Data privacy compliance for hotels & resorts
You scanned this from our Hotel Risk Summary. Hotels handle more personal data than they realise — guest IDs, CCTV, payment cards, and OTA bookings. Here is what the Data Privacy Act expects of a property in Region 8.
Questions, answered
A hotel just keeps guest records. Does the Data Privacy Act really apply to us?
Yes. Names, IDs, contact details, nationality, payment cards, and stay history are all personal data under RA 10173 — and a passport or government ID makes some of it sensitive. Any hotel or resort that records guests is a Personal Information Controller with full obligations under the law.
What about our CCTV cameras?
CCTV captures personal data, so it is covered. The NPC has specific guidance on video surveillance: you need proper notices, a lawful purpose, controlled access to footage, and a retention limit. Cameras in private areas or kept indefinitely are a common violation.
We take bookings through Agoda, Booking.com and other OTAs. Who is responsible for that data?
Both you and the platform have roles, but once guest data reaches your systems you are accountable for it. Online travel agencies, your PMS, and your booking engine form a data flow that needs data-sharing terms and vendor due diligence — a core part of what a DPO maps and documents.
How long can we keep guest information?
Only as long as there is a lawful purpose (legal records, billing, legitimate marketing with consent). Keeping ID scans and full guest histories forever is a retention violation. We help you set a defensible retention and disposal schedule.
Does a hotel need a Data Protection Officer?
Hotels and resorts process personal data — including sensitive IDs — routinely and at scale, which is when RA 10173 calls for a designated DPO. The DPO is also your registered contact with the NPC and the person who handles guest data-privacy complaints.
What if guest data leaks — a lost laptop, a hacked booking system?
You must assess the incident and, where required, notify the NPC and affected guests within 72 hours. Hospitality breaches (payment cards, passport copies) draw real penalties, so a prepared breach-response plan matters.
Can you set this up for our property?
Yes. As a TÜV Certified DPO (Cert #7000532) in Region 8, I can serve as your external DPO, register you with the NPC, build your Privacy Management Program, write your CCTV and guest-data notices, and train your front-desk team.
Keep guest data — and your reputation — protected
Talk to a TÜV Certified Data Protection Officer — no obligation, no jargon.
Atty. Renerio de Dios Jr. · TÜV Cert #7000532 · Dulag, Leyte · serving all of Region 8