For hotels, resorts, homestays and travel agencies
DPDP compliance for hotels and travel
Every check-in collects ID copies, phone numbers and often passports, and much of it ends up photocopied, emailed and forgotten. ConsentKit gives guests a clear notice at booking and check-in, separates marketing from the stay, and keeps ID copies under control.
- Guest ID copies
- Protect and limit
- Foreign guest reporting
- Still required
- Full compliance
- 13 May 2027
Lakeview Retreat asks for your consent
We need some details for your stay and the law. The rest is your choice.
Where the DPDP Act touches a guest’s stay
Pick a stage to see what you collect, why and what the law expects.
What changes for your property on 13 May 2027
The Act applies to every property, from a five-star hotel to a three-room homestay.
A notice at booking and check-inSections 5 and 6
Guests should know what you collect and why, including what the law requires.
Notices for your booking engine, web check-in and a QR code at the desk.
ID copies need strong protectionSection 8(5) and Rule 6
Passport and ID copies are high-risk. Store them securely, limit access and delete when not needed.
Encrypted ID storage with access logs and automatic deletion.
Marketing needs its own consentSection 6
Stay-related messages and promotions are separate. Guests can say no to promotions.
Per-purpose choices synced to your CRM and messaging tools.
OTAs, PMS and channel managers are coveredSection 8
Your PMS, booking engine and channel manager process guest data for you.
A vendor register and processor contract checklist.
Guests can ask for their dataSections 11 to 14
Guests can request access, correction and erasure where law allows.
A request form with identity checks and deadlines.
Breaches go to guests tooRule 7
A PMS hack or leaked ID folder must be reported to the Board and affected guests.
Breach templates ready to send within 72 hours.
A plan around your season
Make changes before the season starts, not in the middle of it.
Find the ID copies
Locate every place ID copies live: PMS, email, WhatsApp, paper files.
Notices and check-in
Put notices on booking and check-in, and move ID storage somewhere secure.
Marketing and vendors
Clean marketing lists and sign terms with your PMS and booking engine.
Train the front desk
Train staff on ID handling, requests and breaches.
For every kind of property
Templates for your size and setup.
Hotel chains
Central loyalty and per-property admins.
Independent hotels
Simple setup with your PMS.
Resorts
Activities, spa and long stays.
Homestays and B&Bs
Small teams, phone and WhatsApp heavy.
Travel agencies
Passports, visas and airline sharing.
Tour operators
Group travel and guide access.
DPDP compliance for hotels near you
Local guidance and onboarding in these cities, with support from our team in Kolkata.
Related sectors
Questions hoteliers are asking
For the full picture, read our DPDP Act guide or compliance checklist.
Do we still need to report foreign guests?
Yes. Form C and police reporting duties continue. The DPDP Act does not override them, but you should tell guests about them in your notice.
Can we keep copies of guests’ IDs?
Keep them only as long as the law requires, store them securely and limit who can see them.
Can we add OTA guests to our newsletter?
Only with their consent for marketing. A booking through an OTA is not consent to your promotions.
Does this apply to homestays?
Yes. There is no size threshold. If you hold guest data digitally, including on WhatsApp, you are a data fiduciary.
Can we share CCTV footage with police?
Yes, when there is a lawful request. Log what you shared and why.
Get your property ready before the season
The readiness check takes about ten minutes and gives you a practical gap report for your property.