---
title: "DPDP for hotels: consent and privacy notices guests can actually understand"
description: "Why hotels need clearer consent and privacy notices under the DPDP Act, especially across booking, check-in, guest apps, in-room TV, and marketing."
url: "https://TVshuru.com/blog-dpdp-hotel-consent-notices.html"
date: "2026-07-16"
image: "https://images.unsplash.com/photo-1556740758-90de374c12ad?auto=format&fit=crop&w=1200&q=80"
last_updated: "2026-07-16"
---

# DPDP for hotels: consent and privacy notices guests can actually understand

![A guest using a tablet at a hotel counter.](https://images.unsplash.com/photo-1556740758-90de374c12ad?auto=format&fit=crop&w=1200&q=80)

Consent is not a buried checkbox. For hotels, it needs to follow the guest journey from booking to post-stay marketing.

## The issue

The DPDP Act puts notice and consent at the centre of lawful processing, with specified legitimate uses for some situations. Hotels often collect data through many channels: OTA bookings, direct website forms, walk-in check-in, Wi-Fi portals, loyalty enrolment, spa bookings, room-TV QR flows, chat, and feedback forms.

If each channel explains data use differently, the guest experience becomes confusing and the hotel loses control of its own compliance story.

## What hotels should do

Create plain-language notices for each major data moment. A booking notice should explain reservation and stay communication. A check-in notice should explain identity, billing, and legal retention. A marketing notice should be separate from essential stay communication. A TV-to-phone service flow should tell guests what data is needed to complete that request.

Consent should be specific enough to show purpose. Do not bundle service fulfilment, loyalty profiling, partner promotions, and third-party marketing into one vague acceptance.

## Why it is important worldwide

GDPR made transparency a global expectation, not just a European legal formality. Travellers now move between jurisdictions with different privacy rules but similar instincts: they want to know what is collected and why. A hotel that uses simple notices reduces anxiety and support burden.

For TVshuru-style in-room experiences, this means the TV can present services without asking for personal data too early. The guest can scan a QR code only when the action needs private details, payment, or confirmation.

## Related reading

- [DPDP hub](blog-dpdp-act-hotels-360.html)
- [Guest rights](blog-dpdp-hotel-guest-rights.html)
- [TV discovery, phone action](blog-tv-discovery-phone-action.html)

## Sources

- PRS Legislative Research: Digital Personal Data Protection Bill, 2023: https://prsindia.org/billtrack/digital-personal-data-protection-bill-2023
- MeitY: Data Protection Framework: https://www.meity.gov.in/data-protection-framework
- ICO: Marriott International fine for failing to keep customer data secure: https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2020/10/ico-fines-marriott-international-inc-184million-for-failing-to-keep-customers-personal-data-secure/
- AP: MGM Resorts data breach expected to cost more than $100 million: https://apnews.com/article/087726961b5366065b6231d1d223b4eb
- European Commission: Data protection under GDPR: https://commission.europa.eu/law/law-topic/data-protection/data-protection-eu_en
