Current legal status — India, 8 August 2026
The Digital Personal Data Protection Act, 2023 received Presidential assent on 11 August 2023. The Digital Personal Data Protection Rules, 2025 and commencement notifications were published in November 2025 with phased commencement. Under the official enforcement timeline, several institutional/enabling provisions commenced on publication; section 6(9) and section 27(1)(d) are scheduled one year from publication; many core processing/right/obligation provisions are scheduled eighteen months from publication. CYVERNA therefore treats DPDP controls as a present implementation-readiness requirement even where a particular obligation is still in its statutory transition period.
Hotel DPDP Responsibility Matrix
| Control | Hotel / Data Fiduciary | CYVERNA / Processor-support |
|---|---|---|
| Purpose & lawful processing | Define lawful hotel purpose and what data is necessary. | Process only to provide configured services and documented instructions. |
| Notice & consent | Issue guest/staff notice and obtain consent where required. | Provide configurable notices, consent log and separate marketing consent. |
| Accuracy | Verify identity, guest, invoice and operational data. | Provide edit/audit workflows; do not independently certify accuracy. |
| Security | Secure users, devices, hosting, permissions and local procedures. | Provide software security controls and secure processor practices within service scope. |
| Rights requests | Verify identity, decide request and communicate outcome. | Provide request register/export/correction/deletion support as instructed. |
| Breach | Assess Data Principal/Board notification duties and legal communications. | Notify/cooperate on processor-side incidents and provide relevant evidence. |
| Retention | Set lawful hotel retention schedule. | Support deletion/export/backup lifecycle consistent with instructions and law. |
Mandatory Readiness SOP
- Maintain an itemised data inventory: guest KYC, booking, payment metadata, CCTV references if any, restaurant, loyalty, employee, vendor and integration data.
- For each data category record the specified purpose, lawful basis, source, recipients/processors, retention period and authorised roles.
- Publish a clear privacy notice independent of other information, with categories/purpose and a route to withdraw consent/exercise rights.
- Keep marketing consent separate from essential reservation/check-in/service processing.
- Use role-based access, encryption/HTTPS where applicable, monitoring, logs, backups and documented incident response.
- Execute processor/data-processing clauses with CYVERNA and each relevant third party.
- Maintain a privacy rights request register and identity-verification SOP.
- Maintain a breach register. On an applicable personal data breach, initiate containment and legal assessment immediately; the Rules contemplate prompt Data Principal/Board notice and further Board details within 72 hours where applicable.
- For minors, implement parent/guardian verification/consent controls required by applicable law and avoid unnecessary tracking/targeted advertising.
- Review retention and delete/anonymise data after purpose/legal retention ends.
- Train Front Office, Accounts, HR, Restaurant and IT teams; do not share KYC or passwords on informal support channels.
CYVERNA DPDP Technical Controls
- Legal & DPDP Centre with Hotel privacy contacts, retention settings, Hotel acceptance and operational checklist.
- Consent/evidence log for booking/privacy acknowledgement, marketing opt-in and Hotel platform terms.
- Privacy/Data Rights Request register with status, verification and response notes.
- Personal Data Breach register with severity, affected count, containment, notification timestamps and 72-hour detail deadline field.
- Role/permission controls, audit trail, protected secrets, backup/data portability, PWA security headers and controlled KYC access.
- FAQ bot coverage for privacy, KYC sharing, consent, breach and escalation SOPs.
Official sources used for this implementation guide
Government of India, Ministry of Electronics & Information Technology: Digital Personal Data Protection Act, 2023; Digital Personal Data Protection Rules, 2025; Enforcement Timeline for the DPDP Act (published 14 November 2025); and MeitY explanatory materials. Always check the latest Gazette/MeitY publication before relying on a deadline or newly notified obligation.
