AMLEGALS — Strategic Lawyering

DPDPA for Hotels, Travel and Hospitality

DPDPA for Hotels, Travel and Hospitality

A photocopy at the front desk is a breach waiting for a date.

The scene

The front desk scanned every guest's ID into a shared folder. Twelve years later the folder held four hundred thousand passports and Aadhaar cards, readable by every property's reception login.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

The law requires us to take IDs.

Legal requirements cover specific records for specific periods, not a permanent archive.

Collect what the law names. Keep it as long as it says.

Loyalty data is ours.

Loyalty is a purpose; profiling guests for other uses needs its own basis.

One programme, one purpose, stated clearly.

OTAs handle their customers.

Bookings flow both ways; you are fiduciary for what you do with guest data.

Map every channel manager and OTA integration.

Travel is cross-border by nature

Section 16 permits transfers except to restricted countries. Global booking systems still need contracts and safeguards.

The full Hospitality & Travel briefing 3 deep dives

Deep dive 01 →

Guests check out. Their passports stay.

A photocopier is a data store with a paper tray.

Deep dive 02 →

Loyalty is a promise. Profiling is a different one.

Know your guest. Ask before you know more.

Deep dive 03 →

The camera remembers longer than the guest stayed.

Footage kept for no reason is evidence waiting for a question.

Monday morning

01 Find every folder of scanned IDs.

02 Set retention to what the law requires, and delete the rest.

03 Restrict reception access to the property and the stay.

Questions, answered plainly

Can hotels keep copies of guest IDs under DPDPA? +

Hotels may collect and keep ID where a law requires it, for the period it requires. Retaining ID copies beyond that, or collecting more than required, is difficult to justify under Section 8(7).

Does DPDPA allow travel companies to transfer data abroad? +

Section 16 permits transfers outside India except to countries restricted by Government notification. Contracts and safeguards are still expected, and sectoral rules may add requirements.

Sector · Gaming Your fastest-growing segment may legally be children. Read →

Sector · Government vendors The State's exemption is not your exemption. Read →

Sector · Banking & BFSI Banks keep everything. The law now asks why. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).