The Indian hospitality sector encompassing restaurants, hotels, Airbnb’s and other hospitality establishments is no stranger to handling vast amounts of personal data. From guest information, employee data, to transaction records, this sector deals with a plethora of sensitive information daily and are often considered as “Repositories of Personal Data”.
Now that the Digital Personal Data Protection Act, 2023 (hereinafter referred to as “DPDP Act”) has come into force with the notification of the Digital Personal Data Protection Rules, 2025, hotels are now undergoing a significant transformation. The 18-month compliance window has prompted hotels and related companies to move quickly, review long-standing contractual frameworks, and put robust data protection measures in place across their systems.
The DPDP Act, which draws much of its underlying philosophy from the European Union’s General Data Protection Regulation, squarely applies to the Hospitality sector. Hotels, by the very nature of their operations, act as “Data Fiduciaries” since they routinely collect and process personal data of various stakeholders such as “Guests, Employees/Workforce, Vendors, Website Users and other categories of individuals.” Large hotel groups or chains which have an established presence in India or those which offer services in India, may additionally be classified as “Significant Data Fiduciaries” depending upon the scale and sensitivity of processing, which may trigger enhanced compliance obligations under the DPDP Act.
The DPDP Act governs personal data in digital form as well as non-digital data that is subsequently digitized, making it relevant for legacy guest records converted into electronic systems.
Why hotels are revising contracts?
1. Multiple data stakeholders – Hotels do not operate in isolation. Personal data of various stakeholders as listed above is routinely shared with international hotel operators, franchise partners, property owners, online and travel agencies, marketing vendors, payment gateways, IT service providers etc. which creates overlapping responsibilities.
2. Cross-border data flows – Large hotel chains, particularly those operating under international brands or global management structures, often transfer personal data of guests, employees/workforce or other stakeholders across jurisdictions. Beside this, personal data may be stored in centralized systems or global databases maintained by parent entities or cloud databases located outside India.
3. Liability exposure – The DPDP Act has introduced significant financial penalties for non-compliance or mishandling with personal data with the maximum amounting upto INR 250 crores (27 million US Dollars).
4. Overlapping responsibilities – In the hotel ecosystem, the roles are rarely fixed. The same entity may act as a Data Fiduciary in one arrangement and as a Data Processor in another. For instance, an online travel agency may act as a Data Fiduciary while collecting booking details on its own platform and the hotels may act as Data Processors. It may also act as a Data Fiduciary for its own operational purposes. In such scenarios, determining who controls the data, who bears primary compliance obligations, and who is responsible in the event of a breach becomes complex.
Modern hotels collect personal data across the entire guest lifecycle. This creates multiple data touch points which is explained below –
1. Pre-arrival and booking stage – At this stage, hotels collect data to enable reservations and personalize the stay. Personal Data collected may include –
Guest identity details such as name, contact information, and nationality
Booking credentials and reservation history
Payment information for advance payments or guarantees
Preferences related to room type, food, accessibility, or special requests
Data received from third-party booking platforms and travel agents
2. Check-in and on-property stay – During check-in and throughout the stay, operational systems collect additional personal and behavioral data:
Government-issued identity documents for verification
Loyalty programme details and membership IDs
Room access logs and key-card or digital lock usage
Usage of hotel facilities such as spa, gym, Wi-Fi, and in-room services
Location and activity data through hotel mobile applications and smart devices
3. Post-departure and guest engagement – Even after check-out, hotels continue to process personal data for service improvement and marketing:
Guest feedback, surveys, and complaint records
Review platform interactions and ratings
Marketing communication preferences and campaign responses
Retention and loyalty programme engagement data
1. Cloud-based booking and property management systems – Cloud-based booking and property management systems (PMS) are web-based software hosted on remote servers, enabling hotel and property managers to manage operations like bookings, check-ins, payments, and housekeeping in real-time from any device with internet access. However, it also means that a single vulnerability, misconfiguration or breach at the vendor level can expose guest data across several hotels at once.
2. Third-Party Integrations – Hotels connect with travel agents, online travel agencies and CRM providers. When any of these partners is compromised, guest data can leak. Italian authorities confirmed a hack across several hotels where identity documents and passport scans were stolen and offered for sale online after attackers accessed a shared booking system.
3. Aadhaar data collection – Hospitality firms are attractive targets for cyberfraud because of the mix of sensitive personal data they hold, one of them being Aadhaar cards or other government identity documents. Aadhaar card serves as the master key to India’s entire financial ecosystem, from personal loans to digital payments and even credit scoring, It also includes biometric data of individuals. Hotels collect Aadhaar cards to verify the identity of guests, and even request photocopies or pictures on WhatsApp. The same is circulated through vendors, security guards and front desk staff with no structured policy for deletion. Even though the concept of masked Aadhaar is ruled out by Unique Identification Authority of India (UIDAI), most hotels and owners of properties registered with Airbnb, still collects Aadhaar. To curb this, Unique Identification Authority of India (UIDAI) has mandated every entity requesting Aadhaar card including hotels to register with the authority to verify the identity of customers through a new Aadhaar application.
4. Mobile check-in applications – Digital and mobile check-ins increase privacy risk in hotels because they collect sensitive guest data such as identity documents, contact details and payment information. The risk is not theoretical. The Spanish Data Protection Agency (AEPD) fined a travelling services providing company because their online check-in process required guests to upload full copies of their identity documents. The data protection authority stated that requesting a copy of the DNI (Spanish ID) or passport violates the principle of data minimization set out in Article 5(1) (c) of the GDPR and involves excessive processing of data. This is because the full ID contains more data than is required under the applicable rules, such as the photograph, the expiry date of the document, the CAN or the name of the parents. Also, providing a copy of personal documentation implies, among other things, an unnecessary risk of identity theft, which should be avoided or at least effectively mitigated.
5. Usage of Artificial Intelligence and automated processing – Recently, a global leader in hospitality sector, announced partnership with a company to ensure guests who are blind or have low vision can experience a more accessible and welcoming stay. Together with the hotel, they are making available AI-powered assistance and dedicated reservations and Customer Care support to guests who are blind or have low vision across the U.S. and Canada. Under the Digital Data Protection Framework, processing personal of disable group of people is considered highly sensitive and therefore mandates for stricter compliance. Beside this, hotels are increasingly using Artificial Intelligence to automate multiple segments such as front desk management, revenue and operations management, security and offering tailored guest experience by analyzing vast datasets, including customer preferences, booking history, and behavioral patterns.
To operationalize compliance with the DPDP Act hotels must move beyond policy documents and embed privacy into day-to-day operations. Given the volume and sensitivity of guest data processed across booking platforms, front desks, surveillance systems and service providers, a structured compliance framework becomes essential.
1. Consent and notice re-design – Section 6 of the DPDP Act provides for the mechanism for explicit and informed consent. However, hotels often rely on bundled consent embedded in booking forms or check-in documents, which may not meet DPDP standards of informed and purpose-specific consent. Consent mechanisms should be unbundled and aligned with actual processing activities such as marketing communications, loyalty programs, biometric verification etc. with distinct consent choices.
2. Biometric governance – Where hotels use biometric identifiers for check-in, access control, or employee attendance, this processing requires heightened safeguards due to the irreversible nature of biometric data. Hotels should assess whether biometric collection is strictly necessary for the intended purpose or whether less intrusive alternatives are available. Appropriate reasonable security practices such as access control measures, defined retention periods must be deployed.
3. Vendor and system contracts – Contracts with such vendors should clearly allocate data protection responsibilities, mandate DPDP-compliant processing, impose security obligations, restrict sub-processing, and require prompt breach notifications. Hotels should also ensure that vendors only process personal data on documented instructions, implement appropriate technical and organizational measures, and support the hotel in responding to Data Principal Requests.
4. Breach preparedness – Section 8(6) read with Rule 7 of the DPDP Rules, 2025 puts an obligation of Breach Notification and undertaking breach redressal mechanisms on the Data Fiduciaries. Therefore, hotels should maintain an incident response plan that defines internal escalation protocols, investigation procedures, containment measures, and notification responsibilities to government authorities. Staff should be trained to identify and promptly report such suspected breaches.
Data Privacy in hotels must be treated as an operational responsibility, not a paperwork exercise. Clear governance across guest touch points reduces regulatory exposure and operational risks. Done right, privacy becomes a competitive advantage and not a constraint.
About the authors: Anuradha Gandhi is a Managing Associate and Rishabh Gupta is an Associate at S. S. Rana & Co.
Disclaimer: The opinions expressed in this article are those of the author(s). The opinions presented do not necessarily reflect the views of Bar & Bench.
If you would like your Deals, Columns, Press Releases to be published on Bar & Bench, please fill in the form available here.