dpdpconsent.in
Resources

What is DPDP, actually?

The Digital Personal Data Protection Act, 2023 is India's first dedicated law on how organisations must handle personal data. For a hotel, that means guest names, phone numbers, addresses, ID numbers, and anything collected at check-in, on WiFi, or through marketing.

What it actually requires

Strip away the drafting, and DPDP asks four things of any business handling personal data: tell people what you’re collecting and why (notice), get a real basis to collect it — usually consent, sometimes a “legitimate use” like a legal filing — keep it only as long as you need it, and let people ask what you hold and have it corrected or deleted.

None of this is exotic. Most of it is what a well-run front desk already half-does — the gap is usually that it’s not written down, not consistent, and not something anyone could show an inspector or a corporate client on request.

What it doesn’t say

DPDP does not require you to buy software, hire a data protection officer if you’re a smaller business, or get a lawyer to sign off on your check-in form. It also doesn’t make audits mandatory for a 40-key property — despite what some vendors will tell you. The obligations scale with what you actually do with data, not with the size of the fine you’ve been shown in a sales deck.

Why hotels specifically

Hospitality collects unusually sensitive data as a matter of routine: government ID at check-in, payment details, sometimes health information for special requests, and — for family bookings — data about minors. Very few sectors combine that volume of sensitive data with as little formal process around it.