At a glance
The statutory duty to report a foreign guest’s arrival (via Form III, the successor to Form C) justifies transmitting specific identity fields to immigration authorities — it doesn’t set, or extend, how long the hotel itself keeps the scanned passport copy. Those are two separate clocks: the reporting duty is a one-time transmission within 24 hours of arrival, while the property’s own retention of the passport image is a question it must answer under the DPDP Act, with a defined, written stay-plus-buffer period rather than an indefinite hold.
Educational resource only. This explains how to set a retention policy under India’s Digital Personal Data Protection Act, 2023 (DPDP Act) for guest ID and passport copies, alongside the separate Form III reporting duty; it is not formal legal advice.
The situation
“We have to keep a copy for the authorities” is the reflexive justification front-desk staff give for holding onto guest ID scans indefinitely. It’s only half right: the authorities need the specific fields reported through Form III, not an indefinitely archived image sitting in the property’s own folder or PMS (property management system) three years after the guest checked out.
Two separate obligations, two separate clocks
The reporting duty is a transmission event; the property’s retention is a separate, ongoing decision. Filing Form III is a point-in-time obligation — submit the required foreign-guest details within 24 hours of arrival, and report departure too. Once that’s done, the statutory purpose for that specific transmission is served. What the property does with its own copy of the passport scan afterwards is governed by the DPDP Act’s general retention principle: keep it only as long as a genuine purpose remains, then delete it.
What actually needs to happen at check-in
- Collect the passport (or other ID) for verification and for the fields Form III requires, for foreign guests specifically — domestic guests follow the ordinary ID-verification flow without the added reporting step.
- Transmit the required fields electronically within 24 hours — the accommodation keeper’s responsibility, not the guest’s.
- Store the working copy (scan or photocopy) securely for the remainder of the stay, access-limited to front-desk and relevant back-office staff.
- Report departure as required, closing out the specific reporting obligation for that guest.
Setting a retention period for the property’s own copy
Write a specific, short retention window for guest ID scans — not “keep everything, always.” A defensible approach:
- Set a defined post-checkout retention period — commonly justified by the property’s own accounting, tax and dispute-resolution needs (a chargeback query, a lost-property claim), rather than an open-ended hold.
- Separate the retained field set from the full document image where practical — a booking record can often retain the guest’s name and dates without needing the passport image itself preserved past a short working window.
- Log the collection date so the retention clock is calculable rather than left to the front desk’s memory.
- Build the purge into the PMS or filing system, whether that means an automated deletion rule or a scheduled manual review.
Handling the scanned copy securely in the meantime
For the period the copy is genuinely needed, treat it with the same discipline as any other sensitive ID document.
- Store scans in the PMS or an access-controlled system, not a shared drive open to all staff or a personal device.
- Limit access to staff who need it for the stay — front desk and relevant back-office roles, not a general shared folder.
- Avoid emailing passport scans internally or to third parties (a travel partner, a corporate booker) without a secure channel.
- Redact or mask fields not needed for the specific purpose where the property’s systems support it — a booking confirmation doesn’t need the full passport number visible.
Hotels, guesthouses and homestays: does size change the duty?
The Form III reporting duty applies to any accommodation keeper hosting a foreign national, regardless of size — a small guesthouse or homestay carries the same statutory obligation as a large hotel chain, even without a dedicated compliance team. What genuinely changes with size is the infrastructure available to meet it well. A large hotel typically has a PMS that automates the Form III submission and can build a retention rule directly into the system; a small guesthouse or homestay owner is often filing manually and storing scans in whatever’s easiest — a phone gallery, a shared email inbox — which is precisely where the DPDP-relevant risk concentrates. The obligation doesn’t shrink for a smaller property; the practical fix does need to look different, since a five-room homestay isn’t installing enterprise PMS software. A locked, access-limited folder with a simple, written monthly-purge habit gets a small property most of the way there without needing hotel-chain infrastructure.
OTA bookings and group reservations
A booking made through an online travel agent (OTA) or a group reservation adds a data flow the property doesn’t fully control — the OTA has already collected some guest information before the guest ever reaches the front desk. An OTA typically holds the name, contact details and payment information used to make the booking, and passes a subset of that to the property; it does not typically hold the passport or ID scan itself, which is still collected directly by the property at check-in for the Form III fields. That split matters for retention: the property’s own retention clock runs only from what it collects directly, and the OTA’s separate retention of the booking data is the OTA’s own responsibility as a distinct Data Fiduciary, not something the property inherits or needs to track. For group bookings — a tour operator checking in ten guests at once — the same per-guest ID collection and Form III duty applies individually; a group booking doesn’t let a property report or retain the group as a single bundled record where individual guest identity actually needs tracking.
Digital check-in kiosks
A self-service kiosk that scans a passport and auto-fills the Form III submission moves the same data through one more system — which needs its own access and retention discipline, not an assumption that “the kiosk vendor handles it.” Kiosks speed up check-in and reduce manual data entry, but the scan typically passes through the kiosk vendor’s own software before reaching the property’s PMS, making that vendor a Data Processor in the chain. Before deploying one, worth confirming directly: does the kiosk retain a local copy of scanned images beyond the transaction, and for how long; does its own retention default match the property’s chosen window, or does it need to be configured down; and is the vendor under a written agreement covering security and deletion, the same as any other processor touching guest ID data.
Franchise and multi-property chains
A franchise brand and its individually-operated properties are usually separate legal entities, which means a franchisor’s head-office retention policy doesn’t automatically bind a locally-owned franchisee’s actual practice unless it’s built into the franchise agreement and the property’s own systems. Chains benefit from setting one retention standard across every property and building it into whatever PMS the brand mandates — consistency is easier to audit and easier to explain to guests. Where properties operate more independently under a shared brand, each one is still the Data Fiduciary for its own guest data and needs its own working retention practice, not an assumption that the brand’s general privacy notice covers what actually happens at the property level.
FAQ
Does the Form III filing requirement mean a hotel must keep a passport copy forever?
No — filing Form III is a one-time reporting obligation for the required fields; it doesn’t justify indefinite retention of the passport image itself. That’s a separate retention decision under the DPDP Act the property sets on its own schedule.
How long should a hotel keep a guest’s ID scan after checkout?
There’s no single DPDP-mandated number — set a defined, written period tied to genuine ongoing needs (billing disputes, accounting records), then delete. An indefinite hold with no defined endpoint is the pattern to avoid.
Do domestic guests’ ID documents follow the same retention logic?
Yes — the Form III reporting duty is specific to foreign nationals, but the underlying DPDP retention principle (keep only as long as a purpose remains, then delete) applies to every guest’s ID documents, foreign or domestic.
Who is responsible if a stored passport scan is leaked after checkout?
The property, as the Data Fiduciary holding the data — the Form III reporting duty to the authorities doesn’t transfer or reduce the property’s own security and retention responsibility for its retained copy.
Does a small guesthouse or homestay have the same Form III duty as a big hotel?
Yes — the statutory duty applies regardless of size. What differs is infrastructure, not obligation: a smaller property needs a simpler, manual version of the same access-control and retention discipline a larger hotel builds into its PMS.
Does an OTA’s collection of my guest’s data become the hotel’s responsibility?
No — the OTA is a separate Data Fiduciary for the booking data it collects; the property’s own retention duty covers only what it collects directly, typically the ID scan taken at check-in.