Personal Data, Practically: Habits for Small Overseas Teams
You are holding passport scans in an email thread from 2023. Nobody needs a compliance department to fix that, but somebody does need to decide it is their job.
We have written about the rules at a level a business owner can hold in their head, in the compliance basics of selling to Chinese consumers. That post says the technical parts — consent, retention, cross-border transfer — are worth a professional conversation, and that is still true.
This one is about what you can do without one. A four-person operator is not going to run a data-protection program, and does not need to. What they can do is stop holding things they never needed, know where the copies are, and be able to delete something when asked. Most of the exposure in a small tourism business comes from three or four ordinary habits, and all of them are fixable in an afternoon.
The short version: write down what you hold, where it lives, and why. That list is usually longer and messier than anyone expects, because customer data accumulates in inboxes and chat threads rather than in a system. Then collect less, keep it for a stated period, and make sure a deletion request is something you could actually carry out. None of that is legal advice and all of it makes the legal question smaller.
Start with the inventory, because it will surprise you
Before any policy, spend twenty minutes listing what you actually hold about a Chinese customer. For a tour operator the list usually runs something like:
- Name, phone, email, WeChat ID
- Passport scans or numbers, collected for a booking, a permit or a hotel
- Party composition, including children's ages
- Dietary requirements, and sometimes medical or mobility notes
- Chat history — the whole conversation, including everything they mentioned in passing
- Photographs of them, from the trip
- Payment references, and occasionally card details somebody wrote down
Then, for each one, where the copies live. This is the part that is worth doing honestly, because the answer is rarely "in the booking system". It is the booking system, plus an email thread, plus a WhatsApp or WeChat conversation, plus a spreadsheet somebody made for the season, plus a guide's phone.
Four copies of a passport scan in four places is the normal state of a small operator, and nobody decided it. It just happened one booking at a time.
Collect less, and the rest gets easier
This one repays the effort more than the rest of the post put together, for a mechanical reason: data you never took cannot leak, cannot be requested, and needs no retention rule.
Two questions before any field goes on a form. Do we need this to deliver the trip? And do we need it after the trip?
Most passport scans fail the second question. The permit was issued, the hotel took the details, the booking is done — and the scan is still sitting in an inbox two years later, doing nothing except being available to whoever eventually gets into that inbox. Medical notes are the same shape: necessary in the week of the trip, rarely necessary in November.
Dietary and mobility information deserves particular care, because it can reveal things about a person's health that they would not have volunteered in any other context. Collect it for the trip, use it, and do not keep it as customer history.
Tell them plainly, at the moment you ask
Consent in practice is not a document nobody reads. It is a plain sentence next to the field, in Chinese, saying what you are collecting and why: that the passport number goes to the permit office, that the phone number is for reaching them on the day, that the dietary note goes to the restaurant.
Two things make this real rather than decorative. Say it where the information is being asked for, not only in a policy page. And do not use the data for something the sentence did not describe — a phone number given so the driver can find them is not a marketing list.
If you want to send them things later, ask for that separately, and make it easy to decline.
Keep it for a stated period, then actually delete it
"As long as necessary" is the standard phrasing and useless as an instruction. Turn it into numbers you pick and can defend.
A workable starting point for a small operator, adjusted to whatever your accountant and insurer require:
- Identity documents: delete once the thing they were for is done. Days, not years.
- Trip-specific notes — dietary, medical, mobility: delete after the trip, unless something happened on it. If there was an incident, that note stops being trip admin and becomes part of the incident record, and how long it lives is your insurer's call rather than yours.
- Booking and payment records: keep for whatever period your tax and accounting obligations require, which is the one place a longer period is easy to justify. A card number is not one of those records — the accounts need the amount, the date and a reference — so if one got written down somewhere, that is the item to delete today rather than at the end of the season.
- Chat history: decide something. Most operators have never considered this and hold everything forever.
Then the part that makes it true: put it in the calendar. A recurring reminder to clear the previous season gets done, and a retention policy written in a document generally does not. The one thing the sweep has to skip is anything attached to an open complaint or claim.
A deletion request is a test of the inventory
Someone asks you to delete what you hold about them. The obligation varies by where you and they are, and that part belongs with a professional. What does not vary is whether you could.
If you did the inventory, this is a fifteen-minute job. If you did not, it is a search through years of email and chat with no way to know when you are finished, and "we think we got most of it" is not an answer you want to give.
That is the practical reason to keep the list: not because a regulator asks for it, but because the day somebody asks, the list is the difference between a task and a panic.
The parts that need a professional
Cross-border transfer. If you are outside China holding data about people in China, it has crossed a border by definition. There are rules about this and they are technical, and no habit in this post resolves them. What you can do is know where the data physically sits, use providers you can name, and not scatter copies into services nobody chose deliberately.
Anything at scale, or anything sensitive. Health information, biometric data, children's data, or volumes beyond a small operator's — these change the picture, and the right move is to ask somebody qualified rather than read another blog post.
A breach. If data gets out, there are notification obligations, and improvising is expensive. Knowing in advance who you would call is most of the preparation.
The one that is not about data at all
The most common place customer information sits in a small operator is a staff member's personal phone — their WeChat, their photo roll, their notes.
That is a data question and also a business one, because when they leave, all of it leaves with them and none of it can be deleted at your request. We wrote about the commercial half of that in WeChat Work vs personal WeChat; the data half is the same problem seen from the other end, and it has the same fix.
Where CN1X fits
Where we handle enquiries for you, the conversations sit in an account registered to your company, so the record is yours and stays yours. We ask for the fields a booking needs and we do not build forms that collect things because they might be interesting later.
We are not your data-protection advisor and will not pretend to be one. Our part is narrower: flagging a form that collects more than the job requires, and writing the Chinese sentence that tells the customer what you are taking and why. If you are about to put a booking form in front of Chinese customers, send us the fields — we will mark the ones we would drop and why.
More from the blog
Korean and Japanese Operators Selling into China
A short flight changes the customer. What long-haul advice gets wrong for operators in Korea and Japan, and which barriers you have already cleared.
What a Month of Running the Account Actually Looks Like
"What is the ongoing commitment" is really a question about calendars. Where the hours land, who they land on, and which parts cannot be batched.
What You Supply Before a Mini Program Build Starts
The quote is signed and then three weeks pass with nothing visible happening. Almost always the build is waiting on things only you can hand over.


