Guests check out.Their passports stay.
Hospitality collects the most sensitive identity documents in the most informal ways.
In one line: Hotels may collect and keep ID where a law requires it, for the period it requires. Retaining ID copies beyond that, or collecting more than required, is difficult to justify under Section 8(7).
A photocopy at the front desk is a breach waiting for a date.
The scene
The front desk scanned every guest's ID into a shared folder. Twelve years later the folder held four hundred thousand passports and Aadhaar cards, readable by every property's reception login.
Where the thinking breaks
Travel is cross-border by nature
Section 16 permits transfers except to restricted countries. Global booking systems still need contracts and safeguards.
The full Hospitality & Travel briefing
3 deep divesGuests check out. Their passports stay.
A photocopier is a data store with a paper tray.
Loyalty is a promise. Profiling is a different one.
Know your guest. Ask before you know more.
The camera remembers longer than the guest stayed.
Footage kept for no reason is evidence waiting for a question.
Monday morning
- 01Find every folder of scanned IDs.
- 02Set retention to what the law requires, and delete the rest.
- 03Restrict reception access to the property and the stay.
Questions, answered plainly
Can hotels keep copies of guest IDs under DPDPA?
Hotels may collect and keep ID where a law requires it, for the period it requires. Retaining ID copies beyond that, or collecting more than required, is difficult to justify under Section 8(7).
Does DPDPA allow travel companies to transfer data abroad?
Section 16 permits transfers outside India except to countries restricted by Government notification. Contracts and safeguards are still expected, and sectoral rules may add requirements.
Tell us where your data sits.We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner