Help
Frequently Asked Questions
Last updated: 23 July 2026
OurGate operates internationally, so guest ID collection and data-protection obligations differ by where your property is located. The section below on the UK comes first, followed by India, each covered in depth because both create a specific tension between hospitality record-retention rules and data-privacy rules that OurGate was built to resolve. The same kind of tension exists in the USA and the UAE, each with its own hospitality registration duty and its own data-protection law, so hosts operating in those countries have their own dedicated sections further down covering exactly what applies. Hosts operating in the EU have a shorter section after that, since EU hospitality registration rules vary by member state.
How OurGate protects guest ID documents
Whichever country your property is in, every guest document on OurGate is handled the same secure way:
- Explicit consent: Guests review and accept clear terms before any document upload — no ID is collected without an affirmative action.
- Purpose limitation: ID documents are collected only to verify a specific booking and are never used for marketing or shared with third parties.
- Encrypted, access-controlled storage: Documents are stored in a private, access-controlled bucket and served only via short-lived, single-use links to authorized hosts.
- Right to deletion: Guests can request their uploaded documents be deleted at any time, in line with GDPR, CCPA, and DPDP data-subject rights.
- Watermarked, traceable viewing: Every ID a manager opens is overlaid with a live watermark of their name, company, and timestamp — deterrence and traceability against casual sharing.
- Time-boxed document access: A guest's ID stays viewable while their stay is active. After that, reopening it requires an explicit, time-limited approval — not indefinite standing access.
- Logged document access: Every time an ID document is viewed, it's logged — who, when, from where — giving an independent record of access for oversight.
- Direct-to-vault upload: Guest ID photos go straight from their phone to encrypted storage — the raw file never passes through or sits on a host's own systems.
Why this matters, legally
Mishandling guest ID documents carries real regulatory weight almost everywhere you operate, not just reputational risk. Under the EU/UK GDPR, fines for failing to secure personal data can reach €20 million or 4% of global annual revenue, whichever is higher. California's CCPA allows penalties per violation, and India's Digital Personal Data Protection Act, 2023 sets penalties up to ₹250 crorefor failing to take “reasonable security safeguards.” The UK and UAE carry their own real penalty regimes too — see the country-specific sections below. Every one of these frameworks applies to any business handling personal data — hotels and homestays included — which is exactly why the guest ID documents collected at check-in need to be treated with this level of care, wherever your property is.
Why does a UK hotel or guest house need to record my name and nationality?
It's a standing legal requirement, not a UK-specific OurGate preference. Under the Immigration (Hotel Records) Order 1972 (made under the Immigration Act 1971), every hotel, guest house, and similar establishment must keep a written record of the full name and nationality of every guest aged 16 or over. For guests who aren't British, Irish, or Commonwealth citizens, the property must additionally record the guest's passport number and place of issue, and their next destination after departure. The record must be kept for at least 12 months and be available for inspection by police or an authorised officer on request.
Doesn't UK GDPR say the opposite — collect and keep as little as possible?
Yes, and the same reconciliation applies here as it does in India. UK GDPR (retained EU GDPR as it applies domestically, enforced by the Information Commissioner's Office under the Data Protection Act 2018) requires data minimisation and gives guests a right to erasure. Read alone, that looks like it conflicts with a duty to keep a 12-month guest register. It doesn't, in practice: UK GDPR's right to erasure does not apply where processing (including continued retention) is necessary for compliance with a legal obligation the controller is subject to — which is exactly the situation the Hotel Records Order creates. OurGate is built to satisfy both at once, not to pick one over the other.
How does OurGate resolve the conflict, for a UK property?
By splitting the roles, using the same terms UK GDPR itself uses. As the party legally obligated under the Hotel Records Order to collect and be able to produce guest identity information, you (the Host) are the data controller. OurGate acts as your data processor: we hold the document securely on your behalf, restrict standing access, log every view, and retain it for the minimum 12-month period the Order requires (or longer only if another UK legal obligation genuinely requires it), and nothing longer by default. You remain fully compliant because the record still exists and can still be produced to police on request; you just don't hold an unrestricted copy sitting in your own systems indefinitely.
What happens if a UK property doesn't comply?
Both sides carry real, separately enforceable penalties.
Penalties for not keeping/producing the hotel guest record (Immigration (Hotel Records) Order 1972)
Failing to keep the required record, or failing to produce it when a police officer or authorised person demands it, is a criminal offence. On conviction, the keeper of the premises can face a fine and up to six months' imprisonment. This is enforced independently of any data-protection question — it's a police-facing obligation, not a privacy one.
Official reference: The Immigration (Hotel Records) Order 1972 (legislation.gov.uk).
Penalties for mishandling guest data (UK GDPR / Data Protection Act 2018)
The Information Commissioner's Office (ICO) can fine a controller or processor up to £17.5 million or 4% of worldwide annual turnover, whichever is higher, for the most serious infringements (such as processing without a lawful basis, ignoring core data-subject rights, or a breach caused by inadequate security). A lower tier of up to £8.7 million or 2% of worldwide turnover applies to other compliance failings. In practice the ICO weighs severity, intent, and mitigation rather than defaulting to the maximum, but the ceiling itself is real and has increased over time, most recently in February 2026 when related PECR fine caps were raised to match these UK GDPR levels.
Official reference: ICO Data Protection Fining Guidance.
Can a UK property face both at once?
Why does a hotel even need to collect my ID?
It's a legal requirement, not a hotel preference. Indian police acts and state tourism regulations require every hotel/homestay to record a Guest Registration Card with an identity document for each guest, and to be able to produce that record to police or state authorities on request. Failing to keep or produce these records can expose the property to penalties under the Bharatiya Nyaya Sanhita (BNS), Sections 206 and 210 (omission to produce a document or give information to a public servant when legally bound to do so). For foreign nationals, the property must additionally file a C-Form with the local FRRO/police within 24 hours of arrival, under the Foreigners Act.
Doesn't India also have a data privacy law that says the opposite?
Yes. The Digital Personal Data Protection Act, 2023 (DPDPA) gives you rights over your personal data, including the right to request its erasure, and requires anyone holding your data to collect and retain only what's necessary. Read on its own, that looks like it conflicts with a police-act rule that says "retain guest ID records." It doesn't, in practice: the DPDPA itself recognizes that data held to meet another legal obligation is exempt from on-demand erasure until that obligation is satisfied (Section 8 and the Act's exemptions for compliance with law). OurGate is built to satisfy both laws at the same time, not to pick one over the other.
How does OurGate resolve the conflict?
By splitting the roles. Under the DPDPA, the hotel is the Data Fiduciary (the party legally obligated to collect your ID and able to answer to police or regulators for it). OurGate acts as the Data Processorand custodian: we hold the document securely on the hotel's behalf, for exactly as long as applicable Indian hospitality and police regulations require, and nothing longer. The hotel remains fully compliant with its retention duty because the record still exists and can still be produced, they just don't hold an unrestricted copy sitting in their own systems indefinitely.
For Guests
What information do you collect from me?
Who can see my document?
How long do you keep my document?
Can I get my document deleted?
- We log your request immediately, with a timestamp.
- We carry out due diligence, checking with the hotel you stayed at and, where relevant, confirming there is no active legal, police, or regulatory requirement still requiring your record to be retained.
- Once that check is complete, we delete your document and personal data from our systems and confirm to you, in writing, once it's done.
- If a legal retention requirement is still active, we'll tell you that plainly, along with why, rather than deleting your data while a hotel or authority may still be legally entitled to it.
Is this optional, or do I have to upload my ID?
For Hotels & Property Owners
Why can't my staff access guest documents whenever they want, like before?
If OurGate holds the data, am I still meeting my police/state retention obligation?
What if police or a court asks us for a guest's document after checkout?
What's OurGate's role vs. ours, in one line?
What happens if a hotel doesn't comply
These aren't abstract rules. Both sides carry real, separately enforceable penalties, and a hotel can be exposed on both at once if guest records aren't handled correctly.
Penalties for not maintaining/producing guest records (police & state regulations)
Under the Bharatiya Nyaya Sanhita (BNS), Sections 206 and 210 (the successors to IPC Section 176), a property that omits to keep or produce guest records when legally bound to furnish them to a public servant (such as police during a verification drive or investigation) can face criminal liability, including fine and/or imprisonment. Separately, state police acts and lodging-house/tourism regulations carry their own administrative penalties, which can include fines, suspension of the property's registration or licence, and, in states where hotel operation requires police/tourism department clearance, non-renewal of that clearance. For foreign guests specifically, failing to file the C-Form within 24 hours under the Foreigners Act, 1946 (and the 2016 amendment to the Foreigners Order) can independently expose the property to imprisonment of up to five years and a fine under Section 14 of that Act, on top of any state-level penalty.
Official references: MHA Foreigners Division, Bureau of Immigration (C-Form/e-FRRO).
Has this actually been enforced against a hotel before?
Yes. In Vijukumar v. State of Kerala, the Kerala High Court examined police invoking the Foreigners Act against a lodging-house keeper for failing to comply with guest-registration requirements, confirming that non-compliance with these registration obligations is a live, prosecutable offence, not just a paperwork formality. Separately, the pre-independence Sarai Act, 1867, still in force in several states, is regularly cited by police to demand guest-register production, and licence suspensions over missing or incomplete guest records are a routine, ongoing enforcement reality for Indian hotels, independent of any DPDPA question.
Penalties for mishandling guest data (DPDPA)
Under the Digital Personal Data Protection Act, 2023, a Data Fiduciary that fails to implement reasonable security safeguards, or otherwise breaches its obligations under the Act, can be penalised up to ₹250 crore per instance under the Schedule referenced in Section 33 (the highest tier in the Act, reserved for failures like a data breach caused by inadequate security). Smaller penalties apply to other lapses, such as failing to notify the Data Protection Board of a breach or failing to fulfil a data principal's request (like an erasure request) without lawful justification. These penalties apply to the Data Fiduciary; in a direct guest-ID-collection setup, that's the hotel itself, not a vendor storing the data on their behalf.
Official reference: DPDP Act, 2023 (PDF, meity.gov.in), Section 33 and Schedule.
Can a hotel actually face both at once?
Is the DPDPA side just a theoretical risk right now?
The legal basis, precisely
For anyone who needs the exact citations rather than the plain-language summary above:
- Retention obligation: State police acts, state tourism/lodging-house regulations, and, for foreign nationals, the Foreigners Act, 1946 (C-Form filing within 24 hours of arrival). Non-production of required records to a public servant can attract liability under Bharatiya Nyaya Sanhita (BNS) Sections 206 and 210 (successors to IPC Section 176).
- Data protection obligation: Digital Personal Data Protection Act, 2023, including the data principal's right to erasure, the data fiduciary's duty of purpose limitation and storage limitation, and the Act's recognition that retention required to comply with another law is not subject to on-demand erasure until that obligation lapses. Read the official Act (PDF, meity.gov.in).
- How OurGate reconciles the two: by acting as Data Processor/custodian on the hotel's behalf, restricting standing access to the retention window required by law, and actioning deletion requests once no active legal retention requirement remains, as described above and in our Privacy Policy and Terms & Conditions.
What applies if my property is in the EU?
The GDPR governs how you and OurGate handle guest personal data. As the party that collects the guest's booking and identity information, you (the Host) are typically the data controller, and OurGate acts as a data processor on your behalf, handling storage, access control, and retention of the identity document. Guests have the right to access, correct, port, restrict, or request erasure of their data, and to object to processing based on legitimate interests — see our Privacy Policy for the full list. Hospitality guest-registration rules also vary by EU member state (for example, many countries still require a signed arrival form and, for some, an ID or passport copy for non-nationals), so there is no single EU-wide citation here the way there is for India, the UK, or the UAE — check your local tourism/police registration requirement for exactly how long guest records must be kept in your country, and treat that as the retention floor OurGate should honour for your property.
Why does a US hotel or B&B need to keep a guest register?
There's no single federal law requiring it — hotel guest-registration duties in the US come from state law, and requirements vary by state. Real examples: New York General Business Law, Article 12, requires the owner, lessee, proprietor, or manager of any hotel, motel, boarding house, or lodging house to keep a register of guests. California similarly requires hotel operators to keep a register available for inspection by peace officers on request, and restricts disclosure of those records to guests' own requests, a subpoena/warrant/court order, or a California peace officer. Many other states carry comparable innkeeper/lodging-house statutes, often dating back a century or more; check your own state's hotel or transient lodging statute for the specifics that apply to your property.
What data-protection law applies, and does it conflict with the state registration duty?
It depends on your state, and this is the fastest-changing area of US privacy law. If you operate in California, the CCPA (as amended by the CPRA) gives California-resident guests the right to know what personal information is collected about them, request deletion, request correction, and opt out of the sale or sharing of their personal information. OurGate does not sell or share guest personal information, so no "Do Not Sell/Share" mechanism is required on our end. As of 2026, over twenty other states have passed their own comprehensive privacy laws with similar rights — including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and more recently Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, and others — so if your property is outside California, check whether your state has one of these laws, since it likely grants your guests a similar deletion/correction right. As with India, DPDPA, and the UK, deletion rights under these laws are generally understood not to override a genuine state-law obligation to retain a guest record, but the exact language and case law varies by state, so treat this as the general pattern rather than a guarantee for every state.
How does OurGate resolve this, for a US property?
The same way as elsewhere. You (the Host) collect the guest's identity information because your state's hotel/lodging statute requires it, and you remain the "business" (CCPA/CPRA terminology) or "controller" (the term most other state laws use) responsible for that data. OurGate acts as your service provider under CCPA/CPRA (or processorunder most other state laws): we hold the document securely, restrict and log access, retain it only for the period your state's statute requires, and action a guest's deletion request once no active state-law retention requirement remains.
What happens if a US property doesn't comply?
Penalties differ sharply between the hospitality-registration side and the privacy-law side, and by state.
Penalties under state hotel/lodging-register statutes
Penalties under CCPA/CPRA (California)
As of 2026, the California Privacy Protection Agency (CPPA), which now holds primary administrative enforcement authority alongside the California Attorney General, can impose penalties of up to $2,663 per unintentional violation and up to $7,988 per intentional violation (the statutory $2,500/$7,500 base figures, adjusted for inflation), assessed per affected consumer — so a single incident touching many guests' records can scale quickly. The largest CCPA settlement to date is a $12.75 million enforcement action against General Motors, announced in 2026.
Official references: California AG — CCPA, California Privacy Protection Agency (CPPA).
Penalties under other state privacy laws
Why does a UAE hotel or holiday home need to register my ID?
It's a strict, security-linked legal requirement, not a UAE-specific OurGate preference, and it's tied directly to police and immigration reporting rather than just hospitality record-keeping. The exact mechanism differs by emirate. In Dubai, every guest checking into a hotel or a Department of Economy and Tourism (DET, formerly DTCM)-licensed holiday home must be registered, with passport or Emirates ID details submitted through the DET-approved electronic platform, which is linked to Dubai Police and Federal Authority for Identity, Citizenship, Customs and Port Security (ICP) systems, typically within hours of check-in. Abu Dhabi and other emirates run comparable guest-registration requirements through their own tourism and police authorities, with their own portals and timelines, so a multi-emirate operator should confirm the specific requirement for each property's emirate rather than assuming Dubai's process applies everywhere.
Doesn't UAE data protection law say the opposite?
Yes, in the same shape as elsewhere. Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the PDPL), in force since January 2022 and detailed further by Cabinet Decision No. 33 of 2024 (its executive regulation), gives individuals rights including access, correction, erasure, restriction, portability, and objection to processing, and requires controllers to collect and retain only what's necessary. Read alone, that looks like it conflicts with a police-linked duty to register and retain guest identity data. It doesn't, in practice: the PDPL's right to erasure does not apply where a legal obligation (such as a guest-registration or security-reporting requirement) requires the data to be kept, and the Act separately recognises exceptions for judicial, security, and public interest purposes. OurGate is built to satisfy both at once.
How does OurGate resolve this, for a UAE property?
By splitting the roles, using the PDPL's own terms. As the party legally obligated to register guests with the relevant emirate's tourism and police authority, you (the Host) are the Controller. OurGate acts as your Processor: we hold the identity document securely on your behalf, restrict standing access, log every view, and retain it for the period your emirate's registration requirement (and any related PDPL retention basis) requires, and nothing longer by default. You remain fully compliant because the record still exists and can still be produced or re-submitted through the relevant portal; you just don't hold an unrestricted copy in your own systems indefinitely.
What happens if a UAE property doesn't comply?
Both sides carry real, separately enforceable penalties.
Penalties for not registering guests (police/tourism authority requirements)
Penalties for mishandling guest data (PDPL)
Under the PDPL and its 2024 executive regulation, administrative fines for violations can range from AED 50,000 up to AED 5 million per violation, with the amount depending on the nature and severity of the breach (for example, processing without a lawful basis or a security-related breach sits at the higher end) and whether it's a repeat violation. The UAE Data Office is the federal regulator responsible for enforcement. As with India's DPDPA, these are the ceiling figures set out in the framework, and the Data Office has discretion in how a given case is penalised.
Official reference: UAE Government Portal — Data Protection Laws.
Can a UAE property face both at once?
Still have a question?
Contact us at urbanescape09@gmail.com or by phone at 9958780399. For formal data access, correction, deletion, or grievance requests under the GDPR (EU or UK), CCPA/CPRA or another US state privacy law, the UAE PDPL, or India's DPDPA, the same contact reaches our Data Protection Contact (and, for Indian users, our Grievance Officer under the DPDPA and applicable IT Rules).