If there’s a legal requirement to store passport numbers you can store them. It’s one of the cases where you don’t need consent. You still have to store them in a safe fashion and the customer still retains most of the rights under GDPR (information about what you store and for which purpose, etc.)
Can GDPR be used as an audit mechanism for breached passport numbers? And if so, what would that process look like? Can hotels be fined if they’re found to not be GDPR compliant?