ConsentKit DPDP

For hotels, resorts, homestays and travel agencies

DPDP compliance for hotels and travel

Every check-in collects ID copies, phone numbers and often passports, and much of it ends up photocopied, emailed and forgotten. ConsentKit gives guests a clear notice at booking and check-in, separates marketing from the stay, and keeps ID copies under control.

Guest ID copies
Protect and limit
Foreign guest reporting
Still required
Full compliance
13 May 2027
lakeviewretreat.inOnline check-in

Lakeview Retreat asks for your consent

We need some details for your stay and the law. The rest is your choice.

Withdraw consent anytime
Consent logRecording

    Where the DPDP Act touches a guest’s stay

    Pick a stage to see what you collect, why and what the law expects.

    What changes for your property on 13 May 2027

    The Act applies to every property, from a five-star hotel to a three-room homestay.

    A notice at booking and check-inSections 5 and 6

    Guests should know what you collect and why, including what the law requires.

    Notices for your booking engine, web check-in and a QR code at the desk.

    ID copies need strong protectionSection 8(5) and Rule 6

    Passport and ID copies are high-risk. Store them securely, limit access and delete when not needed.

    Encrypted ID storage with access logs and automatic deletion.

    Marketing needs its own consentSection 6

    Stay-related messages and promotions are separate. Guests can say no to promotions.

    Per-purpose choices synced to your CRM and messaging tools.

    OTAs, PMS and channel managers are coveredSection 8

    Your PMS, booking engine and channel manager process guest data for you.

    A vendor register and processor contract checklist.

    Guests can ask for their dataSections 11 to 14

    Guests can request access, correction and erasure where law allows.

    A request form with identity checks and deadlines.

    Breaches go to guests tooRule 7

    A PMS hack or leaked ID folder must be reported to the Board and affected guests.

    Breach templates ready to send within 72 hours.

    A plan around your season

    Make changes before the season starts, not in the middle of it.

    1. Find the ID copies

      Locate every place ID copies live: PMS, email, WhatsApp, paper files.

    2. Notices and check-in

      Put notices on booking and check-in, and move ID storage somewhere secure.

    3. Marketing and vendors

      Clean marketing lists and sign terms with your PMS and booking engine.

    4. Train the front desk

      Train staff on ID handling, requests and breaches.

    For every kind of property

    Templates for your size and setup.

    Hotel chains

    Central loyalty and per-property admins.

    Independent hotels

    Simple setup with your PMS.

    Resorts

    Activities, spa and long stays.

    Homestays and B&Bs

    Small teams, phone and WhatsApp heavy.

    Travel agencies

    Passports, visas and airline sharing.

    Tour operators

    Group travel and guide access.

    Questions hoteliers are asking

    For the full picture, read our DPDP Act guide or compliance checklist.

    Do we still need to report foreign guests?

    Yes. Form C and police reporting duties continue. The DPDP Act does not override them, but you should tell guests about them in your notice.

    Can we keep copies of guests’ IDs?

    Keep them only as long as the law requires, store them securely and limit who can see them.

    Can we add OTA guests to our newsletter?

    Only with their consent for marketing. A booking through an OTA is not consent to your promotions.

    Does this apply to homestays?

    Yes. There is no size threshold. If you hold guest data digitally, including on WhatsApp, you are a data fiduciary.

    Can we share CCTV footage with police?

    Yes, when there is a lawful request. Log what you shared and why.

    Get your property ready before the season

    The readiness check takes about ten minutes and gives you a practical gap report for your property.