Help
Frequently Asked Questions
Last updated: 23 July 2026
OurGate exists because two Indian laws pull hotels in different directions at once. This page explains, in plain language, what that means and how OurGate resolves it, for guests, for property owners, and precisely enough for anyone checking our legal position.
Why does a hotel even need to collect my ID?
It's a legal requirement, not a hotel preference. Indian police acts and state tourism regulations require every hotel/homestay to record a Guest Registration Card with an identity document for each guest, and to be able to produce that record to police or state authorities on request. Failing to keep or produce these records can expose the property to penalties under the Bharatiya Nyaya Sanhita (BNS), Sections 206 and 210 (omission to produce a document or give information to a public servant when legally bound to do so). For foreign nationals, the property must additionally file a C-Form with the local FRRO/police within 24 hours of arrival, under the Foreigners Act.
Doesn't India also have a data privacy law that says the opposite?
Yes. The Digital Personal Data Protection Act, 2023 (DPDPA) gives you rights over your personal data, including the right to request its erasure, and requires anyone holding your data to collect and retain only what's necessary. Read on its own, that looks like it conflicts with a police-act rule that says "retain guest ID records." It doesn't, in practice: the DPDPA itself recognizes that data held to meet another legal obligation is exempt from on-demand erasure until that obligation is satisfied (Section 8 and the Act's exemptions for compliance with law). OurGate is built to satisfy both laws at the same time, not to pick one over the other.
How does OurGate resolve the conflict?
By splitting the roles. Under the DPDPA, the hotel is the Data Fiduciary (the party legally obligated to collect your ID and able to answer to police or regulators for it). OurGate acts as the Data Processorand custodian: we hold the document securely on the hotel's behalf, for exactly as long as applicable Indian hospitality and police regulations require, and nothing longer. The hotel remains fully compliant with its retention duty because the record still exists and can still be produced, they just don't hold an unrestricted copy sitting in their own systems indefinitely.
For Guests
What information do you collect from me?
Who can see my document?
How long do you keep my document?
Can I get my document deleted?
- We log your request immediately, with a timestamp.
- We carry out due diligence, checking with the hotel you stayed at and, where relevant, confirming there is no active legal, police, or regulatory requirement still requiring your record to be retained.
- Once that check is complete, we delete your document and personal data from our systems and confirm to you, in writing, once it's done.
- If a legal retention requirement is still active, we'll tell you that plainly, along with why, rather than deleting your data while a hotel or authority may still be legally entitled to it.
Is this optional, or do I have to upload my ID?
For Hotels & Property Owners
Why can't my staff access guest documents whenever they want, like before?
If OurGate holds the data, am I still meeting my police/state retention obligation?
What if police or a court asks us for a guest's document after checkout?
What's OurGate's role vs. ours, in one line?
What happens if a hotel doesn't comply
These aren't abstract rules. Both sides carry real, separately enforceable penalties, and a hotel can be exposed on both at once if guest records aren't handled correctly.
Penalties for not maintaining/producing guest records (police & state regulations)
Under the Bharatiya Nyaya Sanhita (BNS), Sections 206 and 210 (the successors to IPC Section 176), a property that omits to keep or produce guest records when legally bound to furnish them to a public servant (such as police during a verification drive or investigation) can face criminal liability, including fine and/or imprisonment. Separately, state police acts and lodging-house/tourism regulations carry their own administrative penalties, which can include fines, suspension of the property's registration or licence, and, in states where hotel operation requires police/tourism department clearance, non-renewal of that clearance. For foreign guests specifically, failing to file the C-Form within 24 hours under the Foreigners Act, 1946 (and the 2016 amendment to the Foreigners Order) can independently expose the property to imprisonment of up to five years and a fine under Section 14 of that Act, on top of any state-level penalty.
Official references: MHA Foreigners Division, Bureau of Immigration (C-Form/e-FRRO).
Has this actually been enforced against a hotel before?
Yes. In Vijukumar v. State of Kerala, the Kerala High Court examined police invoking the Foreigners Act against a lodging-house keeper for failing to comply with guest-registration requirements, confirming that non-compliance with these registration obligations is a live, prosecutable offence, not just a paperwork formality. Separately, the pre-independence Sarai Act, 1867, still in force in several states, is regularly cited by police to demand guest-register production, and licence suspensions over missing or incomplete guest records are a routine, ongoing enforcement reality for Indian hotels, independent of any DPDPA question.
Penalties for mishandling guest data (DPDPA)
Under the Digital Personal Data Protection Act, 2023, a Data Fiduciary that fails to implement reasonable security safeguards, or otherwise breaches its obligations under the Act, can be penalised up to ₹250 crore per instance under the Schedule referenced in Section 33 (the highest tier in the Act, reserved for failures like a data breach caused by inadequate security). Smaller penalties apply to other lapses, such as failing to notify the Data Protection Board of a breach or failing to fulfil a data principal's request (like an erasure request) without lawful justification. These penalties apply to the Data Fiduciary; in a direct guest-ID-collection setup, that's the hotel itself, not a vendor storing the data on their behalf.
Official reference: DPDP Act, 2023 (PDF, meity.gov.in), Section 33 and Schedule.
Can a hotel actually face both at once?
Is the DPDPA side just a theoretical risk right now?
The legal basis, precisely
For anyone who needs the exact citations rather than the plain-language summary above:
- Retention obligation: State police acts, state tourism/lodging-house regulations, and, for foreign nationals, the Foreigners Act, 1946 (C-Form filing within 24 hours of arrival). Non-production of required records to a public servant can attract liability under Bharatiya Nyaya Sanhita (BNS) Sections 206 and 210 (successors to IPC Section 176).
- Data protection obligation: Digital Personal Data Protection Act, 2023, including the data principal's right to erasure, the data fiduciary's duty of purpose limitation and storage limitation, and the Act's recognition that retention required to comply with another law is not subject to on-demand erasure until that obligation lapses. Read the official Act (PDF, meity.gov.in).
- How OurGate reconciles the two: by acting as Data Processor/custodian on the hotel's behalf, restricting standing access to the retention window required by law, and actioning deletion requests once no active legal retention requirement remains, as described above and in our Privacy Policy and Terms & Conditions.
Still have a question?
Contact us at urbanescape09@gmail.com or by phone at 9958780399. For formal data access, deletion, or grievance requests, the same contact also reaches our Grievance Officer under the DPDPA and applicable IT Rules.