Skip to content

Consent at the gate: what to say to a visitor, and what to store

A practical guide to consent, notice, and retention for visitor data under India's new DPDP Rules

VizPass team 24 September 2026 9 min read
Share:

India's data protection law finally has teeth. The Digital Personal Data Protection Act, 2023 has been on the books for two years, but it stayed mostly theoretical until the DPDP Rules, 2025 were notified on 13 November 2025 and published in the Gazette a day later. Organisations now have an 18-month window, running to 13 May 2027, to bring their data practices in line — and for most Indian offices, factories, and campuses, the single largest stream of personal data collected every day is the one at the gate: names, phone numbers, photographs, vehicle numbers, ID copies, and the reason someone walked in.

Security teams have historically treated the visitor register as a security artifact, not a data collection exercise. That distinction no longer holds. A phone number written in a logbook, a driver's licence photographed at the boom barrier, an ID scanned and filed — all of it is personal data under the Act, and collecting it without a clear notice, without a lawful basis, and without a plan for how long you'll keep it is now a compliance exposure, not just an operational habit.

This article lays out what an admin, HR head, or security manager should actually say to a visitor before collecting their data, and what should — and shouldn't — end up in your records. It draws on the DPDP Act and Rules as currently notified, but it is not legal advice; consult counsel for how the law applies to your specific facility and data flows.

Every visitor who walks through your gate, every contractor who reports for a shift, every delivery rider who drops a package is a data principal under the DPDP Act, and your organisation — the company running the site — is the Data Fiduciary responsible for how that data is collected, used, and retained. If you use software to manage check-ins, the vendor providing that software is a Data Processor, acting on your instructions. That split matters: the obligation to get consent right, to justify retention, and to respond to a data breach sits with you, the fiduciary, even when a vendor's servers are doing the storing.

This is worth internalising before you touch your check-in form, because it reframes a familiar question. "What fields should we collect at the gate?" is no longer just a security design choice — it's a legal one, and the answer has to be defensible if a regulator, an auditor, or a visitor ever asks why you hold a piece of information about them.

What the DPDP Act actually asks for

Free, specific, informed, unambiguous

The Act's consent standard has four words worth memorising: consent must be free, specific, informed, and unambiguous. In gate terms, that means:

  • Free — a visitor shouldn't be denied entry outright for declining a purpose unrelated to the visit (for example, marketing contact), though you can still require the minimum data needed for safety and access control.
  • Specific — the notice has to name the purpose (visitor identification, premises safety, host notification) rather than a vague "for verification."
  • Informed — the visitor needs to actually see what's being collected and why before they hand over an ID or accept a photo capture.
  • Unambiguous — a signature, a tap on "I agree," or an equivalent affirmative act, not silence or a printed notice nobody reads.

Retention: not forever, but not zero either

The Rules require personal data, along with traffic data and logs, to be retained for at least one year after the purpose of processing is served, unless a longer period is mandated by some other law your facility falls under — a factory safety register requirement, for instance, or a contractual audit clause. Once that purpose and any applicable retention period is over, the data is expected to be erased. This cuts both ways: keeping visitor logs indefinitely "just in case" is not a safer posture, it's a liability, and deleting them within days of a visit can conflict with the minimum retention floor. Getting this window right is a policy decision your organisation has to make deliberately — we've written more on how long gate records should realistically be kept.

What to say to a visitor at the gate

The notice, in plain language

A visitor privacy notice doesn't need to be a legal document read aloud at the security desk. It needs to be short, visible before data is captured, and worded so a delivery rider or a job applicant understands it in ten seconds. A workable notice for a corporate office or factory gate covers:

  • What is being collected (name, phone number, photo, ID type and number, vehicle number, purpose of visit).
  • Why it's collected (site security, host notification, statutory safety records where applicable).
  • Who can access it (security team, host, admin — not sold or shared externally).
  • How long it's kept, in plain terms ("retained as required under our data policy and applicable law").
  • How to ask a question or raise a concern about their data (a contact point, not just a QR code).

A sample check-in script

If your front desk or security guard is expected to say something rather than just point at a screen, keep it to one line: "We're going to take your photo and phone number for entry into the building — this is stored for security records and shared only with your host." That single sentence, backed by an on-screen notice the visitor actually reads and accepts, satisfies the spirit of "informed and specific" far better than a printed sign nobody looks at.

What to store — and what to leave out

Fields worth keeping

For most Indian offices, factories, and warehouses, a defensible minimum set includes name, phone number, photo, host or department, purpose of visit, vehicle number if applicable, and a timestamped entry-exit record. For regulated sites — manufacturing units that answer to factory inspectorates, for instance — you may need to retain more, and it's worth checking current guidance from bodies like the Directorate General Factory Advice Service & Labour Institutes on what safety-related visitor and worker records your industry expects.

Fields to think twice about

  • Full ID document copies — a driving licence number may be enough; a scanned copy of the full document, stored indefinitely, increases your exposure without a matching security benefit for most office visits.
  • Aadhaar numbers — collecting and storing Aadhaar at a gate desk carries its own regulatory sensitivity; most facilities don't need it and shouldn't ask for it as a default.
  • Health or medical details — unless your site has a specific screening requirement, don't add fields for this; broader guidance on personal data handling is available from the Ministry of Electronics & Information Technology, which is worth reviewing before you expand any data collection form.

The general principle from the Act — data minimisation — is simple to apply at a gate: collect what you need for the visit and for safety, not what might be "useful someday."

Who is accountable when something goes wrong

Because your organisation is the Data Fiduciary, you carry the primary obligation to justify collection, secure the data, and respond if something goes wrong — even if a third-party platform is technically holding the records. If your visitor software vendor is breached, you are still the one who has to notify the Data Protection Board and the affected visitors; the vendor's job is to process data on your instructions and support that response, not to absorb the obligation. This is why vendor selection questions — where servers sit, who can see an ID photo, whether exports are logged — aren't just IT questions. They're part of how you discharge your own fiduciary duty. It's worth reading through where your provider's infrastructure and access controls actually stand before you assume the compliance box is ticked.

The Act is explicit that withdrawing consent must be as easy as giving it. For a one-time gate visit this is less about a button to click and more about honouring a visitor's request to not be re-contacted or to have incorrect details corrected before their next visit. Build a simple process: a phone number or email a visitor can use to ask "what do you have on me, and can you correct or remove it," and make sure whoever staffs your front desk knows this request exists and where to route it.

On breaches, the requirement is direct: if personal data your organisation holds is compromised, you must notify the Data Protection Board and the affected individuals. Penalties for the most serious failures under the Act can run up to ₹250 crore per instance, which is enough reason to treat gate data with the same rigour as financial or HR records, not as an afterthought bolted onto reception.

What good gate software should actually show you

Whatever platform you use — whether it's a dedicated visitor management system or a spreadsheet at the security desk — you should be able to answer these questions on demand: what notice did this visitor see, when did they accept it, who has viewed their ID photo since, and what happens to their record after the retention period ends. VizPass, for instance, shows each company's own privacy notice on the check-in screen and records the timestamp of acceptance along with a hash of the exact wording shown, so you have proof of what was agreed to, not just that something was. Role-based access limits who can view ID images and phone numbers, exports are permission-controlled and logged, and records are never silently deleted — they're reversed with a stated reason, preserving an audit trail. Data sits on servers based in Mumbai. It's worth being direct about limits too: VizPass is not currently ISO 27001 or SOC 2 certified, and it does not yet have an automatic retention purge — if your policy depends on records being deleted automatically at a fixed date, that step today has to be handled manually or through your own process, not assumed to happen on its own.

Conclusion

Consent at the gate isn't a formality to get past before someone reaches reception — under the DPDP Act and its 2025 Rules, it's a documented step your organisation has to be able to defend, with a clear notice, a lawful retention window, and a record of who can see what. Start by rewriting your check-in notice in plain language, trim your data fields down to what the visit actually requires, and confirm your current process — paper or digital — can show proof of consent and a defensible retention policy if asked. If you want to see how a visitor and gate system that logs consent, controls access by role, and keeps an audit trail actually works day to day, book a walkthrough and bring your current check-in form to compare against it.

Frequently Asked Questions

Does a visitor tapping "I agree" on a tablet at the gate count as valid consent under the DPDP Act?

Yes, a recorded tap can count as valid consent, but only if it happens after the visitor has actually seen a notice explaining what is being collected and why — not before, and not as a pre-ticked default. Mechanically, this means the notice text and the consent action need to sit on the same screen, in the flow, so the visitor reads it before the phone number, photo, or ID field is unlocked. A gate kiosk built around visitor pre-registration can be configured to show the notice first and only enable data fields once the visitor has actively acknowledged it, with each event logged against a timestamp, the visitor's name, and the specific notice version shown. That log is what lets you demonstrate, later, that consent came before collection rather than after — which is the weak point of a paper register, where a signature at the bottom of a page doesn't clearly connect to any notice at all. It also means checkboxes shouldn't come pre-checked, and consent shouldn't be assumed just because someone walked through the gate. For the general framework on how personal data collection and consent should be handled, https://www.meity.gov.in is the relevant government reference.

Should security still photograph or photocopy a visitor's Aadhaar card or driving licence at the gate?

Only if the purpose genuinely requires it, and even then it's worth storing the ID number rather than a full image of the document. Mechanically, this is a matter of what fields a gate form is configured to ask for — a system can prompt for a licence or ID number as text without triggering a photo of the card itself. If visual verification is actually necessary, such as matching a face to a photo ID before allowing entry, the image can be captured at that moment and then excluded from long-term storage rather than filed indefinitely. VizPass allows fields to be toggled per visitor category under features, so a contractor entering a restricted area might require an ID number while a visitor attending a scheduled meeting, already vouched for by their host, doesn't need one collected at all. This follows the basic idea in the DPDP framework that you collect what a specific purpose requires, not everything a form has space for. Since Aadhaar and driving licences are government-issued identity documents, general guidance on handling this category of personal data sits with https://www.meity.gov.in, though the actual configuration of what your gate captures and stores remains a decision your team has to make for each site and visitor type.

How long should we actually keep visitor logs — names, phone numbers, photos — before deleting them?

There's no single mandated number in the Act itself, but the retention period needs to match a purpose you can state, and it shouldn't default to "forever" just because storage is cheap. Mechanically, this means setting a retention window in your gate system and having records purge automatically once that window closes, rather than relying on someone remembering to clean up a spreadsheet or a paper register once a year. A system built for this can separate what's kept for daily security operations — a rolling log of recent gate entries — from what's kept for longer-term audit or safety compliance, and apply different retention rules to each rather than treating all gate data the same way. The use cases around factory and warehouse access, for instance, often need to align gate records with safety documentation, which can mean a longer retention period than an office visitor meeting. Once the stated purpose no longer applies, the mechanism is to have the record deleted or anonymised automatically, not to keep it because it might be useful someday. Facilities with safety-record obligations should also check what factory inspection or incident-record retention expectations apply under https://dgfasli.gov.in, since gate and safety records can overlap.

What exactly should the notice at the gate say to a visitor before we collect their details?

It should state, in plain language, what data is being collected, why, and roughly how long it will be kept — not a generic "we value your privacy" line. Mechanically, this works best as a short screen the visitor sees before any field is unlocked: name, phone number, photo, vehicle number, ID number if applicable, and the reason for the visit, each listed against the purpose it serves (access control, host notification, safety record). VizPass allows this notice text to be customised per site under features, so a factory gate collecting vehicle numbers for a loading dock can show different wording than a corporate office collecting a name and phone number for a meeting. The notice doesn't need to be long, but it does need to appear before data entry, not as a line buried in a printed register the visitor signs without reading. It also helps to state who to contact if the visitor has questions about their data later, since that's part of demonstrating the notice was meaningful rather than a formality. Getting this notice right before the DPDP Rules' compliance window closes on 13 May 2027 is largely a matter of configuring the gate flow correctly once, rather than rewriting it visitor by visitor.

Do contractors, delivery riders, and daily wage workers need the same consent process as office visitors?

They need the same principle applied — notice before collection, consent logged, data minimised — but not necessarily the same form, since what you collect from a contractor differs from what you collect from a guest attending a meeting. Mechanically, this is handled through visitor categories: a gate system can apply one notice and field set to short-term visitors and a different one to recurring contractors or vendors, who might need an ID number and vehicle detail captured once and then reused on subsequent entries rather than re-collected every time. This is particularly relevant across industries like manufacturing and warehousing, where daily worker and contractor movement at the gate is high-frequency and repetitive, compared to an office where most entries are one-off. The consent and notice still need to happen, but the mechanism can be lighter for a recognised, returning contractor than for a first-time visitor, provided the original consent and notice were properly captured and the record isn't just being copied forward without update. If you're setting this up across multiple gate types, it's worth walking through the categories on a call — you can book a walkthrough to see how visitor types are configured differently in practice.

Keep reading

Know who is on your site

Free for 7 days. Add a gate, invite your hosts, and check your first visitor in this afternoon.