Go to Main Contents

:: Industry developments

Real name data management for the WiFi certification system of hotel and hotel: retention, de-sensitivity and destruction of guest information

The real name is a mobile phone number, ID card, room number, name, and name of the guest. This information is a sensitive asset. Many hotels focus on how to make a real name, but not on the real name.

Your position:Home > Content Centre > Industry News > > Text

The real name is the number of the guest, his identity card, his house number, his name, and the information is a sensitive asset. Many hotels focus on how to make a real name, but not exactly what they do. The real name is the name that manages what, where, who can see, how long it lasts, how long it's sold. It protects the guest and the hotel itself. The real name is only the starting point, the end point, and the end point is the end, and it does not work, and it is like stoking a bunch of sensitive information into those people.

Collections are only required to be complied with

The real names are not as many as possible, but only the required and operational requirements: mobile numbers are used for text message authentication, identity cards are used for real name registration, and names of houses are used for name certification. Do not take extra information, the more it is received, the greater the responsibility and disclosure. Minimizing is the first step in data governance. For every field you receive, there is an additional duty to protect, and a point of accountability when leaks.

Transfer and storage are to be encrypted in isolation

Real name information is encrypted in transmission and storage, and the real name library should be kept independently of ordinary business logs. The access control is sent through an encryption channel. Putting the real name data together and the general Internet records in a clear way will be leaked over large areas once they are towed. Segregation encryption is not a technical display; it is a key to holding the loss when the leak occurs, at least without leaving a single explicit message.

The retention period is now over.

The logs and real names data are kept 60 or 180 days by statute, with their expirations automatically destroyed, not indefinitely. Many items are stored only for sale, with the database growing in size and risk increasing. The retention is an obligation, destruction is also an obligation, and neither part of them should be left unattended.

Showing off-mind access leaves a mark.

The front desk, the transport interface, does not show full ID numbers, and the de-sensitivity. Whoever can find out what is known and what is checked leaves an audit trail. The real name information is not anyone who wants to see it, and every visit is traced back to someone. De-esensitization audits, with internal leaks of mouths.

Comply with data formats for public security

The data sent to the public security 32 platform are in regular format, and all the information, Internet access time, IP addresses are authenticated. Foreign visitors’ passport information is processed at borders without opening an unauthorized interface. Console compliance is not just a pusher; it is a push-through that is in the right form and range.

The responsibility to leak is finally at the hotel.

Once the real name data is leaked, the board hits the hotel, not the system manufacturer. So data governance is a hotel's own business, and it cannot be used to dump hands because of certification systems. Regular check for access marks, whether Zazone has been effective or destroyed is the responsibility of the hotel operation.

Governance is auditable and retraceable

Data governance is not done once, but it needs to be audited: who checks when, whether or not they are running on time, and whether the de-sensitivity strategy has been changed. Audits can only detect a quiet deterioration in governance, such as someone turning off desensitization without recovery. Re-discovery returns governance gaps to rules, without re-interpreting; the same problem will appear again next time.

Data are managed in a hierarchical manner

The real name data also contain a slight weight: the identity card number, passport number, mobile phone number, and the house number are relatively low. After graded, different levels of protection and access approval cannot be given to all the most severe (impact efficiency) or relaxed (risk-high). Ranking makes governance both manage risks and not stifling forward processes.

Foreign passport information needs to be handled in a special way.

Passport information received by hotels abroad, covering the boundaries of cross-border data and personal information, is handled with greater caution: collection is strictly required for compliance, encryption levels are higher for storage and transmission, and the same marks are left in retention and destruction. The passport cannot be stored as a regular ID.

Someone's got to be responsible for governance.

Data governance cannot be built on a system that automatically runs, but it has to be looked at: who is responsible for the security of real-name data, how often does an audit visit and destruction go off on time? Responsibility falls on people, and governance does not get forgotten when busy. Many hotel systems are well equipped, but no one regularly looks at audit trails, and governance slowly deteriorates to a virtual vacuum.

Governance is subject to regular health inspections.

Data governance cannot be completed without regular health checks: whether the de-esensitization strategy has been modified, whether destruction tasks have run on time and if unusual visits have been stopped. The inspections bring back degraded governance. The inspection frequency and duty bearers write into the operations manual to avoid being busy and skipping.

Real-name data are well managed, residents feel comfortable and hotels protect themselves. It and real-name compliance and how it is realized are two things: compliance, what a real name to be, governance and how the data can safely be destroyed after real names.

Access Program I'll be right back. Telephone counselling