# Visitor Data Retention: How Long Should You Keep Gate Records?
Most organisations discover they have a visitor data retention policy only when somebody asks to see it. Until that moment the answer is simply whatever the register happens to hold: eleven years of stacked notebooks in a store room, or a database from which no row has ever been deleted.
Neither is a policy. Both are a decision made by accident, and since India's Digital Personal Data Protection Act came into force, an accidental decision has become a harder thing to defend.
Why keeping everything stopped being the safe option
For most of the time gates have been logged, retention was governed by one rule: keep it, because someone might ask. Storage was cheap and the only visible risk was not having the record.
That has inverted. A visitor register holds names, phone numbers, photographs, vehicle numbers and often images of identity documents. Under the DPDP Act that is personal data, your organisation is the Data Fiduciary for it, and the Act is built around the idea that data is collected for a stated purpose and kept only while that purpose lasts.
Holding a photograph of somebody's driving licence for nine years because nobody ever built a delete process is no longer a cautious choice. It is an exposure that grows every month.
What the law actually says about visitor data retention
It does not give you a number, and you should be sceptical of any vendor who claims otherwise.
The Act works on purpose limitation and storage limitation rather than fixed schedules. Personal data is retained for the purpose it was collected for, and erased once that purpose is served and no other legal obligation requires it to be kept. The Ministry of Electronics and IT publishes the Act and the rules made under it at meity.gov.in.
That places the decision on you. Which sounds worse than it is, because it means a written, reasoned schedule is itself most of the compliance. The failure mode regulators and auditors react badly to is not choosing eighteen months instead of twelve. It is having no answer at all.
The obligations pulling the other way
Visitor data retention would be simple if only one rule applied. In practice at least four pull in the opposite direction.
Workplace safety records. For sites covered by factory legislation, records relating to people working on the premises, their induction and their presence are part of what an inspector may ask for. Safety guidance and inspectorate material is published by DGFASLI.
Incident and insurance claims. A claim arising from something that happened at your gate can surface a year or more after the event. The entry record is often the only evidence of who was present.
Financial and stock records. Material gate passes are not really visitor data. They evidence goods movement, and they tie to stock and tax records that carry their own multi-year requirements, commonly six to eight years under GST and company law.
Customer and certification audits. Client security audits and quality certifications routinely ask for twelve months of entry records, sometimes more.
The resolution is not one retention period. It is different periods for different categories, which is why a single "delete after X" setting is rarely enough.
A schedule you can defend
The following is not law and not advice specific to your site. It is a defensible starting point that most Indian workplaces can adopt and then adjust.
Ordinary visitor entries — 12 months. Long enough for an annual audit cycle and for most incidents to surface. Keep name, host, purpose, gate, in and out times.
Visitor photographs and identity document images — 3 to 6 months. This is the sharp end and deserves the shortest period you can live with. A photograph proves who came in during the window when that matters. It is rarely the thing an auditor asks for a year later, and it is the most damaging category to hold.
Contractor records — duration of engagement plus 3 years. Induction validity, insurance and the entry history should outlive the contract, because contractor disputes and claims often do.
Material gate passes — align with financial records. These follow your accounting retention, not your visitor retention. Commonly six to eight years.
Watchlist entries — review annually. A watchlist is the one place where a stale record does active harm, because it denies a real person entry on the basis of something nobody now remembers. Review it, and record who reviewed it.
Evacuation and roll-call snapshots — 12 months. Cheap to keep, occasionally decisive.
Visitor data retention you can actually execute
A visitor data retention schedule your system cannot execute is a document, not a control. Before you commit to periods, establish what your software can actually do.
Ask any vendor, in writing, three things. Can records be deleted permanently rather than hidden or flagged? Are photographs and document images deleted with the record, or do they remain in storage after the row is gone? And can you export the register before deletion, so a period ending does not mean losing an audit trail you still need?
The second question catches more products than you would expect. Deleting a database row while the uploaded image file survives in storage is a common gap, and it defeats the whole purpose of the schedule.
For VizPass specifically: the register exports to CSV, records can be permanently deleted on request, access is role-based and user actions are logged. We describe what the product does and does not do, including where the obligation stays with you, on the DPDP and visitor data page.
What to write down
The visitor data retention document itself can be one page. It needs the categories you hold, the period for each, the reason for that period, who is responsible for the deletion running, and the date it was last reviewed.
Put the review date in your calendar rather than in the document, because a policy nobody revisits ages into something worse than no policy: a written commitment you are visibly not keeping.
If you do nothing else this quarter, do the smallest version. Decide how long you keep visitor photographs, write the number down, and find out whether your current system can enforce it. That single question tends to reveal everything else that needs attention.
Related reading: what an audit-ready visitor record looks like and how we handle security.