Hotels collect more personal data per guest than almost any other consumer business: IDs, payment details, travel companions, dietary and accessibility needs, spend history, even room-entry logs. This checklist is for GMs, revenue and marketing leads, and IT owners at independent hotels and multi-property groups who need to find the gaps before a regulator, a breach, or a guest complaint finds them first.

It is written with India's Digital Personal Data Protection (DPDP) Act and Rules 2025 in mind, and cross-checks against GDPR for properties that host EU guests. Treat it as an operational audit, not legal advice.

Key dates to plan around (India): the DPDP Rules were notified on 13 November 2025. The consent manager framework goes live in November 2026, and full obligations (notice, consent, security safeguards, breach reporting and guest rights) apply from May 2027. If your stack isn't ready, the remaining runway is short.


1. Map what you actually collect

You cannot protect data you haven't inventoried. Most hotels find guest data in 8–15 systems, not the 3 they expect.

  • [ ] List every system that stores guest data: PMS, booking engine, channel manager, CRS, POS, spa and F&B systems, CRM, email platform, Wi-Fi portal, door-lock system, loyalty platform, guest app, CCTV
  • [ ] Include shadow stores: shared drives, front-desk spreadsheets, WhatsApp groups, printed registration cards, email inboxes
  • [ ] For each system, record the data fields, the purpose, who can access it, where it's hosted, and how long it's kept
  • [ ] Flag special-risk data: ID/passport numbers, payment data, children's data, health-related notes (allergies, accessibility, medical requests)
  • [ ] Identify where the same guest exists in multiple systems without a single guest profile. Duplicate records make deletion and access requests unreliable

Under DPDP, consent must be free, specific, informed, unambiguous and given through a clear affirmative action. It must also be as easy to withdraw as it was to give.

CheckpointWhat "good" looks likeCommon failure
Privacy noticePlain-language, itemised list of data and purposes, shown before collection, available in English and the Eighth Schedule languages the guest choosesA single link buried in booking-engine T&Cs
Consent captureSeparate, unticked opt-ins for marketing, profiling/personalisation and third-party sharingOne pre-ticked box bundled with "I accept the terms"
Purpose separationStay fulfilment (reservation, check-in, legal reporting) handled as a legitimate use, not stretched to cover marketingUsing the registration card as blanket marketing consent
WithdrawalOne-click unsubscribe and an in-app or web option to withdraw each consentWithdrawal only by emailing the GM
Consent recordsTimestamp, channel, notice version and scope stored per guest, and synced to every downstream systemConsent lives in the email tool only; the PMS and CRM never learn about it
Consent managersYour systems can accept consent grants and withdrawals from a registered consent managerNo API or process to receive them
  • [ ] Walk through every capture point (website, OTA-sourced bookings, walk-ins, kiosk, guest app, Wi-Fi login, spa booking) and confirm each one presents the notice and captures granular consent
  • [ ] Confirm that consent withdrawal stops processing across all systems within a defined SLA, not just email marketing
  • [ ] For guests under 18, confirm you obtain verifiable parental consent before any processing beyond the stay itself, and that no profiling or targeted marketing is aimed at them

ID handling is where hotels most often over-collect. European regulators have already fined hotels for photographing IDs, and passport scans taken from hotel systems have turned up for sale online.

  • [ ] Capture only the fields a law actually requires (name, document type and number, nationality, dates of stay). Do not store a full scan or photo of the ID unless a specific rule requires it
  • [ ] If scans are required (for example, for foreign nationals), store them encrypted and separately from the general PMS record, with tightly restricted access
  • [ ] Confirm Form C submissions for foreign guests are made to the immigration portal within 24 hours, and that local copies are not kept longer than you need them
  • [ ] Remove ID images from email, WhatsApp and shared drives. Front-desk staff often forward them for convenience
  • [ ] Record the retention period and deletion method for ID data in your retention schedule (section 5)

4. Security safeguards

DPDP requires "reasonable security safeguards", and the Rules spell out a minimum baseline.

  • [ ] Encrypt, mask or tokenise personal data at rest and in transit, including in backups
  • [ ] Use role-based access in the PMS and CRM. Housekeeping doesn't need contact details, and night audit doesn't need marketing profiles
  • [ ] Remove shared front-desk logins. Every user needs a named account, with MFA for remote or admin access
  • [ ] Log access to personal data and keep the logs for at least one year so incidents can be investigated
  • [ ] Keep card data out of your environment wherever possible by using tokenisation and PCI-scoped payment partners
  • [ ] Segment networks so guest Wi-Fi, IoT/door locks and back-office systems cannot reach each other
  • [ ] Test restores from backup at least twice a year

5. Retention and deletion

  • [ ] Publish a retention schedule per data category: reservations, folios and invoices (tax law period), ID data, marketing profiles, CCTV, Wi-Fi logs, loyalty history
  • [ ] Automate deletion or anonymisation when retention ends. Manual clean-ups rarely happen
  • [ ] Make sure deletion reaches every system, including the channel manager, CRM, email tool, data warehouse and vendor copies
  • [ ] Keep anonymised aggregates for revenue and demand analytics so that deleting records doesn't break reporting

6. Guest rights requests

  • [ ] Publish a clear channel for access, correction, erasure and grievance requests, and name the contact person or DPO
  • [ ] Define an internal SLA and a single owner for each request type
  • [ ] Verify the requester's identity before you release or delete data
  • [ ] Be able to return a complete summary of a guest's data across every property and system, which is only realistic if you have PMS, CRM and booking engine integrations or a unified guest record
  • [ ] Log every request and outcome as evidence

7. Vendors and data sharing

Hotels usually share guest data with 10–30 processors: OTAs, channel managers, CRM and email vendors, payment gateways, guest-messaging tools, revenue systems and loyalty partners.

  • [ ] Maintain a processor register with each vendor's purpose, data shared and hosting location
  • [ ] Sign data processing agreements that cover security, breach notification timelines, sub-processors, deletion at contract end and audit rights
  • [ ] Check cross-border transfers against any government-restricted destinations under DPDP, and against GDPR transfer mechanisms for EU guests
  • [ ] Remove integrations and API keys that are no longer used, since old connectors are a common leak path
  • [ ] Share only the fields each vendor needs. A review-request tool doesn't need date of birth

8. Breach readiness

  • [ ] Keep a written incident response plan with named owners across IT, legal, the GM and communications
  • [ ] Under DPDP, notify affected guests without delay, and send the Data Protection Board an initial intimation followed by a detailed report within 72 hours
  • [ ] If EU guests are affected, run the GDPR 72-hour supervisory authority notification in parallel
  • [ ] Prepare guest notification templates that describe the breach, its likely impact and the steps guests can take
  • [ ] Run a tabletop exercise each year, for example "PMS vendor reports a compromised API key"

Red flags to fix first

  • ID scans stored in email or shared folders
  • Pre-ticked or bundled marketing consent
  • No way to push a consent withdrawal from the CRM to the PMS or booking engine
  • Shared staff logins on the PMS
  • Vendors with guest data but no signed DPA
  • No retention schedule, or one that isn't automated

How to use this

Run the checklist per property, then roll it up for the group. Score each section Red, Amber or Green, fix the red flags within 30 days, and schedule the rest against the May 2027 deadline. Revisit it every time you add a new guest-facing system or vendor.

How Syslabs can help

Most privacy gaps in hotels come from integration problems rather than policy: consent captured in one system never reaches the others, and deletion stops at the PMS. Syslabs works with hotel groups on hospitality technology, running a privacy compliance review of the guest data flow and building the consent sync, retention automation and guest-rights tooling that make these controls work across properties.