
Introduction
The hospitality sector presents a distinctive compliance problem under the Digital Personal Data Protection Act, 2023 (“DPDP Act, 2023”), read with the Digital Personal Data Protection Rules, 2025 (“DPDP Rules, 2025”). The personal data a hotel processes rarely originates from a single, controlled channel. It flows in through Online Travel Aggregators, walk-in bookings, corporate travel desks, loyalty programmes and third-party payment gateways, each carrying its own consent trail.
The hotels are not incidental processors of personal data. Guest identification, payment credentials, dietary and health-related preferences and, on occasion, biometric data collected for facial-recognition-enabled check-ins are all processed as part of the core business function. This places hotels within a category of Data Fiduciaries for whom the DPDP Act, 2023 was, in substance, designed.
Hotels as Data Fiduciaries
A hotel qualifies as a Data Fiduciary under the DPDP Act, 2023 because it determines the purpose and means of processing guest, employee and vendor personal data. This classification is not merely definitional. It is the hinge on which liability turns. Unlike a Data Processor, who acts strictly on the instructions of the Data Fiduciary and bears no independent statutory obligation, a hotel cannot contract away its accountability by outsourcing reservations, housekeeping rosters or payment processing to third-party vendors.
This distinction is especially important in hotel management agreements, where the hotel owner and the hotel brand (operator) are often different legal entities. If the operator decides how guest data is collected, stored, and used, for example, for loyalty programmes or marketing across different hotels, it may be treated as the Data Fiduciary, not just the hotel owner. Simply assigning responsibility through a contract is not enough. Under the DPDP Act, 2023, what matters is who actually controls the processing of personal data, not what the agreement labels the parties.
Consent Architecture Across the Guest Lifecycle
Consent under the DPDP Act, 2023 must be free, specific, informed, unconditional and unambiguous, accompanied by a clear affirmative act. Applied to a hotel’s operations, this standard is difficult to satisfy through a single, generic privacy policy, because a guest’s data is collected at multiple, discontinuous points, at the time of booking, at the front desk during check-in, through in-room smart devices, and again at check-out for billing reconciliation.
Every stage of a guest’s stay involves a different purpose for processing personal data. Under the DPDP Act, 2023, hotels may need to give separate information and obtain separate consent for each purpose, instead of relying on one general consent form signed at check-in. For example, if a hotel asks for consent for identity verification, marketing messages, and sharing data with its loyalty programme through a single form, that consent could be considered invalid. This is because the guest cannot refuse marketing or loyalty-related data sharing without also refusing the hotel stay itself.
A further complication arises from bookings made through Online Travel Aggregators, where the guest’s initial consent is obtained by the aggregator, not the hotel. The hotel, upon receiving the booking confirmation and guest details from the aggregator, is processing personal data on the strength of a consent it did not itself collect. Whether this satisfies the DPDP Act, 2023 depends on whether the aggregator’s notice adequately discloses the hotel as a recipient of the data for a specified purpose. Hotels have limited practical ability to verify this at the point of onboarding each booking channel.
Breach Accountability and the Structure of Hotel Operations
The DPDP Rules, 2025 impose defined timelines for breach notification to the Data Protection Board of India and to affected Data Principals. The analytical difficulty for hotels lies less in the timeline itself and more in detection. A hotel’s data estate is distributed across a property management system, a point-of-sale system, a central reservation system and, frequently, an in-room entertainment or Wi-Fi authentication platform, each often licensed from a different vendor and each a potential point of compromise.
This distributed architecture means that a hotel’s breach-response obligation cannot be discharged through a single internal policy. It requires contractual breach-notification triggers embedded in every vendor agreement, so that a compromise at the level of a payment gateway or a booking-engine sub-processor is flagged to the hotel, as Data Fiduciary, within a window that still allows the hotel to meet its own statutory timeline. Absent such contractual back-to-back obligations, a hotel may find itself in breach of the DPDP Rules, 2025 for a failure that originated entirely within a vendor’s systems.
Cross-Border Data Flows in Chain-Affiliated Properties
Hotels affiliated with international chains routinely route guest data through global reservation systems and centralised customer-relationship-management platforms hosted outside India. The DPDP Act, 2023 permits cross-border transfer of personal data except to countries restricted by the Central Government, which reverses the more restrictive, whitelist-based approach that had been contemplated under earlier drafts of Indian data protection legislation.
This permissive default should not be read as an absence of obligation. Where guest data continues to be processed abroad after transfer, the hotel, as the Data Fiduciary of first instance in India, remains accountable for ensuring that downstream processing does not exceed the purpose for which consent was originally obtained. A loyalty programme that aggregates a guest’s stay history across jurisdictions for global personalisation is processing personal data for a purpose distinct from the original booking, and the analytical question is whether that secondary purpose was disclosed at the time consent was first taken in India.
Children’s Data and the Verifiable Consent Problem
Family and leisure bookings routinely involve the processing of a minor’s personal data, whether through identity documents submitted at check-in or activities booked on the minor’s behalf. The DPDP Act, 2023 requires verifiable parental consent before processing a child’s personal data, and prohibits tracking, behavioural monitoring or targeted advertising directed at children.
For hotels, this creates friction with common marketing practices, such as sending targeted offers based on a family’s stay history, where the underlying guest profile may include a minor’s data collected during an earlier visit. A hotel’s marketing analytics that do not segregate a minor’s data from the primary guest’s profile risk falling foul of this restriction, even where the marketing communication is addressed to the adult guest, because the profiling itself may be shown to rely on the minor’s data.
AMLEGALS Remarks
The compliance challenge posed by the DPDP Act, 2023 for the hospitality sector is structural rather than procedural. It does not arise from an absence of policy documentation, but from the fact that a hotel’s data architecture is inherently fragmented across booking channels, property systems and vendor platforms, each generating its own consent trail and its own point of potential failure.
A hotel’s compliance posture, therefore, cannot be assessed merely by the existence of a privacy policy or a consent checkbox at check-in. It must be tested against how consent is itemised across touchpoints, how breach-notification obligations are contractually pushed down to vendors, and how cross-border and minor-related data flows are segregated within the hotel’s own systems. Compliance under the DPDP Act, 2023 is, at its core, an exercise in mapping control over data to the entity that actually exercises it, a test hotel, given their layered operating structures, are only beginning to apply with rigour.
For any queries or feedback, feel free to connect with mridusha.guha@amlegals.com or Khilansha.mukhija@amlegals.com
