The risk of data leakage from accommodation services: lessons from the world and new governance requirements for Vietnamese businesses

Insights
The risk of data leakage from accommodation services: lessons from the world and new governance requirements for Vietnamese businesses
Posted on: 20/07/2026

    In 2018, the world's hospitality industry witnessed one of the largest data breaches in history when Marriott International announced that Starwood Hotels' booking system had been illegally accessed for a long time before it was discovered[1]. According to published information, the data of hundreds of millions of customers globally has been affected. Not only does it include names, email addresses or phone numbers, but many of the compromised information also involves passports, stay histories, and other data that can reproduce almost the entire customer's travel journey over many years.

    Many people think that this is merely a cyberattack. However, from a data governance perspective, the Marriott incident presents a much larger problem. A business can operate thousands of hotels around the world, possess the most modern technology systems, but still may not have full control over the data it holds.

     

    If a bank knows how much money a customer has, a hotel can know who the customer is, where they are, who they are with, how they spend their money, and where they usually appear at certain times

     

    In 2023, MGM Resorts International continues to be the victim of a cyberattack that disrupted the operations of a series of hotels and resorts[2]. Reservation systems, electronic payments, room locks and many other services were affected for days. The damage lies not only in the exposed data, but also in the stalling of the entire business.

    These cases reflect an important fact: data in the hospitality industry today is no longer the information that supports business operations, but has become a strategic asset class. And like every other valuable asset, it has also become the target of trespasses.

    What's so special about your stay data?

    If a bank knows how much money a customer has, a hotel can know who the customer is, where they are, who they are with, how they spend their money, and where they usually appear at certain times. This is the difference that makes accommodation data one of the most valuable types of data in the digital economy.

    In the process of providing services, hotel businesses often collect many different layers of data. The first layer is identifying data such as full name, nationality, citizen or passport identification number, contact address, and payment information. The second layer is transaction data, including booking history, invoices, payment methods, and services used. The third layer is behavioral data. This is the type of data that many customers pay the least attention to, but has great commercial value. Through their stay history, businesses can know what type of room customers prefer, how often they travel for business or vacation, what the average spend is, and how likely they are to return in the future. The fourth layer is sensitive data that may arise during the stay, such as health data at wellness resorts, biometric data for customer identification, or information reflecting the private life of customers.

    If each individual type of data reflects only a certain aspect, then when combined, they can form a relatively complete profile of an individual. That's why hotel databases have always been of great value to cyberattackers, unauthorized data collection organizations, or economic espionage activities.

    Risks don't just come from cyber attacks

    The biggest risk for a lodging business is not a single cyberattack, but rather in the fact that customer data is scattered across an ecosystem of hotel brands, operators, owners, booking platforms, payment gateways, loyalty programs, and multiple technology providers.

    In many cases, the cause of a data incident lies within the business.

    An employee can download customer data to a personal computer for work. A business department can share customer lists with marketing partners. A technology service provider may be granted wider access than necessary. An old system that is no longer in use continues to store data for years without being inspected or deleted.

    From a data governance perspective, risks often appear throughout the entire personal data lifecycle.

    Risks can arise from the time of data collection if the business collects too much information that is not really necessary. Risks can arise during storage when data is distributed across various systems without a centralized management mechanism. Risks may arise during use when data is mined for purposes beyond the original scope. Risks may also arise in the process of sharing data with technology providers, online booking platforms, payment gateways, or other business partners. In other words, data isn't just lost because the business is hacked. Data can be lost simply because businesses don't really know what they're managing.

    From data management to data governance

    Cases around the world show an important shift in management thinking. In the past, businesses often focused on the question of how to secure the system. Today, the more important question is whether businesses are truly in control of their data.

    This is also the "philosophy" that is being reflected in Vietnam's Law on Personal Data Protection 2025.

    If in the past, businesses often considered data protection as the responsibility of the information technology department, now the law puts that responsibility on the entire corporate governance system: legal, human resource administration, information technology and especially the business executive board. Therefore, it is not only important whether the data is encrypted or not. It is more important for businesses to know what data they are processing, for what purpose, on what legal basis, who has access to it, and how long the data is kept. From this perspective, personal data protection is no longer a technical issue but has become a part of corporate governance.

     

    Risks may also arise in the process of sharing data with technology providers, online booking platforms, payment gateways, or other business partners.

     

    New challenges from AI and service personalization

    Over the years, the hospitality industry has invested heavily in loyalty programs, CRM systems, and data analytics tools to personalize the customer experience. A modern hotel can know what kind of pillows customers like, what dishes they usually use, what floors they like to be on, and what time of year they tend to come back. That information helps businesses create better experiences and improve competitiveness. However, the deeper the personalization, the more data the business has to process.

    The development of artificial intelligence is significantly increasing this trend. AI systems are capable of analyzing stay history, predicting customer needs, and automatically making tailored service recommendations. That means businesses are not only storing data, but also building increasingly detailed behavioral records of customers.

    From a legal perspective, this is a new risk area for the hotel industry in the coming years.

    What do Vietnamese enterprises need to do?

    In the context that the Law on Personal Data Protection 2025 and Decree 356/2025/ND-CP have come into effect, the most important solution for accommodation businesses is not to buy more security software but to build data management capacity.

    The first step is to map the data to determine exactly what data the business is collecting, where the data is being stored, who is accessing the data, and to which entities the data is being shared.

    The second step is to review the entire legal basis of data processing. Businesses need to ensure that each data collection, use or sharing activity has an appropriate legal basis in accordance with the law.

    The third step is to apply the principle of data minimization. Unnecessary data should not be collected. Data that is no longer needed should no longer be retained.

    The fourth step is to build a management mechanism for technology service providers and third parties with access to customer data. In fact, many data risks arise from the technology supply chain rather than from the business itself.

    The fifth step is to establish a process for assessing the impact of data processing, managing cross-border data transfers, responding to data incidents, and training personnel regularly.

    Most importantly, businesses need to change their perception. Personal data is not only the property of the business, but first and foremost the rights of the customer. Data mining can only be sustainable when it is done on the basis of respecting that right.

    In the context that data is increasingly becoming a strategic asset of the digital economy, data management capacity will gradually become a core competitiveness of hotel businesses. Customers can choose a hotel because of its location, service quality, or price. But in the future, they will also choose businesses they trust to be able to protect their personal data safely and responsibly.