Skip to content
Tourism & travel · Australia

Your guests trust you with their passports. Attackers know it.

Tour operators, travel agents, accommodation and transport providers sit on passports, payment cards and complete itineraries — often taken card-not-present, across borders, at seasonal volume. One compromised booking platform doesn't expose a single customer. It exposes every guest on the system at once.

Dossier 09 / 10

Tourism

Passports, payment cards and full itineraries make travel operators a rich, seasonal target — and one compromised booking system exposes every guest at once.

  • Privacy Act 1988 / APPs
  • PCI DSS card-data security
  • Cross-border passenger & passport data
Named obligations

What the obligation actually requires of you.

  1. 01

    Privacy Act 1988 / APPs

    Where the Privacy Act applies, passport scans, contact details and travel plans require reasonable protection. Knowing a guest's identity, home address and exact dates away increases the consequences of unauthorised access.

  2. 02

    PCI DSS card-data security

    If you take card payments, PCI DSS sets non-negotiable requirements for how card data is captured, transmitted and stored. High card-not-present volume makes travel a chargeback and fraud magnet, and non-compliance can cost you the ability to process cards at all.

  3. 03

    Cross-border passenger & passport data

    Passenger and passport data frequently crosses borders to airlines, wholesalers and overseas suppliers. Each transfer carries a responsibility to protect that data end to end, not to assume the receiving platform has it handled.

7

controls to review

Use this sector-specific set of practical prompts to identify owners, evidence and the next control to verify.

Illustrative scenario · Boutique tour operator, QLD

A booking inbox quietly forwarding guest data.

Illustrative scenario — In this example, A phishing email harvested the credentials of a reservations account. Rather than lock anyone out, the attacker set a silent forwarding rule and watched — collecting guest passport scans and card confirmations for weeks while the operator noticed nothing.

Example response — A suitable response is to remove unauthorised forwarding rules, reset the booking mailbox credentials, revoke sessions and review guest-data access and retention.

What to verify — Confirm the relevant control is configured, tested and evidenced for this scenario; record the owner, review date and any exception before treating the risk as addressed.

Control evidence to collect

Configuration, test evidence, an accountable owner and a review date for the controls described in this scenario.

Illustrative scenario only. It is not a client case study, endorsement, zero-loss claim or proof of a security outcome.

The compliance checklist

Run it yourself, before we ever speak.

  • MFA enforced on every reservations, email and booking-platform account
  • Card payments processed through a PCI-compliant gateway — never stored in inboxes or spreadsheets
  • Passport and ID scans encrypted, access-limited, and deleted or de-identified when no longer needed, subject to applicable retention obligations
  • Mailbox forwarding and inbox rules monitored for silent exfiltration
  • Third-party booking and channel-manager integrations reviewed for how they secure your guest data
  • Staff trained to recognise supplier- and guest-impersonation phishing in peak season
  • A breach-response process mapped to the Privacy Act's Notifiable Data Breaches scheme

These are practical control prompts, not a legal compliance determination. Exact obligations vary by entity, asset, contract and jurisdiction.

Get the Tourism compliance checklist

A practical web checklist for your sector’s controls and obligations. No call. No obligation.

Before you call us

The questions this vertical always asks.

Find out exactly where your guests’ data is exposed.

The Cyber Readiness Assessment is the forensic starting point, backed by a 100% refund guarantee. Enquire for scope and terms.

Melbourne VIC · Australia · gmanit.com.au