DPDP Act and Guest Data Privacy Compliance for Homestays, Hotels and Resorts

🕑Last updated: 10 August 2026 — reflects the DPDP Rules, 2025 notified in November 2025

Every homestay, hotel and resort in India collects personal data the moment a booking comes in: a name and phone number at first enquiry, a photo ID at check-in, sometimes a payment screenshot, often a WhatsApp chat history that runs for weeks. Until recently, how that data was stored, who could see it and how long it stayed on a host’s phone was entirely a matter of habit. That has changed. The Digital Personal Data Protection Act, 2023, along with its Rules notified in November 2025, is now a real law with real financial penalties, and it applies to a six-room homestay exactly as much as it applies to a national hotel chain.

This guide is a practical, homestay-and-hotel-specific explanation of DPDP Act and guest data privacy compliance: what the law actually asks a small property to do, how it interacts with the guest ID and police registration rules you already have to follow, and what to do in specific situations that come up constantly, a guest’s relative calling to ask which room they are in, a staff member’s phone going missing, an old guest list being reused for a festival-season WhatsApp blast. It also covers, in detail, one question this guide takes a clear position on: which identity document you should actually be asking guests for by default.

A quick note on scope: this guide covers data privacy, what personal data you collect, how you must handle it, and what happens if it leaks or is misused. For the separate question of which guests you are legally required to register and report to the police or FRRO, see our guides to Guest ID Compliance and FRRO and Foreign Guest Registration. The two overlap, the same photo ID you collect for registration is also personal data protected under the DPDP Act, but they are governed by different laws with different purposes.

What the DPDP Act for Homestays and Hotels Actually Is

The Digital Personal Data Protection Act, 2023 is India’s first comprehensive law on how personal data must be collected, used, stored and deleted. It was passed by Parliament in August 2023, but for most of the time since, it existed without the detailed rules needed to operate it day to day. That changed on 14 November 2025, when the Government of India notified the Digital Personal Data Protection Rules, 2025, which spell out exactly how consent notices should look, how a data breach must be reported, and how long organisations get to become compliant. The Rules gave every organisation an eighteen-month phased compliance window from the date of notification, so the practical deadline for having your processes in order runs into mid-2027, but the underlying obligations in the Act itself already apply now, and the phased window is a runway to fix gaps, not a reason to ignore the law until it ends.

The DPDP Act for homestays and hotels applies through one simple test: if your property decides why guest data is collected and how it is used, you are what the law calls a Data Fiduciary, and the Act’s obligations fall on you directly. It does not matter whether you run one homestay room above your own house or a fifty-key resort, and it does not matter whether you keep guest details in a WhatsApp chat, an Excel sheet or a proper property management system. The size of the business changes how much infrastructure you realistically need to build, not whether the law applies to you at all.

The People and Terms This Law Uses

A handful of terms come up throughout this guide and throughout the Act itself, and they are worth defining plainly once, in the homestay and hotel context, rather than in legal language.

DATA PRINCIPAL
The individual the data is about
This is your guest. Every time this guide talks about a Data Principal, it means the person staying at your property, or in some cases their child, whose name, ID number, phone number or payment details you are holding.
DATA FIDUCIARY
The one who decides why and how data is used
This is your property, the homestay, hotel or resort, or you personally if you run it as a sole proprietor. You decide why you are collecting a guest’s ID document (to register them and satisfy police rules) and how long you keep the WhatsApp chat (until the trip is over, or longer if you use it for repeat-guest service). That decision-making role is what makes you a Data Fiduciary under the law, and it is where almost all of the Act’s obligations sit.
DATA PROCESSOR
Anyone processing data on your behalf, under your instructions
If you use a WhatsApp CRM tool, a booking engine, or a bookkeeping service that stores guest details for you, that vendor is typically a Data Processor acting on your instructions. You, the Data Fiduciary, remain responsible for what happens to the data even when a vendor is technically holding it, which is why it matters to pick vendors that take security seriously rather than assuming the responsibility has been outsourced along with the task.
PERSONAL DATA
Any data that identifies a person, directly or indirectly
A guest’s name, phone number, email, ID number, photo, vehicle number, payment details and even a WhatsApp message they sent you asking about a late checkout all count as personal data if they can be linked back to that specific guest.
CONSENT
Free, specific, informed, unconditional agreement, given through a clear affirmative action
Under the DPDP Rules, 2025, the notice asking for consent has to be clear on its own, not buried in a long terms-and-conditions document, and it has to explain what data is being collected and why in language the guest can actually understand. Silence, a pre-ticked box, or a guest simply not objecting does not count as consent.
SIGNIFICANT DATA FIDUCIARY
A category with extra obligations, notified by the government based on data volume and sensitivity
This status is assigned by the government to specific organisations that process a large volume of data or particularly sensitive categories of it, think large OTAs, national hotel chains or payment processors, not a single homestay or a small independent hotel. Significant Data Fiduciaries have to appoint a Data Protection Officer, run periodic audits and data protection impact assessments. Most homestays, guesthouses and independent hotels reading this guide will not be classified this way, but the underlying obligations, notice, consent, security, breach reporting, apply to every Data Fiduciary regardless of size.
DATA PROTECTION BOARD OF INDIA
The regulator that enforces the Act
The Board investigates complaints, orders remedial action and levies financial penalties for non-compliance. It functions similarly to how a consumer court or a tax tribunal works, a guest or another affected person can file a complaint, and the Board has the power to summon the property, examine records and impose a fine after due process.
DPDP ACT FOR HOMESTAYS AND HOTELS, AT A GLANCE
2023
Act passed by Parliament
Nov 2025
DPDP Rules notified
18 months
Phased compliance window from notification
₹250 Cr
Maximum penalty for a security-safeguard failure

What Counts as Guest Data Privacy in a Homestay or Hotel, in Practice

When people hear “data protection law,” it is easy to picture something that only concerns large tech companies with servers full of customer records. In a homestay or small hotel, the same categories of personal data exist, they are just spread across more informal places: a phone gallery, a WhatsApp thread, a notebook at the front desk, a shared Google Sheet. Recognising all of it is the first step, because the DPDP Act’s obligations attach to the data itself, not to the software it happens to be sitting in.

  • Identity documents: photocopies, photographs or scanned images of the guest’s photo ID, along with the ID number itself.
  • Contact details: phone number, email address, and home address collected at booking or check-in.
  • Booking and stay data: arrival and departure dates, number of guests, room preferences, special requests, and any notes about food allergies or accessibility needs.
  • Payment information: UPI transaction IDs, partial card numbers, payment screenshots, and billing details.
  • Communication records: the full WhatsApp or SMS chat history with a guest, including anything they told you in confidence, a flight delay, a family emergency, a reason for an early checkout.
  • Vehicle details: registration numbers noted for parking or security purposes.
  • CCTV footage: if your property has cameras covering common areas, a guest’s face and movements captured on camera are personal data too.
  • Children’s data: names and ages of children accompanying guests, which the Act treats with extra care.
  • Staff and employee data: if you employ housekeeping or caretaking staff, their ID copies, bank details and attendance records are personal data as well, held under the same law, just with you as employer instead of host.

If you run a WhatsApp-first operation, and most Indian homestays and small hotels do, a large share of this data lives inside a single running chat thread per guest: their phone number, their ID photo sent over chat, their payment screenshot, and a written record of everything you discussed. That convenience is exactly why WhatsApp-based guest data deserves the same deliberate handling as a spreadsheet or a property management system, not less, simply because it feels informal.

The Legitimate Use Exception: How This Law Fits With Guest Registration Rules

The most common confusion hosts have about DPDP Act and guest data privacy compliance is assuming it conflicts with the separate legal requirement to register every guest and, in many states, report foreign nationals to the FRRO. It does not. Section 7 of the DPDP Act sets out a list of “legitimate uses” for which a Data Fiduciary can process personal data without going through the full consent process, and one of them is processing that is necessary for a Data Fiduciary to comply with any judgment, decree, order or any instrument under any law currently in force in India. Maintaining a guest register and sharing it with police when legally required falls squarely into this category, because that requirement is itself imposed by law, not something the property chooses to do for its own convenience.

What this means practically: you do not need to run a separate DPDP-style consent flow before writing a guest’s ID details into your legally mandated guest register, that specific collection is already justified by the registration law itself. What you do still need to do is apply the DPDP Act’s other principles, security, minimisation, accurate retention, to that same data once it is in your hands. The legitimate use exception justifies why you are allowed to collect it, it does not exempt you from protecting it properly afterwards. For the specific rules on who must be registered, within what timeframe, and what a valid guest register looks like, see the Guest ID Compliance guide, this page focuses on what happens to that data once it is collected.

The Core Obligations of Every Homestay, Hotel and Resort

Strip away the legal language and the DPDP Act asks a Data Fiduciary to do a short list of concrete things. None of them require a legal team or expensive software for a small property, they require a consistent habit and a written note of what that habit is.

Notice and Consent

Before or at the time you collect a guest’s data for anything beyond the legitimate-use registration purpose, for example if you plan to keep their number for future marketing, you need to give them clear notice of what you are collecting and why, and get their affirmative consent. The DPDP Rules, 2025 require this notice to be understandable on its own, in plain language, not buried inside a long booking policy document. For a homestay, the simplest way to do this is a short line added to your booking confirmation message, stated separately from the registration requirement itself.

EXAMPLE CONSENT LINE
Add to your booking confirmation WhatsApp message
We will save your name and number to share booking updates and, only if you say yes, occasional offers for future stays. Reply STOP anytime to opt out of offers. This is separate from the ID details we need to collect at check-in for guest registration, which is a legal requirement regardless of this choice.

Purpose Limitation

Data collected for one stated purpose should not quietly be reused for a different one without fresh consent. The clearest example in hospitality: a guest’s phone number, collected to coordinate their stay, cannot later be used to WhatsApp-blast unrelated promotional offers to your entire guest history unless they specifically agreed to that at some point. This is covered in more detail in the scenarios section below, and it connects directly to the opt-in guidance already covered in our WhatsApp Guest Communication Templates guide.

Data Minimisation

Collect what you actually need for the stated purpose, not everything a form or habit makes it easy to ask for. A homestay does not need a guest’s occupation, mother’s maiden name or any detail beyond what the registration requirement and a smooth stay actually call for. This principle is also the reason this guide takes a firm position, covered in full in the next section, on preferring Voter ID, Driving Licence or Passport as the documents you ask for.

Accuracy

Keep the personal data you hold accurate and complete for the purpose it is used for. If a guest tells you their phone number changed or corrects the spelling of their name, that correction should be reflected in your records, particularly if that data feeds into a guest register or a repeat-guest file.

Storage Limitation and Erasure

Personal data should not be kept indefinitely once its purpose is served. For most guest communication and payment data, once a stay is complete and any dispute window has passed, there is no ongoing purpose that justifies keeping it. The clear exception is your legally mandated guest register entry, which you are required to retain for whatever period the applicable police or FRRO rules specify, that retention obligation is itself a legal basis to keep that specific data even after the stay ends. Everything else, old WhatsApp media, payment screenshots, informal notes, should have a rough deletion habit rather than living forever in your phone’s gallery.

WHERE THIS GETS CONFUSING
Do not delete your official guest register entries early because of this principle. Storage limitation under the DPDP Act works alongside your registration law obligations, not against them, whichever requires longer retention for a specific piece of data governs that data. See Guest ID Compliance and FRRO and Foreign Guest Registration for the retention periods that apply to your state and guest type.

Reasonable Security Safeguards

This is the obligation with the highest financial penalty attached, and the most relevant one for a property that stores guest ID photos on a personal phone. “Reasonable security safeguards” is not defined as a specific checklist in the Act, it scales to the sensitivity of the data and the size of the operation, but for a homestay or small hotel it realistically means: guest ID copies are not sitting in an unlocked shared photo gallery every staff member can browse, the device or folder they are stored in is protected by at least a passcode, and access is limited to the people who actually need it, usually just the owner or manager.

Breach Notification

If personal data you hold is lost, stolen, or accessed without authorisation, a phone with guest ID photos going missing, a laptop being hacked, an accidental share of one guest’s details with another, the DPDP Rules, 2025 require you to inform affected individuals without delay, in plain language, explaining what happened, what the likely impact is, what you are doing about it, and how they can reach you with questions. Significant breaches also have to be reported to the Data Protection Board. A specific step-by-step response for this exact situation is covered in the scenarios section below.

Grievance Redressal

You need a way for a guest to reach you if they have a concern about how their data was handled, a request to delete their information, a question about who saw it, or a complaint. For a small property this can be as simple as a named contact, usually the owner, and a commitment to respond within a reasonable time. The DPDP Rules, 2025 set a maximum response window of ninety days for data access, correction or erasure requests, though a homestay or small hotel should aim to respond in days, not months, since most such requests are simple to action.

Children’s Data

If a booking includes children, the parent or guardian who made the booking is generally treated as providing consent on the child’s behalf as part of the normal booking and registration process. Where this needs extra care is if a property separately uses a child’s photo or details for marketing, social media, or any purpose beyond the stay itself, that requires distinct, verifiable parental consent under the DPDP Rules, 2025, not an assumption that booking the stay covered it.

The ID Document Question: What to Ask Guests For

Every homestay and hotel needs a valid government photo ID from each guest, that requirement does not go away under the DPDP Act, it comes from the separate guest registration rules covered in our Guest ID Compliance guide. What this guide takes a clear, deliberate position on is which document you should ask for by default: a Voter ID, Driving Licence or Passport, in that order of preference. Treat Aadhaar as a last resort, not your standard request.

Why This Order of Preference

A Voter ID, Driving Licence or Passport is a complete, self-contained photo document, it establishes who someone is without being tied to anything beyond that document itself. A single Aadhaar number works differently, it is linked to a much wider set of a person’s accounts and services, which is exactly why a full copy sitting in a homestay’s files carries more exposure if it is ever lost or misused than a Voter ID or Driving Licence copy does.

It is also worth being plain about what Aadhaar actually is: proof of identity and residency, not proof of citizenship, and sharing it with a private business is meant to be voluntary, not a condition of service. A guest is free to offer a Voter ID, Driving Licence or Passport instead, and a property should never refuse a booking or check-in solely because a guest prefers not to hand over their Aadhaar.

THE PRACTICAL RULE FOR CHECK-IN
What to actually ask for, in order of preference
1. Ask for a Voter ID, Driving Licence or Passport first, complete documents on their own that do not carry the wider account-linkage risk a single ID number tied to other accounts does.
2. If a guest only has Aadhaar available, ask for the masked version, showing only the last four digits, rather than a full copy.
3. Never write down or store a guest’s full Aadhaar number separately in a spreadsheet, notebook or CRM field, even if you photograph the card itself.
4. Never refuse a booking or check-in solely because a guest offers an alternative valid photo ID instead of their preferred document, sharing any specific ID is voluntary, not something you can insist on.

None of this changes what the separate guest registration law requires, a valid government photo ID, in some form, is still mandatory for every guest, and that requirement is unaffected by which specific document type a guest offers. What changes is which document you steer guests toward by default, and how carefully you handle the rare case where Aadhaar is genuinely the only ID a guest has on hand.

Setting Up DPDP Act and Guest Data Privacy Compliance in Practice

Turning the obligations above into an actual routine does not require legal software or a compliance officer for a homestay or small independent hotel. It requires four habits, done consistently, and written down once so that every family member or staff member handling check-ins follows the same routine.

1. Storage: Where Guest ID Copies Actually Live

If you photograph a guest’s ID on your personal phone, that photo defaults into your general camera roll, which is likely backed up to a personal cloud account, visible to anyone who picks up your unlocked phone, and mixed in with years of unrelated personal photos. A better habit is to keep guest ID photos in a single, separate, passcode-protected folder or app, and to delete them from the general camera roll once they have been filed there.

SIMPLE STORAGE ROUTINE
For a homestay or small hotel with no dedicated software
Create one dedicated folder, on a device only the owner or manager uses, protected by a passcode or fingerprint lock separate from the phone’s general lock. Move every guest ID photo into that folder immediately after check-in and delete it from the general gallery. Do not forward guest ID photos into group chats, even staff group chats, unless every recipient in that chat has a genuine reason to see that specific guest’s document.

2. Access: Who Can Actually See This Data

Not every staff member needs access to every guest’s ID copy. A caretaker who manages housekeeping does not need to browse the folder of ID photos going back two years, a night-shift staff member checking someone in needs to be able to add a new entry, not necessarily read every old one. Where your property has more than one or two people involved, decide in advance who can view stored guest data and keep that circle as small as the operation genuinely allows.

3. Retention: How Long to Keep What

Different categories of guest data have different retention logic. Your official guest register entry should be retained for whatever period your state’s police rules or FRRO requirements specify, covered in detail in Guest ID Compliance and FRRO and Foreign Guest Registration. Beyond that specific legal minimum, most other guest data, WhatsApp chat history, payment screenshots, informal notes, has no ongoing legal reason to be kept indefinitely once the stay is complete and a reasonable dispute window, typically a few weeks to a couple of months, has passed.

A SIMPLE RETENTION HABIT
Review roughly every three months
Once a quarter, go through your guest ID folder and WhatsApp chats for stays that ended more than the required registration retention period ago, with no open dispute, refund conversation or repeat-booking relationship, and delete the ID photo and archive or delete the chat. This single quarterly habit does more for compliance than any policy document, because it is the difference between a phone with two years of every guest’s ID sitting on it and one that only holds what current law actually requires.

4. Security Basics That Cost Nothing

Reasonable security safeguards, for a property this size, is mostly about avoiding easy, avoidable mistakes rather than buying software. A passcode on the device or folder where guest data lives. Not sending a guest’s ID photo over an unsecured public Wi-Fi network to a third party unless necessary. Not storing payment card details in plain text anywhere, most Indian homestays already rely on UPI, which does not require this at all. Logging out of shared devices, if a front-desk computer is used by multiple staff members across shifts, so one person’s login is not left open for the next person by default.

5. Handling a Guest’s Request

A guest is entitled to ask what data you hold about them and to request that it be corrected or deleted, subject to your legal retention obligations for the registration record. If this happens, acknowledge the request, explain clearly what you can delete immediately (chat history, photos, informal notes) and what you are required to retain for a defined period (the formal register entry, and why), and action the deletable part promptly rather than waiting for a formal deadline.

Scaling This to the Size of Your Property

The core obligations in this guide, notice, minimisation, security, retention, apply identically whether you run one homestay room or a fifty-key resort, but how you actually implement them looks different depending on how many people are involved.

A Single-Owner Homestay

With one or two rooms and the owner handling every check-in personally, compliance is mostly about personal device discipline: a separate passcode-protected folder for guest ID photos, a habit of clearing out old data every few months, and being the single, obvious point of contact if a guest ever has a question about their data. There is no access-control problem to solve when only one person ever handles guest data in the first place.

A Small Hotel or Multi-Room Guesthouse With Staff

Once housekeeping staff, a caretaker or front-desk help are involved, access control becomes the practical center of compliance. Decide explicitly who can see stored guest ID data and who only needs to be able to add a new check-in entry, and make removing a departing staff member’s access a standard, non-negotiable step, not an afterthought. A shared device used across shifts should log out between users rather than staying open on one person’s session all day.

A Resort or Larger Property With a Marketing or Sales Function

Where a property has a dedicated marketing effort, running WhatsApp campaigns, managing a CRM, posting guest photos, purpose limitation and consent tracking matter more, since more of the guest data collected genuinely does get reused for a second purpose beyond the original stay. This is also the size of property most likely to eventually cross into a Significant Data Fiduciary classification if the government notifies thresholds that apply to it, worth revisiting this guide’s obligations periodically as the property grows rather than assuming what worked at a smaller scale still fully covers a larger one.

Real Scenarios: Applying DPDP Act and Guest Data Privacy Compliance

The obligations above are easiest to understand through the situations that actually create them. The scenarios below are grouped by theme and cover the moments where a host has to make a real, immediate decision about someone’s personal data, not just follow a written policy in the abstract.

Who Gets to Know a Guest Is Staying With You

A guest’s presence at your property, their room number, their length of stay, even the fact that they are your guest at all, is personal data belonging to them, not information you are free to share with whoever asks. This matters more than hosts often assume, because requests for this information can come from people with entirely reasonable-sounding motives and, occasionally, from people with harmful ones.

SCENARIO: A GUEST’S RELATIVE CALLS ASKING FOR THEIR ROOM NUMBER
Someone calls the property phone saying they are a guest’s spouse, parent or sibling and asks which room they are in, or asks you to pass on a message.
1. Do not confirm a guest’s presence, room number or any stay detail to a third party, however plausible their story sounds, this is exactly the kind of disclosure DPDP’s purpose-limitation principle is meant to prevent, and in rare but real cases, it is how a guest is tracked down against their wishes.
2. Instead, tell the caller you cannot share guest information over the phone, but offer to pass a message to the guest yourself if they wish to leave one.
3. Contact the guest directly, tell them who called and what was asked, and let the guest decide whether to respond, call back or ignore it. The decision to be contactable belongs to the guest, not to you or the caller.
4. If the caller becomes insistent or aggressive, this is a signal worth taking seriously rather than a reason to relent, treat it as you would any other guest-safety concern.
SCENARIO: A CALLER CLAIMS TO BE POLICE ASKING FOR GUEST DETAILS OVER THE PHONE
Someone calls or messages claiming to be from the local police station and asks for a guest’s ID details or booking information without visiting in person or providing formal identification.
1. Genuine police requests for guest register information are almost always made in person, in writing, or through the same local station your property already has a registration relationship with, not through an unverified phone call.
2. Politely decline to share details over an unverified call, and ask for the request in writing or for the officer to visit the property, where you can verify their identity before sharing anything.
3. If you are unsure, call the local police station’s official number yourself, not a number the caller gave you, to confirm the request is genuine before disclosing anything.
4. This is not obstruction, verifying who is actually asking before you hand over a guest’s personal data is exactly the kind of reasonable security safeguard the DPDP Act expects, and legitimate police requests will not be undermined by a property confirming identity first.
SCENARIO: A TRAVEL AGENT OR OTA ASKS FOR A COPY OF YOUR GUEST REGISTER
A travel agent, OTA representative or third-party booking partner asks for a copy of your guest register or a list of past guests, framed as a routine request “for their records.”
1. Your guest register exists to satisfy a specific legal registration requirement to the police or FRRO, not as a shared business document available to any commercial partner who asks.
2. Decline to share the register itself. If a travel agent or OTA needs to confirm a specific booking, share only the details relevant to that one booking, not your full guest history.
3. If a partner insists this is needed for their own compliance, ask them to specify the exact legal basis and the exact data they need, most requests of this kind are actually about a single disputed booking, not a genuine need for bulk guest data.

Device Loss, Breaches and Access Mistakes

A breach, under the DPDP Act, is not only a dramatic hacking incident, it includes ordinary, everyday mistakes: a lost phone, a message sent to the wrong chat, an employee who left the job but never lost access to shared files. What matters is how quickly and honestly it is handled once it happens.

SCENARIO: A STAFF MEMBER’S PHONE WITH GUEST DATA IS LOST OR STOLEN
A staff member who handles check-ins loses their phone, or it is stolen, and it contains guest ID photos and WhatsApp chat history for recent stays.
1. Immediately have the phone remotely locked or wiped if that capability exists (most phones support this through the manufacturer’s account), and change passwords for any accounts accessible from that device.
2. Assess which guests’ data was actually on the device, recent ID photos, active chat threads, and treat this as a data breach under the DPDP Act, not just a lost-device inconvenience.
3. Notify the affected guests without delay, in plain language: what happened, what data of theirs may have been exposed, what you are doing about it (device wipe, password changes), and how they can reach you with concerns.
4. Going forward, this is exactly the scenario the storage and access habits earlier in this guide are meant to prevent, a passcode-protected, separate folder limits what is actually exposed even if a device does go missing.
SCENARIO: A GUEST’S ID PHOTO IS ACCIDENTALLY SHARED IN THE WRONG CHAT
While forwarding a document, a guest’s ID photo or personal details are accidentally sent to another guest’s chat, a staff group, or the wrong contact entirely.
1. Delete the message immediately for everyone if the platform allows it, and ask the recipient directly to delete it on their end and confirm they have done so.
2. Inform the affected guest, whose data was mistakenly shared, what happened and to whom, even if you believe the recipient deleted it. Transparency here matters more than hoping it goes unnoticed.
3. If the recipient is a stranger to the affected guest, treat this with more urgency than if it was shared internally among your own trusted staff, and consider whether the affected guest should be advised to watch for any misuse of their ID details.
4. Use the mistake as the trigger to review how documents are forwarded during check-in, a habit of double-checking the recipient before sending anything containing a guest’s ID prevents most versions of this scenario entirely.
SCENARIO: A FORMER STAFF MEMBER STILL HAS ACCESS TO GUEST DATA
A staff member who used to handle check-ins has left the property, but was never removed from a shared drive, WhatsApp Business account, or property management system that holds guest data.
1. Treat access revocation as a standard, non-negotiable part of any staff member leaving, alongside returning keys or uniforms, not an afterthought to handle “when there is time.”
2. Immediately remove their access to shared folders, change shared passwords they knew, and check whether they had forwarded any guest data to a personal device or account before leaving.
3. If a departing staff member had broad access to years of accumulated guest data, this is also a good moment to apply the storage-limitation principle and reduce how much historical data is sitting around, less retained data means less exposure from any future access mistake.

Marketing, Repeat Guests and Reusing Old Data

Guest data collected for one purpose, running a booking, has an obvious commercial pull toward being reused for another, filling rooms during a slow season. The line between reasonable, welcome outreach and a purpose-limitation violation comes down to whether the guest actually agreed to be contacted that way.

SCENARIO: WHATSAPP-BLASTING OLD GUEST NUMBERS WITH FESTIVAL OFFERS
Bookings are slow ahead of a festival weekend, and the owner wants to send a promotional WhatsApp message to every guest who has ever stayed at the property, going back several years.
1. Check whether each guest actually opted in to promotional messages at any point, a booking confirmation and a marketing consent are two different things, and DPDP’s purpose-limitation principle means a number collected only to coordinate a past stay should not automatically be repurposed for unrelated marketing.
2. Message only guests who gave clear consent to future offers, ideally through a specific opt-in like the consent line covered earlier in this guide, or through their own return interaction with the property.
3. For guests without that consent, either skip them for this campaign or use the outreach itself to ask permission first, “we’d love to let you know about upcoming offers, would you like us to?”, rather than sending the offer outright.
4. This connects directly to the message-frequency and opt-out guidance in our WhatsApp Guest Communication Templates guide, a guest who never explicitly agreed to marketing messages and receives one anyway is more likely to block your number than book again.
SCENARIO: A REPEAT-GUEST CRM WITH YEARS OF PREFERENCE NOTES
A property keeps a running note for repeat guests, preferred room, breakfast timing, an allergy mentioned three years ago, and wants to keep building this file indefinitely for better service.
1. Preference data collected with an ongoing service purpose, making a repeat guest’s next stay smoother, is a reasonable use, this is different from marketing data and does not need the same opt-in treatment, as long as it is used for that stated purpose and not shared elsewhere.
2. Still apply basic hygiene: if a guest has not returned in several years and there is no active relationship, treat old preference notes the same as other stale data and consider whether they are still needed.
3. If a guest ever asks what you have on file about them, be ready to show them plainly, “room 4, ground floor requested; mentioned a peanut allergy in 2023,” most guests are reassured rather than alarmed by this kind of transparency, since it demonstrates the data is being used to serve them, not against them.

ID Documents and Consent at Check-in

This is where the ID-document recommendation covered earlier in this guide actually plays out in a live conversation at the front desk.

SCENARIO: A GUEST ASKS WHY YOU NEED THEIR ID AT ALL
A guest, particularly one used to informal or unregistered accommodation, questions why you need a government photo ID just to stay the night.
1. Explain plainly that this is a legal requirement for all registered accommodation providers in India, not a preference of the property, every guest staying overnight has to be recorded with valid ID as part of guest registration rules.
2. Reassure them on handling: explain, briefly, that the ID is used only for the registration record, stored securely, and not shared beyond what the law requires.
3. Offer the choice explicitly: “a Voter ID, Driving Licence or Passport works well, do you have one of those handy?” This framing, offering options rather than demanding one specific document, tends to reduce pushback significantly.
SCENARIO: A GUEST OFFERS ONLY AADHAAR, NO OTHER ID AVAILABLE
A guest checking in only has their Aadhaar card on hand and no Voter ID, Driving Licence or Passport with them.
1. Accept the Aadhaar rather than turning the guest away, refusing service is not the goal here, minimising unnecessary exposure of the full number is.
2. Ask if they have the masked Aadhaar version, showing only the last four digits, many guests who travel frequently already carry this version for exactly this reason.
3. If only the full Aadhaar is available, photograph or note only what your registration record actually requires, and avoid separately writing out the full 12-digit number in any additional register, spreadsheet or note beyond what the official guest register format requires.
4. Treat this document with the storage and access precautions covered earlier in this guide at least as carefully as any other ID, if not more so, given the wider linkage risk a full Aadhaar number carries if it is ever exposed.
SCENARIO: A GUEST ASKS YOU TO DELETE THEIR ID PHOTO RIGHT AFTER CHECKOUT
Immediately after checking out, a guest messages asking you to delete the photo of their ID and their chat history with the property.
1. Explain clearly what you can and cannot delete: the WhatsApp chat history and any informal notes can generally be deleted on request, but the formal guest register entry has to be retained for the legally required period regardless of the guest’s request, because that retention obligation comes from registration law, not from your own discretion.
2. Action the deletable part promptly, delete the chat media and any ID photo stored outside the official register, and confirm to the guest what was deleted and what was retained and why.
3. This kind of request, handled transparently, tends to build trust rather than create friction, most guests asking this are simply privacy-conscious, not adversarial, and a clear, honest answer satisfies the concern.

CCTV, Children and Third-Party Tools

A handful of situations do not come up daily, but are common enough across Indian homestays and hotels, and confusing enough when they do come up, that they deserve a specific answer rather than being left to guesswork in the moment.

SCENARIO: A GUEST ASKS TO SEE OR DELETE CCTV FOOTAGE OF THEMSELVES
A property has CCTV covering common areas like the entrance or parking, and a guest asks to view footage of themselves, or asks for it to be deleted.
1. A guest is entitled to ask what footage exists of them and, subject to your own security and any ongoing investigation need, to request it not be retained longer than necessary.
2. CCTV footage of common areas is a reasonable, standard security measure and does not need individual consent to record in the first place, but it does need visible signage informing guests that cameras are in use, and it should never cover private spaces like guest rooms or bathrooms.
3. If footage is requested by another guest as “evidence” in a dispute rather than by the person appearing in it, do not hand it over directly, this is a data-sharing decision with the same care as any other guest data disclosure, involve the police if the dispute is serious enough to need footage as evidence.
4. Keep CCTV retention short and routine, most properties do not need footage older than a few weeks unless there is an active incident, and a fixed automatic-overwrite cycle is simpler to manage than manual deletion.
SCENARIO: A CHILD IS ACCOMPANYING THE BOOKING GUESTS
A family books a room and one or more children are staying with them, and their names and ages are noted as part of the booking or registration.
1. For the ordinary purpose of the stay itself, room allocation, meal planning, registration where applicable, the parent or guardian who made the booking is treated as providing consent on the child’s behalf, no separate process is needed.
2. Where this changes is if the property wants to use a child’s photo or details for anything beyond the stay, a social media post, a testimonial, a marketing photo, that requires distinct, verifiable consent from the parent or guardian for that specific use, not an assumption that booking the room covered it.
3. When in doubt, simply ask the parent directly and specifically, “would you be comfortable if we shared a photo from today on our Instagram?”, rather than posting first and assuming permission.
SCENARIO: USING A THIRD-PARTY WHATSAPP CRM OR CLOUD TOOL HOSTED ABROAD
A property starts using a third-party tool, a WhatsApp CRM, a booking engine, or a cloud spreadsheet service, to manage guest data, and that tool’s servers are hosted outside India.
1. Cross-border data transfer is generally permitted under the DPDP Act, India has not taken a blanket-restriction approach, the government instead maintains the ability to restrict transfers to specific countries if needed, so using a well-known international tool is not, by itself, a compliance problem.
2. The responsibility that does not go away: you remain the Data Fiduciary even when a vendor processes data on your behalf, so it is worth a basic check of any tool you adopt, does it have a clear security and data-handling policy, does it let you delete guest data on request, is it a reasonably established provider rather than an obscure, unverified app.
3. For guest ID documents specifically, favour tools and habits that keep that most sensitive category of data on-device or within a purpose-built, access-controlled system, rather than scattered across general-purpose cloud photo backups or messaging apps not designed for document storage.
SCENARIO: YOUR SOCIETY SECURITY GUARD ASKS FOR A LIST OF ALL GUESTS THIS WEEK
If your property sits inside an apartment complex or gated community, the security desk or RWA sometimes asks for a running list of all current guests, sometimes for genuine gate-management reasons, sometimes just as a habit.
1. A reasonable, narrow request, confirming that a specific named guest is authorised to enter for a specific date range, is fine to answer, this is similar in spirit to the entry-log requirements already common in gated societies.
2. A broad request for a full list of guest names, ID numbers or contact details going beyond what gate management genuinely needs is a wider data share than the purpose requires, and DPDP’s minimisation principle applies to this handover just as it does to any other.
3. Where possible, share only what the gate actually needs, the guest’s name and stay dates, rather than a full copy of your register, and avoid making this a standing, automatic data feed with no defined limit on how it is used or how long it is kept by the society.

Common Mistakes Homestays and Hotels Make

A few mistakes show up repeatedly across Indian homestays and small hotels, not because owners are careless, but because these habits formed before a real law existed to push back against them. Recognising them is often enough to fix them.

  • Treating the phone camera roll as guest data storage. ID photos taken on a personal phone, with no separate folder or passcode, sit alongside years of unrelated personal photos and are visible to anyone who picks up the unlocked phone, including children in the household or a repair technician.
  • Asking for Aadhaar as the only accepted ID. Beyond the legal problem covered earlier in this guide, it is also simply unnecessary, Voter ID, Driving Licence and Passport all satisfy the same registration requirement without the added risk.
  • Forwarding a guest’s ID into a staff WhatsApp group “so everyone is aware.” Most staff members handling a shift do not need to see every past guest’s ID document, only the ones relevant to their current task.
  • Never deleting anything. Years of guest ID photos, old chats and payment screenshots accumulating with no review creates a larger and larger exposure if a device is ever lost or compromised, for no ongoing benefit to the property.
  • Reusing old guest numbers for marketing without asking. A number collected to coordinate a stay two years ago is not the same as a number given permission to receive festival offers today.
  • Assuming an OTA or booking platform “handles compliance.” Whatever data a property collects directly, ID copies at check-in, its own WhatsApp thread, is the property’s own responsibility regardless of which platform the original booking came through.
  • No plan for what to do if a phone is lost. The single most common realistic breach scenario for a small property, and also the easiest one to prepare for in advance with a basic remote-lock and password-change habit.

Quick-Reference Templates

Two templates worth keeping handy, one for the everyday moment of collecting data, one for the rare but urgent moment when something goes wrong with it.

COPY-PASTE: FULL CHECK-IN CONSENT NOTICE
Use as a printed card at the front desk, or paste into your booking confirmation message
At check-in, we collect your name, contact number and a valid photo ID (Voter ID, Driving Licence or Passport preferred) to meet the guest registration requirements that apply to all registered accommodation in India. This is a legal requirement, not optional. Separately, and only with your permission, we may also save your number to share occasional offers for future stays, you can decline this at any time without affecting your current booking. Your data is stored securely, accessible only to property staff who need it, and is not sold or shared with any third party beyond what the law requires.
QUICK REFERENCE: FIRST 24 HOURS AFTER A SUSPECTED BREACH
For a lost device, unauthorised access, or accidental data share
1. Contain it first: remotely lock or wipe the device if that is possible, and change any passwords or account access that device could reach.
2. Work out exactly what guest data was actually exposed, which stays, which documents, which chats, rather than assuming the worst or guessing.
3. Notify every affected guest without delay, in plain language: what happened, what data of theirs was involved, what you are doing about it, and how they can reach you with questions.
4. If the breach is significant, a large number of guests affected, or sensitive data like full ID numbers exposed, report it to the Data Protection Board of India, as the DPDP Rules, 2025 require.
5. Once contained, revisit the storage and access habits covered earlier in this guide and fix whatever gap allowed this to happen, so the same mistake does not repeat.

When a Guest Asks to See, Correct or Delete Their Data

The DPDP Act gives every guest, as a Data Principal, the right to ask what personal data you hold about them, to have it corrected, and to have it erased once there is no legal reason left to keep it. This comes up less often than a check-in or a data breach, but it is worth having a simple, unpanicked routine ready for it.

A former guest emails asking you to delete their data
A guest who stayed with you three months ago emails your reservations inbox asking you to delete everything you have on file about them: name, phone number, ID copy and the WhatsApp conversation from their trip.
Acknowledge the request within a few days, even a short reply, so the guest knows it has been received.
Check whether any part of what you hold falls under a legal retention requirement, such as the period local police or municipal rules expect guest-registration records to be kept, or the period tax law expects billing records to be kept.
If a legal retention period still applies, explain to the guest what you must keep and for how long, and delete everything else, the ID copy, phone number and chat history, from wherever it sits: your phone, WhatsApp, a spreadsheet, a shared drive.
Confirm back to the guest in writing once it is done, or explain clearly what you retained and why.
A repeat guest asks what personal data you are holding about their last stay
A guest who has booked with you before asks, before deciding whether to book again, exactly what information you still have on file about them.
Pull together what you actually hold: name, contact details, which ID type they used, dates stayed, and any internal notes.
Share it with them in plain language rather than a technical export, most guests just want reassurance that you are not holding more than they would expect.
Use the moment to also ask whether they are happy for you to keep their number for future booking reminders, or whether they would rather you deleted it after this reply.
Note the exchange somewhere so that if the same guest asks again later, you have a record of what was already shared and agreed.

What Non-Compliance Actually Costs

The DPDP Act’s penalties are enforced by the Data Protection Board of India, and they are structured as ceilings tied to the type of failure rather than a fixed fine for every violation. For a homestay or small hotel, the realistic risk is not a government audit knocking on the door unprompted, it is a guest complaint escalating, or a data breach that becomes visible enough to draw scrutiny. Either way, the numbers involved are large enough that they are worth understanding rather than dismissing as something only large companies need to worry about.

Type of FailurePenalty CeilingWhat This Looks Like in Practice
Failure to take reasonable security safeguards, leading to a data breachUp to ₹250 croreGuest ID data or payment details exposed due to careless storage, an unsecured shared folder, no passcode protection, no basic access control.
Failure to notify the Data Protection Board and affected individuals of a breachUp to ₹200 croreA breach occurs, but the property tries to quietly ignore it rather than notifying affected guests, this is treated as a separate, additional failure on top of the breach itself.
Breach of obligations relating to children’s dataUp to ₹200 croreUsing a child’s photo or details for marketing or any purpose beyond the stay without verifiable parental consent for that specific use.
General non-compliance with other obligationsUp to ₹50 croreFailing to provide proper notice, ignoring a legitimate data-access or deletion request beyond the response window, or other procedural gaps.

These are ceiling amounts set by the Act for the most serious violations, and the Data Protection Board has discretion to scale a penalty to the actual severity, scope and intent behind a specific failure, a small property’s honest mistake, corrected quickly and transparently, is treated very differently by the Board’s process than a large-scale, deliberate or repeated failure. The purpose of listing these figures is not to alarm a six-room homestay into thinking it faces a 250-crore fine over a lost phone, it is to make clear that “reasonable security safeguards” is not a soft suggestion, it is the specific obligation the law’s largest penalties are built around, which is exactly why the storage and access habits covered earlier in this guide matter more than any other single piece of this compliance picture.

How OpenStays Fits Into This

OpenStays’ WhatsApp AI already handles the part of the guest journey where most of this personal data first enters your property, the booking conversation, the ID collection request, the payment step. Being specific about what that actually means: guest ID documents collected through the platform are tied to a structured booking record rather than scattered across an open camera roll, retention follows the property’s stated purpose rather than living forever by default, and the guest register export feature exists precisely so an owner is not manually retyping ID details into a separate notebook, one extra place for that data to sit insecurely.

What OpenStays does not do, and should not be mistaken for doing, is make the underlying legal judgment calls covered in the scenarios above. If a guest’s relative calls asking for their room number, if a staff member’s phone goes missing, if a guest asks why their data is being kept, those are decisions a host has to make in the moment, informed by the principles in this guide, not something software can decide on a property’s behalf. The platform is built to reduce how many places sensitive guest data ends up scattered across, it is not a substitute for the judgment calls this guide is meant to prepare a host to make.

Legal Backdrop: The Laws Behind This Guide

This guide draws on a specific set of Indian laws and regulatory actions, listed here for hosts who want to read the primary source rather than a summary, and because a compliance guide should show its work.

  • The Digital Personal Data Protection Act, 2023, the full text as published by the Ministry of Electronics and Information Technology.
  • The Digital Personal Data Protection Rules, 2025, notified by the Government of India in November 2025, which operationalise the Act with an eighteen-month phased compliance window.
  • Justice K.S. Puttaswamy (Retd.) vs Union of India, the Supreme Court’s 2018 judgment recognising privacy as a fundamental right, the constitutional foundation the DPDP Act itself builds on.

This guide is written for homestay, hotel and resort owners, not as a substitute for legal advice specific to your property, your state, or a particular situation you are facing. Where a scenario in this guide genuinely turns on your specific facts, a lost device with sensitive data on it, a formal complaint from a guest, a request from a regulator, it is worth a conversation with a lawyer or a data protection consultant rather than relying on this guide alone.

Frequently Asked Questions

Does a small homestay really need to worry about the DPDP Act, or is this only for big companies?

The DPDP Act applies to any organisation that decides why and how personal data is collected and used, called a Data Fiduciary, regardless of size. A six-room homestay collecting guest ID copies and phone numbers is a Data Fiduciary in exactly the same way a large hotel chain is. What differs by size is the extra layer of obligations reserved for “Significant Data Fiduciaries,” a government-notified category based on data volume and sensitivity, which most independent homestays and small hotels will not fall into. The core obligations, notice, security, breach handling, apply to everyone.

Can I still ask guests for Aadhaar at check-in?

Yes, a guest can offer Aadhaar and you can accept it. What this guide recommends against is making Aadhaar your default, only-accepted request. Ask for Voter ID, Driving Licence or Passport first, and if a guest only has Aadhaar, prefer the masked version showing just the last four digits over a full photocopy, and never write out the full 12-digit number separately.

Do I need a Data Protection Officer for my property?

Only Significant Data Fiduciaries, a category assigned by the government based on data volume and sensitivity, are required to appoint a Data Protection Officer. Most homestays, guesthouses and independent hotels are not in this category, though every Data Fiduciary, regardless of size, still needs a clear point of contact for guests to raise data concerns with, which for a small property is usually just the owner.

Does collecting a guest register for police purposes need separate DPDP consent?

No. Processing personal data to comply with a legal obligation, such as maintaining a guest register required by police or FRRO rules, falls under the DPDP Act’s “legitimate use” exception in Section 7, and does not require a separate consent process. You still need to apply the Act’s other principles, security and minimisation in particular, to that same data once collected.

What should I do if I discover a data breach, like a lost phone with guest data on it?

Act quickly: secure or wipe the device remotely if possible, assess which guests’ data was exposed, and notify those guests without delay in plain language explaining what happened and what you are doing about it. Significant breaches also need to be reported to the Data Protection Board of India. The full step-by-step is covered in the device-loss scenario earlier in this guide.

How long should I keep a guest’s WhatsApp chat and ID photo after checkout?

There is no single fixed number that applies everywhere, since the required retention period for your formal guest register entry depends on your state’s police rules and, for foreign nationals, FRRO requirements, covered in our Guest ID Compliance guide. Beyond that legal minimum, informal chat history and photos have no ongoing legal reason to be kept indefinitely, a reasonable habit is to review and clear out data for completed stays with no open dispute every few months.

Do OTAs like Airbnb or MakeMyTrip handle DPDP compliance for me?

An OTA is responsible for its own data-handling practices as a Data Fiduciary for the data it collects and controls. It does not cover your obligations for data you collect directly, ID copies at check-in, your own WhatsApp conversations, your own guest register. If a booking comes through an OTA but you collect additional data yourself at the property, you are independently responsible for that data.

What if a guest refuses to give any form of ID?

A valid government photo ID is a legal requirement for guest registration in India, not an optional courtesy, so a guest who refuses to provide any acceptable ID cannot be legally checked in. This is a registration-law requirement, not a DPDP Act one, see Guest ID Compliance for the full detail on acceptable documents and what to do in this situation.

Can I post a guest’s photo or review on Instagram or my website?

Only with the guest’s clear, specific consent for that particular use. A guest agreeing to stay at your property, or even leaving a written review, is not the same as agreeing to have their face or full name used in your marketing. Ask directly, “would you be comfortable if we shared this photo on our page, tagging you if you like?”, and treat a lack of response as a no, not a yes by default.

Does DPDP Act compliance mean I need to host guest data only on Indian servers?

No, the DPDP Act does not require Indian data localisation as a general rule, cross-border data transfer is permitted by default, with the government retaining the power to restrict transfers to specific countries if it chooses to. A homestay or hotel using an internationally hosted WhatsApp CRM, cloud spreadsheet or booking tool is not, on that basis alone, non-compliant. What still matters is choosing a reasonably reputable vendor with a clear data-handling policy, since you remain responsible as the Data Fiduciary regardless of where the vendor’s servers happen to sit.

One more point worth stating plainly before wrapping up: none of the obligations in this guide are meant to make a host suspicious of every guest interaction or afraid to run a WhatsApp-first, informal operation, which is how most successful Indian homestays and small hotels actually work. The goal is narrower than that, treat a guest’s ID document and personal details with roughly the same care you would want a stranger to treat your own passport and phone number, and most of what the DPDP Act asks for falls out naturally from that one instinct.

In Summary

DPDP Act and guest data privacy compliance for homestays, hotels and resorts comes down to a short set of habits repeated consistently rather than a one-time legal exercise. Tell guests plainly what data you collect and why, especially anything beyond the registration requirement itself. Collect only what the stated purpose actually needs, and follow the ID-document guidance covered earlier in this guide. Keep guest data in a passcode-protected, access-limited place rather than scattered across an open camera roll or shared group chats. Retain your formal guest register entry for as long as registration law requires, and clear out everything else, chats, photos, informal notes, once its purpose has genuinely passed. Respond honestly and quickly if something goes wrong, a lost device, a misdirected message, rather than hoping it goes unnoticed. None of this requires new software or a legal team for most properties, it requires treating a guest’s ID photo with the same seriousness you would want a stranger to treat yours.


This guide is intended to help homestay, hotel and resort owners understand their obligations under the DPDP Act, 2023 and related regulations in plain, practical terms. It is not legal advice. Data protection law involves specific facts, evolving rules, and in some cases state-level variation, and this guide cannot account for every individual circumstance. For a situation with real legal or financial exposure, a data breach, a regulatory notice, a formal guest complaint, consult a lawyer or a qualified data protection professional familiar with your specific situation.

WhatsApp Us