Guide

The DPDP Act for travel agencies: what India's data law means for booking sites

India's Digital Personal Data Protection Act, 2023 is the country's first comprehensive personal data law, and travel businesses sit squarely inside it: a booking site collects names, contact details, ID document data and payment information as a matter of routine. This guide explains, in general terms, what the law asks of a travel agency and how to get a booking website ready.

Short answer: under the Digital Personal Data Protection Act, 2023 (DPDP Act), a travel agency processing customers' digital personal data is a data fiduciary. In general terms it must process data lawfully for clear purposes, give notice and obtain valid consent where consent is the basis, secure the data, honour customers' rights over it, report breaches as prescribed and provide a grievance channel. The Act is supported by rules notified by MeitY, with obligations arriving in phases, so check the current official texts and take legal advice for your own business.

Advertisement

What the DPDP Act is

The Digital Personal Data Protection Act, 2023 received presidential assent in August 2023 and establishes India's framework for processing digital personal data. It is administered within the remit of the Ministry of Electronics and Information Technology (MeitY), and it is operationalised by the Digital Personal Data Protection Rules notified by the government in November 2025, which set out the working detail and a phased implementation calendar. The Act also establishes a Data Protection Board of India to deal with breaches and complaints.

The vocabulary matters because the obligations hang off it. The person the data is about is the data principal. The business deciding why and how the data is processed, your travel agency, is the data fiduciary. A supplier processing data on your instructions, such as a hosting company or a booking engine vendor, is a data processor. Certain larger or higher-risk businesses can be designated significant data fiduciaries with additional duties. The authoritative sources are the Act and rules themselves, published through official channels including MeitY; this article is a general orientation, not legal advice.

What a booking site actually collects

Travel businesses tend to underestimate their data footprint. A typical online agency touches most of this on every booking:

Typical personal data flowing through a travel booking business
DataWhere it entersWhy it is sensitive in practice
Names and contact detailsSearch, enquiry forms, booking flowCore personal data, used across marketing and operations
Passport and ID detailsFlight and visa-related bookingsHigh impact if leaked; often stored longer than needed
Dates of birth, traveller relationshipsPassenger details, child faresIncludes children's data, which the Act treats with special care
Payment-related dataCheckout via payment gatewaysRegulated separately by payment rules; minimise what you touch
Trip history and preferencesCRM, remarketing, loyaltyProfiles build up silently across systems
Technical identifiersCookies, analytics, ad tagsFeeds tracking and consent questions on the website itself

The practical starting point of any DPDP effort is simply writing this map down for your own systems: what you collect, where it lives, who it is shared with, and how long you keep it.

Where processing rests on consent, the Act sets a high bar: consent is to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, for a specified purpose. It must be preceded by a notice that tells the person, in clear language, what data is collected and why, and how to exercise their rights and complain. Consent can be withdrawn, and the law contemplates consent managers as a mechanism for handling consent at scale. The Act also recognises certain legitimate uses where processing can proceed on other grounds; which basis fits which processing is exactly the kind of question to resolve with counsel rather than by copying another site's banner.

For a booking site, the translation is concrete: purpose-specific notices at the points where data is collected, no pre-ticked boxes, marketing consent separated from booking necessity, and a way for customers to withdraw consent that actually works.

Advertisement

Core duties of a data fiduciary

  • Purpose discipline: process personal data only for lawful purposes, on a valid basis such as consent or a recognised legitimate use
  • Notice: tell customers what is collected and why, in clear language, as the Act and rules prescribe
  • Security safeguards: take reasonable measures to prevent breaches across your own systems and your processors
  • Processor governance: engage processors, such as booking engine and hosting vendors, under contracts that reflect your obligations
  • Accuracy and retention: keep data accurate where it drives decisions, and do not keep it beyond what the purpose and rules justify
  • Breach response: notify the Data Protection Board and affected individuals of personal data breaches in the prescribed manner
  • Children's data: apply the Act's specific protections, including around consent and tracking, when handling minors' data, which family bookings routinely include

Significant data fiduciaries attract further obligations under the framework, such as impact assessments and audits. Whether a travel business is so designated depends on government notification, not on self-assessment, so watch official announcements rather than assuming either way.

Customer rights and grievances

Data principals get enforceable rights: in general terms, to access a summary of their data and its processing, to correction and erasure, to nominate someone to act for them, and to grievance redressal. The grievance piece deserves emphasis because it is visible on your website: the framework expects a working channel through which customers can raise data concerns and get answers within the timelines the rules prescribe, before escalating to the Data Protection Board. For an agency, that means a named contact route, an inbox someone actually reads, and internal procedures to find and act on a customer's data across booking systems, CRM and marketing lists.

Mapping data through a travel booking flow

Data flow through a booking site: collection with notice and consent, processing and sharing with suppliers, storage with security and retention limits, and customer rights and grievance handling 1. CollectionForms, checkout, cookies.Notice and consent happen here. 2. Processing and sharingAirlines, hotels, APIs, paymentgateways, CRM: processors andthird parties, under contracts. 3. StorageSecurity safeguards, accesscontrol, retention limits, backups. 4. Rights and grievancesAccess, correction, erasure,withdrawal, grievance channel. Breach response cuts across all four stagesDetection, containment, and notification to the Board and affected customers.
The four stages every booking passes through. Each stage carries its own DPDP questions, and your vendors are inside the picture, not outside it.

Note how much of this runs through suppliers. A travel agency shares passenger data with airlines, consolidators, hotel suppliers and payment providers on every transaction; API integrations are personal data pipelines. That is why processor contracts and technical security around integrations belong in the compliance plan, not just the privacy policy.

How a travel agency can prepare

  • Map your data: what is collected, where it flows, who holds it, how long it is kept
  • Rebuild notices and consent points on the website around specific purposes, with marketing consent separated
  • Review your privacy policy against the Act and rules, and keep it honest about what actually happens
  • Put contracts and security expectations in place with processors: booking engines, hosts, CRM and marketing tools
  • Set retention rules, especially for passport data and children's details, and delete what you no longer need
  • Stand up the grievance channel and an internal breach response procedure with clear ownership
  • Track MeitY notifications for the phased obligations, and take advice from an Indian data protection lawyer on your specific position

On the build side, consent capture, purpose-tagged data stores, retention jobs and a rights-request workflow are engineering features. We treat them as part of the specification when we take on travel website development and travel portal projects, alongside the security work covered in our travel portal security checklist. Automation helps too: an AI workflow that answers rights requests from a clean data map is far cheaper than manual searches across systems. You can see how we handle data ourselves in our privacy policy, and if you are starting from zero, our guide on starting an online travel agency places data protection among the other launch tasks.

This article is general information about travel technology and online marketing. It is not legal, tax or financial advice, and advertising platform policies change often. Check the current policy documents and take professional advice for your own situation.

Advertisement

Frequently asked questions

Does the DPDP Act apply to small travel agencies?

The Act is written around processing digital personal data rather than around company size, so a small online agency handling customer data is within its world. Some obligations scale with designation, notably the extra duties of significant data fiduciaries, but the core duties of notice, lawful processing, security and grievance handling are general. Confirm your specific position with counsel.

Is the DPDP Act in force now?

The Act was enacted in 2023 and its implementing rules were notified by the government in November 2025, with obligations taking effect in phases rather than all at once. Because the calendar is set by official notification, check MeitY and the official texts for the current status rather than relying on any article, including this one.

Do we need consent for every piece of data on a booking?

Consent is a central basis under the Act, but the framework also recognises certain legitimate uses where processing can rest on other grounds. Which basis covers which processing, for example fulfilling a booking the customer asked for versus marketing to them afterwards, is a legal mapping exercise worth doing properly once, with advice.

What about the data we send to airlines and suppliers?

Sharing passenger data with airlines, consolidators and hotels is part of delivering the service, but it does not leave the Act's scope: you remain responsible as the fiduciary, and vendors processing on your instructions should be bound by appropriate contracts and security expectations. Map these flows; they are where travel data actually moves.

What happens if we have a data breach?

The framework requires personal data breaches to be notified to the Data Protection Board and affected individuals in the prescribed manner, and the Act provides for financial penalties for failures of its obligations. The operational lesson is to have detection, containment and notification procedures ready before you need them.

WhatsApp us