Your guests trust you with their passports. Attackers know it.
Tour operators, travel agents, accommodation and transport providers sit on passports, payment cards and complete itineraries — often taken card-not-present, across borders, at seasonal volume. One compromised booking platform doesn't expose a single customer. It exposes every guest on the system at once.
Dossier 09 / 10
Tourism
Passports, payment cards and full itineraries make travel operators a rich, seasonal target — and one compromised booking system exposes every guest at once.
- Privacy Act 1988 / APPs
- PCI DSS card-data security
- Cross-border passenger & passport data
What the obligation actually requires of you.
- 01
Privacy Act 1988 / APPs
Where the Privacy Act applies, passport scans, contact details and travel plans require reasonable protection. Knowing a guest's identity, home address and exact dates away increases the consequences of unauthorised access.
- 02
PCI DSS card-data security
If you take card payments, PCI DSS sets non-negotiable requirements for how card data is captured, transmitted and stored. High card-not-present volume makes travel a chargeback and fraud magnet, and non-compliance can cost you the ability to process cards at all.
- 03
Cross-border passenger & passport data
Passenger and passport data frequently crosses borders to airlines, wholesalers and overseas suppliers. Each transfer carries a responsibility to protect that data end to end, not to assume the receiving platform has it handled.
controls to review
Use this sector-specific set of practical prompts to identify owners, evidence and the next control to verify.
A booking inbox quietly forwarding guest data.
Illustrative scenario — In this example, A phishing email harvested the credentials of a reservations account. Rather than lock anyone out, the attacker set a silent forwarding rule and watched — collecting guest passport scans and card confirmations for weeks while the operator noticed nothing.
Example response — A suitable response is to remove unauthorised forwarding rules, reset the booking mailbox credentials, revoke sessions and review guest-data access and retention.
What to verify — Confirm the relevant control is configured, tested and evidenced for this scenario; record the owner, review date and any exception before treating the risk as addressed.
Control evidence to collect
Configuration, test evidence, an accountable owner and a review date for the controls described in this scenario.
Illustrative scenario only. It is not a client case study, endorsement, zero-loss claim or proof of a security outcome.
Run it yourself, before we ever speak.
- MFA enforced on every reservations, email and booking-platform account
- Card payments processed through a PCI-compliant gateway — never stored in inboxes or spreadsheets
- Passport and ID scans encrypted, access-limited, and deleted or de-identified when no longer needed, subject to applicable retention obligations
- Mailbox forwarding and inbox rules monitored for silent exfiltration
- Third-party booking and channel-manager integrations reviewed for how they secure your guest data
- Staff trained to recognise supplier- and guest-impersonation phishing in peak season
- A breach-response process mapped to the Privacy Act's Notifiable Data Breaches scheme
These are practical control prompts, not a legal compliance determination. Exact obligations vary by entity, asset, contract and jurisdiction.
The questions this vertical always asks.
The platform secures its own systems, but the moment guest data reaches your inbox, your staff logins or your channel manager, your organisation still needs to manage its own access, retention and incident responsibilities.
Yes — your obligations may differ when you use a compliant provider correctly, but they don't disappear. Keep card data out of email, notes and spreadsheets, and confirm the provider arrangement against your applicable PCI DSS scope.
It's built to. We harden the controls that matter year-round and tighten monitoring through your peak, when phishing and booking-fraud attempts spike alongside your volume.
Find out exactly where your guests’ data is exposed.
The Cyber Readiness Assessment is the forensic starting point, backed by a 100% refund guarantee. Enquire for scope and terms.
Melbourne VIC · Australia · gmanit.com.au