At a glance
Every hotel or guesthouse is a Data Fiduciary under the DPDP Act the moment it collects a guest’s ID, contact and payment details at check-in — every stay. Hospitality carries one wrinkle: for foreign guests, a separate law (the accommodation-keeper’s duty to file Form III) requires transmitting data the Act doesn’t ask for on its own, independent of its usual consent-first approach. The exposure most properties carry is more mundane — ID photocopies kept indefinitely, registers with no access control, and guest data reused for marketing beyond what consent covered.
Educational resource only. This explains how India’s Digital Personal Data Protection Act, 2023 (DPDP Act) applies to hotels and hospitality businesses; it is not formal legal advice.
The situation
Check-in is the densest personal-data moment in hospitality — an ID document, a phone number and email, payment details, sometimes a passport for a foreign guest, all collected in a few minutes at a front desk that’s also juggling keys, luggage and a queue. That speed is exactly where the habits the DPDP Act is written against take root: full ID photocopies kept in a drawer indefinitely, a guest register anyone on shift can flip through, and contact details harvested at check-in that quietly become a marketing list.
Does DPDP apply to a hotel or guesthouse?
Yes — from a single guesthouse to a hotel chain, deciding why and how a guest’s data is used makes the property a Data Fiduciary. There’s no size exemption: a boutique homestay taking a booking over the phone carries the same baseline duties as a large chain — notice, a lawful basis, security safeguards, breach reporting, and the ability to answer a guest’s rights request. What scales with size and volume is exposure and the odds of falling into a more heavily regulated tier, not the existence of the underlying duties.
The guest data a property actually handles
Identity, contact and payment data move together at check-in, plus a distinct layer for foreign guests.
- Identity documents — Aadhaar, passport, driving licence or other government ID, often photocopied or scanned at the desk.
- Contact and booking data — name, phone, email, sometimes a home address, collected at booking and again at check-in.
- Payment data — card details or UPI information, processed at booking, check-in or checkout.
- Foreign-guest identity data — passport number, visa detail and nationality, collected specifically to meet the separate reporting duty covered below.
- Incidental data — CCTV footage covering common areas and sometimes corridors, loyalty-programme preference data, and stay-history records.
The obligation that actually bites: DPDP alongside the Form III duty
A hotel’s foreign-guest paperwork runs on two different legal tracks at once, and conflating them is where the confusion starts. Under the Immigration and Foreigners Act framework, the accommodation keeper — not the guest — carries the legal duty to electronically transmit Form III (the successor to the old Form C) for every foreign national checking in, within 24 hours of arrival, with departure reported too; missing the window carries a real penalty (₹50,000 per case). That reporting duty exists independently of the DPDP Act — it’s a legal obligation that itself supplies a lawful basis under the Act for collecting and transmitting the passport and visa data the form requires, without needing separate guest consent for that specific transmission.
Where the DPDP Act still applies fully is everything around that reporting duty: the property still needs a lawful basis and proper security for the passport copy itself once collected, can’t repurpose the foreign guest’s passport data for marketing or profiling, and still owes the same retention discipline to that data as to any other guest document — the Form III duty justifies transmitting the required fields to the authorities, not holding a scanned passport copy in the property’s own systems indefinitely.
Common mistakes hospitality properties make
Almost all of it traces back to check-in speed and outdated habits, not deliberate carelessness.
- Full ID photocopies kept indefinitely — well past the stay, with no defined deletion point.
- The guest register left accessible to anyone on shift, rather than access limited to front-desk staff actually handling that guest.
- Check-in contact details repurposed for marketing without a separate, clear consent step for that use.
- Confusing the Form III duty with a general licence — treating “we have to report foreign guests” as covering everything else done with that same passport data.
- CCTV footage retained far longer than any genuine security purpose needs, with no access log.
Collecting guest documents compliantly
A controlled front-desk intake process and a defined retention schedule close most of the gap. A notice at booking or check-in that names what’s collected and why (identity verification, the statutory foreign-guest report where applicable, payment processing), ID scanned rather than photocopied where a digital, access-controlled record is feasible, and a retention schedule that actually purges guest documents once the stay and any statutory hold period have passed — the detail on secure document handling generally is common ground across professional intake, covered in the dedicated guide below.
FAQ
Does a small guesthouse or homestay need to comply with the DPDP Act the same way a hotel chain does?
Yes — size doesn’t create an exemption. A small property carries the same baseline duties, scaled to how much data it actually handles.
Who is legally responsible for filing Form III for a foreign guest — the guest or the property?
The accommodation keeper (the property), not the guest, carries the legal duty to file within 24 hours of arrival.
Does the Form III reporting duty override a guest’s rights under the DPDP Act over their passport data?
No — it supplies a lawful basis for the specific transmission the law requires; the property still owes the same security, purpose-limitation and retention discipline to that data as to any other guest document.
Can a hotel keep photocopies of guest IDs indefinitely for “security records”?
Not indefinitely and not without a defined reason — a retention schedule tied to the stay and any specific legal requirement, not an open-ended “just in case” hold, is what the DPDP Act expects.