‹ All sectors

Sector reference

DPDP for Hotels and Hospitality

What is processed
Booking, check in and other details, where the hotel needs them for a service it has stated or to meet a legal requirement.

Why it is allowed, and when

There is no hotel specific regime here. The ordinary rules apply, together with the duty to take reasonable security precautions, which the Rules spell out in detail once they commence.

Where the permission stops

Nothing here specially authorises cameras or keeping a copy of your ID. Each still needs its own reason, and neither should be kept indefinitely without one. A hotel should not describe this law as the thing that requires it.

Questions people actually ask

Can a hotel scan my ID?

There is no hotel specific permission to scan identity documents in this law, and no ban either. Whatever a hotel collects still needs a proper reason, which is either the service you asked for or something another law requires of them.

How long they can keep it follows the same test: while that reason lasts, or while a law requires it.

Can a hotel use CCTV on the property?

There is no hotel specific camera rule. CCTV still needs a proper reason and a basis under the ordinary rules, exactly like any other collection. This law neither specially permits hotel cameras nor prohibits them.

Can a hotel keep a scanned copy of my ID after check out?

Only while a live reason remains, or while a law requires it. Once the stay is over and nothing legal requires the copy, keeping it needs a fresh justification, and that it might be handy next time is not one.

Can they share my stay details with a partner travel company or OTA?

Only with a specific reason for that sharing. Booking a room does not authorise passing your stay details to another company for that company's own purposes.

I booked through a travel app. Who is answerable for my data, the hotel or the app?

Both can be, each for its own part. Whoever decided to collect your details, and why, is answerable for that collection. So the app answers for the booking it took, and the hotel answers for the stay it ran.

Where one of them is only acting on the other's instructions, rather than for its own ends, the one giving the instructions stays answerable whatever the two of them agreed between themselves, and it has to have a proper contract in place before anything moves.

Practically, neither can point at the other for the part it decided itself.

Can hotel staff pull up my previous stays?

Only where there is a reason connected to what they are actually doing. Holding a history because the system keeps one is not the same as everybody on shift needing to see it.

The hotel has to put real technical and organisational measures in place and take reasonable security precautions, and who can open what is part of that. A record anyone on the desk can browse is how one curious employee becomes a breach the hotel has to report to you and to the Board.

What people get wrong

The data protection law requires us to scan and keep a copy of your ID.

This law creates no hotel ID requirement at all. Other laws, or state police rules, may require certain records, and where they do those laws are both the source and the limit. This law should never be given as the reason.

We keep CCTV and ID scans indefinitely for security.

Keeping it needs a live reason or a legal requirement. Once the stay is over and no law requires it, holding on to the footage or the ID copy needs a fresh justification.

Related questions

This sector sits inside the full Sector Reference, which covers 26 sectors and 160 questions. To work through your own organisation rather than the general case, the Template Builder starts from your answers.