News and developments
Data Privacy Risks for Aviation, Travel, and Hospitality Businesses under India’s DPDP Regime: Passenger Data, Surveillance and Global Compliance
By Aniket Ghosh
Introduction: Travel as a Data-Intensive Experience
Modern travel is inseparable from data. From the moment a passenger searches for a flight or hotel to the point of check-out or arrival, personal data is continuously collected, analysed, shared and retained across a complex ecosystem of airlines, airports, hotels, travel intermediaries, technology platforms and government authorities.
Airlines, airports, online travel agencies (OTAs), hotels, resorts, cruise operators and mobility providers routinely process:
Unlike many digital services, travel data processing is unavoidable. Passengers cannot meaningfully opt out without forfeiting the ability to travel. This structural imbalance places the travel and hospitality sector under heightened scrutiny under India’s data protection framework.
With the enactment of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), data privacy compliance has become a core operational, contractual and reputational issue for travel and hospitality businesses.
Applicability of the DPDP Act to Aviation, Travel and Hospitality
Entities Covered
The DPDP Act applies to any entity processing digital personal data, including:
Both Indian and foreign entities offering services to individuals in India fall within the scope of the Act.
Data Fiduciaries in the Travel Ecosystem
Most travel and hospitality entities qualify as data fiduciaries, as they determine:
Third parties namely reservation system providers, payment gateways, cloud vendors, analytics platforms, generally act as data processors, though primary liability remains with the fiduciary.
Large airlines, OTAs and hotel chains may be notified as Significant Data Fiduciaries (SDFs) due to:
Passenger Data: A High-Risk Category by Design
Passenger Name Records and Travel Histories
PNR data typically includes:
Such data can reveal health conditions, religious beliefs, travel habits and personal relationships, making it highly sensitive.
Location and Movement Data
Airports, airlines and hotels process:
Continuous monitoring significantly heightens privacy risk, particularly where retention is excessive or access controls are weak.
Consent and Notice in Travel and Hospitality
Is Consent Meaningful in Travel Contexts?
Under the DPDP Act, consent must be free, informed, specific, unambiguous, and capable of withdrawal. In travel, however, refusal to provide data often means denial of service. Regulators are therefore likely to scrutinise:
DPDP Rules: Enhanced Notice Requirements
The DPDP Rules require clear disclosure of:
Generic global privacy policies that obscure Indian-specific practices pose compliance risk.
Biometric Processing at Airports and Hotels
Facial Recognition and Digi-Yatra-Type Systems
Airports increasingly deploy:
Biometric data processing significantly raises compliance stakes due to:
Such processing must be:
Hotels and Access Control Systems
Hotels and resorts increasingly use Biometric or app-based room access and CCTV and smart surveillance. Without clear notice and proportionate use, such systems expose operators to enforcement risk.
Purpose Limitation and Commercial Use of Travel Data
Service Delivery vs Monetisation
Travel data is often repurposed for:
Under the DPDP Act, secondary commercial use requires explicit disclosure and valid consent. Legacy practices of silent profiling are no longer defensible.
Loyalty Programmes
Loyalty programmes involve long-term tracking of:
Without clear consent boundaries and retention controls, such programmes pose significant compliance risk.
Government Access, Security and Regulatory Overlap
Mandatory Data Sharing
Airlines and hotels often share data with:
While the DPDP Act provides exemptions for certain state functions, exemptions are not blanket permissions. Businesses must:
Intersection with Aviation and Immigration Laws
Travel businesses must navigate overlapping obligations under:
Poor governance of government requests can expose businesses to legal and reputational risk.
Cross-Border Data Transfers: A Structural Challenge
The travel industry is inherently global. Airlines, hotel chains and OTAs routinely transfer data across borders for:
Under the DPDP Act, cross-border transfers are permitted only to government-notified jurisdictions, requiring businesses to:
Data Breaches and Systemic Fallout
Mandatory Breach Notification
Under the DPDP Act and Rules, travel businesses must notify the Data Protection Board of India and the affected passengers or guests. Given the scale of operations, breaches can quickly become high-profile public incidents.
Reputational Impact
Data breaches involving travel data can:
For hospitality brands, trust erosion can have long-term commercial consequences.
Penalties and Enforcement Exposure
Monetary Penalties
The DPDP Act empowers penalties up to INR 250 crore per contravention, based on:
Airlines, OTAs and hotel chains face systemic exposure due to volume and international reach.
Commercial and Regulatory Consequences
Beyond penalties, businesses may face:
Compliance Roadmap for Travel and Hospitality Businesses
Conclusion: Privacy as the New Dimension of Travel Trust
In aviation and hospitality, trust is inseparable from safety and service quality. The DPDP Act and Rules make it clear that operational convenience and security objectives do not justify opaque or excessive data collection.
Travel and hospitality businesses that embed privacy-by-design, respect proportionality and maintain transparent governance will be best positioned to earn passenger trust and regulatory confidence in India’s evolving travel ecosystem.
