Thailand PDPA Toolkit for Hotels and Hospitality
A ten-step guide for Thai hotels and groups, from passport scanning at check-in and TM30 reporting to audit-ready cross-border compliance.
Written for hotel DPOs, general managers, front office, reservations, IT and group compliance leads, with templates and checklists for every step.
Every check-in desk runs a hospitality business and a document-processing operation.
Immigration law requires a passport record for every foreign guest, while the PDPA requires the hotel to collect no more than it needs, secure it and prove both. Getting the balance wrong either way is a live risk.
Add OTA bookings, loyalty programmes, payment systems, CCTV and self-check-in kiosks, and a hotel's data estate is wider than almost any other business. This guide covers each touchpoint in order.
What's inside the 32-page toolkit?
Touchpoint inventory
Map every guest and staff data touchpoint with an illustrative entry.
Governance roles
DPO appointment and group-wide roles and responsibilities.
Passport scanning and TM30
Check-in ID handling and 24-hour immigration reporting without over-collecting.
Consent and transfers
Guest consent checklist and cross-border transfer controls.
Guest rights and security
Rights workflow plus a technical and physical security checklist.
Vendors and annual calendar
OTA and channel manager due diligence and an annual compliance calendar.
Who is this toolkit for?
- Hotel DPOs
- General managers
- Front office managers
- Reservations and IT teams
- Group compliance leads
Frequently asked questions
- Does the PDPA apply if most guests are foreign tourists?
- Yes. It applies to personal data of individuals in Thailand, including foreign guests staying at the property.
- How does TM30 interact with the PDPA?
- Hotels must report foreign guests' residence within 24 hours, so passport data must be collected — but only what is required, stored securely and retained on a defined clock.
- Which steps should we prioritise?
- Steps 3 and 4 — passport handling at check-in and TM30 reporting — because the highest-risk data moves through them every day.
- Does it cover OTAs and channel managers?
- Yes. Step 9 covers due diligence for OTAs, channel managers and other hospitality vendors.
- Is it suitable for hotel groups?
- Yes. It covers group-wide governance, cross-border transfers and loyalty programmes spanning several countries.
Get the Toolkit
Complete the download form to receive the Thailand PDPA Toolkit for Hotels.