EN
+66 93 656 8090
Client Data and Your Thailand DMC: What to Send, What Not To
Thailand DMCB2BAgency operations

Client Data and Your Thailand DMC: What to Send, What Not To

Dispatch No. 391

7 September 2026 · David Leo · Explera Trade Desk · 9 min read

Send your Thailand DMC the minimum client data the booking actually needs, send it through a channel you would be comfortable describing to the client, and agree at the start of the relationship what happens to it when the trip is over. Most agencies do none of those three deliberately — they forward the whole email chain, passport scan attached, and hope. This is the operational side of client data written for the trade by a Thailand DMC for travel agents. It is not legal advice, and it is not a substitute for whatever your own regulator requires of you.

Explera DMC Thailand is the ground partner behind these files for agencies worldwide — IATA 96215733, 340+ agency partners, and a trade desk on b2b@explera.co.th that would rather receive one clean rooming list than a forwarded thread with a passport in it.

Two regimes, not one, and they both reach you

An agency selling Thailand is usually sitting inside at least two data regimes at once, and the common mistake is assuming only the home one applies.

  • Your own. A European or UK agency carries GDPR obligations wherever the data goes, including when it is sent to a supplier outside Europe. Agencies elsewhere have their own equivalents. Your obligations follow the data.
  • Thailand's. Thailand has a Personal Data Protection Act, the PDPA, which came fully into force in 2022 and is overseen by a national data protection committee. It is broadly in the same family as GDPR, and it reaches organisations outside Thailand that offer services to people in Thailand.
  • What this means in practice is unglamorous: the ground partner you choose is a party your client's data passes through, so how that partner handles it is part of your own compliance picture rather than a separate matter you can leave to them.
  • What it does not mean is that you need a legal opinion before every booking. It means the questions in this guide should have answers, and the answers should be the same every time.

What actually has to travel

Start from the operation and work backwards. Each item below exists because something on the ground cannot happen without it — that is the test.

  • Names as they appear in the passport, because domestic flights, ferries and hotel registration are matched against the travel document, not against the booking form.
  • Passport details where a supplier is legally required to collect them. Thai accommodation has to register foreign guests with immigration, which is why hotels and villas ask; our guide to TM30 guest registration covers who files what.
  • Dates of birth where a fare, an entry fee or a child policy actually turns on age, and not otherwise.
  • Flight numbers and arrival times, which are the difference between a greeter at the right door and a driver on the wrong side of an airport.
  • Dietary requirements and allergies, which are health information and therefore the most sensitive thing most files contain — send them, because a kitchen cannot act on what it does not know, but send them as a requirement rather than as a diagnosis.
  • Mobility and accessibility needs, for the same reason and with the same discipline: what the client needs the operation to do, not their medical history.
A guest signing a registration form at a hotel reception desk while a receptionist hands over a pen
The registration form is where a passport number stops being paperwork and becomes a legal requirement. That is the test for everything you send: what does the operation actually need in order to happen?

What usually does not need to travel at all

This is the shorter, more useful list, and it is where most of the unnecessary risk sits.

  • Full passport scans by default. Where a supplier needs the number and expiry, the number and expiry are what it needs. A photograph of the whole document contains more than the operation ever uses.
  • Home addresses, unless something is genuinely being delivered.
  • Payment card details. Never in an email, never in a chat message, never in a shared document — the settlement routes exist precisely so that card data does not travel through a booking thread.
  • The whole email chain. A forwarded thread usually carries three other clients' details in the quoted text below, and nobody ever reads that far before hitting send.
  • Anything about the client's health beyond the operational requirement, and anything about the reason for the trip that the ground team does not need in order to run it.

How to send it, and what to stop doing

The channel matters as much as the content, and the improvements here are cheap.

  • One structured rooming list beats ten emails. A single file, in a fixed shape, with only the columns the operation needs, is easier for the desk and safer for you.
  • Send the passenger detail once, close to travel, rather than trickling it through a thread from the day of the enquiry. Most of a quotation cycle needs pax numbers and ages, not identities.
  • Keep the sensitive detail out of the subject line and the file name. Both get copied into places you do not control.
  • Use one agreed address for the file, not whichever individual replied last, so the data lands where it is meant to live.
  • Do not put client data into consumer chat apps for convenience and then leave it there. A message asking us to check a booking is fine; a message containing a passport is a copy you no longer control.
A person at an office desk comparing a printed document against figures on a monitor
One structured list, sent once, close to travel. A forwarded email chain carries three other clients in the quoted text underneath, and nobody reads that far before pressing send.

What to ask a ground partner, before you send anything

These are the questions a professional operator should be able to answer without escalating, and the answers should not change from one booking to the next.

  • Who inside your operation sees this, and which onward suppliers receive it? Hotels, transport and guides genuinely need some of it; the answer should be specific rather than reassuring.
  • How long do you keep it after the trip, and what happens then?
  • Where can we send a client's request to have their data corrected or removed, and how quickly does that get actioned?
  • What happens if something goes wrong at your end, and who tells us?
  • Is there a written arrangement covering this between our two companies, or are we relying on habit? For many agencies, a data-processing agreement is a requirement rather than a nicety, and it is easier to put in place at onboarding than mid-season.

When the trip is over

The end of a file is the part nobody plans, which is why old client data accumulates in inboxes for years.

  • Decide what you keep and why. Commercial records and a client's passport image are different things with different lifetimes.
  • Delete the working copies — the spreadsheet on a laptop, the attachment in a sent folder, the file in a shared drive that three people can still open.
  • Handle a client's request properly and promptly when they ask what you hold. Knowing where a file lives is most of the work; if you cannot answer that, the answer is the problem.
  • Review it once a season, not once after an incident.

How a Thailand DMC handles client data

The reason this is worth asking a ground partner about is that a DMC sits in the middle of it by design. Booking through Thailand DMC services for travel agents means one counterparty receives the file and passes on only what each supplier needs — the hotel gets what registration requires, the transfer team gets flight numbers and names, the guide gets the day's manifest. Booking eight suppliers direct means eight copies of your client's details in eight systems you have never assessed, which is the part agencies tend to notice only when someone asks them to account for it.

It also means one place to send a correction or a deletion request, whether the programme runs in Bangkok or Phuket. Agencies across our source markets ask these questions at onboarding and we would rather they did. If your agency needs a written arrangement in place before the first booking, raise it with the trade desk at b2b@explera.co.th and it can be dealt with then rather than in the middle of a season.

Frequently asked questions

Do we have to send passport scans to a Thailand DMC?

Usually not the whole document. Thai accommodation is required to register foreign guests with immigration, so the passport number, nationality and expiry are genuinely needed; a photograph of the full page carries more than the operation uses. Ask what the specific supplier requires and send that, rather than defaulting to the scan because it is quicker.

Does GDPR still apply when the data goes to Thailand?

Your obligations follow the data — sending it outside your own jurisdiction does not leave them behind. Thailand also has its own regime, the PDPA, which came fully into force in 2022 and is broadly in the GDPR family. What your particular agency must do about transfers is a question for your own adviser; this guide is about the operational practice, not the legal position.

What is the single easiest improvement for a small agency?

Stop forwarding email chains. A forwarded thread routinely carries other clients' details in the quoted text underneath, and it is the most common way information reaches people who had no reason to receive it. One structured rooming list, sent once, close to travel, fixes most of it.

Can we send dietary and medical requirements?

Yes, and you should — a kitchen or a guide cannot act on what it does not know. Send it as an operational requirement rather than a diagnosis: what the client needs to happen, not their medical history. That is both safer and more useful to the team actually delivering it.

How long should a ground partner keep our client's data?

Long enough to run and account for the trip, and no longer by default. The important part is that the answer is stated rather than assumed, that it is the same for every booking, and that you know where to send a client's request if they ask what is held.

Should we have a written data agreement with our DMC?

For many agencies it is a requirement rather than an option, and it is far easier to arrange at onboarding than halfway through a season. If your compliance team needs one before the first booking, say so at the start — it is a normal request and a partner who cannot answer it is telling you something.

Become a partner

Start quoting Thailand at net rates this week.

Join 340+ agencies who trust Explera with their guests on the ground. Registration is free and approval is fast.

Trade newsletter

Net-rate offers and Thailand intel, monthly.

New programs, seasonal openings and trade-only rates — one email a month, no noise.