Every day the front desk of a small hotel records each guest's full name, date of birth, ID card or passport number, phone number and vehicle plate number. Since 1 January 2026 all of that information falls under Vietnam's Personal Data Protection Law. Owners need to know two things: what has to be done, and which obligations are waived.
This article is written for owners of mini hotels, guesthouses and homestays who cover the desk themselves or with a handful of staff. Risk at small properties rarely comes from anyone's bad intent; it comes from habits of convenience — photographing documents on a phone, posting them in a group chat for the next shift. Habits can be changed.
⚖️ Note: this article is for general information only and is compiled from the original legal texts as of the time of writing. Hotels should check the original texts or consult a legal professional about their own situation. DiCloud is an operational and compliance-support tool, not a substitute for legal advice.
Part 1: What the new law is and how it applies to a small hotel
- Personal Data Protection Law No. 91/2025/QH15, passed by the National Assembly on 26 June 2025, in force from 1 January 2026.
- Decree 356/2025/ND-CP of 31 December 2025, which details the Law, in force on the same date and replacing Decree 13/2023/ND-CP. Consent validly obtained under Decree 13/2023 before then remains valid and need not be collected again.
- Decree 330/2026/ND-CP of 19 August 2026 on administrative penalties in cybersecurity and personal data protection, in force from 19 August 2026.
In the Law's terms, the hotel is the data controller: the property decides what to collect, for what purpose and for how long. The software provider is usually the data processor and may receive data only under a contract or agreement with the property. So whoever's software the data sits in, the property remains responsible towards the guest.
On fines, Decree 330/2026 sets 30 to 50 million dong for processing data without valid consent where consent is required, and 40 to 60 million dong for reporting a violation later than 72 hours. These are the levels for organisations; household businesses are fined as individuals, which means half. The Law's maximum of up to 5% of the previous year's revenue applies only to violations involving transfers of data abroad, not to the everyday slips seen at a front desk.
Part 2: Which guest data is basic and which is sensitive
Under Decree 356/2025, the data a small hotel handles every day falls into two groups:
- Basic data: full name, date of birth, gender, nationality, place of residence; personal identification number and passport number; phone number, vehicle plate number, an image of the individual.
- Sensitive data: images of the ID card, citizen ID card or people's identity card; bank card information and account transaction history; health status; biometric data; location determined through location services.
A point many properties miss: the number printed on the card is basic data, but a photo of the card itself is sensitive data. For sensitive data the Decree requires access restricted by permissions, a defined processing procedure and security measures — which a photo on the duty phone or in a group chat can hardly meet.
📌 A five-minute test: open the phone used at the desk and count the photos of guests' ID cards in its photo library and the property's group chats. Each one is a copy of sensitive data with no permissions and no log, often still sitting on the phone of someone who has since left.
Part 3: What household businesses are exempt from — and what they are not
What is waived
- Household businesses and micro-enterprises do not have to prepare or update a personal data processing impact assessment, or appoint a department or staff member for data protection.
- Small enterprises and start-ups may choose whether to do so for 5 years from 1 January 2026.
Three situations in which the exemption is lost
The exemption does not apply to an entity that (1) provides personal data processing services as a business, (2) directly processes sensitive personal data, or (3) processes the data of 100,000 people or more, counted cumulatively. Situation (2) is close to home for a small hotel: a property in the habit of photographing and keeping guests' ID cards is holding exactly this type of sensitive data, and so risks falling outside the exemption. This is a cautious reading of the wording; no guidance addresses the case by name, so a property in that position should consult a legal professional.
What is never waived, whatever the size
Obtaining consent properly where consent is required; honouring guests' rights to view, correct and delete their data on time; applying appropriate protective measures; reporting violations within 72 hours. In short: being small spares a property some paperwork, not its obligations to guests.
Part 4: Consent and guests' rights
Is consent needed to collect ID details for stay reporting?
The safe reading: collecting ID details in order to report a guest's stay is an obligation under the Residence Law; the Personal Data Protection Law sets out cases where data may be processed without consent, including cases provided for by law (Article 19). Using phone numbers or email addresses for guest care or to send offers is a different purpose and should have its own consent. This is an interpretation, not stated by name in any text, so it should not be treated as an absolute exemption.
Where consent is needed: one consent per purpose, no pre-ticked boxes, silence is not consent, and keep evidence — in a dispute, the property has to prove it.
Guests asking to view, correct or delete — how quickly to respond
- Respond within 2 working days to any request.
- View, correct or provide data: 10 days; withdraw consent, restrict or object: 15 days; delete: 20 days (30 days if a processor or third party has to carry it out). The 10-, 15- and 20-day deadlines can each be extended by no more than 10, 15 and 20 days respectively.
Information the property must keep by law, such as guest stay records, usually does not have to be deleted; the guest should then be told why. Having no procedure or form for guests, or not responding within 2 working days, can be fined 10 to 20 million dong (the level for organisations; household businesses face half).
Part 5: Six things to do at the front desk now
- Step 1 — Stop photographing and storing documents on personal phones and in group chats. Record the necessary details in the register or system and hand the document back; once you are sure the details are recorded, delete the old photos.
- Step 2 — Decide who can see what. One account per person, no shared passwords; the person on shift does not necessarily need years of guest history.
- Step 3 — Keep records for the full period, not forever. Decree 96/2016/ND-CP (Article 44) requires information on guests and their room visitors to be kept for at least 36 months; the Law requires data not to be kept longer than its purpose needs. Check the current texts.
- Step 4 — One form and one contact person for requests to view, correct or delete, with a log of the date each request arrived so no deadline is missed.
- Step 5 — Separate purposes when asking for phone numbers and email addresses. If you want to send offers via Zalo or text, ask separately and note the answer. Keeping past guests the right way is covered in CRM for small hotels.
- Step 6 — Write the incident procedure in advance. On discovering a violation that may harm a guest's life, health, honour or property, or cause harm to national defence, security or public order, the property must notify the specialised personal data protection authority under the Ministry of Public Security within 72 hours of discovery and make a written record. The procedure should state who reports and who writes the record.
Summary of obligations for a small hotel
| Obligation | Household and micro businesses | Legal basis | What to do |
|---|---|---|---|
| Impact assessment, data protection staff | Exempt, unless processing sensitive data or data of 100,000 people | Law 91/2025, Art. 38; Decree 356/2025, Art. 41 | Do not keep document images, reducing the risk of losing the exemption |
| Consent | Still applies | Law 91/2025, Art. 9, 11, 19 | Separate purposes, no pre-ticked boxes, keep evidence |
| Rights to view, correct, delete | Still applies | Decree 356/2025, Art. 5 | A form, a contact person, respond within 2 working days |
| Protecting sensitive data | Still applies | Decree 356/2025, Art. 4 | Permissions; no ID card photos on personal phones |
| Keeping guest records | Still applies | Decree 96/2016, Art. 44 | At least 36 months; a plan for what has passed that period |
| Reporting violations | Still applies | Law 91/2025, Art. 23 | Report within 72 hours; make a record |
Part 6: What management software can help with, and what it cannot replace
Software does not discharge legal obligations, but its design decides how much risk the property carries from the outset. This is how DiCloud, a cloud AI hotel management software, helps within the scope of this article:
- ID and passport scanning stores only the extracted details, never the document image. The system holds the name, document number and date of birth — basic data — not a photo of the ID card. The property therefore has one less type of sensitive data to protect; the obligations in Part 3 remain in full. Document scanning is covered in 6 standout features of DiCloud.
- User permissions and an activity log. One account per person, the owner decides which role can see and change what, and important actions are logged with who, when and what. The underlying infrastructure and security are covered in a solid platform — security and compliance.
- Stay reporting: a file exported in the required template for the desk to submit. Guest details are already there from check-in, so DiCloud exports a file in the template the stay-reporting portal requires, for the desk to upload without retyping. Submission is still made by the person holding the property's account, because the portal requires sign-in and verification.
Software cannot replace choosing purposes, obtaining consent, the habits of the person on duty, or a data processing contract with the provider — the property should require one from any provider holding its guest data. The whole chain from booking to reporting sits within DiCloud's total hotel management solution.
Want to know where your property is keeping guest data?
Tell the DiCloud team how your property takes guests' documents, keeps its guest register and contacts guests. We will go through the six steps in this article with you and point out what can be fixed right away by internal convention and where a tool can help. The review is operational in nature and does not replace legal advice.
Get a free guest data reviewFrequently asked questions
Does a small hotel run as a household business have to comply with the Personal Data Protection Law?
Yes. A household business is exempt only from the data processing impact assessment and from appointing data protection staff; the obligations on consent, guests' rights, data protection and reporting violations within 72 hours still apply. The exemption is lost if the property directly processes sensitive data or the data of 100,000 people or more.
Is a photo of a guest's ID card sensitive data?
Under Decree 356/2025/ND-CP, images of the ID card, citizen ID card and people's identity card are sensitive data, while the personal identification number, passport number, full name and date of birth are basic data. Recording only the necessary details instead of keeping document images leaves the property one less type of sensitive data to protect.
Is guest consent needed to collect ID details for stay reporting?
Collecting ID details in order to report a guest's stay is an obligation under the Residence Law; the Personal Data Protection Law sets out cases where data may be processed without consent, including cases provided for by law (Article 19). Using phone numbers or email addresses for guest care or to send offers is a different purpose and should have its own consent. This is an interpretation, and no guidance addresses it by name.
How quickly must a hotel act when a guest asks for their data to be deleted?
Respond within 2 working days and delete within 20 days, extendable by no more than 20 days; 30 days if a processor or third party is involved. Information that must be kept by law, such as guest stay records, usually does not have to be deleted; the guest should then be told why.
How long must a hotel keep guest stay records?
Decree 96/2016/ND-CP requires accommodation businesses to keep information on guests and on people visiting guests in their rooms for at least 36 months. Properties should check the current texts.
If guest data is leaked, who must be notified and how quickly?
The specialised personal data protection authority under the Ministry of Public Security, within 72 hours of discovery, together with a written record. Reporting later than 72 hours carries a fine of 40 to 60 million dong for organisations; household businesses face half that.
Conclusion
The Personal Data Protection Law does not require a small hotel to have a legal department. It requires three things any small property can do: do not keep sensitive data you do not need — starting with document images; know who can see what, and leave a trail; and have answers ready for guests and for incidents. On that footing, an online AI hotel management software such as DiCloud carries the technical side — part of the DiHotel Solutions Corps ecosystem, which has served more than 300 accommodation properties in Vietnam and Japan over more than 20 years.
If you run a 4–5 star hotel, a resort or several properties, the companion article on the DiHotel Blog (in Vietnamese) covers that tier: personal data protection for hotels — what resorts and chains need to review. At that tier the work is handled by DiHotel, the AI hotel management software.