Thailand PDPA Toolkit for Hotels and Hospitality

A ten-step guide for Thai hotels and groups, from passport scanning at check-in and TM30 reporting to audit-ready cross-border compliance.

Written for hotel DPOs, general managers, front office, reservations, IT and group compliance leads, with templates and checklists for every step.

Get the Toolkit

Every check-in desk runs a hospitality business and a document-processing operation.

Immigration law requires a passport record for every foreign guest, while the PDPA requires the hotel to collect no more than it needs, secure it and prove both. Getting the balance wrong either way is a live risk.

Add OTA bookings, loyalty programmes, payment systems, CCTV and self-check-in kiosks, and a hotel's data estate is wider than almost any other business. This guide covers each touchpoint in order.

What's inside the 32-page toolkit?

  • Touchpoint inventory

    Map every guest and staff data touchpoint with an illustrative entry.

  • Governance roles

    DPO appointment and group-wide roles and responsibilities.

  • Passport scanning and TM30

    Check-in ID handling and 24-hour immigration reporting without over-collecting.

  • Consent and transfers

    Guest consent checklist and cross-border transfer controls.

  • Guest rights and security

    Rights workflow plus a technical and physical security checklist.

  • Vendors and annual calendar

    OTA and channel manager due diligence and an annual compliance calendar.

Who is this toolkit for?

  • Hotel DPOs
  • General managers
  • Front office managers
  • Reservations and IT teams
  • Group compliance leads

Frequently asked questions

Does the PDPA apply if most guests are foreign tourists?
Yes. It applies to personal data of individuals in Thailand, including foreign guests staying at the property.
How does TM30 interact with the PDPA?
Hotels must report foreign guests' residence within 24 hours, so passport data must be collected — but only what is required, stored securely and retained on a defined clock.
Which steps should we prioritise?
Steps 3 and 4 — passport handling at check-in and TM30 reporting — because the highest-risk data moves through them every day.
Does it cover OTAs and channel managers?
Yes. Step 9 covers due diligence for OTAs, channel managers and other hospitality vendors.
Is it suitable for hotel groups?
Yes. It covers group-wide governance, cross-border transfers and loyalty programmes spanning several countries.

Get the Toolkit

Complete the download form to receive the Thailand PDPA Toolkit for Hotels.