reverse path should also be possible. Links, identifiers, and process documentation help preserve that chain.
Immutability and change logs
Section 146(4) of the Abgabenordnung protects the original content of bookings and records. A later change must not hide the earlier content. It must also remain clear whether an entry was original or added later.
Immutability does not mean errors can never be corrected. A correction needs a visible trail. Users must be able to identify the original entry, the correction, and the fact that a change occurred.
Before selecting software, test the correction workflow. Ask what follows a finalized invoice or closed cash period. Check who can reverse, cancel, or amend entries. The log should preserve the user, time, old value, and new value. It should also preserve the reason.
Electronic documents and archiving
Electronic retention must preserve more than a readable page. Incoming electronic business records generally remain in the format received. Data and documents created by a processing system generally remain in their original format.
Conversion can be allowed under set conditions. It must not change content or lose required information. It must preserve machine review and tax access. Document the conversion process.
Retention periods differ by document class. Section 147(3) AO sets several periods. Certain books and organization records have a ten-year period. Booking vouchers have an eight-year period. Other listed records may have a six-year period. Other rules can extend retention. Do not use one deletion date for every file.
Word, Excel, PDF, and editable files

The GoBD do not ban Word or Excel by product name. The risk comes from how an editable file is used. The guidance gives an impermissible example involving cash or merchandise data. The data is exported to an Office program, edited without logging, and imported again.
PDF is not automatically compliant or non-compliant. It may be an original, generated, or converted document. It may also contain structured data. Each case has different retention needs.
Converting structured cash, merchandise, or journal data into PDF can destroy machine readability. A PDF/A-3 invoice may contain embedded XML. Flattening it into an image can remove the structured component. A visible page is therefore not always the complete electronic record.
Cloud storage and shared folders
It is inaccurate to say that Dropbox, Google Drive, or every cloud service is automatically not GoBD-compliant. The official text expressly includes cloud-operated systems. It does not determine conformity from a provider’s name.
A simple shared folder may not provide enough protection. Ordinary file storage often needs added safeguards. Check permissions, version history, deletion controls, and retention settings. Also check metadata, exports, backup, and recovery.
E-invoices and structured data
The 2025 amendment gives structured e-invoices more precise treatment. At least the structured part must remain intact in its original form. A printout or visual PDF alone cannot replace that data.
Hybrid formats require care. ZUGFeRD can combine a readable image with structured information. Extra tax-relevant content in the readable part may also require retention. See the BMF’s official e-invoice FAQ.

Digital cash books in hotel workflows
A digital cash book can organize cash income, expenses, receipts, and daily balances. Integration with billing or point-of-sale systems may reduce repeated entry. It does not make every posting correct.
Cash records need particular care. Section 146(1) AO says cash income and expenses should be recorded daily. A hotel should confirm its exact recording duties and chosen method with a tax adviser.
The workflow should preserve each source transaction and document. It should keep chronological order and prevent silent overwriting. Corrections must remain visible. Define controls for cash counts, shifts, discrepancies, deposits, refunds, and closing balances.
Automatic postings can reduce manual work. They can also repeat wrong mappings or tax codes. Hotels still need reconciliation and exception review. Automation does not guarantee correct accounting.
Procedural documentation and internal controls
The GoBD call for clear, current procedural documentation, or Verfahrensdokumentation. It should explain each relevant digital procedure. Cover its content, structure, flow, and results.
A skilled third party should understand the process within a reasonable time. The document must describe the system in use. Include relevant versions and historical changes.
Official examples include access rules and separated duties. They also include input checks, reconciliations, and processing controls. Software may supply tools, but the hotel must configure and operate them.
Tax audits and data availability
Section 147(6) AO gives the tax authority several access methods during an external audit. It may use read-only access within the system. It may require analyses performed by the taxpayer or a third party. It may also request data in a machine-readable and analyzable format.
A visual report may not be enough. Metadata, master data, transactions, links, and structure details may be required. The authority chooses a lawful method and must act proportionately.
Tax risks of inadequate records
No single consequence follows every defect. Section 158 AO addresses when books and records receive evidentiary weight. Section 162 AO allows the tax authority to estimate the tax base in defined situations. Missing required records or unusable records can be relevant.
The result depends on the defect and facts. Weak process documents are not always a weighty formal defect. A specific case may still remain traceable and open to review.
Input tax deduction is a separate VAT issue under section 15 UStG. A GoBD defect does not automatically remove every deduction. A tax adviser should assess the actual transaction and invoice.
What hotels should check in software
Ask vendors for evidence tied to the current release and planned configuration. Review:
- ● Tax records created, received, changed, retained, and exported.
- ● Correction, cancellation, deletion, and period-lock workflows.
- ● User roles, permissions, approvals, and separated duties.
- ● Source documents and structured e-invoice retention.
- ● Machine-readable exports and structure descriptions.
- ● Backup, restore, retention, migration, and contract exit.
- ● Process documents supplied to customers.
- ● Release and configuration change records.
- ● Controls assigned to the hotel or tax adviser.
A certificate or expert report may inform vendor selection. It does not bind the tax authority. General findings cannot cover every system setup. Actual configuration and use still matter.
What HotelFriend can responsibly claim

HotelFriend’s public pages describe a digital Cash Book, accounting exports, timestamps, and controls for closed periods. They also market support for GoBD-related workflows. These are first-party product statements.
This review received no independent report for a defined HotelFriend version and setup. It did not test logs, source formats, exports, backups, or e-invoice data. This article therefore does not certify HotelFriend as GoBD-compliant.
Hotels considering HotelFriend products should request current evidence and involve their tax adviser. HotelFriend should confirm the module, version, setup, controls, and evidence before making broad claims.
Conclusion
GoBD readiness comes from the complete hotel process, not a storage brand or software label. Map each tax-relevant record from creation or receipt through correction, export, and final retention. Include every connected system and interface.
Then document responsibilities, permissions, controls, recovery, and system changes. Test the workflow with real examples and preserve the evidence. Suitable software can support this work, but disciplined operation and qualified tax review remain essential.






