DPDP Compliance for Hotels in India. Guest consent at check-in. Breach-ready. ₹250 Cr fine safe.
Every hotel, resort and restaurant in India collects Aadhaar, phone, payment card and stay preferences on every guest. The DPDP Act 2023 makes each of those a Data Fiduciary obligation with penalties up to ₹250 crore. dcomply ships QR-based consent capture at reception, a guest DSR portal, breach notification workflow, POSH IC for the workforce, FSSAI licence tracker for kitchens, and Fire NOC + Shop & Est renewals. One workspace, every regulator, nothing to install in your PMS.
Get your GM and HR certified first. Free DPDP course + POSH course
If any of this sounds familiar, you're in the right place.
These are the exact sentences hotel general managers and hospitality compliance heads say on the first call. If two or three are true for you, dcomply is the workspace you have been trying to build in Excel.
Your front-desk still ticks a paper box for "consent to marketing" that would not survive a DPDP inspection.
A guest asked to see the personal data you hold on them and you did not have a workflow.
Your OTA partners email guest lists with Aadhaar numbers and nobody has signed a Data Processing Agreement.
Your PMS holds fifteen years of guest history and nobody has thought about retention rules.
Your FSSAI licence, Fire NOC and Shop & Est renewal dates are on someone's WhatsApp.
For guest data specifics, see the DPDP door. If you also run a hotel loyalty programme with in-app payments, the Fintech door covers RBI and CERT-In.
Every Indian hotel lives under all of these.
DPDP is the foundation because every guest interaction generates personal data. FSSAI sits on top for your kitchens. Fire NOC and Shop & Est are the operational baseline. POSH and Labour Codes catch every hotel because of the workforce size. dcomply ships modules for each layer.
One hotel, eight regulators, endless renewals
From reception to housekeeping to your OTA channel manager, everyone keeps a separate register. dcomply collapses them into one workspace.
Guest consent chaos
Paper check-in cards, kiosk taps, WhatsApp bookings. No single record of what each guest agreed to.
Payment card storage
PMS keeps card tokens, back office keeps invoices, POS keeps swipes. DPDP wants retention rules on all three.
OTA data sharing
MakeMyTrip, Booking.com, Agoda send guest lists daily. No DPA in place. Both parties liable.
Retention creep
Guest history from 2010 still in the PMS. DPDP wants purpose-limited retention with a defined schedule.
Every hospitality module, pre-mapped to Indian law
Subscribe to dcomply Business and you get all of these. No three-month implementation.
Guest Consent Capture
QR code, tablet, WhatsApp flows at reception. 22 Indian languages. Versioned, timestamped, auditable.
Guest DSR Portal
Guest right-to-access, correct, delete via public portal. SLA tracking. Auto-drafted responses.
Breach Notification
72-hr DPB notice + CERT-In 6-hr filing. AI severity classification, evidence pack, board summary.
Retention Schedule
Guest history, payment cards, CCTV, WiFi logs. Each with a purpose-based retention rule and auto-purge.
DPA Templates
OTA channel manager, PMS vendor, cloud host. Every processor DPA drafted and countersigned in-app.
FSSAI Licence Tracker
State + central licence expiry, kitchen hygiene checklist, staff medical certificates, waste disposer MoU.
POSH Compliance
Internal Committee, annual return, training records, complaint intake. Hospitality is POSH-mandated.
Labour Code Tracker
Shop & Est, PF/ESIC challans, gratuity records, minimum wages, holiday register.
Fire NOC Renewals
Annual NOC alerts, mock drill logs, emergency lighting register, evacuation SOP.
CERT-In Reporting
Ransomware, breach or unauthorised access. 6-hour incident report pre-filled.
Evidence Locker
One vault: FSSAI certificates, Fire NOC, POSH IC minutes, breach reports, DSR responses.
Virtual DPO Add-on
Fractional DPO from ₹2,499/month. Named advocate DPO tier for SDF hotels from ₹19,999/month.
What dcomply replaces
| Regulator / Framework | Why it applies | dcomply module |
|---|---|---|
| DPDP Act 2023 | You process guest personal & payment data | Data Privacy pack (11 modules) |
| DPDP Rules 2025 | Consent format, breach format, DPO obligations | Rules 2025 mapping built-in |
| FSSAI | Any F&B operation on premises | FSSAI licence tracker |
| Fire Safety | Occupancy permit prerequisite | Fire NOC renewals |
| CERT-In | Payment-card systems + guest WiFi | CERT-In reporting module |
| POSH Act | Hotels with > 10 employees | POSH IC + annual return |
| Labour Codes | Every hospitality workforce | Labour code tracker |
| Shop & Est | State-level operational registration | Renewals + register |
DPDP says you need a DPO. We become one.
Hotel chains and large resorts processing guest data at scale fall under DPDP Section 10 SDF criteria. A DPO is mandatory.
dcomply vDPO bolts onto your tenant from ₹2,499/mo with AI Q&A, monthly DPO PDF, auto-DPIA triggers and DSR auto-drafts. Standard tier adds a human checkpoint each month. Premium gives you a dedicated retained advocate-DPO who liaises with the DPB.
See vDPO tiersDedicated advocate-DPO on retainer.
- Named advocate as your DPO
- Weekly compliance review call
- Breach response in 4 hours
- DPB liaison (regulator-facing)
- Quarterly board report
- Annual staff training
Guest data lives in many places. We find it all.
PMS in the cloud, POS at the bar, WhatsApp in the concierge's phone. Connect them and the discovery engine maps the PII automatically.
Questions hotel general managers actually ask.
DPDP, POSH, FSSAI, Fire, Labour. Everything a hotel needs to know about running compliance in India.
"Reception took to it in an afternoon."
"We had two weeks before a group audit. Rolled out the QR consent boards at reception, opened the guest DSR portal, and pushed a POSH refresher. Reception took to it in an afternoon. Auditors accepted the exported binder."
Start free. Scale when you're ready.
Pay-per-module from ₹1,499. Corporate Compliance pack from ₹11,999. vDPO from ₹2,499.