Passport scans on WhatsApp: what the DPDP Act requires of you
Passport and visa scans sitting in WhatsApp and Gmail make your agency a Data Fiduciary under the DPDP Act. Here is what that actually requires.
Reykjavík · 23:10Every enquiry that turns into a booking leaves you holding someone's passport scan, visa copy, PAN card, sometimes a minor's birth certificate for a school group. Under India's DPDP Act (the Digital Personal Data Protection Act), that makes you a Data Fiduciary: the entity legally responsible for how that data is collected, stored, and protected. Not a bank. Not a hospital. Your six-person agency in a Tier-2 city, with the passport scan sitting in a WhatsApp chat, a Gmail thread, or a shared Drive folder your ops team has had access to since 2021.
This isn't hypothetical. The Digital Personal Data Protection Rules, 2025 (the operating manual for the 2023 Act) were notified in November 2025, starting a countdown clock. Corporate clients are starting to ask agencies to sign data-protection clauses before they'll route staff travel bookings to them. Foreign DMCs are adding the same clauses to contracts. Nobody explained what any of this means at the scale of an agency running on WhatsApp Business and a shared Gmail login.
This post is that explanation. Not the legal filing you'd send a corporate client's compliance team. This is the version you can act on this month: what to change on your booking form, where your scans currently live, how long you can keep them, and what the penalties really mean for a business your size.
You're a Data Fiduciary whether you registered as one or not
The DPDP Act doesn't have a size threshold that exempts small businesses from its core duties. If you collect a client's phone number, passport number, or ID proof digitally (even just to type it into an airline booking portal), you're processing "personal data," and the Act's obligations around consent, notice, security, and breach reporting apply to you the same way they apply to an airline or an OTA. There is no revenue-based carve-out for these core duties.
That surprises most operators, because every other compliance regime they know has a small-business exemption. GST has its ₹20 lakh threshold, labour law has headcount thresholds. The DPDP Act's security and consent obligations don't work that way: they attach to the act of processing digital personal data, not to turnover.
What does scale with size is enforcement risk and the sophistication expected of your safeguards. A five-person agency isn't going to be held to the same audit standard as a 500-person BPO. But "we're too small to matter" is not a defence that exists in the text of the law. It sits alongside the licence question every new agency asks as compliance that doesn't scale down with headcount, and it's exactly what a corporate client's legal team will ask about before signing you as a vendor.
The compliance clock: what's already live and what's coming
The Rules roll out in phases. As of July 2026, roughly eight months have passed since notification, which matters for knowing what's already binding versus what you still have runway on.
| Milestone | Timing from November 2025 notification | What it means for you |
|---|---|---|
| Data Protection Board provisions | Effective immediately | The complaints/enforcement body exists now. Breach complaints can be filed today |
| Consent manager registration | 12 months (roughly November 2026) | Framework for third-party consent platforms goes live; doesn't force you to use one |
| Full compliance with core obligations | 18 months (by May 2027) | Consent notices, security safeguards, breach reporting become fully enforceable |
Source: India Briefing's DPDP compliance timeline.
The arithmetic that matters right now: you have roughly ten months from July 2026 until the full-compliance deadline, not eighteen. That's not much runway if your booking form asks for nothing more than "name and mobile number" and your passport-scan folder is really just a WhatsApp media gallery.
Careful: "The rules aren't fully in force yet" is not the same as "nothing can happen to me yet." The Data Protection Board can already receive and act on complaints. A breach before May 2027 doesn't wait for the deadline to matter. It just means the standard you'll be judged against is still firming up, which cuts both ways.
Where your clients' passport scans actually live right now
Before you can fix anything, you need an honest map of where identity documents sit today. For most agencies, it looks like this:
- WhatsApp chats: passport photos sent by the client, sitting in the thread indefinitely, backed up to Google Drive/iCloud automatically, visible to whichever staff member's phone the WhatsApp Business account runs on.
- Gmail/email: visa application PDFs, insurance forms with passport numbers, forwarded between your team and the client, and often forwarded again to a DMC or ground handler abroad.
- Shared Drive folders: a "Client Documents" folder that's grown organically since the agency outgrew its old Excel sheet, and that every staff member who's ever worked here still has edit access to, including people who left two years ago.
- DMCs and ground handlers abroad: passport and visa details forwarded to a partner in Dubai, Bangkok, or Almaty to arrange visas or hotel check-in, now sitting on a server outside your control and outside India.
- Old devices: a former employee's laptop, a phone that got replaced, still holding a synced copy of everything above.
None of this is unusual. It's how almost every agency in the country runs. But each item is a place a passport scan can leak from, and "we didn't know it was still there" is exactly the gap the security-safeguard obligation is designed to close.
Example: Say you've been operating for six years and average 40 outbound bookings a month. That's roughly 2,880 sets of passport/visa scans that have passed through your WhatsApp and email over that period. If even a fraction sit in an unmanaged Drive folder that three former employees can still open, you don't have a hypothetical risk. You have an active one, today.
Doing this map once, even roughly, is the single highest-value hour you can spend here. Write down which document types you collect, which app or folder each lives in, who has access, and how long it's kept. You now have the shape of your actual exposure.
The consent notice your booking form needs
The Act's consent requirement is simpler than the legal language sounds: before you collect a passport scan or ID proof, the client needs to have been told, in plain language, what you're collecting, why, and for how long, and to have actively agreed. A pre-ticked checkbox in terms and conditions doesn't count as informed consent; a specific, readable notice does.
A version that works for a WhatsApp-and-form workflow, added just above where you ask for the document:
"To book your flights, hotels, and visa, we need a copy of your passport and any visa documents. We'll use these only for your booking and required visa/insurance filings, share them only with the airline, hotel, or visa agency needed to process your trip, and delete our copy [X months] after your trip ends unless you ask us to keep it for a repeat booking. Reply YES to confirm."
Adapt the retention window and the "shared with" list to what's actually true for your agency. The point of the notice is that it has to match your real practice, not read like boilerplate copied from somewhere else. Keep a copy of the message or form submission where the client agreed; that record is your proof of consent if it's ever questioned.
This single change (a plain notice plus a recorded "yes") covers the bulk of the Act's consent obligation for a small agency. You do not need a lawyer to draft this, and you do not need a client-facing privacy portal.
Retention and deletion: how long can you actually keep a passport copy
The honest answer is that the Act doesn't hand you a fixed number of days. It asks you to keep personal data only as long as it's needed for the purpose you collected it for, and to delete it (or stop processing it) once that purpose is served, unless another law requires you to retain it longer. In practice, that means:
- Decide a retention window per document type: a passport scan has served its purpose once the trip is complete and any post-trip claims window (refunds, insurance) has closed.
- Write the window into your consent notice: six months post-trip is a reasonable default unless you have a specific reason to keep longer, such as a repeat-client relationship.
- Actually delete on a schedule: a quarterly reminder to clear the "Client Documents" folder of anything past its window beats any policy document you don't act on.
- Revoke access before you delete data: when staff leave, remove their access to shared folders and WhatsApp Business the same day.
Careful: Keeping every passport scan "forever, just in case" feels safer but is the opposite. Every document you hold past its purpose is pure downside. It can't help a future booking you haven't been asked to make, and it's one more record exposed if there's ever a breach.
Baseline security hygiene that satisfies "reasonable safeguards"
The Act requires "reasonable security safeguards" against breach, without a fixed technical checklist for a business your size. Enforcement judges this against what's proportionate to the data you hold, not enterprise-grade infrastructure you don't have. For a small agency, reasonable and achievable looks like this:
- Restrict who can open the documents folder: scope access to the two or three people actually processing bookings, not the whole office.
- Turn off auto-backup of WhatsApp media to personal Drive/iCloud on the phone running your WhatsApp Business account, or use a device dedicated to it.
- Use a shared password manager instead of a shared login written on a sticky note, for any tool touching client documents.
- Set screen locks and device passcodes as a non-negotiable rule for any laptop or phone with client data on it.
- Encrypt or password-protect the Drive folder holding scanned documents where the storage platform allows it.
- Log who downloads or forwards a document, even informally: a spreadsheet noting "sent to [DMC name] for visa on [date]" answers "who had this" later.
- Have a written offboarding step: revoke access to email, Drive, and WhatsApp Business the day someone leaves.
None of this needs a security consultant. It needs deciding these are rules, writing them on one page, and actually following them, which is most of what "reasonable safeguards" means at your scale.
What happens if there's a breach: the response sequence
A breach, for this purpose, is any unauthorised access, loss, or disclosure of personal data: a lost phone with client documents, a Drive folder shared publicly by accident, a former employee downloading data before leaving. If one happens:
- Contain it first: revoke access, change passwords, recover or remote-wipe the device, take the exposed folder/link down.
- Document what happened: what data, how many clients, when discovered, when it likely started. You'll need this regardless of what comes next.
- Notify affected clients: plainly, promptly. Waiting to see if anyone notices turns a manageable incident into a penalty case.
- Assess whether it needs reporting to the Data Protection Board: the breach-notification duty is what the up-to-₹200-crore penalty attaches to, so treat this as a real question and get a professional opinion if the exposure is more than trivial.
- Fix the underlying gap: the access control or process that let it happen, so the same failure can't repeat.
Speed and honesty in steps 1–3 are what separates an incident you recover from and one that becomes a regulatory matter.
The penalties, honestly
This is where the headlines get scary. The maximum penalty for failing to implement reasonable security safeguards is up to ₹250 crore, and the maximum for failing to notify the Board or affected individuals of a breach is up to ₹200 crore. A single incident can attract both, putting the theoretical worst case at ₹450 crore.
Those numbers exist to be credible against a data-processing conglomerate with millions of records and a legal team that ignores obligations on purpose. They are not a realistic outcome for a six-person agency that has a consent notice on its form, restricts folder access, and responds honestly when something goes wrong. Penalties scale with the nature, gravity, and duration of the failure. A small operator with basic hygiene and a good-faith breach response looks nothing like the case those ceilings were built for.
Example: The gap between "existential" and "avoidable" is the gap between doing nothing and doing the five things this post covers: a consent notice, an access list, a deletion habit, a breach checklist, an offboarding step. None of that costs money. All of it is what the Board will actually look at.
Treat the ceiling as the reason to take this seriously this year, not as a realistic threat over a business that's made a genuine effort.
What you don't need
Compliance vendors are already marketing "DPDP packages" to small businesses, and some of what they sell is overkill. You do not need:
- A Data Protection Officer (DPO): that applies to "Significant Data Fiduciaries," a designation for large-scale processors the government notifies specifically; a six-person agency isn't in that category.
- A registered consent manager platform: the framework arriving around November 2026 lets clients route consent through third-party platforms; that's for large platforms with millions of users, not a booking-form checkbox.
- A dedicated legal/compliance hire: the actions in this post are operational habits, not a legal department's job.
What you need is the one-page version: a consent notice on your form, a written access list, a retention-and-deletion habit, and a breach plan. That's achievable inside the ten months you actually have.
Common questions
Can I still keep client passport copies at all?
Yes. The Act doesn't ban holding identity documents for a legitimate business purpose like booking flights, hotels, and visas. It requires that clients know you're holding them, agree to it, and that you delete the copy once the purpose is served, not that you stop collecting them.
Does this apply to domestic bookings too, or only outbound?
Any digital personal data you process is covered, so a domestic client's Aadhaar or PAN for a hotel booking counts the same as a passport. Outbound bookings simply involve more sensitive documents and more parties data passes through, which is why this post leans on that example.
What about scans already sitting in six years of WhatsApp chats?
Do the data-map exercise from earlier, then run a one-time cleanup: keep what's needed for open files, delete what belongs to closed trips past their window, and turn off chat backup to personal cloud storage going forward. You can't fix six years of habit in one afternoon, but you can stop the ongoing exposure today.
Do I need to update contracts with DMCs and ground handlers abroad?
If you forward passport or visa data to a partner outside India to arrange visas or check-in, it's worth a short written understanding on what they do with it and how long they keep it. Foreign DMCs increasingly ask for the same from their side.
The short version
- You're a Data Fiduciary under the DPDP Act the moment you collect a passport, visa, or ID copy digitally. There's no small-business exemption for consent, notice, or security duties.
- The Rules were notified in November 2025, with full core-obligation compliance due by roughly May 2027; as of July 2026, that's about ten months away, not eighteen.
- Map where passport scans actually live today: WhatsApp, Gmail, shared Drive, ex-employees' devices, and any DMC abroad you've forwarded documents to.
- Add a plain-language consent notice to your booking form and keep a record of the client's "yes." That single change covers most of the Act's consent obligation.
- Set a retention window per document type, actually delete on a schedule, and revoke former staff's access immediately: "keep everything forever" is pure downside, not safety.
- Reasonable security safeguards for your scale means access control, device passcodes, no auto-backup of business WhatsApp media, and a written offboarding step, not enterprise software spend.
- The penalty ceilings of up to ₹250 crore and ₹200 crore are real on paper and built for large-scale offenders; basic hygiene and an honest breach response put a small agency nowhere near them.