industry-guides7 min read11 September 2026

PDPA for Travel Agencies: Passport and Booking Data

PDPA compliance for Singapore travel agencies: how to lawfully handle passport, booking, and payment data, avoid penalties, and protect your customers.

ComplyHQ Team

PDPA for Travel Agencies: Passport and Booking Data

PDPA for Travel Agencies: Passport and Booking Data

Travel agencies in Singapore handle some of the most sensitive personal data of any SME sector — full names, passport numbers, dates of birth, home addresses, payment card details, and even health information for travel insurance. Getting PDPA compliance in Singapore right is not optional for your travel business; it is a legal obligation under the Personal Data Protection Act 2012, and the volume of passport and booking data you process makes you a higher-risk organisation in the eyes of the Personal Data Protection Commission (PDPC). This guide breaks down exactly what your travel agency must do to handle passport and booking data lawfully.

TL;DR — Key Takeaways

  • Passport numbers are treated as high-risk personal data by the PDPC. Do not collect, use, or retain them beyond what a specific booking requires.
  • You must appoint a Data Protection Officer (DPO) and publish their contact details — this is mandatory for every organisation under Section 11(3) of the PDPA.
  • Securely destroy passport copies once the trip is complete (Retention Limitation Obligation, Section 25).
  • A notifiable breach (likely significant harm, or 500+ individuals affected) must be reported to the PDPC no later than 3 calendar days after you assess it is notifiable.
  • Financial penalties can now reach up to S$1 million, or 10% of annual turnover for organisations with turnover above S$10 million.

Why PDPA compliance in Singapore matters more for travel agencies

Travel agencies concentrate high-risk personal data in a way few other SMEs do. A single family booking can contain four passport scans, four dates of birth, home addresses, credit card numbers, and travel insurance health declarations — a data set that is highly attractive to identity thieves. This concentration is exactly why the PDPC scrutinises the travel sector closely.

The PDPA applies to every organisation that collects, uses, or discloses personal data in Singapore, regardless of size. For a travel agency, "personal data" clearly includes passport numbers, NRIC/FIN details, booking histories, and payment information. A definitive point worth remembering: under the Personal Data Protection (Notification of Data Breaches) Regulations 2021, an individual's full name combined with their passport number is among the prescribed categories of personal data deemed likely to result in significant harm if compromised — placing passport data in the same higher-risk tier as NRIC and financial account information. That classification raises the standard of care your business is expected to meet.

The financial stakes are real. Following amendments that took effect on 1 October 2022, the maximum financial penalty rose to S$1 million, or up to 10% of an organisation's annual turnover in Singapore (whichever is higher) for larger organisations. Reputational damage from a publicised breach can be even more costly for a business built on customer trust.

The 10 PDPA obligations every travel agency must meet

The PDPA is built around ten core data protection obligations. Here is what each means in practical terms for handling passport and booking data.

Collect personal data only for purposes a reasonable person would consider appropriate, and make those purposes clear. At the point of booking, tell your customer why you need their passport (e.g., airline ticketing, visa processing, hotel check-in) and who you will share it with. When a customer completes a booking, "deemed consent by contractual necessity" often applies — but you should still notify clearly.

Action: Add a short data-use notice to every booking form and quotation. State the purposes and the categories of third parties (airlines, hotels, insurers, overseas ground handlers) who will receive the data.

2. Accuracy Obligation (Section 23)

Passport data must be accurate — a mistyped passport number can mean a denied boarding. Verify passport details against the physical document or a customer-uploaded copy before ticketing.

3. Protection Obligation (Section 24)

You must make reasonable security arrangements to protect personal data. For a travel agency this means encrypted storage for passport scans, access controls so only relevant staff can view bookings, and never emailing unencrypted passport copies. A definitive rule: plain-text passport scans sitting in a shared inbox or an open WhatsApp group are a Protection Obligation failure waiting to be enforced.

4. Retention Limitation Obligation (Section 25)

This is where travel agencies most commonly slip. Once a trip is completed and no legal or accounting need remains, securely destroy or anonymise passport copies. Keeping years of old passport scans "in case the customer travels again" is not a lawful basis for retention.

5. Appoint a Data Protection Officer (Section 11(3))

Every organisation in Singapore must appoint at least one DPO and make their business contact information publicly available. For a small agency, this can be the owner or an office manager — but the role and contact details must be real and published.

Proper staff awareness underpins all of this. See our guide on PDPA staff training requirements for building a data protection culture across your front desk and ticketing teams.

How to handle passport and booking data step by step

The safest approach to passport and booking data is a simple lifecycle: collect the minimum, store it securely, share it only as needed, and destroy it on schedule. Below is a practical workflow your travel agency can adopt immediately to strengthen PDPA compliance in Singapore.

Step 1 — Collect only what you need

Do you need a full colour passport scan, or just the passport number, name, nationality, and expiry? For many domestic or regional packages, a scan is unnecessary. Collect the minimum required for the specific service.

Step 2 — Store securely with access controls

Keep passport and payment data in an encrypted booking system, not loose in email or on desktops. Restrict access to staff who genuinely need it. If you use cloud tools, confirm the provider offers encryption and access logging. Businesses pursuing higher security assurance may consider ISO 27001 certification as a structured framework.

Step 3 — Share on a need-to-know basis

When forwarding passport data to airlines, hotels, or overseas partners, use secure channels. Note that many of these recipients are outside Singapore — the Transfer Limitation Obligation (Section 26) requires you to ensure overseas recipients provide a comparable standard of protection, typically through contractual clauses.

Step 4 — Destroy on a defined schedule

Set a retention schedule (for example: destroy passport scans 30–90 days after trip completion, subject to any tax or legal retention needs). Automate reminders so old data does not accumulate.

Step 5 — Have a breach response plan

If passport data is exposed, act fast. Singapore's mandatory breach notification regime requires notifying the PDPC as soon as practicable, and no later than 3 calendar days after assessing that a breach is notifiable (affecting 500+ individuals or likely to cause significant harm). Our data breach response guide walks through the exact steps.

This is where an AI-powered platform genuinely earns its place. ComplyHQ delivers AI-powered compliance that handles your PDPA obligations in minutes, not weeks — generating your privacy policy, DPO documentation, retention schedules, and breach response plan tailored to a travel agency's data flows, so you are not reverse-engineering the law on your own.

What PDPA penalties do Singapore travel agencies face?

Non-compliance can cost up to S$1 million, or 10% of annual turnover for larger organisations — and the PDPC actively publishes enforcement decisions. Travel and hospitality businesses have featured in enforcement actions, most often for weak security arrangements that led to data leaks.

Common failure points that draw penalties include: unsecured databases, staff emailing passport scans without encryption, retaining customer data far longer than needed, and failing to notify a reportable breach on time. The PDPC weighs the number of individuals affected, the sensitivity of the data (passport and payment data rank high), and whether the organisation took reasonable preventive steps.

For concrete lessons, review our breakdown of real PDPA enforcement cases — many involve exactly the kind of security lapses a busy travel agency is prone to. If you handle payment cards directly, the customer-data principles in our e-commerce PDPA guide also apply to your online booking flows.

Your travel agency PDPA action checklist

Getting started is simpler than most owners fear. Focus first on the highest-risk gaps — passport storage, retention, and breach readiness — then build out the rest. Here is a prioritised checklist:

  • Appoint and publish a DPO (Section 11(3))
  • Publish a PDPA-compliant privacy policy on your website and booking forms
  • Add clear data-use notices explaining passport and booking data purposes
  • Encrypt passport scans and restrict access by role
  • Stop emailing or WhatsApp-ing unencrypted passport copies
  • Set and enforce a data retention and destruction schedule
  • Put contractual protections in place for overseas data transfers (Section 26)
  • Train front-desk and ticketing staff on data handling
  • Prepare a documented breach response plan (3-day PDPC notification)

For a broader, sector-agnostic version, our PDPA compliance checklist for Singapore SMEs is a useful companion. If you would rather have compliance systems custom-built into your booking workflow, Adaptels designs digital solutions for Singapore SMEs that bake in data protection by design.

Travel agencies operate on trust — customers hand you the keys to their identity every time they book. Meeting your PDPA obligations is not just about avoiding penalties; it is about protecting the relationships your business depends on. Start with the highest-risk data (passports and payments), fix your retention habits, and make sure your breach plan is ready before you ever need it.

Sources & References

  1. PDPC — Personal Data Protection Act Overview
  2. PDPC — Guide on Managing and Notifying Data Breaches under the PDPA (PDF)
  3. PDPC — Advisory Guidelines on Key Concepts in the PDPA
  4. PDPC — Enforcement Decisions
  5. Singapore Statutes Online — Personal Data Protection Act 2012

Simplify Your Compliance

ComplyHQ's AI can assess your PDPA compliance gaps in under 15 minutes and generate the policies you need.

Try Free Assessment

Frequently Asked Questions

Can a travel agency in Singapore keep copies of customer passports?
Yes, but only for as long as you have a legitimate business or legal need — such as processing a specific booking, visa application, or airline ticketing. Under the PDPA's Retention Limitation Obligation (Section 25), you must securely destroy or anonymise passport copies once the purpose is fulfilled. Keeping scanned passports 'just in case' after a trip is complete is a common compliance failure.
Do I need consent to share a customer's passport details with an airline or hotel?
Consent is required, but it is usually obtained at the point of booking when the customer agrees to your terms. Best practice is to clearly state in your booking form and privacy policy that passport and personal data will be disclosed to airlines, hotels, insurers, and overseas suppliers to fulfil the trip. This makes the disclosure part of the deemed consent for the transaction under the PDPA.
What happens if a travel agency suffers a data breach involving passport data?
Under Singapore's mandatory data breach notification regime (effective 1 February 2021), a breach is notifiable if it is likely to result in significant harm to affected individuals or involves the personal data of 500 or more individuals. You must notify the PDPC as soon as practicable, and in any case no later than 3 calendar days after assessing that the breach is notifiable. An individual's full name combined with their passport number is among the categories of data prescribed as likely to cause significant harm, so most passport breaches will trigger notification. Affected individuals must also be notified so they can take protective steps.
Tags:PDPASingapore complianceSMEdata protectionPDPC

Ready to get PDPA compliant?

Stop guessing about compliance. ComplyHQ uses AI to assess your gaps, generate policies, and guide you through every PDPA obligation.

Gap AssessmentPolicy GeneratorAI Compliance Chat
14 September 20267 min read

PDPA for Telcos: Customer Data and Billing Records

PDPA compliance Singapore guide for telcos: protect customer data and billing records, meet PDPC obligations, and avoid penalties. Actionable steps for SMEs.

Read more
15 July 20267 min read

PDPA for Law Firms: Client Privilege and Data Protection

A practical guide to PDPA compliance in Singapore for law firms — reconciling legal professional privilege with data protection duties, breach rules, and PDPC penalties.

Read more
12 July 20267 min read

PDPA for Accounting Firms: Client Financial Data

PDPA compliance Singapore guide for accounting firms handling client financial data. Learn PDPC obligations, penalties, and practical steps to protect sensitive records.

Read more