Travel and hospitality DPDP compliance
knowing where the data went.
Travel moves personal data across borders as a matter of routine, and much of it is collected because a law requires it. The DPDP Act allows the transfers. What it does not allow is losing track of them, or turning a legally required registration into a marketing profile.
Which laws apply to travel and hospitality data?
The DPDP Act governs traveller data; several other laws require it to be collected and shared. Hotels report foreign guests under the Immigration and Foreigners Act, 2025; airlines send passenger records to customs under the PNR regulations; card payments bring RBI's card data rules; and CERT-In's directions apply to incidents.
| Law or rule | What it requires | Notes |
|---|---|---|
| DPDP Act s.16 | Transfer abroad allowed except to restricted countries | Stricter sectoral rules survive under s.16(2) |
| Immigration and Foreigners Act, 2025, s.8 | Accommodation providers report foreign guests | Form III (formerly Form C) within 24 hours of arrival and on departure; in force 1 September 2025 |
| Passenger Name Record Information Regulations, 2022 | Airlines transfer PNR for international flights to customs | CBIC notification 67/2022 of 8 August 2022; data held up to five years |
| RBI card-on-file rules | Card credentials not stored by merchants | Online travel agents and hotels taking cards |
| CERT-In directions, 2022 | Six-hour incident reporting, 180-day logs in India | See the CERT-In guide |
The obligation travel gets wrong: transfers nobody recorded
Section 16 lets travel businesses send data abroad to airlines, hotel chains, global distribution systems and overseas partners, unless the government restricts a country. Permissive is not the same as unrecorded. The obligation that bites is knowing which data went to whom, because rights requests and inspections ask exactly that.
Most transfers happen inside booking integrations: an OTA's API call to a GDS, a channel manager pushing guest details to a property system hosted abroad, an airline sharing a PNR with a codeshare partner. Nobody wrote them down because nobody decided them; they came with the integration. When a customer asks under section 11 for a summary of the personal data processed and the identities of those it was shared with, the answer has to come from somewhere.
The work is a transfer map: for each integration, what data, to which recipient, in which country, for which purpose, and whether the recipient is your processor or a fiduciary in its own right. Keep it current, because the government can notify restricted countries at any time. The DPDP cross-border transfer guide covers section 16 and Rule 15.
Legally required data, and the marketing built on it
Much traveller data is collected because a law requires it: foreign guest registration, passenger records for customs, identity checks at check-in. Processing for those purposes is lawful. Using the same records for loyalty marketing, profiling or resale is a new purpose that needs its own consent.
Hotels are the sharpest example. Since the Immigration and Foreigners Act, 2025 came into force, the keeper of any accommodation, from a chain hotel to a homestay, must report every foreign guest on Form III within 24 hours of arrival and again on departure, and OCI cardholders are no longer exempt. That record, and the passport scan behind it, is held to meet a legal duty. The guest's loyalty profile, stay preferences and marketing consent are separate, even when the property system stores them in the same table.
Airlines face the same split with the PNR regulations. The customs targeting centre may keep PNR data for up to five years for its purposes. That period belongs to customs. The airline's own retention of booking and loyalty data needs its own basis and period under the DPDP Act.
Bookings made for other people
Travel is one of the few sectors where the customer routinely supplies other people's data: co-travellers, children, employees on a corporate booking. Each is a Data Principal. The booker's click on the notice does not tell the co-travellers anything, and children's data carries the section 9 rules.
Three cases cover most of it. Family and group bookings: the lead booker provides names, dates of birth and passport numbers for everyone. The data is needed to perform the booking, but the notice should say how co-travellers' data is used and how they can exercise their rights. Children: a parent booking for their own child is an identifiable adult providing the child's data, which fits section 9(1) far better than a teenager booking alone. Section 9(3) still bars targeted advertising directed at the child, so the child's profile should not feed the recommendation engine. Corporate travel: the employer usually books under an employment purpose, which section 7(i) recognises. The travel management company is then the employer's processor for the booking and a fiduciary in its own right only for anything it does beyond it, such as enrolling the traveller in its own loyalty scheme.
Passport and identity data
The DPDP Act has no higher tier for passport or identity data. It requires reasonable security safeguards for all personal data under section 8(5). But the Board sets penalties by the gravity of a breach, and a leak of passport scans enables identity fraud, so expect the safeguards to be judged against that harm.
In practice that means scans encrypted at rest, access restricted to the staff who check guests in, and no copies in email or messaging groups, which is where front-desk teams often keep them. Retention should match the legal requirement, not the hotel's storage capacity. The Act's cap for failing to take reasonable security safeguards is ₹250 crore.
Travel and hospitality control checklist
For online travel agents, airlines, hotels, homestay platforms and tour operators.
| Control | Why | Evidence to hold |
|---|---|---|
| Transfer map per integration: data, recipient, country, purpose, role | DPDP s.16, s.11 | The map, reviewed on each new integration |
| Form III data kept separate from loyalty and marketing profiles | Immigration and Foreigners Act s.8; DPDP s.6(1) | Data model; access rules |
| Separate consent for loyalty marketing and personalisation | DPDP s.6(1) | Consent record per purpose |
| Passport scans encrypted, access-restricted, deleted on schedule | DPDP s.8(5), s.8(7) | Access logs; retention job |
| No card credentials stored outside tokenisation | RBI card-on-file rules | PCI scope documentation |
| Booking pages hold ad and analytics tags until consent | DPDP s.6 | Two-pass scan of search and booking flows |
| Rights requests answerable with recipient list | DPDP s.11 | Sample response built from the transfer map |
Where to go next
The cross-border transfer guide covers section 16 in depth, and the data discovery engine maps cross-border flows with the residencies named. For the law underneath all of it, read the DPDP Act and Rules 2025 guide. To see what your own website does before a visitor answers the banner, run the free two-pass cookie scan. The consent platform holds versioned notices in 22 languages, a hash-chained consent ledger, withdrawal relayed to each processor, and rights requests and breaches on their statutory clocks. The industries overview compares all eight sectors.
The things people ask us
Can a travel company send customer data abroad under the DPDP Act?
Yes, by default. Section 16 permits transfer outside India except to countries the Central Government restricts by notification, subject to any stricter sectoral law. Airlines, hotel chains and global distribution systems can receive data. What the Act does require is that you know where it went and can answer a rights request about it.
Must hotels report foreign guests in India?
Yes. Under section 8 of the Immigration and Foreigners Act, 2025, in force since 1 September 2025, anyone providing accommodation to a foreigner must report the stay. The report, Form C now called Form III, is filed online within 24 hours of arrival and again on departure. That processing is required by law.
Can a hotel use guest registration data for marketing?
Not on the strength of the registration. The data is collected to meet a legal reporting duty and to provide the stay. Loyalty marketing is a separate purpose that needs its own consent. Using the Form III record, or the passport scan behind it, to build a marketing profile is purpose creep the Act does not allow.
How long can airlines keep passenger data in India?
Depends on the purpose. Under the Passenger Name Record Information Regulations, 2022, airlines transfer PNR data for international flights to the customs targeting centre, which may retain it for up to five years. The airline's own retention needs its own basis and period under the DPDP Act, not the customs period.
Do travel companies need to protect passport data more strictly?
The Act sets one standard, reasonable security safeguards under section 8(5), for all personal data. In practice the Board weighs the gravity of a breach when setting a penalty, and a leak of passport scans enables identity fraud. Expect encryption, restricted access and short retention to be judged against that harm.
See what your search and booking pages share.
Travel sites carry some of the heaviest ad stacks online. Scan yours, then see how the platform holds those tags back and keeps a consent record per traveller.