AMLEGALS — Strategic Lawyering

Loyalty Programmes and Guest Profiling Under DPDPA

Loyalty Programmes and Guest Profiling Under DPDPA

Know your guest. Ask before you know more.

The scene

The loyalty profile knew the guest's pillow preference, her dietary needs, her travel companions, her anniversary and the bar tab from every stay. It shared segments with a partner bank. She had joined for free breakfast.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

Members agreed to the programme terms.

Terms bundle purposes; profiling and partner sharing need specific consent.

Separate the programme from the profiling.

Preferences improve service.

Service preferences and marketing profiles are different purposes.

Keep service data out of marketing unless the guest says yes.

Partner sharing

Co-branded cards and partner offers usually mean sharing member data. Each partner is a new recipient and often a new purpose.

Monday morning

01 List every data field in a loyalty profile.

02 Mark which serve the stay and which serve marketing.

03 Add a consent step for the second group.

Questions, answered plainly

Do loyalty programmes need consent under DPDPA? +

Yes, for purposes beyond the programme's core function. Profiling for marketing and sharing with partners are separate purposes requiring specific consent.

Can hotels share guest data with partner brands? +

Sharing with partners for their own purposes typically needs clear notice and specific consent. Sharing with processors needs a contract.

Sector · Hospitality & Travel Guests check out. Their passports stay. Read →

Hospitality & Travel · Deep dive Guests check out. Their passports stay. Read →

Hospitality & Travel · Deep dive The camera remembers longer than the guest stayed. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).