Hotels collect more personal data per guest than almost any other consumer business: IDs, payment details, travel companions, dietary and accessibility needs, spend history, even room-entry logs. This checklist is for GMs, revenue and marketing leads, and IT owners at independent hotels and multi-property groups who need to find the gaps before a regulator, a breach, or a guest complaint finds them first.
It is written with India's Digital Personal Data Protection (DPDP) Act and Rules 2025 in mind, and cross-checks against GDPR for properties that host EU guests. Treat it as an operational audit, not legal advice.
Key dates to plan around (India): the DPDP Rules were notified on 13 November 2025. The consent manager framework goes live in November 2026, and full obligations (notice, consent, security safeguards, breach reporting and guest rights) apply from May 2027. If your stack isn't ready, the remaining runway is short.
1. Map what you actually collect
You cannot protect data you haven't inventoried. Most hotels find guest data in 8–15 systems, not the 3 they expect.
- [ ] List every system that stores guest data: PMS, booking engine, channel manager, CRS, POS, spa and F&B systems, CRM, email platform, Wi-Fi portal, door-lock system, loyalty platform, guest app, CCTV
- [ ] Include shadow stores: shared drives, front-desk spreadsheets, WhatsApp groups, printed registration cards, email inboxes
- [ ] For each system, record the data fields, the purpose, who can access it, where it's hosted, and how long it's kept
- [ ] Flag special-risk data: ID/passport numbers, payment data, children's data, health-related notes (allergies, accessibility, medical requests)
- [ ] Identify where the same guest exists in multiple systems without a single guest profile. Duplicate records make deletion and access requests unreliable
2. Consent and notice
Under DPDP, consent must be free, specific, informed, unambiguous and given through a clear affirmative action. It must also be as easy to withdraw as it was to give.
| Checkpoint | What "good" looks like | Common failure |
|---|---|---|
| Privacy notice | Plain-language, itemised list of data and purposes, shown before collection, available in English and the Eighth Schedule languages the guest chooses | A single link buried in booking-engine T&Cs |
| Consent capture | Separate, unticked opt-ins for marketing, profiling/personalisation and third-party sharing | One pre-ticked box bundled with "I accept the terms" |
| Purpose separation | Stay fulfilment (reservation, check-in, legal reporting) handled as a legitimate use, not stretched to cover marketing | Using the registration card as blanket marketing consent |
| Withdrawal | One-click unsubscribe and an in-app or web option to withdraw each consent | Withdrawal only by emailing the GM |
| Consent records | Timestamp, channel, notice version and scope stored per guest, and synced to every downstream system | Consent lives in the email tool only; the PMS and CRM never learn about it |
| Consent managers | Your systems can accept consent grants and withdrawals from a registered consent manager | No API or process to receive them |
- [ ] Walk through every capture point (website, OTA-sourced bookings, walk-ins, kiosk, guest app, Wi-Fi login, spa booking) and confirm each one presents the notice and captures granular consent
- [ ] Confirm that consent withdrawal stops processing across all systems within a defined SLA, not just email marketing
- [ ] For guests under 18, confirm you obtain verifiable parental consent before any processing beyond the stay itself, and that no profiling or targeted marketing is aimed at them
3. Identity documents and legal reporting
ID handling is where hotels most often over-collect. European regulators have already fined hotels for photographing IDs, and passport scans taken from hotel systems have turned up for sale online.
- [ ] Capture only the fields a law actually requires (name, document type and number, nationality, dates of stay). Do not store a full scan or photo of the ID unless a specific rule requires it
- [ ] If scans are required (for example, for foreign nationals), store them encrypted and separately from the general PMS record, with tightly restricted access
- [ ] Confirm Form C submissions for foreign guests are made to the immigration portal within 24 hours, and that local copies are not kept longer than you need them
- [ ] Remove ID images from email, WhatsApp and shared drives. Front-desk staff often forward them for convenience
- [ ] Record the retention period and deletion method for ID data in your retention schedule (section 5)
4. Security safeguards
DPDP requires "reasonable security safeguards", and the Rules spell out a minimum baseline.
- [ ] Encrypt, mask or tokenise personal data at rest and in transit, including in backups
- [ ] Use role-based access in the PMS and CRM. Housekeeping doesn't need contact details, and night audit doesn't need marketing profiles
- [ ] Remove shared front-desk logins. Every user needs a named account, with MFA for remote or admin access
- [ ] Log access to personal data and keep the logs for at least one year so incidents can be investigated
- [ ] Keep card data out of your environment wherever possible by using tokenisation and PCI-scoped payment partners
- [ ] Segment networks so guest Wi-Fi, IoT/door locks and back-office systems cannot reach each other
- [ ] Test restores from backup at least twice a year
5. Retention and deletion
- [ ] Publish a retention schedule per data category: reservations, folios and invoices (tax law period), ID data, marketing profiles, CCTV, Wi-Fi logs, loyalty history
- [ ] Automate deletion or anonymisation when retention ends. Manual clean-ups rarely happen
- [ ] Make sure deletion reaches every system, including the channel manager, CRM, email tool, data warehouse and vendor copies
- [ ] Keep anonymised aggregates for revenue and demand analytics so that deleting records doesn't break reporting
6. Guest rights requests
- [ ] Publish a clear channel for access, correction, erasure and grievance requests, and name the contact person or DPO
- [ ] Define an internal SLA and a single owner for each request type
- [ ] Verify the requester's identity before you release or delete data
- [ ] Be able to return a complete summary of a guest's data across every property and system, which is only realistic if you have PMS, CRM and booking engine integrations or a unified guest record
- [ ] Log every request and outcome as evidence
7. Vendors and data sharing
Hotels usually share guest data with 10–30 processors: OTAs, channel managers, CRM and email vendors, payment gateways, guest-messaging tools, revenue systems and loyalty partners.
- [ ] Maintain a processor register with each vendor's purpose, data shared and hosting location
- [ ] Sign data processing agreements that cover security, breach notification timelines, sub-processors, deletion at contract end and audit rights
- [ ] Check cross-border transfers against any government-restricted destinations under DPDP, and against GDPR transfer mechanisms for EU guests
- [ ] Remove integrations and API keys that are no longer used, since old connectors are a common leak path
- [ ] Share only the fields each vendor needs. A review-request tool doesn't need date of birth
8. Breach readiness
- [ ] Keep a written incident response plan with named owners across IT, legal, the GM and communications
- [ ] Under DPDP, notify affected guests without delay, and send the Data Protection Board an initial intimation followed by a detailed report within 72 hours
- [ ] If EU guests are affected, run the GDPR 72-hour supervisory authority notification in parallel
- [ ] Prepare guest notification templates that describe the breach, its likely impact and the steps guests can take
- [ ] Run a tabletop exercise each year, for example "PMS vendor reports a compromised API key"
Red flags to fix first
- ID scans stored in email or shared folders
- Pre-ticked or bundled marketing consent
- No way to push a consent withdrawal from the CRM to the PMS or booking engine
- Shared staff logins on the PMS
- Vendors with guest data but no signed DPA
- No retention schedule, or one that isn't automated
How to use this
Run the checklist per property, then roll it up for the group. Score each section Red, Amber or Green, fix the red flags within 30 days, and schedule the rest against the May 2027 deadline. Revisit it every time you add a new guest-facing system or vendor.
How Syslabs can help
Most privacy gaps in hotels come from integration problems rather than policy: consent captured in one system never reaches the others, and deletion stops at the PMS. Syslabs works with hotel groups on hospitality technology, running a privacy compliance review of the guest data flow and building the consent sync, retention automation and guest-rights tooling that make these controls work across properties.