Visitor management system and DPDP: what to collect, mask and keep for a year
Running a visitor management system under DPDP: notice at the desk, Aadhaar masking, photos for 90 days, a minimal entry log for one year and erasure requests.
Last checked 5 min read
The visitor register used to be a thick notebook at the gate: name, phone, company, whom to meet, time in, time out, signature. Digital visitor systems collect far more: a photo, an ID number, sometimes a face template, a vehicle number. Under the DPDP Act all of that is personal data. Running a visitor management system under DPDP is mostly about collecting less, keeping each item only as long as it is needed, and being able to explain both.
Visitor management system DPDP basics: the dates
The Digital Personal Data Protection Act came with Rules notified on 13 November 2025. The duties that matter for a reception desk, notice, security, breach reporting, retention and erasure, apply from 13 May 2027. That gives you about seven months to set the system up properly.
Who is responsible? The company running the premises is the data fiduciary. A visitor software vendor is a processor acting on its behalf.
Notice at the desk: the visitor register privacy line
A visitor who types their name and phone into a kiosk is giving those details voluntarily for the visit. The Act treats that kind of processing as a legitimate use, so a consent tick box for the basic entry is not the point. What visitors do need is a clear, short notice they can see before they hand over details:
We record your name, phone, host, and time in and out to manage visits and site safety. Photos and ID details are deleted after 90 days. A basic record of your visit is kept for one year, as the law requires. Ask reception to see or delete your data.
Show it on the kiosk, on the pass link and at the desk. If you want to keep anything beyond the visit itself, such as the last four digits of an ID for repeat visitors, ask for a separate yes.
Aadhaar masking for visitors
Reception desks are one of the commonest places Aadhaar is over-collected. Three rules keep you safe:
- Do not make Aadhaar the only ID. Accept a driving licence, PAN, passport or company ID.
- No photocopies. UIDAI has publicly cautioned against sharing Aadhaar photocopies, and the law says the number must never be displayed publicly.
- Keep only the last four digits. UIDAI's masked Aadhaar shows only those. If you need to verify identity, the Aadhaar Secure QR can be checked offline without storing the full number.
Visitor data retention: the one-year rule
Rule 8(3) of the DPDP Rules is the part most visitor systems miss. From 13 May 2027, a data fiduciary must keep personal data, traffic data and "other logs of the processing" for at least one year from the processing, for purposes listed in the Rules' Seventh Schedule, which are about requests from the State. After that, it erases them unless another law requires longer.
A check-in is processing, and the visit row (who came, whom they met, when) is both the personal data and the record of that processing. So a flat "delete everything after 90 days" policy would breach the rule for the log part.
The sensible split, and the one we recommend:
| Item | Keep for | Why |
|---|---|---|
| Photo, ID image, signature, vehicle number, notes | About 90 days | Needed for security on recent visits, not for a year |
| Minimal entry log: name, phone, host, site, time in and out | One year from the visit | Rule 8(3) |
| Anything else | Delete as soon as the visit is over | No purpose left |
The literal words of Rule 8(3) could be read to cover photos too. We think the minimal log meets the rule's purpose, and say so openly; a company that wants to be stricter can keep media longer. The year-long copy should be locked away, not available to reception, and used only for the purposes the Rules list.
When a visitor asks you to delete their data
Under the Act, erasure gives way to "compliance with any law", and Rule 8(3) is law. So from 13 May 2027:
- At once: delete the photo, ID details, signature, vehicle number and notes; remove the visitor from every list, search and report.
- Keep, locked: the minimal entry log until one year after the visit, reachable only through a recorded legal request.
- Then: erase that too.
Until May 2027, immediate erasure of everything is fine.
A worked example from a Chennai IT park
A reception desk in a Chennai IT park handles about 150 visitors a day, roughly 40,000 a year. Under the split above, on any given day the system holds:
- photos and ID details for about three months of visits, around 10,000;
- minimal entry logs for the last year, around 40,000, locked from everyday use;
- nothing older, except entries under a recorded legal hold.
That is a far smaller target than five years of photos and Aadhaar numbers in a shared drive, which is what many older systems quietly accumulate.
Checklist for reception and admin
- Put up the notice on the kiosk, pass and desk.
- Accept IDs other than Aadhaar; keep the last four digits at most.
- Set retention: media around 90 days, entry log one year.
- Make erasure requests a two-step job: immediate deletion, then a locked log.
- Restrict who can export visitor data, and record every export.
- Add visitor data to your breach runbook.
Employee data follows the same Act with different rules; see the DPDP Act for HR. Gate and security teams also deal with company assets leaving the premises, covered in asset physical verification.
Vatsin VMS shows the notice at check-in, keeps only the last four digits of an ID, can check an Aadhaar Secure QR, purges photos and IDs on the company's schedule, and handles erasure requests with a legal hold. From the May 2027 date, an erasure request leaves only a locked minimal record of the visit, deleted a year after it.