India's data protection law finally has teeth. The Digital Personal Data Protection Act, 2023 has been on the books for two years, but it stayed mostly theoretical until the DPDP Rules, 2025 were notified on 13 November 2025 and published in the Gazette a day later. Organisations now have an 18-month window, running to 13 May 2027, to bring their data practices in line — and for most Indian offices, factories, and campuses, the single largest stream of personal data collected every day is the one at the gate: names, phone numbers, photographs, vehicle numbers, ID copies, and the reason someone walked in.
Security teams have historically treated the visitor register as a security artifact, not a data collection exercise. That distinction no longer holds. A phone number written in a logbook, a driver's licence photographed at the boom barrier, an ID scanned and filed — all of it is personal data under the Act, and collecting it without a clear notice, without a lawful basis, and without a plan for how long you'll keep it is now a compliance exposure, not just an operational habit.
This article lays out what an admin, HR head, or security manager should actually say to a visitor before collecting their data, and what should — and shouldn't — end up in your records. It draws on the DPDP Act and Rules as currently notified, but it is not legal advice; consult counsel for how the law applies to your specific facility and data flows.
Why gate consent is now a compliance question
Every visitor who walks through your gate, every contractor who reports for a shift, every delivery rider who drops a package is a data principal under the DPDP Act, and your organisation — the company running the site — is the Data Fiduciary responsible for how that data is collected, used, and retained. If you use software to manage check-ins, the vendor providing that software is a Data Processor, acting on your instructions. That split matters: the obligation to get consent right, to justify retention, and to respond to a data breach sits with you, the fiduciary, even when a vendor's servers are doing the storing.
This is worth internalising before you touch your check-in form, because it reframes a familiar question. "What fields should we collect at the gate?" is no longer just a security design choice — it's a legal one, and the answer has to be defensible if a regulator, an auditor, or a visitor ever asks why you hold a piece of information about them.
What the DPDP Act actually asks for
Free, specific, informed, unambiguous
The Act's consent standard has four words worth memorising: consent must be free, specific, informed, and unambiguous. In gate terms, that means:
- Free — a visitor shouldn't be denied entry outright for declining a purpose unrelated to the visit (for example, marketing contact), though you can still require the minimum data needed for safety and access control.
- Specific — the notice has to name the purpose (visitor identification, premises safety, host notification) rather than a vague "for verification."
- Informed — the visitor needs to actually see what's being collected and why before they hand over an ID or accept a photo capture.
- Unambiguous — a signature, a tap on "I agree," or an equivalent affirmative act, not silence or a printed notice nobody reads.
Retention: not forever, but not zero either
The Rules require personal data, along with traffic data and logs, to be retained for at least one year after the purpose of processing is served, unless a longer period is mandated by some other law your facility falls under — a factory safety register requirement, for instance, or a contractual audit clause. Once that purpose and any applicable retention period is over, the data is expected to be erased. This cuts both ways: keeping visitor logs indefinitely "just in case" is not a safer posture, it's a liability, and deleting them within days of a visit can conflict with the minimum retention floor. Getting this window right is a policy decision your organisation has to make deliberately — we've written more on how long gate records should realistically be kept.
What to say to a visitor at the gate
The notice, in plain language
A visitor privacy notice doesn't need to be a legal document read aloud at the security desk. It needs to be short, visible before data is captured, and worded so a delivery rider or a job applicant understands it in ten seconds. A workable notice for a corporate office or factory gate covers:
- What is being collected (name, phone number, photo, ID type and number, vehicle number, purpose of visit).
- Why it's collected (site security, host notification, statutory safety records where applicable).
- Who can access it (security team, host, admin — not sold or shared externally).
- How long it's kept, in plain terms ("retained as required under our data policy and applicable law").
- How to ask a question or raise a concern about their data (a contact point, not just a QR code).
A sample check-in script
If your front desk or security guard is expected to say something rather than just point at a screen, keep it to one line: "We're going to take your photo and phone number for entry into the building — this is stored for security records and shared only with your host." That single sentence, backed by an on-screen notice the visitor actually reads and accepts, satisfies the spirit of "informed and specific" far better than a printed sign nobody looks at.
What to store — and what to leave out
Fields worth keeping
For most Indian offices, factories, and warehouses, a defensible minimum set includes name, phone number, photo, host or department, purpose of visit, vehicle number if applicable, and a timestamped entry-exit record. For regulated sites — manufacturing units that answer to factory inspectorates, for instance — you may need to retain more, and it's worth checking current guidance from bodies like the Directorate General Factory Advice Service & Labour Institutes on what safety-related visitor and worker records your industry expects.
Fields to think twice about
- Full ID document copies — a driving licence number may be enough; a scanned copy of the full document, stored indefinitely, increases your exposure without a matching security benefit for most office visits.
- Aadhaar numbers — collecting and storing Aadhaar at a gate desk carries its own regulatory sensitivity; most facilities don't need it and shouldn't ask for it as a default.
- Health or medical details — unless your site has a specific screening requirement, don't add fields for this; broader guidance on personal data handling is available from the Ministry of Electronics & Information Technology, which is worth reviewing before you expand any data collection form.
The general principle from the Act — data minimisation — is simple to apply at a gate: collect what you need for the visit and for safety, not what might be "useful someday."
Who is accountable when something goes wrong
Because your organisation is the Data Fiduciary, you carry the primary obligation to justify collection, secure the data, and respond if something goes wrong — even if a third-party platform is technically holding the records. If your visitor software vendor is breached, you are still the one who has to notify the Data Protection Board and the affected visitors; the vendor's job is to process data on your instructions and support that response, not to absorb the obligation. This is why vendor selection questions — where servers sit, who can see an ID photo, whether exports are logged — aren't just IT questions. They're part of how you discharge your own fiduciary duty. It's worth reading through where your provider's infrastructure and access controls actually stand before you assume the compliance box is ticked.
Consent withdrawal, corrections, and breaches
The Act is explicit that withdrawing consent must be as easy as giving it. For a one-time gate visit this is less about a button to click and more about honouring a visitor's request to not be re-contacted or to have incorrect details corrected before their next visit. Build a simple process: a phone number or email a visitor can use to ask "what do you have on me, and can you correct or remove it," and make sure whoever staffs your front desk knows this request exists and where to route it.
On breaches, the requirement is direct: if personal data your organisation holds is compromised, you must notify the Data Protection Board and the affected individuals. Penalties for the most serious failures under the Act can run up to ₹250 crore per instance, which is enough reason to treat gate data with the same rigour as financial or HR records, not as an afterthought bolted onto reception.
What good gate software should actually show you
Whatever platform you use — whether it's a dedicated visitor management system or a spreadsheet at the security desk — you should be able to answer these questions on demand: what notice did this visitor see, when did they accept it, who has viewed their ID photo since, and what happens to their record after the retention period ends. VizPass, for instance, shows each company's own privacy notice on the check-in screen and records the timestamp of acceptance along with a hash of the exact wording shown, so you have proof of what was agreed to, not just that something was. Role-based access limits who can view ID images and phone numbers, exports are permission-controlled and logged, and records are never silently deleted — they're reversed with a stated reason, preserving an audit trail. Data sits on servers based in Mumbai. It's worth being direct about limits too: VizPass is not currently ISO 27001 or SOC 2 certified, and it does not yet have an automatic retention purge — if your policy depends on records being deleted automatically at a fixed date, that step today has to be handled manually or through your own process, not assumed to happen on its own.
Conclusion
Consent at the gate isn't a formality to get past before someone reaches reception — under the DPDP Act and its 2025 Rules, it's a documented step your organisation has to be able to defend, with a clear notice, a lawful retention window, and a record of who can see what. Start by rewriting your check-in notice in plain language, trim your data fields down to what the visit actually requires, and confirm your current process — paper or digital — can show proof of consent and a defensible retention policy if asked. If you want to see how a visitor and gate system that logs consent, controls access by role, and keeps an audit trail actually works day to day, book a walkthrough and bring your current check-in form to compare against it.