Overview
OYO operates across 800+ cities through a franchise model β OYO branded hotels are independently owned and operated. When a guest books, their personal data (ID documents, phone number, stay details) flows to both OYOβs platform and the independent hotel operator. This creates thousands of uncontrolled data access points.
DPDP Readiness: Section-by-Section Analysis
Section 6 β Consent & Notice π΄
OYO guests provide:
- Government ID documents (Aadhaar, PAN, passport) β scanned and stored
- Phone numbers shared with hotel owners
- Stay patterns (frequency, locations, solo vs. couple bookings)
- Payment information
Unique concern: In India, OYO bookings have social stigma implications. βCouple bookingsβ and βlocal IDβ policies create data that reveals sensitive personal situations. This data should have enhanced privacy protections.
Section 9 β Data Retention π΄
No retention timelines for:
- ID document scans (Aadhaar numbers stored on hotel ownersβ phones)
- Stay history across 800+ cities
- Co-guest information
- Booking modification patterns (room upgrades, late checkouts)
Section 11 β Rights of Data Principal π΄
- Can guests request deletion from both OYO and the hotel operator?
- ID scans on hotel ownersβ devices β uncontrollable
- No data portability for stay history
- No nomination rights
Risk Assessment
| Category | Risk Level | Potential Impact |
|---|---|---|
| ID document handling | Critical | Aadhaar scans on thousands of hotel operatorsβ devices |
| Franchise data governance | Critical | Independent operators = uncontrolled data access |
| Stay pattern inference | High | Booking patterns reveal lifestyle and relationships |
| Data retention | High | ID documents with no defined lifecycle |
Recommendations
- Implement centralized ID verification β Hotels verify through OYOβs platform; never retain raw ID scans
- Establish franchise data agreements β All hotel partners must sign data handling commitments
- Mask guest phone numbers β Route communications through OYO platform
- Define stay data retention β βActive booking: until checkout + 24 hours; ID verification: system-verified, raw scans deleted; stay history: 1 yearβ
- Add enhanced privacy for sensitive bookings β Option to minimize data shared with hotel operators for privacy-sensitive stays
How Does Your Policy Compare?
π Run Your Free DPDP Audit β
Analysis conducted by DPDP Consulting, a Meridian Bridge Strategy initiative. For a comprehensive compliance roadmap, book a free consultation.