Guests check out.Their passports stay.

Hospitality collects the most sensitive identity documents in the most informal ways.

In one line: Hotels may collect and keep ID where a law requires it, for the period it requires. Retaining ID copies beyond that, or collecting more than required, is difficult to justify under Section 8(7).

The estate · Hospitality & TravelHover to inspect

A photocopy at the front desk is a breach waiting for a date.

The scene

The front desk scanned every guest's ID into a shared folder. Twelve years later the folder held four hundred thousand passports and Aadhaar cards, readable by every property's reception login.

Where the thinking breaks

The unclear thoughtWhat it breaksThe clearer thought
The law requires us to take IDs. Legal requirements cover specific records for specific periods, not a permanent archive. Collect what the law names. Keep it as long as it says.
Loyalty data is ours. Loyalty is a purpose; profiling guests for other uses needs its own basis. One programme, one purpose, stated clearly.
OTAs handle their customers. Bookings flow both ways; you are fiduciary for what you do with guest data. Map every channel manager and OTA integration.

Travel is cross-border by nature

Section 16 permits transfers except to restricted countries. Global booking systems still need contracts and safeguards.

The full Hospitality & Travel briefing

3 deep dives
Deep dive 01→

Guests check out. Their passports stay.

A photocopier is a data store with a paper tray.

Deep dive 02→

Loyalty is a promise. Profiling is a different one.

Know your guest. Ask before you know more.

Deep dive 03→

The camera remembers longer than the guest stayed.

Footage kept for no reason is evidence waiting for a question.

Monday morning

  1. 01Find every folder of scanned IDs.
  2. 02Set retention to what the law requires, and delete the rest.
  3. 03Restrict reception access to the property and the stay.

Questions, answered plainly

Can hotels keep copies of guest IDs under DPDPA?

Hotels may collect and keep ID where a law requires it, for the period it requires. Retaining ID copies beyond that, or collecting more than required, is difficult to justify under Section 8(7).

Does DPDPA allow travel companies to transfer data abroad?

Section 16 permits transfers outside India except to countries restricted by Government notification. Contracts and safeguards are still expected, and sectoral rules may add requirements.

Sector · GamingYour fastest-growing segment may legally be children.Read → Sector · Government vendorsThe State's exemption is not your exemption.Read → Sector · Banking & BFSIBanks keep everything. The law now asks why.Read →

Tell us where your data sits.We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner