Are you need IT Support Engineer? Free Consultant

Guest Data Privacy for Hotels: DPDP Act Compliance India

  • August 14, 2026

Quick Answer

Hotels in India collect extensive personal data from Aadhaar and passport details to health records and CCTV footage that falls under the Digital Personal Data Protection Act, 2023. As Data Fiduciaries, hotels must obtain purpose-specific consent, limit data retention, sign Data Processing Agreements with all vendors, and report breaches within prescribed timelines. Full enforcement is expected by May 2027.

A hotel guest’s check-in creates more personal data than a bank account opening. Passport details, Aadhaar numbers, credit card information, room preferences, dietary requirements, health conditions collected at the spa, CCTV footage, and location data all of it qualifies as regulated personal data under the Digital Personal Data Protection Act, 2023. Hotels sitting on this volume of data without a structured compliance programme carry significant legal exposure.

This guide breaks down exactly what data hotels collect, what the Digital Personal Data Protection Act, 2023 requires of them, and how to build a compliance framework that holds up when enforcement begins. 

What Guest Data Does a Hotel Collect?

Hotels collect personal data across multiple touchpoints at the front desk, through online travel agencies, at the spa, and across property surveillance systems. The table below maps each data category to its collection point and sensitivity level under the Digital Personal Data Protection Act, 2023.

Data Category

Where Collected

Sensitivity Level

Identity documents (passport, Aadhaar, driving licence)

Front desk check-in, online booking forms

High – government-issued identifiers

Payment card data

POS terminals, online payment gateways

High – financial data

Contact details (email, phone, address)

Booking forms, loyalty programme registration

Standard personal data

Room preferences (floor level, pillow type, temperature)

Guest profile, reservation system

Standard personal data

Dietary restrictions

Restaurant and room service orders

Sensitive may reveal religion or health

Health conditions

Spa intake forms, F&B allergy declarations

Sensitive personal data

CCTV footage

Property-wide surveillance systems

High biometric-adjacent

Location data

Wi-Fi network logs, keycard access records

Standard to high depending on use

Loyalty programme history

CRM and property management systems

Standard personal data

Wi-Fi usage data

Guest internet access portals

Standard to high depending on content

Review and feedback data

Post-stay surveys, third-party review platforms

Standard personal data

Each category triggers different obligations under the Digital Personal Data Protection Act, 2023. Health data from the spa, dietary data that reveals religious belief, and CCTV footage all attract heightened compliance requirements.

DPDP Act 2023: What It Means for Hotels

Under the Digital Personal Data Protection Act, 2023, hotels are classified as Data Fiduciaries. This means hotels determine the purpose and means of processing guest personal data. That classification carries direct, enforceable obligations.

What Does "Consent for Every Processing Purpose" Mean for Hotels?

The Digital Personal Data Protection Act, 2023 requires hotels to obtain free, specific, informed, and unconditional consent from guests before processing their personal data. Critically, consent must be sought separately for each distinct processing purpose.

A single privacy policy buried in a booking confirmation does not satisfy this requirement. If a hotel collects a guest’s email address for the reservation and then wants to use that same email address for marketing communications, it must obtain a separate, explicit consent for the marketing purpose. Bundled or blanket consent is not valid under the Act.

Hotels must also provide guests with a clear mechanism to withdraw consent at any time. Withdrawal must be as simple as the original act of giving consent. Once consent is withdrawn, the hotel must cease processing for that purpose and delete the relevant data unless another legal basis for retention applies.

How Should Hotels Handle Sensitive Health Data from Spas and F&B?

Health information collected at the spa including medical history, allergies, or physical conditions documented in intake forms qualifies as sensitive personal data under the Digital Personal Data Protection Act, 2023. Dietary restrictions that reveal religious belief or medical conditions carry the same classification.

Hotels must:

  1. Collect health and dietary data only where operationally necessary and proportionate to the stated purpose
  2. Obtain explicit, specific consent before collecting any sensitive personal data
  3. Restrict access to sensitive data to only those staff members who require it to deliver the service
  4. Store sensitive data separately from standard guest profile data, with enhanced access controls
  5. Delete sensitive data as soon as the purpose for which it was collected has been fulfilled

A spa intake form that asks for health conditions but routes that data into the general guest CRM without restriction is a direct compliance failure under the Act.

What Does Data Minimisation Require in Hotel Operations?

Data minimisation under the Digital Personal Data Protection Act, 2023 prohibits hotels from collecting personal data beyond what is adequate, relevant, and necessary for the stated processing purpose.

In practice, this means reviewing every data collection point across the property. A front desk that captures date of birth for all guests when only passport number and nationality are legally required for Form C registration is over-collecting. A spa intake form that asks for a guest’s full medical history when only known allergies are operationally necessary is over-collecting. Each data field collected must have a documented justification tied to a specific processing purpose.

What Retention Limits Apply to Guest Personal Data?

The Digital Personal Data Protection Act, 2023 does not prescribe universal fixed retention periods. Instead, it requires hotels to retain personal data only for as long as the purpose for which it was collected continues to be served.

Hotels must establish documented retention schedules by data category. The schedules below represent recommended compliance benchmarks:

Data Category

Recommended Retention Period

Legal Basis for Retention

Form C registration data (foreign nationals)

5 years from check-out

Foreigners Act, 1946 / State Police requirements

Payment card transaction records

7 years from transaction date

Income Tax Act, 1961 / PCI-DSS requirements

Invoice and GST records

7 years from financial year end

Central Goods and Services Tax Act, 2017

Health and spa intake data

30 days post check-out unless ongoing treatment

DPDP Act 2023 data minimisation principle

CCTV footage

30 to 90 days depending on property policy

Internal security requirement not indefinitely

Marketing consent records

Duration of consent plus 2 years

DPDP Act 2023 accountability obligation

Loyalty programme data

Duration of membership plus reasonable period

Contractual necessity

Retention schedules must be documented, operationalised within the hotel’s property management system, and subject to regular audit.

What Are a Hotel's Obligations When a Data Breach Occurs?

The Digital Personal Data Protection Act, 2023 requires Data Fiduciaries to notify the Data Protection Board of India and the affected Data Principals upon becoming aware of a personal data breach. The notification must describe the nature of the breach, the categories and approximate volume of data affected, the likely consequences, and the measures taken or proposed to address it.

Hotels must have a documented data breach response plan before a breach occurs. The plan must assign clear responsibilities, set internal escalation timelines that precede the Board notification deadline, and include a communication template for affected guests.

How Does the DPDP Act Apply to Foreign Guest Data Processed at Indian Hotels?

The Digital Personal Data Protection Act, 2023 applies to the processing of digital personal data within India. It also applies to processing outside India where the purpose of that processing is to offer goods or services to individuals located in India.

For hotels, the practical consequence is direct: personal data collected from foreign nationals at Indian hotel properties, passports, credit cards, health conditions, CCTV footage is subject to the full requirements of the Act. The guest’s nationality does not determine whether the Act applies. The location of processing does.

Hotels accommodating international travellers, particularly properties in business destinations such as Chennai, Bangalore, and Hyderabad, or leisure destinations such as Kochi, must ensure their guest data practices meet the Act’s requirements regardless of where the guest is ordinarily resident.



CCTV Data: What Consent and Retention Obligations Apply?

CCTV surveillance across hotel properties captures significant volumes of personal data continuously. Hotels cannot rely on the absence of a signed form to claim that guests consented to CCTV recording. The Digital Personal Data Protection Act, 2023 requires that consent be demonstrably obtained.

For CCTV specifically, posted signage constitutes constructive notice. Hotels that display clear, visible notices at all entry points and surveillance areas informing guests that CCTV is in operation for stated security purposes satisfy the constructive notice requirement. Those notices must specify:

  1. That CCTV recording is in operation
  2. The purpose of the recording (security and safety)
  3. The hotel’s data controller identity and contact details
  4. The retention period applicable to the footage

CCTV footage must not be retained beyond the period necessary for its security purpose. A retention period of 30 to 90 days is a defensible operational benchmark for most hotel properties. Footage retained beyond this period without a specific legal justification (such as an ongoing police investigation) creates unnecessary compliance exposure. Access to CCTV systems must be restricted to authorised security personnel, with access logs maintained.

What Obligations Apply When Hotels Share Guest Data with Third Parties?

Hotels operate within a complex ecosystem of third-party vendors. Online travel agencies, property management system providers, channel managers, payment processors, food delivery partners, shuttle service operators, and marketing platforms all receive guest personal data in the ordinary course of hotel operations.

Under the Digital Personal Data Protection Act, 2023, hotels remain responsible for the personal data they share with these third parties. Every vendor that processes guest data on the hotel’s behalf qualifies as a Data Processor, and the hotel must execute a Data Processing Agreement with each of them.

A Data Processing Agreement must:

  1. Specify the categories of personal data being shared
  2. Define the permitted purposes for which the Data Processor may use that data
  3. Prohibit the Data Processor from using guest data for any purpose beyond what is specified
  4. Require the Data Processor to implement appropriate technical and organisational security measures
  5. Specify what the Data Processor must do with the data upon termination of the agreement (return or deletion)
  6. Require the Data Processor to notify the hotel promptly in the event of a breach affecting guest data

Online travel agencies present particular complexity. OTAs receive guest data before the hotel does, acting as Data Fiduciaries in their own right at the point of booking. Hotels must review their OTA agreements and ensure that the data shared with the hotel by the OTA is received under terms consistent with the Digital Personal Data Protection Act, 2023. For a detailed analysis of legal obligations in hospitality business relationships, refer to our Legal Guide for Hospitality Businesses in India.

DPDP Compliance Checklist for Hotels

The eight-point checklist below provides a structured starting point for hotel compliance teams, operations heads, and general managers responsible for guest data in Indian hotel properties.

  1. Map every data collection point. Audit all touchpoints, front desk, booking forms, spa intake, Wi-Fi portals, loyalty registration, CCTV, and third-party platforms and document what personal data each point collects, for what purpose, and where that data flows.
  2. Implement purpose-specific consent mechanisms. Replace blanket privacy policies with layered consent notices that seek separate, explicit consent for each processing purpose, particularly for marketing communications, third-party sharing, and sensitive data collection.
  3. Classify sensitive data and restrict access. Identify all health, dietary, and biometric-adjacent data collected across the property. Implement access controls, storage segregation, and processing restrictions appropriate to the sensitivity of the data.
  4. Establish documented retention schedules. Set and operationalise retention periods for each data category within the property management system. Build automated deletion or anonymisation workflows where technically feasible.
  5. Post CCTV notices at all surveillance points. Ensure signage at every entry point and surveillance zone meets the constructive notice standard under the Digital Personal Data Protection Act, 2023.
  6. Execute Data Processing Agreements with all vendors. Audit every third-party relationship that involves guest personal data OTAs, PMS providers, payment processors, marketing platforms and execute compliant Data Processing Agreements with each.
  7. Implement PCI-DSS controls for payment card data. Payment card data requires compliance with the Payment Card Industry Data Security Standard independently of the Digital Personal Data Protection Act, 2023. Both frameworks apply simultaneously to card data collected at hotel properties.
  8. Prepare and test a data breach response plan. Draft a response plan that assigns named responsibilities, sets internal escalation timelines, and includes a Data Protection Board of India notification protocol. Test the plan annually.

For a comprehensive breakdown of the Digital Personal Data Protection Act, 2023 obligations applicable across industries, refer to our complete DPDP Act guide.

Build Your Hotel's Guest Data Compliance Framework Now

Phase III full enforcement of the Digital Personal Data Protection Act, 2023 is expected by May 2027. That timeline is shorter than it appears. Building a compliant consent management system, executing Data Processing Agreements with all OTA and vendor relationships, establishing retention schedules, and training front-of-house and spa staff on data handling obligations all require structured lead time.

Hotels that begin now will complete compliance implementation before enforcement pressure arrives. Hotels that delay will be working against a regulatory deadline.

Altacit Global advises hotels and hospitality businesses on every aspect of Digital Personal Data Protection Act, 2023 compliance guest consent management, Data Processing Agreements with OTAs and third-party vendors, data breach response planning, retention schedule design, and staff training frameworks. Our hospitality compliance practice operates across offices in Chennai, Bangalore, Hyderabad, and Kochi.

Contact Altacit Global at info@altacit.com to schedule a compliance consultation with our team.

For broader legal context on operating a hospitality business in India, refer to our Legal Guide for Hospitality Businesses in India.

Frequently Asked Questions: Hotel Data Privacy India

Hotels cannot retain personal data indefinitely after a guest checks out. The Digital Personal Data Protection Act, 2023 requires deletion once the purpose for which data was collected is fulfilled. In practice, retention periods vary by data category. GST invoice records must be retained for 7 years under the Central Goods and Services Tax Act, 2017. Form C registration data for foreign nationals must be retained as required under the Foreigners Act, 1946. Health and spa data should be deleted within 30 days of check-out absent an ongoing treatment relationship. Hotels must document retention schedules for every data category and operationalise them within their property management systems.

No. The Digital Personal Data Protection Act, 2023 prohibits hotels from using personal data collected for one purpose such as completing a reservation for a different purpose, such as sending marketing communications, without obtaining separate and explicit consent for that new purpose. A pre-ticked marketing consent box in the booking form does not satisfy the Act’s consent requirements. Hotels must implement distinct, affirmative consent mechanisms for marketing use cases, and must provide guests with a simple mechanism to withdraw that consent at any time.

Yes. The Digital Personal Data Protection Act, 2023 applies to the processing of personal data within India. The nationality of the guest does not affect the Act’s applicability. Personal data collected from a foreign tourist at an Indian hotel property including passport details, payment information, health conditions, and CCTV footage is subject to the full requirements of the Act. Hotels in cities with high international visitor volumes, including Chennai, Bangalore, Hyderabad, and Kochi, must ensure their compliance frameworks cover all guests regardless of nationality.

Hotels must comply with both the Digital Personal Data Protection Act, 2023 and the Payment Card Industry Data Security Standard for payment card data. PCI-DSS requires hotels to maintain a secure network and systems, protect stored cardholder data, maintain a vulnerability management programme, implement strong access control measures, regularly monitor and test networks, and maintain an information security policy. Hotels that process, store, or transmit card data must validate PCI-DSS compliance annually, either through a Qualified Security Assessor or a self-assessment questionnaire, depending on transaction volume. Failure to comply with PCI-DSS creates liability toward card-issuing banks and payment networks independently of any DPDP Act enforcement action.

This Web site is not intended to be a source of advertising or solicitation and the contents of the web site should not be construed as legal advice. The reader should not consider this information to be an invitation for a client relationship.