A woman assaulted at a Travelodge in Maidenhead has called for hotels to get a guest’s consent before giving room access to anyone not listed on the booking. Travelodge says it has tightened key-issuing procedures and introduced other security measures, but an independent review published in September 2026 found that important safeguards were still not being applied consistently in practice.
What happened in the Maidenhead and York cases?
The two incidents were reported in different years and places, with different circumstances. Both raise questions about how hotels verify requests for access to an occupied room.
Maidenhead: an assault after a false claim
According to Irwin Mitchell, a woman was assaulted at a Travelodge in Maidenhead in December 2022 after a man falsely claimed to be her boyfriend and obtained a keycard to her room. He was convicted and sentenced in January 2026. In March 2026, the woman urged hotels to review their safety policies and said they should obtain consent from the person staying in a room before giving access to someone not listed on the booking.
York: a separate reported incident
ITV reported that a woman identified by the pseudonym Sarah was harassed in the lobby of a Travelodge in York in June 2025. She said the man learned her room number and obtained a key. Travelodge acknowledged that its room-access policies at the time had not been followed correctly and described policy changes made afterward.
#1 Best Overall
What does Travelodge say it has changed?
Travelodge’s announcements describe measures rolled out across its hotels. They are company-reported changes, not independently verified outcomes.
- Additional or replacement keys: Travelodge says a key now requires explicit permission from the person or people staying in the room, and that customer-facing staff received training on the rule.
- Doors and overnight security: The company reports a full deadbolt audit across UK rooms, secondary deadbolts on key-card-operated doors, 24-hour reception and regular overnight security walks.
- Room information and allocations: Travelodge says room numbers are written or shown rather than spoken aloud, and that it uses room-allocation practices for solo female travellers where possible.
- Monitoring: The company reports ongoing audits and mystery-shopping activity.
In its September 2026 update, Travelodge said it had published the independent review led by Paul Greaney KC and established a board committee to oversee implementation. It also committed to independent progress assessments after six and 12 months. As of 3 October 2026, those assessments were commitments, not completed findings.
Rank #2
What did the independent review find?
Greaney KC’s review, dated 21 September 2026, made 38 recommendations. It concluded that Travelodge had made meaningful reforms but that material room-security weaknesses remained and procedures were not sufficiently embedded in day-to-day practice.
Tests identified weaknesses, but do not establish a chain-wide failure rate
- Housekeeping access: In a stress test of five hotels, the review team said it obtained access to a room through housekeeping at all five without being redirected to reception or asked to prove entitlement. This was a limited test, not an estimate of how often the problem occurs across the chain.
- Replacement keys: In the small number of replacement-key cases tested, the correct procedure was not followed in 50% of cases. Greaney cautioned that the sample was small; that figure is not a representative failure rate for all key requests.
- Customer reports: In the four weeks before 6 August 2026, 91% of Travelodge hotels had no customer-reported room intrusion, while reports covered nearly one in ten hotels. This records customer reports in that period; it does not count every actual incident or measure the general risk of a hotel stay.
What the review recommends
The recommendations cover policy, day-to-day access control and management oversight. They include:
Free tools Windows power users keep installed
One-click scans. No signup required.
- a comprehensive violence-against-women-and-girls policy and training;
- clearer key-security procedures, more effective staff training and clear rules for housekeeping access;
- better protection of guest details at points such as breakfast;
- broader, more comprehensive mystery shopping and technology or access-control changes;
- a risk-benefit assessment of secondary door locks; and
- independent reviews after six and 12 months.
The reviewer also said that room-intrusion risk is not unique to Travelodge and deserves attention across the accommodation sector. That is a call for sector-wide attention, not a quantified estimate of incidents across hotels.
What should a hotel do before giving someone access to a room?
UKHospitality’s Guest Security: Hospitality Industry Principles and Good Practice, published on 27 August 2026, offers voluntary sector guidance. It is not legislation or a binding universal standard: operators are expected to adapt it through risk assessment, training and operational planning, because there is no single solution for every accommodation setting.
Rank #4
- Protect guest presence and room details. As a general rule, staff should not confirm whether a named person is staying at the property and should avoid unnecessarily disclosing room numbers.
- Verify requests for keys or digital credentials. Treat replacement keys as access-control decisions, not routine customer-service requests. UKHospitality says photo ID is the most secure form of verification, while noting there is no legal requirement to show photo ID and a guest may not have it available. Staff need an effective, proportionate way to verify entitlement in those circumstances.
- Check authorization for an unlisted person. Appearance, familiarity or knowledge of booking details alone should not establish a right to enter. Seek appropriate verification and confirmation from the named guest before granting access.
- Apply consistent procedures across teams. Reception and housekeeping staff should know the same rules, have a way to escalate unusual requests and receive training and management support.
- Learn from incidents and near misses. Review guest feedback, reported incidents and procedures over time, and adapt controls to the property’s risks and operating context.
Greaney’s review says no law mandates a particular method for hotels to achieve room safety, while noting that general criminal, civil and employment law still applies. The review’s point is about the absence of a prescribed hotel-security method, not an exemption from other legal duties.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why does implementation matter as much as policy?
A rule can be well designed and still fail if staff do not know it, cannot apply it consistently or lack support when a request is unusual. The review’s housekeeping and replacement-key findings illustrate why a hotel’s safeguards need to work across departments, not just at reception or in written policy.
UKHospitality frames guest security around five principles: security comes first; privacy is part of security; verification should be proportionate but effective; well-trained staff are the strongest safeguard; and arrangements should improve continually. These principles connect information handling, access decisions, staff practice and follow-up rather than treating room locks as the sole answer.
Secondary locks may add a layer against entry by someone who has a key but lacks authorization. The review recommends assessing their risks and benefits rather than assuming one device is suitable for every door. A personal portable lock, if a guest chooses to use one and it is compatible with the door, cannot replace the hotel’s responsibility to control keys and credentials properly.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




