I'm only half joking: I used to work in payments, hotels didn't care about PCI. Full card numbers stored everywhere.
Are you 'avin a laugh mate?
A photocopy of my passport is going nowhere and is shreadded afterwards. An electronic copy..... God lord.
The GDPR also requires data deletion once you no longer need it; physical as well as electronic. This is common sense, and why some organisations don't do this is simply mind boglling.
If you think photocopies kept in some folder accessible to anyone working in the hotel, with a promise to delete it at some point, is "secure" in any way, I don't know what to tell you.
When I toured apartments they would often take a photocopy of my ID. Okay, overkill. But realistically I have no idea where that photocopy is stored.
Probably in a OneDrive somewhere to this day.
Rather a paper data breach exposed to a few hotel employees than eletronic data exposed to the entire planet!
This said, the police already has a database with these info, and it likely is somehow already on the network, so adding an api (if done properly) would not dramatically alter the exposure profile.