Hotel owners across India are renegotiating long-term contracts with international hotel operators and online booking platforms to clearly define data protection responsibilities under the Digital Personal Data Protection (DPDP) Act, which came into force last year.
The move reflects rising concern over liability exposure in an industry where guest data flows through multiple stakeholders—property owners, global hotel brands, online travel agencies (OTAs), and technology vendors. Legal experts say hospitality is particularly vulnerable due to past instances of hacking, credit card theft, and the widespread sharing of personal data across interconnected systems.
Many existing hotel management and franchise agreements span 20–30 years and were signed well before data privacy became a regulatory priority. As a result, they often lack clarity on who controls guest data and who bears responsibility in the event of a breach.
The DPDP Act imposes steep penalties for mishandling personal data and grants consumers stronger rights, prompting owners to reassess risk allocation. Industry experts note that hotel companies are struggling to interpret their obligations, especially as they may act as both data fiduciaries and data processors under different arrangements.
Property owners are now seeking clearer responsibility matrices with international hotel chains, most of which operate through asset-light management or franchise models rather than owning properties. These concerns are increasingly influencing brand negotiations and new signings.
Questions around cross-border data laws, ownership of customer data, and responsibility after contract termination have become key sticking points, making data protection a central issue in hotel contracting discussions.
Source: ET


