Visitor Data and India's DPDP Act 2023: A Practical Checklist
Reception collects personal data on every person who walks in. Under the DPDP Act that makes your front desk a processing activity — here is what that requires in practice.
By Pass Point Team
Key takeaways
- Visitor check-in is personal data processing, and the DPDP Act's consent, purpose, and retention principles apply to it.
- Collect the minimum that serves a stated purpose — every optional field you add is a field you must later justify, secure, and delete.
- The controls that matter operationally are consent capture, configurable retention, and working export and delete tooling.
India's Digital Personal Data Protection Act 2023 governs how organisations handle the personal data of individuals. Most compliance attention goes to customer databases and marketing lists, and reception is quietly overlooked. It should not be: the front desk collects names, phone numbers, employers, photographs, and signatures from people who are not customers and often have no other relationship with the organisation at all.
This post is a practical checklist rather than legal advice. The Act's obligations are broader than what follows, and how they apply depends on your organisation. Treat this as a starting point for a conversation with whoever owns compliance where you work.
Reception is a processing activity
The moment a visitor writes their name and phone number at your desk, you are collecting personal data. That triggers the same broad expectations that apply anywhere else you handle it: you should have a purpose, you should collect only what serves that purpose, the individual should understand what is happening, and the data should not outlive its usefulness.
None of this is exotic. It is difficult with paper mainly because paper cannot enforce any of it.
The checklist
1. Write down why you collect each field
Go through your check-in form field by field and state the purpose of each one. Name and host serve a security and wayfinding purpose. Phone number serves notification. Photograph serves identification at the badge. If a field has no stated purpose — and there is usually at least one, inherited from a template — remove it. Data minimisation is the cheapest compliance control available, because data you never collected requires no protection, no retention rule, and no deletion.
2. Capture consent where consent is the basis
Where you rely on consent, it needs to be a real, recorded act rather than an assumption. In a digital flow this is straightforward: the notice appears during check-in, the visitor agrees, and the agreement is stored with the visit record along with what they agreed to and when. That last part matters — a consent record without the version of the notice it applied to is difficult to rely on later.
3. Set a retention period and enforce it automatically
Decide how long a visit record needs to exist. Security investigations, contractor compliance records, and general footfall analytics all imply different periods, and the honest answer for most visitor data is shorter than sites assume. Then configure the system to delete on that schedule. A retention policy that relies on someone remembering to run a purge is a policy that quietly expires.
4. Make export and deletion actually work
If a visitor asks what you hold about them, you need to find it and produce it. If they ask you to delete it, you need to do so without dismantling records you are separately required to keep. Test this before you need it — pick a visitor from last month and try to fulfil both requests end to end. The gap between the policy and the tooling usually appears within about ten minutes.
5. Restrict who can read the visitor log
The reception book's core flaw is uncontrolled access. Digital does not automatically fix this — a shared login on a front-desk tablet reproduces the same problem with better handwriting. Give individuals their own access, scope it to the sites they are responsible for, and remove it when they change role.
6. Know where the data lives and who else touches it
If your visitor system sends host notifications by email, prints badges through a local printer, or exports to an access control system, each of those is a place visitor data goes. Map them. You cannot describe your processing accurately if you only account for the database.
What to look for in a system
Compliance is mostly a matter of whether the tooling lets you do the things above without heroics. Concretely, that means configurable fields so you can minimise collection, consent capture built into the check-in flow, retention controls that run on a schedule, per-user access rather than a shared front-desk login, and export and delete tooling that works on an individual record.
Pass Point is built around privacy-by-design principles with configurable consent capture, data-retention controls, and export and delete tooling. If you need documentation specific to your compliance programme, our team can provide it — get in touch and tell us what your assessors are asking for.
Frequently asked questions
Visitor check-in collects personal data about identifiable individuals, so the Act's general principles around purpose, consent, and retention are relevant to it. Exactly how they apply depends on your organisation and the basis on which you process the data, which is a question for your compliance or legal team rather than a blog post.
The Act does not set a fixed number of days for visitor logs. The operative principle is that personal data should not be retained longer than it is needed for the purpose it was collected for. In practice that means deciding a period you can justify against your stated purpose, documenting it, and — critically — configuring your system to enforce it automatically rather than relying on manual clean-up.
Not necessarily — consent is one basis for processing, not the only one, and some visitor data may be handled on another basis depending on your circumstances. The more useful discipline is minimisation: for each field, state the purpose it serves. Fields that survive that test are easier to justify on any basis, and fields that do not should not be collected at all.
See Pass Point at your front desk
Digital check-in, host notifications, and a searchable visitor log. Start a 14-day free trial — no credit card required.