Skip to content

Visitor Data and the Factories Act: Two Registers, One Record

How Indian Factories Can Satisfy the Factories Act and The DPDP Act With a Single Visitor Record

VizPass Team 22 September 2026 11 min read
Share:
Illustration of a factory gate check-in kiosk representing combined safety and DPDP data protection compliance for visitor re

Every factory gate in India runs on two record-keeping habits. These habits grew up separately but now share one system. The first is decades old: the visitor or gate register. Safety officers, contractors, and factory inspectors expect to see this register. It is rooted in the Factories Act, 1948 and the state rules made under it. The second habit is new: personal data obligations now apply too. These obligations cover any organisation collecting a visitor's name, phone number, photo, or ID copy. They are codified in India's Digital Personal Data Protection Act, 2023 and its Rules. The Rules were notified on 13 November 2025. They were published in the Gazette on 14 November 2025. Organisations get an 18-month window to comply. This compliance window runs to 13 May 2027.

Most factory admins we talk to think of these as two separate problems — one for the safety file, one for the IT or legal file. In practice, they are the same event, captured at the same gate, at the same moment. A visitor signs in once. That single entry has to satisfy an inspector checking who was on the shop floor during a shift, and it has to satisfy a data protection framework that treats that visitor's phone number and photograph as personal data requiring a lawful basis, a notice, and a defined retention period. This article is about designing one record that answers to both masters, without duplicating registers or creating gaps between them. This is not legal advice — treat it as an operational starting point and confirm specifics with your compliance counsel and the applicable state factory rules. Factory inspectors reviewing shift records now expect the factory gate register DPDP compliance trail to show a lawful basis alongside the visitor's name and entry time. Factory safety teams building a new onboarding workflow should treat the factory gate register DPDP compliance requirement as the baseline, not an afterthought bolted onto security logs.

Why the Factory Gate Register Exists in the First Place

The gate or visitor register at a factory is not a formality inherited from a security guard's habit. It exists because factories are classified as hazardous or semi-hazardous workplaces under the Factories Act framework, and knowing exactly who is on the premises — worker, contractor, or visitor — is a basic safety control, not a paperwork exercise. In an emergency, evacuation, or accident, the register is often the first document an inspector or safety officer asks for, because it answers a simple question: who was inside, and when.

What the Register Is Actually Used For

  • Establishing headcount during fire drills, evacuations, or accidents
  • Verifying contractor and visitor presence against work permits
  • Supporting statutory inspections and audits by factory inspectors
  • Cross-checking against incident timelines if something goes wrong on the floor

The Directorate General Factory Advice Service & Labour Institutes, whose guidance and standards inform factory safety practice across states, is a useful reference point for understanding how safety recordkeeping expectations are framed at the national level, even though day-to-day enforcement sits with state factory inspectorates. You can see how that guidance is structured on the DGFASLI website.

The DPDP Layer: The Same Entry, a Different Set of Duties

The moment that register captures a name, a phone number, a photograph, or a copy of an ID card, it stops being purely a safety document and becomes a personal data record under the DPDP Act. Under that Act, the company running the factory or office is the Data Fiduciary — the entity that decides why and how the data is collected. If that company uses a software vendor to run its check-in process, the vendor is a Data Processor, acting on the fiduciary's instructions rather than deciding independently what happens to the data. That distinction matters when an inspector, an auditor, or the Data Protection Board asks who is accountable for a mishandled record — the answer is the company at the gate, not the software behind it. Many state factory rules never anticipated that a factory gate register DPDP compliance obligation would require defined retention limits on photographs and ID copies collected at entry. Before 13 May 2027, every plant must redesign its visitor sign-in sheet so the factory gate register DPDP compliance fields capture consent alongside the Factories Act headcount data.

What the DPDP Rules Actually Require

  • Consent must be free, specific, informed, and unambiguous.
  • A visitor must know in plain language what is collected and why.
  • This information cannot be buried in fine print.
  • Withdrawing consent must be as easy as giving it.
  • Personal data, traffic data, and logs generally need retention for one year.
  • This applies after processing is complete, unless another law requires longer.
  • Data must be erased once its collection purpose has been served.
  • Breaches must be notified to the Data Protection Board.
  • Affected individuals must also be notified of any breaches.
  • Penalties for the most serious failures can reach ₹250 crore per instance.

The Ministry of Electronics and Information Technology publishes the Act and Rules directly, and it is worth bookmarking as the primary source rather than relying on secondhand summaries — you can find it at meity.gov.in.

Where the Two Registers Overlap — And Where They Don't

This is the part that trips up most facilities teams. The Factories Act and state rules were written with a safety and inspection lens: keep the register, keep it available, don't lose track of who was inside. The DPDP framework layers a privacy lens on the same data: don't keep it longer than needed, don't let it be seen by people who don't need to see it, and be able to prove consent was given.

The Overlap

Both frameworks agree that the record should exist, that it should be accurate, and that it should be retrievable when someone in authority asks for it — an inspector on one side, the Data Protection Board on the other. Safety officers who treat the visitor log purely as an evacuation headcount tool often overlook that factory gate register DPDP compliance also demands a clear notice explaining why a phone number is being captured. A contractor's photo and ID copy logged at the gate now fall squarely under factory gate register DPDP compliance, triggering retention-period obligations that didn't exist when the register was purely a safety tool.

The Tension

Where they pull apart is retention. A safety register might need to be kept for years to support long-tail audits or accident investigations, especially where state factory rules prescribe a specific retention period. The DPDP Rules set a floor — at least one year after processing — but explicitly allow a longer period where another law requires it, and require erasure once the purpose is served. The practical reading here is not "delete everything after a year" — it is "know why you are keeping each field, and be able to justify the retention period against a specific legal or operational need." We've written a deeper breakdown of how to think about this in Visitor Data Retention: How Long to Keep Gate Records, which is worth reading alongside your factory rules before you set a retention policy.

The DPDP Rules put real weight on the notice a visitor sees before they hand over their details. It has to be specific — not a generic "we value your privacy" line — and it has to be shown before or at the point of collection, not retroactively.

What a Compliant Check-In Notice Actually Needs

The notice should clearly state what data is collected, including name, phone, photo, and ID type. It should explain why this data is collected, such as site access, safety compliance, and contractor verification. It must specify who may receive this information, including host employees, security teams, and occasionally regulators. The notice should also state how long the data is retained. It should explain how a visitor can ask questions about their data. Finally, it needs an easy way to withdraw consent. This option should not be hidden behind multiple menus.

This is one of the areas where digitising the register genuinely helps rather than just being a convenience upgrade — a paper book cannot timestamp consent or prove what wording a visitor actually saw. VizPass is built around this gap: every company using it sets its own visitor privacy notice on the check-in screen, and every pass generated records when the visitor accepted it along with a hash of the exact wording shown at that moment, so there is a defensible record of what was disclosed and when — not just that a box was ticked. If you're comparing how different systems handle this, our guide on DPDP-aligned visitor data management walks through the mechanics in more detail. Because the 18-month transition window closes on 13 May 2027, factories cannot postpone factory gate register DPDP compliance until an inspector or auditor forces the issue. HR and EHS departments should jointly review how long visitor entries are stored, since factory gate register DPDP compliance demands a defined deletion timeline that the old gate register never specified.

What a Single Digital Record Needs to Do for Both Laws

Once you accept that the gate entry has to satisfy a safety inspector and a privacy framework at the same time, the design requirements become fairly concrete.

Access Control by Role, Not by Default

ID images and phone numbers should not be visible to every guard or receptionist who can open the visitor list — only to the roles that genuinely need them, such as a security supervisor investigating an incident. Broad visibility is the single easiest way to turn a safety register into a data protection liability.

Exports That Are Permission-Gated

A CSV export of the visitor log is often the point where a well-controlled system becomes an uncontrolled spreadsheet on someone's laptop. Exports should require explicit permission, logged against the person who requested them.

Correction Without Deletion

If a record needs fixing — like a wrong contractor name or a mistyped phone number — the system should reverse or amend it. It should state a clear reason for the change. Both the original entry and the correction should stay visible. The system should not silently delete history. An inspector or auditor might later need that history to reconstruct events. Merging the gate register with a digital consent notice simplifies compliance. This is the easiest way to achieve factory gate register DPDP compliance. It avoids maintaining two separate logs for the same visitor entry. When an inspector cross-checks shift attendance against a data audit, the factory gate register DPDP compliance notation on lawful basis becomes the single thread connecting both reviews.

Hosting and Residency

Where the data physically sits matters for both frameworks. VizPass hosts its servers in Mumbai, which keeps visitor data within Indian jurisdiction — details on how that's structured are on our data hosting and residency page.

Being Honest About What the Tooling Does Not yet Do

No system should be sold as a compliance guarantee. VizPass is not currently ISO 27001 or SOC 2 certified, and it does not yet run an automatic retention purge — if your retention policy requires records to be automatically deleted after a fixed period, that step today has to be handled as a manual or scheduled process by your team, not assumed to happen on its own. Full detail on current security practices is on our security page, and it's worth reviewing before you finalise a retention SOP.

Conclusion

Treating the factory gate register and the DPDP data record as separate filing exercises causes problems. It leads to duplicate effort and, eventually, gaps. A register might satisfy an inspector but can't prove consent. Or a privacy policy might look clean but not match what the register retains. The fix isn't two systems; it's one record. That record must answer both questions correctly. It should show who was on site. It should also show the lawful basis for collecting their data. Start by mapping every field your gate register captures. Match each field against a stated purpose and retention period. Check this mapping against your state's factory rules. Compare it side by side with the DPDP Rules too. If you want to see how that mapping works in practice, explore the actual check-in flow, roles, and export controls. You can look through VizPass's features to learn more. Or you can book a walkthrough instead. This lets you work through your specific site's requirements. You'll talk with someone who has helped other Indian factories and campuses.

Frequently Asked Questions

How Long Should We Retain Visitor Data to Satisfy Both the Factories Act Register and DPDP Retention Rules?

You need one retention period per record that satisfies the longer of the two obligations, not two separate schedules. The Factories Act and state rules generally expect the gate register to be available for inspection long after the visit, while the DPDP Act asks that personal data such as a phone number, photo, or ID copy be kept only as long as the purpose for collecting it lasts, then deleted. In VizPass, retention is set once per site as a configuration on the whole entry, not on isolated fields, so the safety-relevant parts of the log (name, time in and out, host, purpose) and the personal-data parts (photo, ID copy, phone number) move through the same lifecycle instead of drifting apart. When the period you configure lapses, the entry is queued for archival or purge automatically, rather than left for someone to remember. Because the underlying visitor and gate management is described under features, you can review how the retention setting sits alongside check-in, host notification, and reporting screens. Confirm the actual number of days or years you set with your compliance counsel and your state factory rules before locking it in, since the right figure depends on your sector and the inspector's expectations, not on the software.

Can VizPass Print or Export the Gate Register in the Paper Format a Factory Inspector Expects?

Yes, VizPass can generate a printable or exportable version of the gate register in the layout an inspector is used to seeing, drawn from the same digital entries used for reporting. Each sign-in captures the fields a factory inspector typically checks — visitor name, time in, time out, host, and purpose of visit — alongside the personal-data fields required under the DPDP framework. Because both sets of fields live in one record rather than two separate logs, the export pulls directly from that single entry instead of requiring someone to reconcile a paper book against a digital file. This matters at the gate because use-cases like contractor and visitor sign-in are built around one entry point, so the register you show an inspector and the data you're accountable for under data protection law are literally the same rows, filtered for what each audience needs to see. What you keep off the printed export — such as an ID photograph, which an inspector rarely asks for — stays digital and access-controlled. Whether a printed register alone satisfies your state's specific Factories Act rule is worth checking with your safety officer, since formats and expectations can vary by state.

What Consent Notice Does a Visitor See When Signing in at the Gate, and Is It Enough for DPDP?

A visitor sees a short notice at the point of sign-in stating what data is being collected — typically name, phone number, photo, and sometimes an ID number — why it's collected, and how long it will be kept, before the entry is logged. Under the DPDP Act, this notice paired with the visitor's action of proceeding with sign-in is what establishes the lawful basis for processing that data, so the notice has to appear before the record is created, not after. In VizPass, this notice sits on the same check-in screen used for visitor pre-registration and walk-in sign-in, so it isn't a separate step a busy gate can skip. The exact wording — what counts as adequate notice, what "purpose" needs to be stated, and how specific the retention line has to be — is a legal judgment, not a software setting, so it should be drafted or reviewed by your compliance counsel. For general guidance on how personal data should be notified and handled, the Ministry of Electronics & IT publishes materials on the DPDP framework. What the system does is make sure the notice is shown consistently, at every gate, for every visitor, rather than depending on a guard remembering to mention it.

Who Should Be Able to See Visitor Photos and ID Copies Once They're Collected at the Gate?

Not everyone who works at the gate needs to see a visitor's photograph or ID copy, and VizPass separates that view from the general log. Security staff checking who's on-site during a shift can see the operational fields — name, time in, time out, host, purpose — the same fields a factory inspector expects, without needing to open the photo or ID image attached to that entry. Full access to the personal-data fields, including any uploaded ID copy, phone number, and photo, is restricted to roles you assign as admin or compliance access, and each time that fuller record is opened, it's logged. This distinction matters under the DPDP Act because access to personal data is expected to be limited to what a role actually needs, not open to anyone who can see the register. It also matters practically: a shift security guard doesn't need ID images to do a headcount, but your safety or compliance officer might need the full record if a dispute or an inspection comes up. You can see how these access roles sit alongside check-in and reporting on the features page. Exactly which roles you configure, and who counts as compliance access in your organisation, is a decision to make internally, ideally with input from whoever owns your DPDP compliance.

Can One System Manage Visitor Registers for Multiple Factory Sites Under a Single DPDP Compliance Approach?

Yes, one VizPass account can run visitor and gate registers for multiple factory or campus sites, with each site keeping its own configuration rather than a single blanket setting forced across all of them. This matters because Factories Act rules are made at the state level, so a plant in one state may have a slightly different register expectation than one in another, and your DPDP retention period might reasonably differ by site depending on what's actually collected there. In practice, each location's gate or reception logs into the same system, but the admin settings — retention period, mandatory fields, notice text — are set per site rather than inherited automatically. A central admin can still see across sites for reporting purposes, which is useful if a compliance review or an internal audit wants to check consistency between locations. Which industries and site types this applies to — offices, warehouses, factories, campuses — is covered on the industries page. What the system won't do is decide for you whether two sites should actually share the same policy; that call still depends on your state rules and your own data protection assessment, which is worth confirming with counsel before you configure it.

Keep Reading

Know Who Is on Your Site

Free for 7 days. Add a gate, invite your hosts, and check your first visitor in this afternoon.