A guest sends an ID photo to speed up check-in. The receptionist downloads it, forwards it to the owner and uploads it to a booking folder. One lawful business purpose has now produced several uncontrolled copies.

This article is practical information, not legal advice. POPIA compliance depends on your processing, systems and contracts.

Map the guest's data journey

List what you collect from enquiry to deletion: name, contact details, dates, ID/passport data, payment information, dietary or accessibility requests, CCTV, Wi-Fi logs and marketing preferences. Record why each item is needed, who sees it, where it is stored and when it is removed.

Collect the minimum for a clear purpose

Booking communication, legal guest-register duties, payment records and optional marketing are different purposes. Do not bundle them into “we need everything to manage the booking.” A guest should not have to accept promotional WhatsApp messages merely to check in.

Move records off personal phones

Use a controlled business process for receiving sensitive documents. Restrict access by role, enable strong authentication and remove unnecessary downloads. When staff leave, business records should not leave with them.

Keep a retention schedule, not a vague promise

Reconcile legal and accounting retention duties with POPIA's requirement not to keep information longer than necessary. For example, safeguard the prescribed lodging register for its required period while deleting duplicate ID images from WhatsApp and email once the controlled record is complete.

Plan for the lost phone before it happens

Your incident process should identify affected systems and people, contain access, preserve evidence, assess notification duties and record decisions. The Information Regulator publishes guidance on security compromises; use the current process rather than an old template.

Make privacy visible to guests

A practical privacy notice explains what is collected, why, recipients, retention, rights and how to contact the Information Officer. Staff must follow the same story at reception.

Primary references: Protection of Personal Information Act and the Information Regulator.

Five controls a small property can implement now

  1. Use named staff accounts instead of a shared password.
  2. Remove guest ID downloads from personal devices after controlled capture.
  3. Review access when roles change or employment ends.
  4. Separate booking communication from marketing consent.
  5. Test the incident contact list twice a year.

Ask every supplier where the data goes

Booking, payment, email, cloud storage and messaging providers may process guest information. Record the provider, purpose, location, security commitments and contract. “It is in the cloud” is not a data map.