Home
Solutions
Packages
Technical NewsNew
Blog
About Us
VN VI US EN

Guest data protection for small hotels under Vietnam's 2026 law

Every day the front desk of a small hotel records each guest's full name, date of birth, ID card or passport number, phone number and vehicle plate number. Since 1 January 2026 all of that information falls under Vietnam's Personal Data Protection Law. Owners need to know two things: what has to be done, and which obligations are waived.

This article is written for owners of mini hotels, guesthouses and homestays who cover the desk themselves or with a handful of staff. Risk at small properties rarely comes from anyone's bad intent; it comes from habits of convenience — photographing documents on a phone, posting them in a group chat for the next shift. Habits can be changed.

⚖️ Note: this article is for general information only and is compiled from the original legal texts as of the time of writing. Hotels should check the original texts or consult a legal professional about their own situation. DiCloud is an operational and compliance-support tool, not a substitute for legal advice.

Part 1: What the new law is and how it applies to a small hotel

In the Law's terms, the hotel is the data controller: the property decides what to collect, for what purpose and for how long. The software provider is usually the data processor and may receive data only under a contract or agreement with the property. So whoever's software the data sits in, the property remains responsible towards the guest.

On fines, Decree 330/2026 sets 30 to 50 million dong for processing data without valid consent where consent is required, and 40 to 60 million dong for reporting a violation later than 72 hours. These are the levels for organisations; household businesses are fined as individuals, which means half. The Law's maximum of up to 5% of the previous year's revenue applies only to violations involving transfers of data abroad, not to the everyday slips seen at a front desk.

Part 2: Which guest data is basic and which is sensitive

Under Decree 356/2025, the data a small hotel handles every day falls into two groups:

A point many properties miss: the number printed on the card is basic data, but a photo of the card itself is sensitive data. For sensitive data the Decree requires access restricted by permissions, a defined processing procedure and security measures — which a photo on the duty phone or in a group chat can hardly meet.

📌 A five-minute test: open the phone used at the desk and count the photos of guests' ID cards in its photo library and the property's group chats. Each one is a copy of sensitive data with no permissions and no log, often still sitting on the phone of someone who has since left.

Part 3: What household businesses are exempt from — and what they are not

What is waived

Three situations in which the exemption is lost

The exemption does not apply to an entity that (1) provides personal data processing services as a business, (2) directly processes sensitive personal data, or (3) processes the data of 100,000 people or more, counted cumulatively. Situation (2) is close to home for a small hotel: a property in the habit of photographing and keeping guests' ID cards is holding exactly this type of sensitive data, and so risks falling outside the exemption. This is a cautious reading of the wording; no guidance addresses the case by name, so a property in that position should consult a legal professional.

What is never waived, whatever the size

Obtaining consent properly where consent is required; honouring guests' rights to view, correct and delete their data on time; applying appropriate protective measures; reporting violations within 72 hours. In short: being small spares a property some paperwork, not its obligations to guests.

Part 4: Consent and guests' rights

Is consent needed to collect ID details for stay reporting?

The safe reading: collecting ID details in order to report a guest's stay is an obligation under the Residence Law; the Personal Data Protection Law sets out cases where data may be processed without consent, including cases provided for by law (Article 19). Using phone numbers or email addresses for guest care or to send offers is a different purpose and should have its own consent. This is an interpretation, not stated by name in any text, so it should not be treated as an absolute exemption.

Where consent is needed: one consent per purpose, no pre-ticked boxes, silence is not consent, and keep evidence — in a dispute, the property has to prove it.

Guests asking to view, correct or delete — how quickly to respond

Information the property must keep by law, such as guest stay records, usually does not have to be deleted; the guest should then be told why. Having no procedure or form for guests, or not responding within 2 working days, can be fined 10 to 20 million dong (the level for organisations; household businesses face half).

Part 5: Six things to do at the front desk now

Summary of obligations for a small hotel

Obligation Household and micro businesses Legal basis What to do
Impact assessment, data protection staff Exempt, unless processing sensitive data or data of 100,000 people Law 91/2025, Art. 38; Decree 356/2025, Art. 41 Do not keep document images, reducing the risk of losing the exemption
Consent Still applies Law 91/2025, Art. 9, 11, 19 Separate purposes, no pre-ticked boxes, keep evidence
Rights to view, correct, delete Still applies Decree 356/2025, Art. 5 A form, a contact person, respond within 2 working days
Protecting sensitive data Still applies Decree 356/2025, Art. 4 Permissions; no ID card photos on personal phones
Keeping guest records Still applies Decree 96/2016, Art. 44 At least 36 months; a plan for what has passed that period
Reporting violations Still applies Law 91/2025, Art. 23 Report within 72 hours; make a record

Part 6: What management software can help with, and what it cannot replace

Software does not discharge legal obligations, but its design decides how much risk the property carries from the outset. This is how DiCloud, a cloud AI hotel management software, helps within the scope of this article:

Software cannot replace choosing purposes, obtaining consent, the habits of the person on duty, or a data processing contract with the provider — the property should require one from any provider holding its guest data. The whole chain from booking to reporting sits within DiCloud's total hotel management solution.

Want to know where your property is keeping guest data?

Tell the DiCloud team how your property takes guests' documents, keeps its guest register and contacts guests. We will go through the six steps in this article with you and point out what can be fixed right away by internal convention and where a tool can help. The review is operational in nature and does not replace legal advice.

Get a free guest data review

Frequently asked questions

Does a small hotel run as a household business have to comply with the Personal Data Protection Law?

Yes. A household business is exempt only from the data processing impact assessment and from appointing data protection staff; the obligations on consent, guests' rights, data protection and reporting violations within 72 hours still apply. The exemption is lost if the property directly processes sensitive data or the data of 100,000 people or more.

Is a photo of a guest's ID card sensitive data?

Under Decree 356/2025/ND-CP, images of the ID card, citizen ID card and people's identity card are sensitive data, while the personal identification number, passport number, full name and date of birth are basic data. Recording only the necessary details instead of keeping document images leaves the property one less type of sensitive data to protect.

Is guest consent needed to collect ID details for stay reporting?

Collecting ID details in order to report a guest's stay is an obligation under the Residence Law; the Personal Data Protection Law sets out cases where data may be processed without consent, including cases provided for by law (Article 19). Using phone numbers or email addresses for guest care or to send offers is a different purpose and should have its own consent. This is an interpretation, and no guidance addresses it by name.

How quickly must a hotel act when a guest asks for their data to be deleted?

Respond within 2 working days and delete within 20 days, extendable by no more than 20 days; 30 days if a processor or third party is involved. Information that must be kept by law, such as guest stay records, usually does not have to be deleted; the guest should then be told why.

How long must a hotel keep guest stay records?

Decree 96/2016/ND-CP requires accommodation businesses to keep information on guests and on people visiting guests in their rooms for at least 36 months. Properties should check the current texts.

If guest data is leaked, who must be notified and how quickly?

The specialised personal data protection authority under the Ministry of Public Security, within 72 hours of discovery, together with a written record. Reporting later than 72 hours carries a fine of 40 to 60 million dong for organisations; household businesses face half that.

Conclusion

The Personal Data Protection Law does not require a small hotel to have a legal department. It requires three things any small property can do: do not keep sensitive data you do not need — starting with document images; know who can see what, and leave a trail; and have answers ready for guests and for incidents. On that footing, an online AI hotel management software such as DiCloud carries the technical side — part of the DiHotel Solutions Corps ecosystem, which has served more than 300 accommodation properties in Vietnam and Japan over more than 20 years.

If you run a 4–5 star hotel, a resort or several properties, the companion article on the DiHotel Blog (in Vietnamese) covers that tier: personal data protection for hotels — what resorts and chains need to review. At that tier the work is handled by DiHotel, the AI hotel management software.

Related topics:
cloud AI hotel management software · online AI hotel management software · total hotel management solution · AI hotel management software · CRM for hotels