DPDP Rules, 2025 are now in effect. See where your business stands, in 3–5 minutes.Find out — free →
Where your data travels · Hotels, Hospitality & Travel

One guest. One journey. Many systems and partners.

Follow one guest or traveller's information through search and booking, identity and passport collection, payment, airlines and hotels, transfers, check-in, the stay itself, Wi-Fi and CCTV, guides and activity partners, complaints and reviews, loyalty programmes and long-term archives - and count every place it ends up, and where you lose control of it.

Show the journey for:
11 stages
  1. 1

    Search, enquiry & booking-channel capture control breaks

    +7 places · 7 so far

    A guest searches, taps an OTA listing, fills the website form, phones the desk or messages on WhatsApp. Within minutes the same person exists on a booking platform you do not own, in an ad platform's audience, on a reservation executive's own handset and in a lead sheet.

    Where control breaks: The guest exists on the OTA before they exist with you

    Moving hereGuest & traveller identity (new at this stage)Companions, children & emergency contacts (new at this stage)Booking, reservation & itinerary (new at this stage)Corporate & employer travel records (new at this stage)Preferences, occasions & special requests (new at this stage)Health, dietary & accessibility needs (new at this stage)+3 more

    DPDPAThis is the moment to say what you collect and why. An enquiry about one stay or one trip is not permission to hold that person and market to them for years, and an OTA booking arrives with terms about the guest that you still have to be able to explain.

  2. 2

    Reservation, quotation & guest profile creation control breaks

    +4 places · 11 so far

    The booking or quotation is built, and with it a guest profile: names of everyone travelling, dates, room or package, rate, corporate code, preferences and the executive's own notes. The same person is now created separately in the OTA, the channel manager, the reservation system and the CRM.

    Where control breaks: Everyone on shift can read the allergy, the complaint and the note

    Moving herePayment, deposit & billing (new at this stage)Guest & traveller identityCompanions, children & emergency contactsBooking, reservation & itineraryCorporate & employer travel recordsPreferences, occasions & special requests+4 more

    DPDPADuplicate guest records are a rights problem before they are a data-quality one - a correction or deletion applied to one of four copies has not been applied. Decide which record is the master and keep companions as separate people, not fields.

  3. 3

    Passport, visa & identity-document collection control breaks

    +5 places · 16 so far

    Passports, visas, photographs, dates of birth, nationality and - for a visa file - bank statements, employment letters and family papers arrive by WhatsApp, by email, as photographs and as hard copies, and are saved into whichever folder the coordinator uses.

    Where control breaks: Passports arrive on WhatsApp and are still there years later

    Moving herePassport, visa & identity documents (new at this stage)Guest & traveller identityCompanions, children & emergency contacts

    DPDPAThese are the highest-impact documents in the sector. Collect them only when the booking genuinely needs them, use one controlled channel, record the verification outcome where a full copy is unnecessary, and know which copies exist where.

  4. 4

    Payment, deposit, billing & corporate settlement

    +6 places · 22 so far

    Deposits, pre-authorisations, instalments, folios and invoices move through gateways, terminals, banks, the accounting system and - for a business trip - the employer's travel desk and expense platform, which receives an itemised account of what the person did.

    Moving hereDining, spa, housekeeping & activity records (new at this stage)Complaints, incidents & lost property (new at this stage)Guest & traveller identityBooking, reservation & itineraryPayment, deposit & billingCorporate & employer travel records+1 more

    DPDPANever store card credentials, and treat the corporate invoice as a disclosure: an employer needs the amount, not a line-by-line record of the spa, the bar and the second guest in the room. Financial retention is its own clock, separate from the guest record.

  5. 5

    Pre-arrival documents, itineraries & special requests control breaks

    +4 places · 26 so far

    Confirmations, final itineraries, rooming lists, arrival manifests, transfer sheets and emergency-contact lists are assembled and sent - by email, in a WhatsApp group, as a printed travel pack - and with them arrive allergies, celebrations, mobility needs and flight numbers.

    Where control breaks: One sheet shows every traveller to every other traveller

    Moving hereLocation, transport & movement (new at this stage)Access, Wi-Fi & monitoring records (new at this stage)Guest & traveller identityCompanions, children & emergency contactsBooking, reservation & itineraryPreferences, occasions & special requests+3 more

    DPDPAA consolidated list is a disclosure to everyone who receives it. Give each traveller their own document, keep dietary, health and accessibility details with the team that needs them, and expire shared links rather than leaving them live.

  6. 6

    Arrival, check-in & guest registration

    +2 places · 28 so far

    At the desk the guest is registered: name, address, nationality, identity document, signature, vehicle, companions. The document is scanned or photocopied, the register is filled in front of the next guest in the queue, and for a foreign national a report goes to the authorities.

    Moving hereGuest & traveller identityPassport, visa & identity documentsCompanions, children & emergency contactsBooking, reservation & itineraryPreferences, occasions & special requestsHealth, dietary & accessibility needs+3 more

    DPDPASeparate what the law requires you to submit from what you chose to keep a copy of. Government-reported records are authority-controlled and not yours to amend; the scan sitting on the front-desk desktop is entirely yours, and usually nobody has decided how long it stays.

  7. 7

    Access, Wi-Fi, CCTV & movement records control breaks

    +5 places · 33 so far

    The journey starts recording where the person physically is: key-card and mobile-key events, Wi-Fi logins and device identifiers, CCTV, parking and lift access, transport GPS, a shared live location, and a tour manager's running note of where the group has got to.

    Where control breaks: The stay records where the guest was, and nobody set a retention period

    Moving hereGuest & traveller identityLocation, transport & movementAccess, Wi-Fi & monitoring recordsComplaints, incidents & lost property

    DPDPASafety and marketing are different purposes and should not share a database. Set a retention period for footage, logs and location history, keep room and location data away from general staff visibility, and close credentials the moment the stay or trip ends.

  8. 8

    Stay, dining, activities & guest services control breaks

    +2 places · 35 so far

    Service creates the behavioural half: room-service orders, dining and bar history, spa treatments, housekeeping notes, minibar use, excursion attendance, guide and driver assignments, and a running commentary of service-recovery notes and staff opinion.

    Where control breaks: Every guide, driver and vendor gets the whole list because it is quicker

    Moving hereGuest & traveller identityCompanions, children & emergency contactsBooking, reservation & itineraryPayment, deposit & billingPreferences, occasions & special requestsHealth, dietary & accessibility needs+5 more

    DPDPAOperational notes become a profile whether or not anyone intended one. Keep them factual, restrict them to the department that needs them, give each partner and vendor the minimum the service requires, and do not reuse service history for marketing by default.

  9. 9

    Checkout, complaints, reviews & lost property

    +4 places · 39 so far

    Departure produces the last cluster: the final folio, a feedback form, a public review and your reply to it, a complaint thread, a refund file, a photograph of a lost item, a compensation note - and a quiet internal label about how the guest behaved.

    Moving hereGuest & traveller identityPassport, visa & identity documentsBooking, reservation & itineraryPayment, deposit & billingCorporate & employer travel recordsAccess, Wi-Fi & monitoring records+4 more

    DPDPAA public reply that mentions the room, the dates or the complaint discloses the stay. Keep internal notes factual and correctable, separate the public record from the guest file, and set a retention period for lost-property photographs and refund evidence.

  10. 10

    Loyalty, marketing & cross-property profiling control breaks

    +3 places · 42 so far

    The completed stay or trip becomes a loyalty tier, a stay frequency, a spend profile, a preferred property, a churn score, a WhatsApp broadcast list, an uploaded lookalike audience and a cross-brand campaign that runs indefinitely.

    Where control breaks: One stay becomes permission to market forever, across every brand

    Moving hereStaff, device & access records (new at this stage)Guest & traveller identityBooking, reservation & itineraryCalls, messages, photos & reviewsScores & labels about the guest· inferredLoyalty & marketing profile· inferred

    DPDPAFinishing the service is not permission to market. Keep booking communication separate from promotion, hold one suppression list every channel must check, and make a withdrawal reach the agency export and the uploaded audience, not only the CRM flag.

  11. 11

    Archive, vendor copies & deletion control breaks

    +2 places · 44 so far

    Everything settles: reservation and travel-system archives, the CRM, loyalty, folders of passport scans, Wi-Fi and CCTV stores, finance records, supplier and GDS systems, backups, staff phones, the physical register - and a guest history kept because it is what makes the next stay easier to sell.

    Where control breaks: Checking out does not delete anything

    Moving hereGuest & traveller identityPassport, visa & identity documentsCompanions, children & emergency contactsBooking, reservation & itineraryPayment, deposit & billingCorporate & employer travel records+9 more

    DPDPARetention has to be decided per category, not for the guest as a whole. Tax records, a filed government report and a ticketed booking have grounds to be kept; a five-year-old passport scan taken for a stay that ended does not.

In this reference model, one guest's data ends up in 44 distinct places across 11 stages, with 8 places where control breaks.

Top risk hotspots - where control usually breaks

The 8 places guest data most often slips out of your control. Each links to the matching check in the readiness assessment.

  1. Hotspot 1 Critical risk

    Passport and visa pages, photographs and ID cards come in as images and email attachments, get saved to a folder, scanned again at the desk, downloaded to a laptop to attach to a supplier email, printed for the file and backed up overnight.

    Why this matters

    It is the highest-impact collection in the sector, and it exists in five places at once because it was never collected through one. Long after the guest has gone, a copy of their passport is still sitting in a folder nobody owns - and no one in the business can say how many copies there are.

    Fix: Collect through one secure upload link, keep one folder per booking with named access, record that the document was checked instead of keeping a full copy wherever that is enough, and delete the scans on a clock once the stay or trip has closed.

    Check this in the assessment
  2. Hotspot 2 Critical risk

    Guides, excursion and safari operators, event vendors, photographers, spa and restaurant partners and transfer drivers are each sent what they need to do the job - which in practice is the entire party list, with names, numbers, ages, room allocations and dietary and medical notes, forwarded into a WhatsApp group.

    Why this matters

    The guest file is broken up and handed to a long tail of small independent operators, none of whom has a contract, a retention rule or any reason to delete anything. When the guest later asks who holds their details, this is the part of the answer no business in this sector can give.

    Fix: Send each partner only the rows and fields their job actually needs, use a booking reference in place of the guest's number where the partner has no reason to call, put deletion terms into the contracts of the partners you use repeatedly, and stop forwarding party lists into vendor group chats.

    Check this in the assessment
  3. Hotspot 3 Critical risk

    Past reservations, cancelled and no-show bookings, enquiries that never converted, folios, preferences, complaint notes and passport scans from stays years ago all settle into the archive - and stay, because past-guest history is what makes the next booking easier to sell.

    Why this matters

    Most of the people in it have had no relationship with the business for years, and many never had one at all. This is the single place where a retention decision would do the most good and is least likely to have been taken - and it is where a deletion request quietly fails.

    Fix: Set a retention period per category - enquiry, booking, identity document, financial record - and run it on a clock. An identity document almost never needs to survive the stay; a tax record does. Separate what you must keep from what you have merely never deleted.

    Check this in the assessment
  4. Hotspot 4 Critical risk

    Most bookings are collected by an online travel agency, a metasearch listing or a booking engine first - name, contact, dates, party size, sometimes a card - then synced to your systems by a channel manager, leaving the same guest in four places within minutes.

    Why this matters

    A large share of your guests were collected under somebody else's notice, on terms you did not set. Deleting your copy leaves theirs untouched, and when a guest asks what you hold and who else has it, the honest answer starts with a platform you do not control.

    Fix: Read what each platform's contract actually permits, pull only the fields you need into your own systems, decide which record is your master so a correction lands in one place, and tell guests plainly which parts of their booking record you cannot reach.

    Check this in the assessment
  5. Hotspot 5 High risk

    The guest profile holds companions, preferences, dietary and medical notes, past complaints, a value band and whatever the last executive typed into the notes field - open to nearly everyone on duty, exportable by most of them, and kept indefinitely.

    Why this matters

    Housekeeping does not need the medical note and marketing does not need the complaint history, but both can usually see them. A guest can ask to see and correct what you hold, including the opinions - and a departing employee can export the lot on their way out.

    Fix: Move to role-based access so each team sees the service note and not the whole profile, keep notes factual and separate observation from opinion, restrict exports to named people, and put a retention clock on guest history.

    Check this in the assessment
  6. Hotspot 6 Critical risk

    Key-card and mobile-key events, Wi-Fi logins and device identifiers, lift and parking access, CCTV, transfer GPS and a live location a coordinator asked someone to share - all generated continuously, and on a trip, often still updating days after everyone got home.

    Why this matters

    This is the only record in the series that says where a named person physically was, at what time - and by implication, when their home was empty. It is created without a decision, viewable by staff who have no need for it, and it outlives the stay it belonged to.

    Fix: Write down the purpose and the retention period for each kind of movement record, keep safety records out of marketing and analytics, restrict access to named accounts with a viewing log, and close credentials and stop location sharing the moment the stay or trip ends.

    Check this in the assessment
  7. Hotspot 7 High risk

    The final itinerary, the rooming list, the arrival manifest, the transfer schedule and the emergency-contact sheet are assembled into one document and sent to the group by email, dropped into a WhatsApp group, forwarded to the hotel and the transfer vendor, and printed for the folder.

    Why this matters

    It discloses room allocations, who is travelling with whom, who needs a wheelchair and whose emergency contact is whose - to everybody who receives it. It is forwarded onward more often than any other file in the sector, and no version of it can be recalled.

    Fix: Send each traveller their own document, give each partner only the rows they need, keep health, accessibility and emergency details on a separate need-to-know sheet, and use links that expire rather than attachments that do not.

    Check this in the assessment
  8. Hotspot 8 High risk

    The completed booking becomes a loyalty tier, a spend band, a churn score, a seasonal campaign list, a WhatsApp broadcast sent from a manager's own number and an audience uploaded back to the ad platform - and at a group, a stay at one property starts marketing from all of them.

    Why this matters

    Marketing permission is usually bundled into the booking, and a withdrawal recorded in the CRM does not reach the uploaded audience, the agency's export or the broadcast list on somebody's personal phone. The guest keeps hearing from you after asking you to stop, which is the complaint that actually gets made.

    Fix: Separate booking communication from promotion, keep one suppression list that every channel and agency must check before sending, remove uploaded audiences when someone withdraws, and set an inactivity rule that closes dormant loyalty profiles.

    Check this in the assessment

What happens when someone asks

The map above shows where guest data ends up. This is what that means the day someone asks you to find it, fix it or remove it - including the places a request realistically cannot reach.

Who asks: A past guest who has started getting calls and offers from businesses they never dealt with

Where you have to look

  • Property management / travel management systemYour business
  • Passport, visa & ID document folderYour business
  • Shared enquiry & lead spreadsheetYour business
  • Staff phones & guest WhatsApp threadsYour business
  • Loyalty, CRM campaigns & broadcast listsYour business
  • Guest history archive & old-booking databaseYour business
  • Accounting, invoicing & tax recordsYour business
  • Access, Wi-Fi & movement record trailYour business

Where this usually cannot reach

  • OTA, booking engine & channel managerPlatforms, systems & service vendors
  • Guides, activity partners & on-ground vendorsAirlines, hotels, guides & partners
  • Departed staff's devices & exportsAirlines, hotels, guides & partners
  • Ad platforms, pixels & analyticsPlatforms, systems & service vendors

What has to happen

  1. Confirm who is asking, using the number or email the booking was made on.
  2. Search on more than the name - the same person is usually in the reservation system, the lead sheet, the archive and the loyalty record under slightly different spellings.
  3. Include what you created about them, not only what they gave you: the preference notes, the value band, the complaint history and any behaviour flag.
  4. Include the identity documents you still hold, and say where each copy is.
  5. List who the booking was shared with - the platform it came from, the transfer vendor, the partners who delivered the service.
  6. Say plainly which of those recipients you can reach and which you cannot.

The part that usually fails: The honest answer has two halves. You can account for what is inside your systems. You cannot account for the platform that collected them in the first place, or for the guides, drivers and local vendors who were sent a list over WhatsApp - and those are the recipients the guest is usually asking about.

Check whether you could answer this today

When it has already gone wrong

An operational response reference for the incidents this sector actually has - what to do in the first hour, what to put right afterwards, and the control that stops a repeat. Whether an incident needs to be reported is a decision to take with your own advisers.

Severe

How you find out: A stranger replies to say they have received somebody's passport, or the guest calls having been told by a friend

Systems involved

  • Staff phones & guest WhatsApp threadsYour business
  • Passport, visa & ID document folderYour business
  • Property management / travel management systemYour business
  • Complaint & guest-support deskYour business

First - stop it spreading

  1. Delete the message for everyone immediately - the window is short, so do this before anything else.
  2. Establish exactly what was sent, to which number, and whether it was forwarded on.
  3. Ask the recipient to delete it, in writing, and keep their reply.
  4. Check whether the same file was sent to any other wrong recipient in the same thread.

Then - correct it and record it

  1. Tell the guest what happened, what was in it and what you have done - before they hear it from someone else.
  2. Write down the facts: the file, the recipient, the time, the steps taken and the outcome.
  3. Assess whether the exposure needs to be escalated, and record the reasoning either way.
  4. Check whether the document needed to be held at all, and delete the remaining copies if not.

The control that prevents a repeat: Stop sending identity documents through personal chat in either direction. A controlled upload link into the booking record removes both the wrong-number risk and the copy that stays on the handset.

How to read this journey

Pick your model

Switch between Hotel / resort, Travel agency / tour operator and Integrated hospitality & travel group to see the journey each kind of business actually runs. This is not a filter over one journey - a hotel owns the stay, registers the guest against an identity document and generates access, Wi-Fi and CCTV records on its own premises; an agency never owns a bed and instead distributes the traveller's passport and itinerary across airlines, hotels, wholesalers, visa consultants and guides; a group runs both and then joins them into a single cross-brand profile. The stage count and the place-counter recalculate for the model you choose.

When it leaves you

A violet left edge and a tag mark everything outside your business - the OTA and channel manager that collected the guest before you did, airlines and GDS, partner hotels and wholesalers, visa consultants and insurers, transfer vendors, guides and activity operators, payment and Wi-Fi providers, employers receiving an itemised invoice, immigration authorities, and anything that becomes a public review. Once data is there your control is indirect at best: it runs through your instructions and your contract, not your systems. Risk is shown separately, as an amber or red fill - so an outside system can be low risk, and your own reservations executive's phone can be one of the worst things on the page.

Where control breaks

Red flags mark the hotspots - the eight places hospitality and travel businesses most often lose control of guest data, from a passport photographed onto WhatsApp and never deleted, to a party list forwarded into a vendor group chat, to a key-card and Wi-Fi trail that records where a named person was and has no retention period. Tap any system to see what it holds and how to fix it.

Now check whether your controls hold up

The map shows where guest and traveller data travels in a typical hospitality or travel business. The 3-minute readiness scan checks whether your business has the controls that matter at each hotspot - and the Discovery tool builds your own data inventory.

Educational reference model - not legal advice, and not a scan of your actual systems.