Hospitality door. DPDP + POSH + FSSAI + Fire NOC + Labour codes.

DPDP Compliance for Hotels in India. Guest consent at check-in. Breach-ready. ₹250 Cr fine safe.

Every hotel, resort and restaurant in India collects Aadhaar, phone, payment card and stay preferences on every guest. The DPDP Act 2023 makes each of those a Data Fiduciary obligation with penalties up to ₹250 crore. dcomply ships QR-based consent capture at reception, a guest DSR portal, breach notification workflow, POSH IC for the workforce, FSSAI licence tracker for kitchens, and Fire NOC + Shop & Est renewals. One workspace, every regulator, nothing to install in your PMS.

Get your GM and HR certified first. Free DPDP course + POSH course

QR consent at reception Guest DSR portal in 22 languages No PMS integration required
Live Hotel Compliance Snapshot
Acme Grand Hotel & Resort
DPDP Health: 79/100 AMBER
───────────────────────────────
Guest consent capture ....... 92%
DSR requests (last 30d) ..... 6 closed
Breach drill last run ...... 45 days ago
FSSAI licence expires in ... 62 days
POSH IC quorum ............. Compliant
───────────────────────────────
Fire NOC renewal in: 18 days · Open incidents: 1
Powered by dcomply
Sound familiar?

If any of this sounds familiar, you're in the right place.

These are the exact sentences hotel general managers and hospitality compliance heads say on the first call. If two or three are true for you, dcomply is the workspace you have been trying to build in Excel.

Your front-desk still ticks a paper box for "consent to marketing" that would not survive a DPDP inspection.

A guest asked to see the personal data you hold on them and you did not have a workflow.

Your OTA partners email guest lists with Aadhaar numbers and nobody has signed a Data Processing Agreement.

Your PMS holds fifteen years of guest history and nobody has thought about retention rules.

Your FSSAI licence, Fire NOC and Shop & Est renewal dates are on someone's WhatsApp.

For guest data specifics, see the DPDP door. If you also run a hotel loyalty programme with in-app payments, the Fintech door covers RBI and CERT-In.

Your regulator stack

Every Indian hotel lives under all of these.

DPDP is the foundation because every guest interaction generates personal data. FSSAI sits on top for your kitchens. Fire NOC and Shop & Est are the operational baseline. POSH and Labour Codes catch every hotel because of the workforce size. dcomply ships modules for each layer.

POSH + Labour Codes
Mandatory for any hotel with over 10 staff. IC constitution, complaint intake, annual return, PF/ESIC challans, gratuity records, Shop & Est registration.
Fire NOC + Building Safety
Annual NOC renewal, mock drill records, emergency lighting checks. Non-negotiable for occupancy permits.
FSSAI + F&B licences
Kitchen FSSAI (state/central), bar excise, liquor licence, MoU with waste disposer, staff medical certificates.
CERT-In + Cyber Incident Reporting
6-hour ransomware and data breach notice. Hotels are a frequent ransomware target because of payment-card data.
DPDP Act 2023
The foundation. Every guest booking generates personal data. Consent capture, DSR portal, breach notification, retention. Rule 11 for guests under 18.
₹250 Cr
Max DPDP penalty per violation
72 hours
DPB breach notice window
18 months
DPDP Rules transition ends May 2027
22 languages
Regional-language consent notices
Why hospitality compliance is a spreadsheet nightmare

One hotel, eight regulators, endless renewals

From reception to housekeeping to your OTA channel manager, everyone keeps a separate register. dcomply collapses them into one workspace.

Guest consent chaos

Paper check-in cards, kiosk taps, WhatsApp bookings. No single record of what each guest agreed to.

Payment card storage

PMS keeps card tokens, back office keeps invoices, POS keeps swipes. DPDP wants retention rules on all three.

OTA data sharing

MakeMyTrip, Booking.com, Agoda send guest lists daily. No DPA in place. Both parties liable.

Retention creep

Guest history from 2010 still in the PMS. DPDP wants purpose-limited retention with a defined schedule.

In your tenant on day one

Every hospitality module, pre-mapped to Indian law

Subscribe to dcomply Business and you get all of these. No three-month implementation.

DPDP
Guest Consent Capture

QR code, tablet, WhatsApp flows at reception. 22 Indian languages. Versioned, timestamped, auditable.

DPDP
Guest DSR Portal

Guest right-to-access, correct, delete via public portal. SLA tracking. Auto-drafted responses.

DPDP
Breach Notification

72-hr DPB notice + CERT-In 6-hr filing. AI severity classification, evidence pack, board summary.

DPDP
Retention Schedule

Guest history, payment cards, CCTV, WiFi logs. Each with a purpose-based retention rule and auto-purge.

DPDP
DPA Templates

OTA channel manager, PMS vendor, cloud host. Every processor DPA drafted and countersigned in-app.

FSSAI
FSSAI Licence Tracker

State + central licence expiry, kitchen hygiene checklist, staff medical certificates, waste disposer MoU.

POSH
POSH Compliance

Internal Committee, annual return, training records, complaint intake. Hospitality is POSH-mandated.

Labour
Labour Code Tracker

Shop & Est, PF/ESIC challans, gratuity records, minimum wages, holiday register.

Fire
Fire NOC Renewals

Annual NOC alerts, mock drill logs, emergency lighting register, evacuation SOP.

CERT-In
CERT-In Reporting

Ransomware, breach or unauthorised access. 6-hour incident report pre-filled.

Audit
Evidence Locker

One vault: FSSAI certificates, Fire NOC, POSH IC minutes, breach reports, DSR responses.

vDPO
Virtual DPO Add-on

Fractional DPO from ₹2,499/month. Named advocate DPO tier for SDF hotels from ₹19,999/month.

Coverage by regulator

What dcomply replaces

Regulator / FrameworkWhy it appliesdcomply module
DPDP Act 2023You process guest personal & payment data Data Privacy pack (11 modules)
DPDP Rules 2025Consent format, breach format, DPO obligations Rules 2025 mapping built-in
FSSAIAny F&B operation on premises FSSAI licence tracker
Fire SafetyOccupancy permit prerequisite Fire NOC renewals
CERT-InPayment-card systems + guest WiFi CERT-In reporting module
POSH ActHotels with > 10 employees POSH IC + annual return
Labour CodesEvery hospitality workforce Labour code tracker
Shop & EstState-level operational registration Renewals + register
vDPO Add-on

DPDP says you need a DPO. We become one.

Hotel chains and large resorts processing guest data at scale fall under DPDP Section 10 SDF criteria. A DPO is mandatory.

dcomply vDPO bolts onto your tenant from ₹2,499/mo with AI Q&A, monthly DPO PDF, auto-DPIA triggers and DSR auto-drafts. Standard tier adds a human checkpoint each month. Premium gives you a dedicated retained advocate-DPO who liaises with the DPB.

See vDPO tiers
vDPO Premium₹19,999/mo

Dedicated advocate-DPO on retainer.

  • Named advocate as your DPO
  • Weekly compliance review call
  • Breach response in 4 hours
  • DPB liaison (regulator-facing)
  • Quarterly board report
  • Annual staff training
Built for hospitality

Guest data lives in many places. We find it all.

PMS in the cloud, POS at the bar, WhatsApp in the concierge's phone. Connect them and the discovery engine maps the PII automatically.

MySQL
PMS / booking DB
MongoDB
Guest analytics
AWS S3
CCTV / backups
Google Sheets
Reservations & rosters
WhatsApp Business
Guest chat + DSR
Razorpay
Payment PII
Hospitality DPDP FAQs

Questions hotel general managers actually ask.

DPDP, POSH, FSSAI, Fire, Labour. Everything a hotel needs to know about running compliance in India.

Every guest booking generates personal data. Name, phone, government ID, payment details, sometimes food preferences and health notes. Under the DPDP Act 2023, hotels are Data Fiduciaries and must obtain free, specific, informed and unambiguous consent before collecting or using this data. Consent must be capable of withdrawal. Non-compliance can invite penalties up to ₹250 crore.

The DPDP Rules 2025 were notified in November 2025 with an 18-month transition window, making compliance mandatory by May 2027. Large hotel chains classified as Significant Data Fiduciaries face additional obligations including mandatory DPO appointment, DPIA and independent audits.

Guest name, phone, email, address, ID proof (Aadhaar/passport), payment card, room preferences, loyalty programme details, in-room service history, CCTV footage in public areas, WiFi captive-portal logs, restaurant/bar consumption, spa bookings and health forms, and reviews on OTA channels. Every one of these is personal data.

dcomply provides QR-based consent capture at reception, tablet-based digital consent forms in 22 Indian languages, and a WhatsApp consent flow for advance-booking guests. Every consent is versioned, timestamped and produces an auditable artefact.

This is a Data Principal Rights Request (DSR). Under DPDP you must fulfil it within statutory timelines. dcomply provides a public portal at yourhotel.dcomply.in where guests can raise access, correction and erasure requests. Every DSR is tracked to an SLA clock.

dcomply runs as a parallel compliance workspace and does not require PMS integration. Guest data stays in your PMS. Compliance evidence, workflows and audit trails live in dcomply. Native connectors for major PMS platforms are on the roadmap.

The DPDP Rules 2025 require notice to the Data Protection Board of India and to affected data principals without undue delay. Ransomware and unauthorised access incidents additionally trigger the CERT-In 6-hour reporting requirement. dcomply auto-pre-fills both formats and preserves logs.

Yes. DPDP Rule 11 requires verifiable parental consent for anyone under 18. For hotels this covers bookings made for or by minors, in-room children's activities, and any loyalty programme sign-up. dcomply's children-data module implements verifiable consent with age verification.

Included. Hotels, restaurants and resorts hit both because of the size of the workforce and the frequency of guest interaction. Every dcomply tenant gets POSH IC constitution, annual return, complaint intake, PF/ESIC challans, gratuity records and Shop & Establishment registration tracker.

Both. Under DPDP the OTA and the hotel are typically joint or independent Data Fiduciaries depending on operational control. Contracts must clearly define who is Data Fiduciary and who is Data Processor. dcomply ships DPA templates for OTA channel-manager relationships.

It works for both. Pricing scales with the modules you activate. A single-property boutique hotel can start at ₹12,999/month; multi-property chains use the Corporate Compliance pack from ₹49,999/month.

Failure to obtain valid consent, failure to notify a breach and failure to implement reasonable security safeguards each carry penalties up to ₹250 crore. Given the volume of guest data hotels process, exposure is real. dcomply's Breach Notification and Gap Assessment modules keep you inspection-ready.
Real properties, real compliance programmes

"Reception took to it in an afternoon."

"We had two weeks before a group audit. Rolled out the QR consent boards at reception, opened the guest DSR portal, and pushed a POSH refresher. Reception took to it in an afternoon. Auditors accepted the exported binder."
General Manager, a boutique five-star property in Goa.

Start free. Scale when you're ready.

Pay-per-module from ₹1,499. Corporate Compliance pack from ₹11,999. vDPO from ₹2,499.