In India’s booming hospitality sector, Guest ID Compliance is more than a procedural formality — it is a legal obligation, a security safeguard, and a critical component of running a professional, audit-ready property. Whether you manage a beach resort in Goa, a 5-room heritage homestay in Kerala, a city boutique hotel in Bengaluru, or a mountain retreat in Himachal, failing to follow guest identification rules can result in heavy fines, license suspension, or even imprisonment.
This comprehensive guide, prepared specifically for Indian property owners, covers every aspect of Guest ID management in 2026 — from legal foundations to practical implementation, digital tools, common mistakes and how AI-powered systems make compliance effortless.
Why Guest ID Compliance Matters in India
India hosts millions of domestic and international travelers every year. The government uses guest records for:
- National security and anti-trafficking efforts
- Tracking foreign nationals (immigration control)
- Assisting police investigations
- Tourism data and planning
- Protecting guests and property owners from liability
Every paid accommodation provider — hotels, resorts, homestays, guest houses, B&Bs, and even farm stays — falls under these regulations. Non-compliance is treated seriously under the Foreigners Act, 1946, Registration of Foreigners Rules, 1992, and various state-specific Hotel & Lodging House Acts.
And then there’s the liability angle. If something happens at your property — a theft, an assault, a fraud — the police will ask for your register within hours. If you can’t produce it, the investigation shifts toward you, not away from you.
Real-world consequences of non-compliance:
- Fines ranging from ₹5,000 to ₹50,000+ per violation
- Property license cancellation
- Up to 5 years imprisonment for serious foreign guest reporting failures
- Civil liability if an incident occurs and records cannot be produced
Legal Framework Governing Guest ID in India
The reason so many operators are confused about compliance is that no single law covers it. There are at least five overlapping frameworks, and they don’t always point in exactly the same direction.
The Registration of Foreigners Act, 1939
The oldest piece of the puzzle, and still the most operationally significant for anyone hosting international guests. Originally enacted under British colonial administration, this Act makes hotels and lodging houses responsible for registering foreign nationals’ arrivals. The Registration of Foreigners Rules, 1992 remain the operative ruleset today — meaning the daily practice of filling out Form C and submitting it to police derives directly from legislation that is over 80 years old.
The Foreigners Act, 1946
This is where the 24-hour reporting requirement for foreign guests comes from. The Act defines “foreigner” broadly — any person who is not an Indian citizen — and gives the central government sweeping powers over their registration and movement. The obligation to report foreign guests to police within 24 hours of check-in is a direct consequence of this Act.
State Police Acts and Local Hotel Regulations
This is where compliance gets ground-level and highly specific. Every state has its own police act, and many have dedicated hotel and lodging regulations on top of that. The Maharashtra Police Act (1951), Karnataka Police Act (1963), and Delhi Police Act (1978) all contain specific provisions about guest registers, police access to them, and penalties for non-maintenance. These are the rules that beat cops and inspectors actually enforce during raids, not the central legislation.
The Digital Personal Data Protection Act, 2023
The newest layer, and the one most operators haven’t thought about yet. Once you start collecting digital copies of IDs — scanned Aadhaar cards, passport photos, driving licences stored in a PMS — you’re a data fiduciary under the DPDP Act. That comes with obligations around data minimisation, purpose limitation, breach notification, and deletion timelines. The full implementation rules were still being notified as of mid-2025, but the core framework applies now.
One thing worth clarifying separately: you cannot legally mandate Aadhaar from guests. The Aadhaar Act restricts mandatory collection to specific government purposes. A private hotel or homestay can accept Aadhaar if a guest voluntarily offers it, but requiring it as the only acceptable ID is not lawful.
Who Must Comply — And Who Gets a Pass?
Short answer: almost everyone running commercial short-stay accommodation. The compliance obligation applies to:
- Hotels and lodges of any size or star rating
- Guesthouses and dharamshalas
- Paying guest (PG) accommodations on a per-night or short-term basis
- Homestays listed on any platform or direct bookings
- Serviced apartments offering stays under 30 days
- Hostels and dormitory-style accommodations
- Resorts and boutique properties regardless of room count
What about long-term renters? Tenancies of 30 days or more under a formal lease generally fall under tenancy law rather than hotel/lodging regulations. But the dividing line between a “short stay” and a “tenancy” is interpreted differently across states and is increasingly contested as more properties try to use lease agreements to avoid compliance obligations. If you’re in this grey zone, get specific legal advice for your state.
What about tiny properties — one or two rooms? You may face lighter state-level registration requirements, but there is no size threshold that exempts you from the foreign guest reporting obligation. A one-room homestay that hosts a foreign national must still submit Form C within 24 hours.
A note for platform-listed properties specifically: listing your home as “rent a room” on a platform does not change your legal status. If you’re charging guests for overnight accommodation, you are operating a lodging house in the eyes of the law, regardless of what the platform calls it.
What Counts as Valid Guest Identification
For Indian (Domestic) Guests
The key requirement is a government-issued photo ID. Acceptable documents:
Primary identification:
- Aadhaar Card (front and back — voluntarily provided by the guest)
- Voter ID Card (EPIC)
- Driving Licence
- Passport
Not acceptable:
- Private company employee ID cards
- Student IDs from private colleges or universities
- Credit or debit cards
- Utility bills (useful as address proof, not as standalone ID)
- PAN Card (since it does not have address)
Police inspectors flag private company IDs and student cards regularly. If your check-in staff are accepting these, retrain them.
For Foreign Guests
Foreign guests must provide:
- Passport — mandatory, no exceptions
- Valid visa for the purpose of their visit (tourist, business, e-Visa, etc.)
- Citizens of Nepal and Bhutan: specific documents as per bilateral arrangements (no visa required, but passport or national identity document is still needed for your register)
Critically, copying just the passport photo page is not enough. You need to record: passport number, nationality, visa type, visa number, place and date of visa issue, date of arrival in India, and intended duration of stay. Every field matters, and Form C has mandatory boxes for each.
On Photographing vs. Photocopying IDs
Following the Supreme Court’s 2018 judgment in Justice K.S. Puttaswamy v. Union of India and the subsequent DPDP Act framework, the rules around retaining copies of IDs have tightened:
- Recording ID details (type, number, name, expiry) in your register: permitted
- Retaining a photocopy or scan for statutory compliance purposes: permitted, for a limited period
- Using that data for any other purpose — marketing, analytics, selling to third parties: not permitted
- Storing Aadhaar numbers in plain text in a database: not compliant; the Aadhaar Act requires masking/tokenisation
If you’re running a digital system, make sure your vendor can explain how they handle this.
The Form C Requirement: Property and the Police Register
What Is Form C?
Form C is the formal guest registration form prescribed under the Registration of Foreigners Rules, 1992. Every accommodation provider in India is required to submit one for each foreign national guest, to the local police station or FRRO.
The form captures: full name, father’s/husband’s name, nationality, passport number, visa details, arrival date, port of entry, and intended duration of stay. It’s not a long form, but every field is required and non-negotiable.
The 24-Hour Deadline
Form C must be submitted within 24 hours of check-in. This is measured from the actual check-in time, not from midnight. A foreign guest who checks in at 11:30 PM means your Form C deadline is 11:30 PM the following night.
There are no weekend or holiday exemptions. This is where a lot of operators slip up — a Friday night check-in gets forgotten over the weekend. Automate the trigger wherever possible.
Digital Form C Submission
The Ministry of Home Affairs has been progressively moving Form C to digital submission. The e-FRRO portal(indianfrro.gov.in) handles this in most major cities, and many property management systems now offer direct integration. In some cities — parts of Delhi, Mumbai, and Bengaluru — digital submission is now the required method, not just an option.
Check with your local police station or FRRO office about the current requirement in your area. If you’re using a PMS or platform that handles this for you, verify that their integration is active and current, not just a checkbox on a feature list.
The Domestic Guest Register
For Indian guests, the obligation is to maintain a complete register, but proactive daily submission to police is generally required only in specific circumstances (high-security zones, designated areas, or by specific state circular). In practice, most states require the register to be available on demand during inspections. Some states additionally require a daily occupancy report — Delhi and J&K are notable examples. Know what your state requires.
Record-Keeping: What to Collect, Store, and for How Long
The Minimum Record for Every Guest
For all guests (Indian and foreign):
| Field | Required |
|---|---|
| Full name as on ID | Yes |
| Permanent address as on ID | Yes |
| ID document type | Yes |
| ID document number | Yes |
| Check-in date | Yes |
| Check-out date | Yes |
| Room number | Yes |
Additionally for foreign guests:
| Field | Required |
|---|---|
| Nationality | Yes |
| Passport number | Yes |
| Passport expiry date | Yes |
| Visa type and number | Yes |
| Visa validity | Yes |
| Port of entry into India | Yes |
| Date of arrival in India | Yes |
Retention Periods
There’s no single national standard here, which contributes to the widespread confusion. Based on prevailing state police guidelines and legal practice:
- Domestic guest records: minimum 1 years from the date of stay
- Foreign guest records (Form C): minimum 1 years, given their relevance to immigration and security investigations
Many lawyers advise keeping all records for 7 years to cover civil liability windows. If you’re running a digital system, automated retention enforcement is one of the most practical things you can implement.
Physical vs. Digital Records
Most states formally recognise the physical bound register as the legal record. Digital records are increasingly accepted — and in some states, required — but must meet specific conditions: printable in the prescribed format, tamper-evident with edit logs, accessible without specialist technical knowledge, and backed up securely. If your digital register can’t be printed as a clean, police-readable document within two minutes of an inspector’s request, it’s not actually compliant.
Collecting ID before the guest arrives — through a secure upload link sent at booking confirmation — is legally permissible and practically sensible. It means your register can be substantially complete before check-in, reducing the pressure on arrival. For digital pre-check-in to satisfy compliance, you still need to physically verify the original document at check-in. The digital upload is not a substitute for that.
What You Cannot Do Digitally
- Use Aadhaar biometric authentication unless your property is a registered Authentication User Agency (AUA) under UIDAI — a specific licensing process most operators have not undertaken
- Store raw Aadhaar numbers in plain text; the Aadhaar Act requires masking or tokenisation
- Share guest data with third parties without explicit consent
- Use compliance data for marketing purposes
Common Compliance Mistakes (and How to Avoid Them)
These are the failures that come up most frequently in police inspections and platform compliance audits.
Not collecting ID at all. More common than you’d expect, especially among first-time homestay hosts who assume guests booking through a platform have already been verified. They haven’t — at least not in a way that satisfies your legal obligation.
Collecting ID from the primary guest only. If two or more unrelated adults are checking in together, each adult needs to be individually registered. Listing companions without their own ID records is non-compliant and will get flagged.
Accepting private company IDs or college cards. Train your check-in staff on this specifically. Keep a laminated reference card at reception showing which documents are acceptable.
Recording passport details but not visa details for foreign guests. The visa fields on Form C are mandatory. A photocopy of the passport bio page is not enough.
Missing the 24-hour Form C deadline. Late-night check-ins followed by busy mornings are the most common cause. Automate the trigger so it fires at check-in, not when staff remember.
Unsecured record storage. A physical register left at an unmanned front desk, or digital records in an open shared folder, is both a compliance and data protection risk. Physical registers should be locked when unattended; digital records need access controls and audit logs.
Not updating the register when stays are extended. A guest who books 3 nights and extends to 7 needs an updated record. Open-ended or inaccurate departure dates are a red flag during inspections.
Disposing of records too early. Many small operators throw away registers when guests leave, not realising the retention obligation runs for years. Physical registers should be archived by year and stored for the minimum period.
Penalties for Non-Compliance
The penalties come from multiple statutes, which means they can stack.
Under the Registration of Foreigners Act and Rules: The formal fine is up to ₹1,000 per violation (set in 1992 and not revised significantly, though newer rules may impose higher amounts). More consequentially, serious violations can lead to prosecution under the Foreigners Act, which carries imprisonment of up to 5 years.
Under State Police Acts: Most state acts allow for licence suspension or cancellation, fines from ₹500 to ₹50,000 depending on state and severity, and closure orders for persistent non-compliance. A licence suspension means you cannot operate; for a platform-listed property, it usually triggers automatic de-listing.
Under the DPDP Act: For digital data breaches or misuse of guest personal data, penalties up to ₹250 crore apply for significant breaches. Even smaller violations attract fines in the ₹10,000–₹1 crore range depending on scale.
The practical risk: In tourist-heavy states, the most immediate consequence of a police inspection isn’t a fine — it’s having your property sealed while the investigation runs. That can mean days or weeks of lost bookings, with reputational damage on top.
Guest Privacy vs. State Security: Walking the Line
Some guests push back on ID collection, particularly for personal or sensitive trips. This is understandable — the amount of information the law requires you to collect is significant. But your position is straightforward: this is a statutory requirement, not a choice you’ve made, and it applies to every accommodation provider in India without exception.
When guests object, a simple explanation helps: “Under Indian law, all accommodation providers — hotels, homestays, guesthouses — are required to collect a government-issued photo ID from every guest. Your details are stored securely and shared only with law enforcement as required by law.”
If a guest still refuses, you cannot accommodate them. Providing accommodation without ID verification exposes you to criminal liability. This is not a situation where discretion applies.
On data minimisation: collect what the law requires, then stop. If your compliance obligation requires name, ID type, ID number, and address — don’t also harvest email addresses, dates of birth, or phone numbers as a matter of course unless the guest is explicitly opting into something else (like a loyalty programme). The DPDP Act’s purpose limitation principle applies.
On security: guest ID data is sensitive personal data. It needs to be in access-controlled systems, not shared with vendors who don’t need it, and deleted after the retention period ends. If you have a digital breach, you’re required to notify affected guests and, under the DPDP Act’s breach notification rules, the Data Protection Board of India.
Building a Compliance-First Booking Workflow
The goal is to make compliance automatic — something that happens as part of your normal booking process, not a separate task that gets skipped when things are busy.
At booking confirmation: Require digital ID upload as part of the confirmation step. For domestic guests, a government ID photo; for international guests, passport and visa. Set the expectation in the confirmation email: “As required under Indian law, we will need to verify your government-issued photo ID at check-in. To speed up arrival, you can upload it now.”
Pre-arrival: Review uploaded documents before the guest arrives. Flag any international guests for Form C preparation so you’re not doing it under pressure at check-in. If a visa says “registration required within 14 days,” note it and be ready to direct the guest to the FRRO.
At check-in: Physically verify the original document against the digital upload. Record check-in time (not just date). For foreign guests, complete and submit Form C at this point — don’t wait for the morning shift. Assign the room only after the register entry is complete.
During the stay: Update the register immediately if a booking is extended. Note any additional adult guests who weren’t in the original booking.
At check-out: Record actual departure time. Confirm that foreign guest Form C has been filed (check your submitted records).
Monthly and quarterly: Review register completeness before each month closes. Quarterly, audit Form C submissions for all international guests. Annually, archive completed registers to long-term storage with the year clearly labelled.
How OpenStays Handles Guest ID Compliance
OpenStays was built with Indian regulatory requirements as a core constraint, not a feature added later. The compliance tooling in the platform reflects how Indian law actually works — Form C obligations, state-level variations, DPDP Act data handling requirements — rather than a generic global template.
Digital pre-check-in: Hosts can require document upload as a mandatory step in the booking confirmation flow. Guests receive a secure upload link; the system accepts government IDs for domestic guests and passport/visa for international guests. The pre-arrival record is available for host review before the guest arrives.
Automatic international guest flagging: The platform identifies international guests from the nationality field and automatically queues them for Form C completion. The Form C template pre-populates from submitted guest information, reducing manual entry at check-in.
The digital register: OpenStays maintains a tamper-evident register — every edit is logged with a timestamp and user ID. The register is exportable in formats suitable for police inspection. Data retention enforcement is automated against the legally required timelines.
Data handling under DPDP Act principles: Guest ID data collected through the platform is used only for compliance purposes. The system enforces data minimisation (only legally required fields are mandatory), and deletion is automated after retention periods expire.
The compliance dashboard: Hosts see at a glance which active bookings have complete vs. incomplete records, which Form C submissions are pending or overdue, and a full audit history of submitted records.
OpenStays doesn’t handle every scenario out of the box — direct FRRO integration is still in progress and there are specific restricted-area requirements in places like Spiti and the Andamans that require additional steps beyond what the platform automates. But for the vast majority of operators handling standard domestic and international guests, the compliance workflow is built into your normal operation
Frequently Asked Questions
My guest booked through Airbnb and they have “verified” status. Do I still need to collect ID?
Yes, without exception. Airbnb’s verification process satisfies Airbnb’s platform requirements, not India’s legal requirements for accommodation providers. You are independently required to collect and record ID under Indian law.
I run short term rental — just one room. Do I really need all this?
Yes. The legal obligation applies regardless of property size. The foreign guest reporting requirement applies even to a one-room operation. For domestic guest records, the register requirement applies as soon as you’re running a short-stay accommodation.
Can I refuse to accommodate someone who won’t show ID?
Yes — and legally, you must. Accommodating a guest without collecting valid ID puts you in violation of the law. You are within your rights and have an affirmative legal obligation to refuse accommodation to anyone who won’t provide identification.
In Summary
Guest ID compliance is one of those areas where the gap between what operators think they need to do and what the law actually requires is surprisingly large. The framework is multi-layered, enforcement is real, and the consequences of getting it wrong — a sealed property, a revoked licence, a de-listed platform account — can be severe enough to end a small operation.
The practical path forward is to stop treating ID collection as a check-in formality and start treating it as a core part of your booking workflow. That means collecting documents before guests arrive, not scrambling at the front desk. It means submitting Form C at check-in for international guests, not the next morning. It means keeping records for years, not months, and keeping them securely.
At OpenStays, we’ve built the compliance workflow into the platform specifically so that doing the right thing is also the path of least resistance. But the platform only works if you understand what you’re complying with — which is what this guide is for.
If you’re unsure about specific requirements in your state, feel free to formally file RTI applications in your state and seek formal responses.
This guide is intended as an informational resource for accommodation operators in India. It does not constitute legal advice. Regulations vary by state and may change. Consult a qualified legal professional for advice specific to your property and jurisdiction.