Hotel Guest ID Copies and DPDPA: Collect What the Law Names
Hotel Guest ID Copies and DPDPA: Collect What the Law Names
A photocopier is a data store with a paper tray.
The scene
The property scanned every guest's ID into a folder named ‘ID 2012’. It grew by a thousand files a month. Every reception login across the group could open it.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
The law requires ID copies.
The law requires specific records, such as Form C for foreign guests, not a permanent archive of everyone.
Collect what the law names, keep it for the period it names.
Reception needs access to everything.
Staff need the current stay, not twelve years of guests.
Restrict access to property and stay dates.
Aadhaar at the desk
Collecting full Aadhaar numbers and copies carries its own legal restrictions. Prefer masked or verified forms, and avoid storing copies.
Monday morning
01 Find every folder of scanned IDs.
02 Set retention to what law requires.
03 Delete the rest.
Questions, answered plainly
Can hotels keep copies of guest IDs under DPDPA? +
Hotels may collect and retain ID where law requires it, such as for foreign guest reporting, for the period required. Retaining copies beyond that is difficult to justify under Section 8(7).
Should hotels store Aadhaar copies? +
Hotels should avoid storing Aadhaar copies where not required, use masked Aadhaar or verification methods, and follow Aadhaar-specific legal restrictions.
Hospitality & Travel · Deep dive Loyalty is a promise. Profiling is a different one. Read →
Hospitality & Travel · Deep dive The camera remembers longer than the guest stayed. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).