Compliance frameworks, security audits, and quality certifications this company maintains.
Expedia Group maintains PCI DSS Level 1 compliance for its payment processing infrastructure, governing secure handling of traveler credit card data across Expedia.com, Hotels.com, Vrbo, and all Expedia Group booking platforms.
Expedia Group's cloud platform and SaaS services undergo SOC 2 Type II audits, providing enterprise Open World API partners and corporate travel customers with independent assurance of security and data availability controls.
Expedia Group complies with GDPR across its European operations covering Expedia.com, Hotels.com, Vrbo, and Trivago, with data subject rights management, consent frameworks, and EU data residency controls for European traveler data.
Expedia Group complies with the California Consumer Privacy Act, providing California users with data access, deletion, and opt-out rights for personal travel booking data and behavioral targeting information used across Expedia Group brands.
Expedia Group's technology infrastructure and data centers are ISO 27001 certified, governing information security management for the systems processing 325M+ annual room nights and 145M+ One Key loyalty member records.
Expedia Group's consumer booking platforms — including Expedia.com, Hotels.com, and Vrbo — comply with WCAG 2.1 AA accessibility standards, ensuring travelers with disabilities can independently search and book travel.
Regulatory
IATA Accreditation
CertifiedExpedia Group holds IATA (International Air Transport Association) accreditation, authorizing Expedia to issue airline tickets and earn IATA commission revenue as an accredited travel agency for all major global airlines.
Regulatory
ARC Accreditation
CertifiedExpedia Group is ARC (Airlines Reporting Corporation) accredited for domestic U.S. airline ticket issuance, enabling Expedia to process and settle airline ticket sales for all ARC-participating U.S. carriers including Delta, United, and American.
Expedia Group complies with HIPAA requirements for health-related travel data handled through Expedia for Business corporate travel programs, implementing appropriate protections for employee health travel records managed through Expedia business travel tools.
Expedia Group maintains ISO 27017 cloud security certification for its travel marketplace platforms including Expedia, Hotels.com, and Vrbo, providing travelers and partners with assurance that cloud-hosted reservation and payment data is protected to international standards.