DPDP compliance for travel and hospitality companies
Hotels, airlines, and travel platforms collect sensitive guest data including health information, passport details, and payment records. Here is the DPDP compliance picture.
What personal data do travel companies process under DPDP?
Airlines collect: passport details, visa information, frequent flyer data, meal preferences (which may reveal religious beliefs), health information for special assistance requests, and payment data. Hotels collect: identity documents, credit card pre-authorisations, room preferences, check-in/check-out times, and loyalty programme history. Travel agencies collect all of the above plus visa application data, insurance details, and emergency contact information. Several of these categories — health, religious preference — are sensitive under the Act.
Does dietary preference data require special consent under DPDP?
Dietary preferences — halal, kosher, vegetarian, Jain — can reveal religious beliefs, which is sensitive personal data under the DPDP Act. Collecting meal preferences to fulfil an airline booking is a legitimate operational use covered by the service contract. However, using dietary preference data for profiling, selling to third parties, or building inferences about religious beliefs beyond meal service is a secondary use requiring explicit consent. Be specific in your privacy notice about how meal preference data is used.
How does DPDP apply to cross-border data transfers for international travel?
International travel inherently involves cross-border data transfers — booking a foreign hotel shares guest data with that hotel; booking an international flight shares passenger data with foreign airlines and immigration authorities. When the government publishes the DPDP cross-border transfer allowlist, travel companies must ensure their international hotel and airline partners are in approved countries. Where immigration authorities require data (Advance Passenger Information), this is a statutory requirement with its own lawful basis.
What are DPDP obligations for hotel loyalty programmes?
Loyalty programmes process significant personal data — stay history, location patterns, payment records, preferences — and require explicit consent covering each use case: stay history analysis, partner offers, third-party sharing. Members must be able to access their loyalty data, correct errors (particularly point balances), and exit the programme with data erasure. Sharing loyalty member data with partner hotels or airlines requires the member's consent or a clear disclosure at enrolment.
How do OTAs and travel aggregators fit into the DPDP framework?
Online Travel Agencies that collect personal data on behalf of airlines and hotels are Data Processors for the data they collect on behalf of those principals. However, when an OTA uses the data for its own purposes — building its own customer profile, sending its own marketing, conducting its own analytics — it steps into the Fiduciary role for that data. Most OTA agreements need to be updated to clearly define the Fiduciary/Processor split and to ensure DPA provisions cover both the airline/hotel data sharing and the OTA's own use.
What must travel companies do about health data for special assistance?
Health data collected for special assistance requests — wheelchair assistance, medical equipment, severe allergies — is sensitive personal data under the Act. It must be processed only for the stated purpose (arranging the assistance), disclosed in the privacy notice, and deleted after the journey is complete unless the passenger consents to retention in their profile. Sharing health data with airport medical services or destination hotels for continued assistance must be covered by the original consent or by a separate disclosure.
Frequently asked questions
Can a hotel retain guest profiles for marketing after checkout?
Retaining guest profiles for marketing — sending promotional offers, pre-arrival upsell, loyalty invitations — requires consent beyond the room booking contract. If the guest consented to marketing at check-in, data can be retained for the consent period. If they only agreed to the room booking terms, retain data only for statutory periods (GST records, dispute resolution) and delete the rest. Loyalty programme members have a separate, ongoing consent.
Does DPDP apply to visa facilitation services?
Visa facilitation services collect extremely sensitive data — passport, financial statements, travel history, biometrics for some visas. As a service provider collecting this data on behalf of the applicant to share with a foreign embassy, you are a Data Fiduciary for the collection and processing, even though the ultimate recipient (the embassy) is a foreign government authority. You must have a privacy notice covering the data collection, and delete the data after the visa application is resolved.
Do travel companies need DPAs with foreign hotels and airlines?
When you share guest personal data with a foreign hotel or airline to complete a booking, that partner processes data on the guest's behalf but under your direction as their booking agent. A data sharing agreement (which may function as a DPA) should specify what data is shared, prohibit the partner from using it for their own marketing beyond the booking, and require adequate security. Check whether the destination country's data protection standards are adequate under India's transfer rules once the allowlist is published.
Assess your travel company DPDP readiness
Niti Bharat's DPDP Readiness Assessment covers travel and hospitality companies — sensitive preference data, cross-border transfers, loyalty programme consent, and OTA data sharing agreements.
Start Travel DPDP Assessment