How do I collect passports and emergency contacts without becoming a data breach risk?
Passport scans, dietary needs and next of kin details are sensitive records you are holding for months. A concrete checklist for collecting, storing and deleting them.
You reduce the risk by holding less, for less time, in fewer places. Most of the exposure small operators carry is not from a sophisticated attack. It is from full passport images sitting in an email inbox from a trip that ended two years ago.
Three decisions do most of the work. Collect only the fields a supplier will actually ask you for. Take intake through a form that stores the file somewhere access controlled, not through email or a group chat. And put a deletion date on every document at the moment you receive it, so the default is that it goes away.
Everything below is the detail underneath those three decisions, ending with a checklist you can run before each departure.
What you genuinely need versus what you are asking out of habit
Start by asking what each field is for and who receives it. If you cannot name the supplier who will ask, you do not need it yet.
| Field | Who actually needs it | Verdict |
|---|---|---|
| Full name as printed in passport | Airlines, some hotels, ferry and rail bookings | Collect |
| Date of birth | Airlines, age restricted activities, some insurers | Collect |
| Passport number, issuing country, expiration | Airlines on international tickets, some visa or entry forms | Collect the data fields |
| Full color scan of the passport page | Rarely anyone, unless a specific visa or permit requires it | Collect only on demand, delete on submission |
| Emergency contact name and phone | You, on the ground, in an emergency | Collect |
| Allergies and dietary needs | Restaurants and your leader | Collect the requirement, not the diagnosis |
| Medications and conditions | Nobody in advance, in most itineraries | Do not collect routinely |
| Insurance policy number and limits | You, to verify coverage | Collect |
| Social Security number | Nobody on a leisure trip | Never collect |
Two lines deserve emphasis. A passport image is a far heavier record to hold than the four data fields printed on it, and in most bookings the fields are all anyone asks for. And the difference between "severe tree nut allergy, carries an epinephrine auto injector" and a traveler's full medical history is the difference between an operational note and a health record you have no reason to store.
The sealed envelope option
For genuine medical detail some leaders want available in a crisis, the low technology answer still works. Ask the traveler to carry her own sealed information card in her daypack, and to tell you only that it exists and where it is. You get the emergency capability without becoming the custodian.
Keep reading: What actually happens when one traveler cancels six weeks before a twelve person trip?
Why email and group chats are the wrong intake channel
Email is a copying machine. A passport scan sent to you exists in her sent folder, your inbox, your mail provider's servers, your phone, and any device where you previewed it. Forward it once to a co leader and it multiplies again. There is no delete button that reaches all of those copies.
Group chats are worse in a specific way. A traveler who is confused about where to send something will often post it to the group thread, which means twelve strangers now have her passport page and her phone number. Once that happens the chat history is not really recallable, and you are the one who has to tell her.
Attachments also sit in whatever downloads folder they landed in. Most breaches at this scale are a stolen laptop or a reused password on a mail account, not anything clever.
What to do instead: a single intake form per traveler, per trip, that writes into one system with a login. Then say once, in the welcome email and again in the chat rules, that documents are only ever submitted through that form and never by email or message. Expect to repeat it. Enforce it by declining what arrives the wrong way and asking her to resubmit, which teaches the group faster than any instruction.
Retention windows and a deletion date for every file
The question is not whether to delete, it is when. Write a retention schedule once, and apply it to every departure.
- Passport images: delete as soon as the booking or visa that required them is confirmed. Days, not months.
- Passport data fields: keep through the trip, purge within 30 days of return.
- Emergency contacts and dietary notes: purge within 30 days of return.
- Insurance verification: keep through the claim window. Many policies allow claims for a period after return, so 12 months is a reasonable window, then delete.
- Signed waivers and enrollment agreements: keep. These are contracts with a legal exposure tail. Ask your attorney for the right number in your state, and store them apart from everything else.
- Financial records: keep for tax purposes, but strip the personal detail that belongs to the other categories.
Notice that waivers are the exception. Almost everything else in your file has a short useful life and a long risk life, which is the reason to set the date on arrival rather than deciding later.
Put a recurring reminder 30 days after every return date, titled with the trip name, whose only task is the purge. Then actually do it, including the copies on your phone.
Keep reading: Are women only trips getting harder to fill, or is the buyer just changing on me?
Access control when you add a co leader or ground guide
Your ground guide in Kyoto does not need passport numbers. She needs a rooming list, a dietary summary and first names. Your co leader needs emergency contacts. Your bookkeeper needs payment records and nothing else.
Three habits cover almost all of it:
- Share by role, not by folder. Give each person the narrowest view that lets her do the job, and prefer a purpose built export over access to the master record.
- Individual logins, never a shared password. A shared account cannot be revoked for one person, and it tells you nothing about who opened what.
- Revoke on the return flight. Add removal of seasonal helpers to your post trip closeout, the same week you reconcile the cash.
When you do send something out, send the minimum. A hotel asking for a rooming list is asking for names and bed configuration, not birthdates.
State breach notification duties that reach small businesses
All fifty states, plus the District of Columbia, have data breach notification laws, and they generally apply to any business holding personal information about their residents. There is no small business exemption in most of them. Your obligations follow your travelers' home states, not yours, which for a national roster means you could be answering to several statutes at once.
The common structure is worth knowing before you need it. Most statutes define personal information as a name combined with a sensitive identifier, and passport numbers are named explicitly in a number of states. Most require notice to affected individuals without unreasonable delay, with several setting an outer limit measured in days. Many require notice to the state attorney general once the number of affected residents crosses a threshold. Details and thresholds genuinely differ by state, so this is a question for counsel in the moment rather than something to memorize.
Two practical implications. First, know at all times which residents' data you hold, because your notification map is your roster's state column. Second, the cheapest compliance strategy is holding less: data you deleted in August is not part of a November incident.
See how RoamRoster handles this for small group travel for women
What to hand a hotel or airline and what to withhold
Suppliers ask broadly because it is easier for them. You are allowed to send less.
- Airline group booking: full name as in passport, date of birth, gender marker as it appears on the travel document, and on international tickets the passport number, issuing country and expiry. Send data, not images.
- Hotel: rooming list with names and bed type. Some countries require passport details at check in by law, in which case travelers present their own documents at the desk. You do not need to email them ahead.
- Ground operator or DMC: names, arrival and departure details, dietary and mobility notes phrased as requirements.
- Activity vendor: headcount, first names, and any specific constraint that affects safety, such as a weight limit or a non swimmer.
When a vendor asks for scans by email, ask whether a secure upload link exists. Many have one and do not offer it by default. If they insist and the booking requires it, send only the required page, note the date, and delete your copy once the booking is confirmed.
A pre departure data checklist to run before every trip
Work through this at your final payment date, when the roster is settled.
- Confirm every traveler submitted through the form. Note anyone who emailed, and delete those messages after moving the content in.
- Search your inbox, sent folder and downloads for attachments related to this trip. Delete every copy you find outside the system of record.
- Review the field list. Delete anything you collected that no supplier asked for.
- Confirm passport expirations meet the destination's validity rule, commonly six months beyond entry, and flag anyone short.
- Verify insurance dates and limits against your stated minimums.
- Build the exports you will actually share: rooming list, dietary summary, emergency contact sheet. Nothing else leaves.
- Check who has access to the trip record. Remove anyone not working this departure.
- Decide how the emergency contact sheet travels. If it goes on a phone, that phone needs a passcode and encryption.
- Set the purge reminder for 30 days after the return date, named for this trip.
- After the trip, run the purge, then confirm the deletion actually happened rather than assuming.
Making the default safe
None of this is difficult. It is just persistent, and it competes with everything else in the eight weeks before a departure, which is why it usually loses.
The fix is structural rather than disciplinary. RoamRoster takes passport details, emergency contacts and insurance through a per traveler intake form tied to the departure, keeps them in the trip record instead of your inbox, controls who on your team can see what, and lets you clear a trip's documents when the retention window closes. Set the rules once and the safe path becomes the easy one.