Your reception desk collects names, phone numbers, photographs, ID details, vehicle numbers and the name of the person each visitor came to meet. That is personal data, gathered dozens of times a day, usually by whoever is on shift.
India's Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 put rules around that. Most coverage of those rules is written for CISOs and legal teams. This guide is written for the people who actually own the front desk.
It covers what the law applies to, what changes at the desk, how long you can keep visitor records, what the deadlines are, and what to ask your vendor. Every date, rule number and penalty figure below is linked to its source.
|
Is your visitor management DPDP-ready? VizMan is built for Indian offices, factories and hospitals — with built-in consent capture, role-based access and automated data erasure. Book a free demo → |
Does the DPDP Act apply to your visitor register?
Almost certainly yes — but not for the reason most people assume. The Act applies to digital personal data. Under Section 3 of the DPDP Act, it covers personal data collected "(i) in digital form; or (ii) in non-digital form and digitised subsequently."
That second clause is the one that catches most Indian offices. A paper register sitting in a drawer and never touched again is outside the Act's scope. A paper register that someone photographs, scans, or types into Excel at month-end is inside it, from the moment it is digitised.
| How you record visitors today | In scope of the DPDP Act? |
|---|---|
| Paper register, never digitised, never photographed | Not covered by the Act (other duties may still apply) |
| Paper register, typed into Excel or scanned for reporting | Covered — the digitisation brings it in |
| Photo of the register page shared on WhatsApp with the admin team | Covered |
| Tablet or kiosk check-in, or any visitor management software | Covered |
| Gate pass printed from a system, with a record retained | Covered |
So the honest answer to "are paper registers illegal?" is no — nothing in the Act or the Rules bans a notebook. But the notebook is rarely the end of the process, and the moment it is digitised, every obligation in this guide attaches.
What counts as visitor personal data?
Anything at the desk that identifies a person. In a typical Indian office or plant, that is more than people expect.
| Field collected at the gate | Why it is usually collected | Notes |
|---|---|---|
| Full name | Identification, audit trail | Core personal data |
| Mobile number | OTP, contact during emergency | Also a marketing risk if reused |
| Photograph | Badge, security verification | Higher sensitivity; needs a clear purpose |
| ID proof number or copy | Identity verification | Consider whether a number is needed at all, or just a visual check |
| Vehicle registration number | Parking, gate control | Identifies an individual in most cases |
| Host name and department | Routing, approval | Personal data about your own employee |
| Time in / time out | Security, contractor hours | Behavioural record |
| Reason for visit | Screening | Can reveal sensitive context, e.g. in hospitals |
| Health declarations | Site safety rules | Treat with particular care |
The DPDP Act does not use a separate "sensitive personal data" category the way the older SPDI Rules did. But a photograph, an ID copy and a reason-for-visit field held together in one log is a meaningful concentration of data about a person, and it should be handled accordingly.
Is your organisation a Data Fiduciary for visitor data?
Yes. If you decide why visitor data is collected and how it is processed, you are the Data Fiduciary. That is true whether you use a notebook-plus-Excel process or enterprise software.
Your visitor management software provider is typically a Data Processor — they process visitor data on your instructions. That distinction matters in two ways. First, the legal obligations sit with you, not the vendor. Second, Rule 6 expects contractual safeguards binding your processors to equivalent protection, so the contract with your VMS vendor is itself a compliance artefact.
What does the DPDP Act actually require at the reception desk?

Six things change. None of them require a legal background to implement.
Give a notice the visitor can read
Section 5 of the Act requires a notice accompanying the request for consent, telling the person what data you are collecting, the purpose, how to exercise their rights, and how to complain. Rule 3 adds that it must be in clear, plain language, standalone and understandable, and available in any of the languages listed in the Eighth Schedule of the Constitution on request.
In practice: a short, readable notice on the check-in screen or a printed card at the desk. Not a paragraph of legalese in six-point type taped to the counter.
Take consent that means something
Section 6 requires consent that is "free, specific, informed, unconditional and unambiguous with a clear affirmative action", and limited to the data necessary for the stated purpose. Visitors can withdraw consent, and withdrawal must be as easy as giving it.
Collect only what the visit needs
The necessity limit in Section 6(1) is the cheapest compliance win available to a facilities team. Walk through your check-in form field by field and ask what each one is for.
Erase when the purpose is served
Under Section 8(7), personal data must be erased when the Data Principal withdraws consent, or as soon as it is reasonable to assume the specified purpose is no longer being served — whichever is earlier.
Control who can see the visitor log
Rule 6 sets out reasonable security safeguards: encryption, masking or tokenisation, access control, logging and monitoring, retention of those logs for at least one year, backups, and contractual safeguards on processors.
Name someone visitors can complain to
Section 8(9) requires you to publish the business contact information of a Data Protection Officer, if applicable, or of a person who can answer questions about the processing.
How long can you keep visitor data under the DPDP Act?
There is no fixed retention period for visitor records. The rule is purpose-based: keep it while the purpose is live, erase it when the purpose ends, per Section 8(7).
| Data type | Suggested basis for the period | Who should sign off |
|---|---|---|
| Routine visitor record | Shortest period that supports security review | Admin + legal |
| Contractor entry log | Work order duration + statutory record-keeping | HSE + legal |
| CCTV linked to visitor entry | Existing CCTV policy, aligned to purpose | Security head |
| Access and activity logs | Minimum one year (Rule 6) | IT |
| Marketing consent | Until withdrawn | Marketing + legal |
What happens if visitor data leaks?

You have to tell people, fast. Under Rule 7, a Data Fiduciary must intimate each affected Data Principal without delay, and notify the Data Protection Board without delay as well — then follow that initial notification with a fuller report, containing the full particulars of the breach, within 72 hours.
| Failure | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards | Up to ₹250 crore |
| Failure to notify a personal data breach | Up to ₹200 crore |
| Breach of other provisions of the Act | Up to ₹50 crore |
What are the DPDP deadlines?
| Date | What comes into force |
|---|---|
| 13 November 2025 | Rules 1, 2 and 17 to 21 — Data Protection Board established |
| 13 November 2026 | Rule 4 — Consent Manager framework |
| 13 May 2027 | Rules 3, 5 to 16, 22 and 23 — notice, consent, security, breach reporting, erasure |
13 May 2027 is the substantive compliance deadline for your reception desk — not November 2026.
Reception desk DPDP readiness checklist

- List every place visitor data currently lives
- Identify which are digitised, and therefore in scope under Section 3
- Review each check-in field and remove anything the visit does not need
- Write a short, plain-language notice and display it where the visitor checks in
- Separate security consent from any marketing consent
- Replace shared logins with named, role-based accounts
- Draft a retention schedule with a stated purpose for each line
- Confirm you can actually delete a specific visitor's record on request
- Publish a contact point for visitor data questions and grievances
- Check your VMS contract has processor safeguards and breach-notification obligations
- Train gate and reception staff — they are the ones taking consent
|
See VizMan's DPDP-ready check-in flow in action Go through this checklist with us on a live demo — we'll show you exactly how VizMan handles each item before May 2027. Book a 30-minute session → |
What to ask your visitor management vendor
- Where is our visitor data hosted, and is it stored in India?
- Is visitor data encrypted at rest and in transit?
- Can we configure retention periods and automatic deletion by visitor type?
- Can we delete an individual visitor's record on request, and is that deletion logged?
- Does the system support role-based access so reception, hosts and admins see different data?
- Are access and activity logs retained for at least one year, per Rule 6?
- Will you sign a data processing agreement with DPDP-aligned processor obligations?
- What is your breach notification commitment to us, in hours?
- Can we configure the check-in notice and consent text ourselves?
- Can consent for security be captured separately from consent for marketing?
Where a visitor management system helps
VizMan supports several of the operational requirements above with role-based access for Admin, Security, Reception and Host; OTP verification at the gate; digital visitor passes and ePasses; dashboard and analytics so you know what visitor data you hold; and offline visitor management for sites with unreliable connectivity.
Read our privacy policy, and our earlier piece on what happens to visitor data after the visit. The requirements land differently by sector: a corporate office is mostly managing volume; a factory is managing contractors and statutory registers; a hospital is managing a reason-for-visit field that can reveal a patient's condition.
The short version
The DPDP Act does not care whether your visitor record starts on paper or on a tablet. It cares what you collect, why, who can see it, how long you keep it, and what you do when it leaks.
Most reception desks fail on two of those: they collect more than the visit needs, and they keep it forever. Both are fixable before 13 May 2027, and neither requires a large budget.
|
Want to see what a DPDP-ready check-in flow looks like in practice? Book a VizMan demo and bring the ten vendor questions with you. |
This guide explains the law in plain English. It is not legal advice. Confirm your retention periods and sector-specific obligations with your own legal counsel. Legal position verified against sources as at 15 September 2026.