Passport data may be necessary, but keeping images indefinitely is riskier
Accommodation providers may need passport information for check-in, guest identification, or legally required reporting. A full passport image contains far more data than necessary and is easy to forward incorrectly.
Collect fields required for check-in, reporting, or property operations. Do not keep copies "just in case" without a clear reason.
Tell guests why you need the data, who manages it, and how it will be used.
Raw document images should be removed after reading and review, not left in chats or personal devices.
Where passport photos become a problem
- Forwarding passport images in LINE groups with unrelated staff
- Keeping images on personal phones or laptops without a deletion cycle
- Sharing Google Drive or email access too broadly
- No audit trail of who accessed, edited, or exported guest data
- Using passport images for purposes guests were not told about
Separate raw images from operational guest data
Use passport photos to read and verify information, then keep only the structured fields your property needs, such as name, passport number, nationality, stay dates, and review history.
Higher risk. Use briefly for reading and review. Do not forward or store in multiple places.
Keep in the workspace with role limits and delete when business or legal reasons no longer require it.
Reduce image sprawl and keep work in one workflow
tomororo reads passport data with OCR/AI for team review, then keeps structured records in a workspace instead of passing images through multiple channels. tomororo generally strives to remove raw passport uploads from active systems within 48-72 hours, even when parsing fails.
Read policy details at Trust & Data Safety, Privacy Policy, and PDPA Notice.
Passport photo and PDPA questions
Properties may have reasons to use passport data for check-in or reporting, but they should collect only what is necessary, inform guests, limit access, and reduce raw image retention.
It separates raw passport images from structured guest records, limits workspace access, and generally removes raw uploads from active systems within 48-72 hours.