dpdpconsent.in
Resources

Consent vs. legal obligation

Ask most front-desk managers why they collect guest ID, and the honest answer is 'we've always done it.' Under DPDP, why you collect something matters as much as what you collect — and hotels routinely mix up two very different reasons.

Two different baskets

Recording a guest’s ID for Form C or the local police register isn’t consent-based at all — it’s a legal obligation. You’re required to keep that record because a law says so, and the guest doesn’t get to opt out of it any more than they can opt out of paying GST.

Everything else — a phone number for a WiFi login, an email address for a promotional offer, a birthday for a loyalty program — sits in a completely different basket. That data needs a real basis: usually consent, freely given and specific, not implied by the act of checking in.

Where hotels get this wrong

The most common failure mode: treating the statutory ID collection as blanket permission to use that same data for marketing, or storing both records in the same system with no distinction between them. If a guest later asks you to delete their data, you can’t delete the statutory filing — but you absolutely should be able to delete the marketing record. If they’re tangled together, you can’t do either cleanly.

The fix is mostly organisational, not technical

Keep the statutory record where the law requires it, retained for the period the law requires, and nothing more. Keep your guest marketing list separately, built only from guests who affirmatively opted in, with an unsubscribe that’s actually honoured. Two lists, two purposes, two retention rules — most of the confusion disappears once they’re separated.