Every homestay, hotel and resort in India collects personal data the moment a booking comes in: a name and phone number at first enquiry, a photo ID at check-in, sometimes a payment screenshot, often a WhatsApp chat history that runs for weeks. Until recently, how that data was stored, who could see it and how long it stayed on a host’s phone was entirely a matter of habit. That has changed. The Digital Personal Data Protection Act, 2023, along with its Rules notified in November 2025, is now a real law with real financial penalties, and it applies to a six-room homestay exactly as much as it applies to a national hotel chain.
This guide is a practical, homestay-and-hotel-specific explanation of DPDP Act and guest data privacy compliance: what the law actually asks a small property to do, how it interacts with the guest ID and police registration rules you already have to follow, and what to do in specific situations that come up constantly, a guest’s relative calling to ask which room they are in, a staff member’s phone going missing, an old guest list being reused for a festival-season WhatsApp blast. It also covers, in detail, one question this guide takes a clear position on: which identity document you should actually be asking guests for by default.
A quick note on scope: this guide covers data privacy, what personal data you collect, how you must handle it, and what happens if it leaks or is misused. For the separate question of which guests you are legally required to register and report to the police or FRRO, see our guides to Guest ID Compliance and FRRO and Foreign Guest Registration. The two overlap, the same photo ID you collect for registration is also personal data protected under the DPDP Act, but they are governed by different laws with different purposes.
What the DPDP Act for Homestays and Hotels Actually Is
The Digital Personal Data Protection Act, 2023 is India’s first comprehensive law on how personal data must be collected, used, stored and deleted. It was passed by Parliament in August 2023, but for most of the time since, it existed without the detailed rules needed to operate it day to day. That changed on 14 November 2025, when the Government of India notified the Digital Personal Data Protection Rules, 2025, which spell out exactly how consent notices should look, how a data breach must be reported, and how long organisations get to become compliant. The Rules gave every organisation an eighteen-month phased compliance window from the date of notification, so the practical deadline for having your processes in order runs into mid-2027, but the underlying obligations in the Act itself already apply now, and the phased window is a runway to fix gaps, not a reason to ignore the law until it ends.
The DPDP Act for homestays and hotels applies through one simple test: if your property decides why guest data is collected and how it is used, you are what the law calls a Data Fiduciary, and the Act’s obligations fall on you directly. It does not matter whether you run one homestay room above your own house or a fifty-key resort, and it does not matter whether you keep guest details in a WhatsApp chat, an Excel sheet or a proper property management system. The size of the business changes how much infrastructure you realistically need to build, not whether the law applies to you at all.
The People and Terms This Law Uses
A handful of terms come up throughout this guide and throughout the Act itself, and they are worth defining plainly once, in the homestay and hotel context, rather than in legal language.
What Counts as Guest Data Privacy in a Homestay or Hotel, in Practice
When people hear “data protection law,” it is easy to picture something that only concerns large tech companies with servers full of customer records. In a homestay or small hotel, the same categories of personal data exist, they are just spread across more informal places: a phone gallery, a WhatsApp thread, a notebook at the front desk, a shared Google Sheet. Recognising all of it is the first step, because the DPDP Act’s obligations attach to the data itself, not to the software it happens to be sitting in.
- Identity documents: photocopies, photographs or scanned images of the guest’s photo ID, along with the ID number itself.
- Contact details: phone number, email address, and home address collected at booking or check-in.
- Booking and stay data: arrival and departure dates, number of guests, room preferences, special requests, and any notes about food allergies or accessibility needs.
- Payment information: UPI transaction IDs, partial card numbers, payment screenshots, and billing details.
- Communication records: the full WhatsApp or SMS chat history with a guest, including anything they told you in confidence, a flight delay, a family emergency, a reason for an early checkout.
- Vehicle details: registration numbers noted for parking or security purposes.
- CCTV footage: if your property has cameras covering common areas, a guest’s face and movements captured on camera are personal data too.
- Children’s data: names and ages of children accompanying guests, which the Act treats with extra care.
- Staff and employee data: if you employ housekeeping or caretaking staff, their ID copies, bank details and attendance records are personal data as well, held under the same law, just with you as employer instead of host.
If you run a WhatsApp-first operation, and most Indian homestays and small hotels do, a large share of this data lives inside a single running chat thread per guest: their phone number, their ID photo sent over chat, their payment screenshot, and a written record of everything you discussed. That convenience is exactly why WhatsApp-based guest data deserves the same deliberate handling as a spreadsheet or a property management system, not less, simply because it feels informal.
The Legitimate Use Exception: How This Law Fits With Guest Registration Rules
The most common confusion hosts have about DPDP Act and guest data privacy compliance is assuming it conflicts with the separate legal requirement to register every guest and, in many states, report foreign nationals to the FRRO. It does not. Section 7 of the DPDP Act sets out a list of “legitimate uses” for which a Data Fiduciary can process personal data without going through the full consent process, and one of them is processing that is necessary for a Data Fiduciary to comply with any judgment, decree, order or any instrument under any law currently in force in India. Maintaining a guest register and sharing it with police when legally required falls squarely into this category, because that requirement is itself imposed by law, not something the property chooses to do for its own convenience.
What this means practically: you do not need to run a separate DPDP-style consent flow before writing a guest’s ID details into your legally mandated guest register, that specific collection is already justified by the registration law itself. What you do still need to do is apply the DPDP Act’s other principles, security, minimisation, accurate retention, to that same data once it is in your hands. The legitimate use exception justifies why you are allowed to collect it, it does not exempt you from protecting it properly afterwards. For the specific rules on who must be registered, within what timeframe, and what a valid guest register looks like, see the Guest ID Compliance guide, this page focuses on what happens to that data once it is collected.
The Core Obligations of Every Homestay, Hotel and Resort
Strip away the legal language and the DPDP Act asks a Data Fiduciary to do a short list of concrete things. None of them require a legal team or expensive software for a small property, they require a consistent habit and a written note of what that habit is.
Notice and Consent
Before or at the time you collect a guest’s data for anything beyond the legitimate-use registration purpose, for example if you plan to keep their number for future marketing, you need to give them clear notice of what you are collecting and why, and get their affirmative consent. The DPDP Rules, 2025 require this notice to be understandable on its own, in plain language, not buried inside a long booking policy document. For a homestay, the simplest way to do this is a short line added to your booking confirmation message, stated separately from the registration requirement itself.
Purpose Limitation
Data collected for one stated purpose should not quietly be reused for a different one without fresh consent. The clearest example in hospitality: a guest’s phone number, collected to coordinate their stay, cannot later be used to WhatsApp-blast unrelated promotional offers to your entire guest history unless they specifically agreed to that at some point. This is covered in more detail in the scenarios section below, and it connects directly to the opt-in guidance already covered in our WhatsApp Guest Communication Templates guide.
Data Minimisation
Collect what you actually need for the stated purpose, not everything a form or habit makes it easy to ask for. A homestay does not need a guest’s occupation, mother’s maiden name or any detail beyond what the registration requirement and a smooth stay actually call for. This principle is also the reason this guide takes a firm position, covered in full in the next section, on preferring Voter ID, Driving Licence or Passport as the documents you ask for.
Accuracy
Keep the personal data you hold accurate and complete for the purpose it is used for. If a guest tells you their phone number changed or corrects the spelling of their name, that correction should be reflected in your records, particularly if that data feeds into a guest register or a repeat-guest file.
Storage Limitation and Erasure
Personal data should not be kept indefinitely once its purpose is served. For most guest communication and payment data, once a stay is complete and any dispute window has passed, there is no ongoing purpose that justifies keeping it. The clear exception is your legally mandated guest register entry, which you are required to retain for whatever period the applicable police or FRRO rules specify, that retention obligation is itself a legal basis to keep that specific data even after the stay ends. Everything else, old WhatsApp media, payment screenshots, informal notes, should have a rough deletion habit rather than living forever in your phone’s gallery.
Reasonable Security Safeguards
This is the obligation with the highest financial penalty attached, and the most relevant one for a property that stores guest ID photos on a personal phone. “Reasonable security safeguards” is not defined as a specific checklist in the Act, it scales to the sensitivity of the data and the size of the operation, but for a homestay or small hotel it realistically means: guest ID copies are not sitting in an unlocked shared photo gallery every staff member can browse, the device or folder they are stored in is protected by at least a passcode, and access is limited to the people who actually need it, usually just the owner or manager.
Breach Notification
If personal data you hold is lost, stolen, or accessed without authorisation, a phone with guest ID photos going missing, a laptop being hacked, an accidental share of one guest’s details with another, the DPDP Rules, 2025 require you to inform affected individuals without delay, in plain language, explaining what happened, what the likely impact is, what you are doing about it, and how they can reach you with questions. Significant breaches also have to be reported to the Data Protection Board. A specific step-by-step response for this exact situation is covered in the scenarios section below.
Grievance Redressal
You need a way for a guest to reach you if they have a concern about how their data was handled, a request to delete their information, a question about who saw it, or a complaint. For a small property this can be as simple as a named contact, usually the owner, and a commitment to respond within a reasonable time. The DPDP Rules, 2025 set a maximum response window of ninety days for data access, correction or erasure requests, though a homestay or small hotel should aim to respond in days, not months, since most such requests are simple to action.
Children’s Data
If a booking includes children, the parent or guardian who made the booking is generally treated as providing consent on the child’s behalf as part of the normal booking and registration process. Where this needs extra care is if a property separately uses a child’s photo or details for marketing, social media, or any purpose beyond the stay itself, that requires distinct, verifiable parental consent under the DPDP Rules, 2025, not an assumption that booking the stay covered it.
The ID Document Question: What to Ask Guests For
Every homestay and hotel needs a valid government photo ID from each guest, that requirement does not go away under the DPDP Act, it comes from the separate guest registration rules covered in our Guest ID Compliance guide. What this guide takes a clear, deliberate position on is which document you should ask for by default: a Voter ID, Driving Licence or Passport, in that order of preference. Treat Aadhaar as a last resort, not your standard request.
Why This Order of Preference
A Voter ID, Driving Licence or Passport is a complete, self-contained photo document, it establishes who someone is without being tied to anything beyond that document itself. A single Aadhaar number works differently, it is linked to a much wider set of a person’s accounts and services, which is exactly why a full copy sitting in a homestay’s files carries more exposure if it is ever lost or misused than a Voter ID or Driving Licence copy does.
It is also worth being plain about what Aadhaar actually is: proof of identity and residency, not proof of citizenship, and sharing it with a private business is meant to be voluntary, not a condition of service. A guest is free to offer a Voter ID, Driving Licence or Passport instead, and a property should never refuse a booking or check-in solely because a guest prefers not to hand over their Aadhaar.
2. If a guest only has Aadhaar available, ask for the masked version, showing only the last four digits, rather than a full copy.
3. Never write down or store a guest’s full Aadhaar number separately in a spreadsheet, notebook or CRM field, even if you photograph the card itself.
4. Never refuse a booking or check-in solely because a guest offers an alternative valid photo ID instead of their preferred document, sharing any specific ID is voluntary, not something you can insist on.
None of this changes what the separate guest registration law requires, a valid government photo ID, in some form, is still mandatory for every guest, and that requirement is unaffected by which specific document type a guest offers. What changes is which document you steer guests toward by default, and how carefully you handle the rare case where Aadhaar is genuinely the only ID a guest has on hand.
Setting Up DPDP Act and Guest Data Privacy Compliance in Practice
Turning the obligations above into an actual routine does not require legal software or a compliance officer for a homestay or small independent hotel. It requires four habits, done consistently, and written down once so that every family member or staff member handling check-ins follows the same routine.
1. Storage: Where Guest ID Copies Actually Live
If you photograph a guest’s ID on your personal phone, that photo defaults into your general camera roll, which is likely backed up to a personal cloud account, visible to anyone who picks up your unlocked phone, and mixed in with years of unrelated personal photos. A better habit is to keep guest ID photos in a single, separate, passcode-protected folder or app, and to delete them from the general camera roll once they have been filed there.
2. Access: Who Can Actually See This Data
Not every staff member needs access to every guest’s ID copy. A caretaker who manages housekeeping does not need to browse the folder of ID photos going back two years, a night-shift staff member checking someone in needs to be able to add a new entry, not necessarily read every old one. Where your property has more than one or two people involved, decide in advance who can view stored guest data and keep that circle as small as the operation genuinely allows.
3. Retention: How Long to Keep What
Different categories of guest data have different retention logic. Your official guest register entry should be retained for whatever period your state’s police rules or FRRO requirements specify, covered in detail in Guest ID Compliance and FRRO and Foreign Guest Registration. Beyond that specific legal minimum, most other guest data, WhatsApp chat history, payment screenshots, informal notes, has no ongoing legal reason to be kept indefinitely once the stay is complete and a reasonable dispute window, typically a few weeks to a couple of months, has passed.
4. Security Basics That Cost Nothing
Reasonable security safeguards, for a property this size, is mostly about avoiding easy, avoidable mistakes rather than buying software. A passcode on the device or folder where guest data lives. Not sending a guest’s ID photo over an unsecured public Wi-Fi network to a third party unless necessary. Not storing payment card details in plain text anywhere, most Indian homestays already rely on UPI, which does not require this at all. Logging out of shared devices, if a front-desk computer is used by multiple staff members across shifts, so one person’s login is not left open for the next person by default.
5. Handling a Guest’s Request
A guest is entitled to ask what data you hold about them and to request that it be corrected or deleted, subject to your legal retention obligations for the registration record. If this happens, acknowledge the request, explain clearly what you can delete immediately (chat history, photos, informal notes) and what you are required to retain for a defined period (the formal register entry, and why), and action the deletable part promptly rather than waiting for a formal deadline.
Scaling This to the Size of Your Property
The core obligations in this guide, notice, minimisation, security, retention, apply identically whether you run one homestay room or a fifty-key resort, but how you actually implement them looks different depending on how many people are involved.
A Single-Owner Homestay
With one or two rooms and the owner handling every check-in personally, compliance is mostly about personal device discipline: a separate passcode-protected folder for guest ID photos, a habit of clearing out old data every few months, and being the single, obvious point of contact if a guest ever has a question about their data. There is no access-control problem to solve when only one person ever handles guest data in the first place.
A Small Hotel or Multi-Room Guesthouse With Staff
Once housekeeping staff, a caretaker or front-desk help are involved, access control becomes the practical center of compliance. Decide explicitly who can see stored guest ID data and who only needs to be able to add a new check-in entry, and make removing a departing staff member’s access a standard, non-negotiable step, not an afterthought. A shared device used across shifts should log out between users rather than staying open on one person’s session all day.
A Resort or Larger Property With a Marketing or Sales Function
Where a property has a dedicated marketing effort, running WhatsApp campaigns, managing a CRM, posting guest photos, purpose limitation and consent tracking matter more, since more of the guest data collected genuinely does get reused for a second purpose beyond the original stay. This is also the size of property most likely to eventually cross into a Significant Data Fiduciary classification if the government notifies thresholds that apply to it, worth revisiting this guide’s obligations periodically as the property grows rather than assuming what worked at a smaller scale still fully covers a larger one.
Real Scenarios: Applying DPDP Act and Guest Data Privacy Compliance
The obligations above are easiest to understand through the situations that actually create them. The scenarios below are grouped by theme and cover the moments where a host has to make a real, immediate decision about someone’s personal data, not just follow a written policy in the abstract.
Who Gets to Know a Guest Is Staying With You
A guest’s presence at your property, their room number, their length of stay, even the fact that they are your guest at all, is personal data belonging to them, not information you are free to share with whoever asks. This matters more than hosts often assume, because requests for this information can come from people with entirely reasonable-sounding motives and, occasionally, from people with harmful ones.
2. Instead, tell the caller you cannot share guest information over the phone, but offer to pass a message to the guest yourself if they wish to leave one.
3. Contact the guest directly, tell them who called and what was asked, and let the guest decide whether to respond, call back or ignore it. The decision to be contactable belongs to the guest, not to you or the caller.
4. If the caller becomes insistent or aggressive, this is a signal worth taking seriously rather than a reason to relent, treat it as you would any other guest-safety concern.
2. Politely decline to share details over an unverified call, and ask for the request in writing or for the officer to visit the property, where you can verify their identity before sharing anything.
3. If you are unsure, call the local police station’s official number yourself, not a number the caller gave you, to confirm the request is genuine before disclosing anything.
4. This is not obstruction, verifying who is actually asking before you hand over a guest’s personal data is exactly the kind of reasonable security safeguard the DPDP Act expects, and legitimate police requests will not be undermined by a property confirming identity first.
2. Decline to share the register itself. If a travel agent or OTA needs to confirm a specific booking, share only the details relevant to that one booking, not your full guest history.
3. If a partner insists this is needed for their own compliance, ask them to specify the exact legal basis and the exact data they need, most requests of this kind are actually about a single disputed booking, not a genuine need for bulk guest data.
Device Loss, Breaches and Access Mistakes
A breach, under the DPDP Act, is not only a dramatic hacking incident, it includes ordinary, everyday mistakes: a lost phone, a message sent to the wrong chat, an employee who left the job but never lost access to shared files. What matters is how quickly and honestly it is handled once it happens.
2. Assess which guests’ data was actually on the device, recent ID photos, active chat threads, and treat this as a data breach under the DPDP Act, not just a lost-device inconvenience.
3. Notify the affected guests without delay, in plain language: what happened, what data of theirs may have been exposed, what you are doing about it (device wipe, password changes), and how they can reach you with concerns.
4. Going forward, this is exactly the scenario the storage and access habits earlier in this guide are meant to prevent, a passcode-protected, separate folder limits what is actually exposed even if a device does go missing.
2. Inform the affected guest, whose data was mistakenly shared, what happened and to whom, even if you believe the recipient deleted it. Transparency here matters more than hoping it goes unnoticed.
3. If the recipient is a stranger to the affected guest, treat this with more urgency than if it was shared internally among your own trusted staff, and consider whether the affected guest should be advised to watch for any misuse of their ID details.
4. Use the mistake as the trigger to review how documents are forwarded during check-in, a habit of double-checking the recipient before sending anything containing a guest’s ID prevents most versions of this scenario entirely.
2. Immediately remove their access to shared folders, change shared passwords they knew, and check whether they had forwarded any guest data to a personal device or account before leaving.
3. If a departing staff member had broad access to years of accumulated guest data, this is also a good moment to apply the storage-limitation principle and reduce how much historical data is sitting around, less retained data means less exposure from any future access mistake.
Marketing, Repeat Guests and Reusing Old Data
Guest data collected for one purpose, running a booking, has an obvious commercial pull toward being reused for another, filling rooms during a slow season. The line between reasonable, welcome outreach and a purpose-limitation violation comes down to whether the guest actually agreed to be contacted that way.
2. Message only guests who gave clear consent to future offers, ideally through a specific opt-in like the consent line covered earlier in this guide, or through their own return interaction with the property.
3. For guests without that consent, either skip them for this campaign or use the outreach itself to ask permission first, “we’d love to let you know about upcoming offers, would you like us to?”, rather than sending the offer outright.
4. This connects directly to the message-frequency and opt-out guidance in our WhatsApp Guest Communication Templates guide, a guest who never explicitly agreed to marketing messages and receives one anyway is more likely to block your number than book again.
2. Still apply basic hygiene: if a guest has not returned in several years and there is no active relationship, treat old preference notes the same as other stale data and consider whether they are still needed.
3. If a guest ever asks what you have on file about them, be ready to show them plainly, “room 4, ground floor requested; mentioned a peanut allergy in 2023,” most guests are reassured rather than alarmed by this kind of transparency, since it demonstrates the data is being used to serve them, not against them.
ID Documents and Consent at Check-in
This is where the ID-document recommendation covered earlier in this guide actually plays out in a live conversation at the front desk.
2. Reassure them on handling: explain, briefly, that the ID is used only for the registration record, stored securely, and not shared beyond what the law requires.
3. Offer the choice explicitly: “a Voter ID, Driving Licence or Passport works well, do you have one of those handy?” This framing, offering options rather than demanding one specific document, tends to reduce pushback significantly.
2. Ask if they have the masked Aadhaar version, showing only the last four digits, many guests who travel frequently already carry this version for exactly this reason.
3. If only the full Aadhaar is available, photograph or note only what your registration record actually requires, and avoid separately writing out the full 12-digit number in any additional register, spreadsheet or note beyond what the official guest register format requires.
4. Treat this document with the storage and access precautions covered earlier in this guide at least as carefully as any other ID, if not more so, given the wider linkage risk a full Aadhaar number carries if it is ever exposed.
2. Action the deletable part promptly, delete the chat media and any ID photo stored outside the official register, and confirm to the guest what was deleted and what was retained and why.
3. This kind of request, handled transparently, tends to build trust rather than create friction, most guests asking this are simply privacy-conscious, not adversarial, and a clear, honest answer satisfies the concern.
CCTV, Children and Third-Party Tools
A handful of situations do not come up daily, but are common enough across Indian homestays and hotels, and confusing enough when they do come up, that they deserve a specific answer rather than being left to guesswork in the moment.
2. CCTV footage of common areas is a reasonable, standard security measure and does not need individual consent to record in the first place, but it does need visible signage informing guests that cameras are in use, and it should never cover private spaces like guest rooms or bathrooms.
3. If footage is requested by another guest as “evidence” in a dispute rather than by the person appearing in it, do not hand it over directly, this is a data-sharing decision with the same care as any other guest data disclosure, involve the police if the dispute is serious enough to need footage as evidence.
4. Keep CCTV retention short and routine, most properties do not need footage older than a few weeks unless there is an active incident, and a fixed automatic-overwrite cycle is simpler to manage than manual deletion.
2. Where this changes is if the property wants to use a child’s photo or details for anything beyond the stay, a social media post, a testimonial, a marketing photo, that requires distinct, verifiable consent from the parent or guardian for that specific use, not an assumption that booking the room covered it.
3. When in doubt, simply ask the parent directly and specifically, “would you be comfortable if we shared a photo from today on our Instagram?”, rather than posting first and assuming permission.
2. The responsibility that does not go away: you remain the Data Fiduciary even when a vendor processes data on your behalf, so it is worth a basic check of any tool you adopt, does it have a clear security and data-handling policy, does it let you delete guest data on request, is it a reasonably established provider rather than an obscure, unverified app.
3. For guest ID documents specifically, favour tools and habits that keep that most sensitive category of data on-device or within a purpose-built, access-controlled system, rather than scattered across general-purpose cloud photo backups or messaging apps not designed for document storage.
2. A broad request for a full list of guest names, ID numbers or contact details going beyond what gate management genuinely needs is a wider data share than the purpose requires, and DPDP’s minimisation principle applies to this handover just as it does to any other.
3. Where possible, share only what the gate actually needs, the guest’s name and stay dates, rather than a full copy of your register, and avoid making this a standing, automatic data feed with no defined limit on how it is used or how long it is kept by the society.
Common Mistakes Homestays and Hotels Make
A few mistakes show up repeatedly across Indian homestays and small hotels, not because owners are careless, but because these habits formed before a real law existed to push back against them. Recognising them is often enough to fix them.
- Treating the phone camera roll as guest data storage. ID photos taken on a personal phone, with no separate folder or passcode, sit alongside years of unrelated personal photos and are visible to anyone who picks up the unlocked phone, including children in the household or a repair technician.
- Asking for Aadhaar as the only accepted ID. Beyond the legal problem covered earlier in this guide, it is also simply unnecessary, Voter ID, Driving Licence and Passport all satisfy the same registration requirement without the added risk.
- Forwarding a guest’s ID into a staff WhatsApp group “so everyone is aware.” Most staff members handling a shift do not need to see every past guest’s ID document, only the ones relevant to their current task.
- Never deleting anything. Years of guest ID photos, old chats and payment screenshots accumulating with no review creates a larger and larger exposure if a device is ever lost or compromised, for no ongoing benefit to the property.
- Reusing old guest numbers for marketing without asking. A number collected to coordinate a stay two years ago is not the same as a number given permission to receive festival offers today.
- Assuming an OTA or booking platform “handles compliance.” Whatever data a property collects directly, ID copies at check-in, its own WhatsApp thread, is the property’s own responsibility regardless of which platform the original booking came through.
- No plan for what to do if a phone is lost. The single most common realistic breach scenario for a small property, and also the easiest one to prepare for in advance with a basic remote-lock and password-change habit.
Quick-Reference Templates
Two templates worth keeping handy, one for the everyday moment of collecting data, one for the rare but urgent moment when something goes wrong with it.
2. Work out exactly what guest data was actually exposed, which stays, which documents, which chats, rather than assuming the worst or guessing.
3. Notify every affected guest without delay, in plain language: what happened, what data of theirs was involved, what you are doing about it, and how they can reach you with questions.
4. If the breach is significant, a large number of guests affected, or sensitive data like full ID numbers exposed, report it to the Data Protection Board of India, as the DPDP Rules, 2025 require.
5. Once contained, revisit the storage and access habits covered earlier in this guide and fix whatever gap allowed this to happen, so the same mistake does not repeat.
When a Guest Asks to See, Correct or Delete Their Data
The DPDP Act gives every guest, as a Data Principal, the right to ask what personal data you hold about them, to have it corrected, and to have it erased once there is no legal reason left to keep it. This comes up less often than a check-in or a data breach, but it is worth having a simple, unpanicked routine ready for it.
Check whether any part of what you hold falls under a legal retention requirement, such as the period local police or municipal rules expect guest-registration records to be kept, or the period tax law expects billing records to be kept.
If a legal retention period still applies, explain to the guest what you must keep and for how long, and delete everything else, the ID copy, phone number and chat history, from wherever it sits: your phone, WhatsApp, a spreadsheet, a shared drive.
Confirm back to the guest in writing once it is done, or explain clearly what you retained and why.
Share it with them in plain language rather than a technical export, most guests just want reassurance that you are not holding more than they would expect.
Use the moment to also ask whether they are happy for you to keep their number for future booking reminders, or whether they would rather you deleted it after this reply.
Note the exchange somewhere so that if the same guest asks again later, you have a record of what was already shared and agreed.
What Non-Compliance Actually Costs
The DPDP Act’s penalties are enforced by the Data Protection Board of India, and they are structured as ceilings tied to the type of failure rather than a fixed fine for every violation. For a homestay or small hotel, the realistic risk is not a government audit knocking on the door unprompted, it is a guest complaint escalating, or a data breach that becomes visible enough to draw scrutiny. Either way, the numbers involved are large enough that they are worth understanding rather than dismissing as something only large companies need to worry about.
| Type of Failure | Penalty Ceiling | What This Looks Like in Practice |
|---|---|---|
| Failure to take reasonable security safeguards, leading to a data breach | Up to ₹250 crore | Guest ID data or payment details exposed due to careless storage, an unsecured shared folder, no passcode protection, no basic access control. |
| Failure to notify the Data Protection Board and affected individuals of a breach | Up to ₹200 crore | A breach occurs, but the property tries to quietly ignore it rather than notifying affected guests, this is treated as a separate, additional failure on top of the breach itself. |
| Breach of obligations relating to children’s data | Up to ₹200 crore | Using a child’s photo or details for marketing or any purpose beyond the stay without verifiable parental consent for that specific use. |
| General non-compliance with other obligations | Up to ₹50 crore | Failing to provide proper notice, ignoring a legitimate data-access or deletion request beyond the response window, or other procedural gaps. |
These are ceiling amounts set by the Act for the most serious violations, and the Data Protection Board has discretion to scale a penalty to the actual severity, scope and intent behind a specific failure, a small property’s honest mistake, corrected quickly and transparently, is treated very differently by the Board’s process than a large-scale, deliberate or repeated failure. The purpose of listing these figures is not to alarm a six-room homestay into thinking it faces a 250-crore fine over a lost phone, it is to make clear that “reasonable security safeguards” is not a soft suggestion, it is the specific obligation the law’s largest penalties are built around, which is exactly why the storage and access habits covered earlier in this guide matter more than any other single piece of this compliance picture.
How OpenStays Fits Into This
OpenStays’ WhatsApp AI already handles the part of the guest journey where most of this personal data first enters your property, the booking conversation, the ID collection request, the payment step. Being specific about what that actually means: guest ID documents collected through the platform are tied to a structured booking record rather than scattered across an open camera roll, retention follows the property’s stated purpose rather than living forever by default, and the guest register export feature exists precisely so an owner is not manually retyping ID details into a separate notebook, one extra place for that data to sit insecurely.
What OpenStays does not do, and should not be mistaken for doing, is make the underlying legal judgment calls covered in the scenarios above. If a guest’s relative calls asking for their room number, if a staff member’s phone goes missing, if a guest asks why their data is being kept, those are decisions a host has to make in the moment, informed by the principles in this guide, not something software can decide on a property’s behalf. The platform is built to reduce how many places sensitive guest data ends up scattered across, it is not a substitute for the judgment calls this guide is meant to prepare a host to make.
Legal Backdrop: The Laws Behind This Guide
This guide draws on a specific set of Indian laws and regulatory actions, listed here for hosts who want to read the primary source rather than a summary, and because a compliance guide should show its work.
- The Digital Personal Data Protection Act, 2023, the full text as published by the Ministry of Electronics and Information Technology.
- The Digital Personal Data Protection Rules, 2025, notified by the Government of India in November 2025, which operationalise the Act with an eighteen-month phased compliance window.
- Justice K.S. Puttaswamy (Retd.) vs Union of India, the Supreme Court’s 2018 judgment recognising privacy as a fundamental right, the constitutional foundation the DPDP Act itself builds on.
This guide is written for homestay, hotel and resort owners, not as a substitute for legal advice specific to your property, your state, or a particular situation you are facing. Where a scenario in this guide genuinely turns on your specific facts, a lost device with sensitive data on it, a formal complaint from a guest, a request from a regulator, it is worth a conversation with a lawyer or a data protection consultant rather than relying on this guide alone.
Frequently Asked Questions
Does a small homestay really need to worry about the DPDP Act, or is this only for big companies?
The DPDP Act applies to any organisation that decides why and how personal data is collected and used, called a Data Fiduciary, regardless of size. A six-room homestay collecting guest ID copies and phone numbers is a Data Fiduciary in exactly the same way a large hotel chain is. What differs by size is the extra layer of obligations reserved for “Significant Data Fiduciaries,” a government-notified category based on data volume and sensitivity, which most independent homestays and small hotels will not fall into. The core obligations, notice, security, breach handling, apply to everyone.
Can I still ask guests for Aadhaar at check-in?
Yes, a guest can offer Aadhaar and you can accept it. What this guide recommends against is making Aadhaar your default, only-accepted request. Ask for Voter ID, Driving Licence or Passport first, and if a guest only has Aadhaar, prefer the masked version showing just the last four digits over a full photocopy, and never write out the full 12-digit number separately.
Do I need a Data Protection Officer for my property?
Only Significant Data Fiduciaries, a category assigned by the government based on data volume and sensitivity, are required to appoint a Data Protection Officer. Most homestays, guesthouses and independent hotels are not in this category, though every Data Fiduciary, regardless of size, still needs a clear point of contact for guests to raise data concerns with, which for a small property is usually just the owner.
Does collecting a guest register for police purposes need separate DPDP consent?
No. Processing personal data to comply with a legal obligation, such as maintaining a guest register required by police or FRRO rules, falls under the DPDP Act’s “legitimate use” exception in Section 7, and does not require a separate consent process. You still need to apply the Act’s other principles, security and minimisation in particular, to that same data once collected.
What should I do if I discover a data breach, like a lost phone with guest data on it?
Act quickly: secure or wipe the device remotely if possible, assess which guests’ data was exposed, and notify those guests without delay in plain language explaining what happened and what you are doing about it. Significant breaches also need to be reported to the Data Protection Board of India. The full step-by-step is covered in the device-loss scenario earlier in this guide.
How long should I keep a guest’s WhatsApp chat and ID photo after checkout?
There is no single fixed number that applies everywhere, since the required retention period for your formal guest register entry depends on your state’s police rules and, for foreign nationals, FRRO requirements, covered in our Guest ID Compliance guide. Beyond that legal minimum, informal chat history and photos have no ongoing legal reason to be kept indefinitely, a reasonable habit is to review and clear out data for completed stays with no open dispute every few months.
Do OTAs like Airbnb or MakeMyTrip handle DPDP compliance for me?
An OTA is responsible for its own data-handling practices as a Data Fiduciary for the data it collects and controls. It does not cover your obligations for data you collect directly, ID copies at check-in, your own WhatsApp conversations, your own guest register. If a booking comes through an OTA but you collect additional data yourself at the property, you are independently responsible for that data.
What if a guest refuses to give any form of ID?
A valid government photo ID is a legal requirement for guest registration in India, not an optional courtesy, so a guest who refuses to provide any acceptable ID cannot be legally checked in. This is a registration-law requirement, not a DPDP Act one, see Guest ID Compliance for the full detail on acceptable documents and what to do in this situation.
Can I post a guest’s photo or review on Instagram or my website?
Only with the guest’s clear, specific consent for that particular use. A guest agreeing to stay at your property, or even leaving a written review, is not the same as agreeing to have their face or full name used in your marketing. Ask directly, “would you be comfortable if we shared this photo on our page, tagging you if you like?”, and treat a lack of response as a no, not a yes by default.
Does DPDP Act compliance mean I need to host guest data only on Indian servers?
No, the DPDP Act does not require Indian data localisation as a general rule, cross-border data transfer is permitted by default, with the government retaining the power to restrict transfers to specific countries if it chooses to. A homestay or hotel using an internationally hosted WhatsApp CRM, cloud spreadsheet or booking tool is not, on that basis alone, non-compliant. What still matters is choosing a reasonably reputable vendor with a clear data-handling policy, since you remain responsible as the Data Fiduciary regardless of where the vendor’s servers happen to sit.
One more point worth stating plainly before wrapping up: none of the obligations in this guide are meant to make a host suspicious of every guest interaction or afraid to run a WhatsApp-first, informal operation, which is how most successful Indian homestays and small hotels actually work. The goal is narrower than that, treat a guest’s ID document and personal details with roughly the same care you would want a stranger to treat your own passport and phone number, and most of what the DPDP Act asks for falls out naturally from that one instinct.
In Summary
DPDP Act and guest data privacy compliance for homestays, hotels and resorts comes down to a short set of habits repeated consistently rather than a one-time legal exercise. Tell guests plainly what data you collect and why, especially anything beyond the registration requirement itself. Collect only what the stated purpose actually needs, and follow the ID-document guidance covered earlier in this guide. Keep guest data in a passcode-protected, access-limited place rather than scattered across an open camera roll or shared group chats. Retain your formal guest register entry for as long as registration law requires, and clear out everything else, chats, photos, informal notes, once its purpose has genuinely passed. Respond honestly and quickly if something goes wrong, a lost device, a misdirected message, rather than hoping it goes unnoticed. None of this requires new software or a legal team for most properties, it requires treating a guest’s ID photo with the same seriousness you would want a stranger to treat yours.
This guide is intended to help homestay, hotel and resort owners understand their obligations under the DPDP Act, 2023 and related regulations in plain, practical terms. It is not legal advice. Data protection law involves specific facts, evolving rules, and in some cases state-level variation, and this guide cannot account for every individual circumstance. For a situation with real legal or financial exposure, a data breach, a regulatory notice, a formal guest complaint, consult a lawyer or a qualified data protection professional familiar with your specific situation.