Skip to content
Company

DPDP and visitor data: who is responsible for what

This page explains dpdp visitor data management under the DPDP Rules 2025, clarifying that companies—not security contractors—are legally responsible as data fiduciaries for gate register data, and outlines retention, consent and breach-notification duties ahead of the 13 May 2027 compliance deadline.

A visitor register at the gate is personal data the moment a name, phone number and photograph go into it — and on most plant floors nobody has decided who owns that data, who can see it, or how long it should sit in a drawer or a spreadsheet. The guard who wrote it down is not the one who should answer for it if something goes wrong. Once the DPDP Rules, 2025 take effect, that gap between who collects the data and who is accountable for it becomes a real compliance question, not just a housekeeping one.

Who is actually responsible

Under the Digital Personal Data Protection Act, 2023, your company — not the security agency, not the guard on duty — is the data fiduciary for every visitor entry logged at your gate. That means the plant or the parent company carries the legal duty to protect that data, respond to breaches, and answer to the Data Protection Board if something goes wrong. Contract security staff execute the process; they don't own the compliance obligation.

This matters because most plants outsource gate security to a contractor, and it's tempting to assume the contractor is on the hook for how visitor data is handled. They aren't, in the eyes of the Act. If a register is left open on a table, or a spreadsheet of visitor phone numbers is emailed around without control, the liability sits with the business running the plant, up to ₹250 crore per instance for the most serious failures. Knowing this early is more useful than finding it out during an audit.

What the rules actually require

The DPDP Rules, 2025 were notified on 13 November 2025, and businesses have until 13 May 2027 — eighteen months — to be compliant. That's a real runway, but it's not a reason to wait, especially if your visitor process today is a physical register or an unmanaged spreadsheet that nobody has looked at from a data-protection angle.

The core obligations that touch a visitor register are:

  • Consent must be free, specific, informed and unambiguous — a visitor should know clearly what's being collected (name, phone, photo, ID) and why, and withdrawing that consent must be as easy as giving it.
  • Personal data, traffic data and logs must be retained for at least one year after processing, unless a longer period is legally required, and erased once the purpose is served — so "we've kept every visitor entry since 2019" is exactly the kind of practice that needs a second look.
  • Breaches have to be notified to the Data Protection Board and to affected individuals — which is only possible if you know what data exists, where, and who touched it.

None of this is exotic. It's closer to what a well-run HR file or a payroll record already does. The difference is that visitor data has historically been treated as a formality — a signature and a phone number in a register — rather than as personal data with the same handling duties. The Ministry of Electronics & IT is the reference point for how personal-data handling is expected to work under the Act, and it's worth having your compliance or legal team read the rules directly rather than relying on secondhand summaries.

Where responsibility splits on the ground

A useful way to think about this is in three layers, each with a different job:

  • The plant head or company decides policy — what's collected, how long it's kept, who can see what, and who is told if something goes wrong. This is the data fiduciary role and it can't be delegated to a contractor or a guard.
  • The security supervisor or admin operates within that policy — sets up permissions, runs exports when legitimately needed (say, for a safety audit or a police request), and is the point of contact if a visitor asks what data you hold on them.
  • The guard at the gate executes the day-to-day check-in and check-out. Their job is to move people through safely, not to hold or move data around. A guard should be able to see who's expected and let them in — nothing more.

This layering sounds obvious once it's written down, but it's rarely how a physical register or a loose spreadsheet actually works. A paper register sits at the gate where anyone walking past can read it — previous visitors' names, phone numbers, company affiliations, all visible to the next person signing in. A shared spreadsheet is worse: once it's emailed to three people "for reference," nobody can say for certain who has a copy, and an erasure obligation becomes almost impossible to honour.

What VizPass controls — and what it doesn't

VizPass was built around this three-layer split, because it maps to how Indian plants actually run their gates, with contract security staff, shift handovers and a plant management team that needs oversight without wanting to log every entry themselves.

  • Exports of the visitor register are permission-controlled — set who can pull data out, and for what purpose, rather than leaving it open to anyone with register access.
  • The guard role cannot export at all. A guard manages the gate — checking a visitor in, matching them to an expected appointment, printing a badge — but has no path to download or copy the register.
  • ID images and phone numbers are visible only to roles that actually need them. A guard sees the gate — who's arriving, whether they're expected, what pass to issue — not the underlying register with every visitor's ID photo and phone number laid bare.
  • A record is reversed with a reason, never silently deleted. If an entry was made in error or needs correction, the correction is logged alongside the reason, so an audit trail shows exactly what changed and why — instead of a record simply disappearing.

This is the practical shape of what a data fiduciary needs to demonstrate: that access is restricted to those who need it, that changes are traceable, and that the people managing the gate cannot casually move data outside the system. You can see the full set of these controls, along with badge printing, pre-approval and host notification, on the features page, and how they apply across a manufacturing unit, a warehouse, or a corporate campus on the industries page.

What VizPass does not do

VizPass is a register and a set of access controls — it does not provide legal advice, and it does not carry a "DPDP certification," because no such certification currently exists. Anyone claiming their software is "DPDP-certified" is describing something that doesn't yet exist in law. What VizPass gives you is the register controls a data fiduciary needs to show — permission-based access, export restrictions, and an auditable trail — so that when your legal or compliance team maps your obligations under the Act, the gate is already one of the fewer places you have to worry about.

Getting ready before May 2027

Eighteen months is enough time to move a gate off paper or a loose spreadsheet and onto a system with defined roles, provided you start with a straightforward inventory:

  • List what visitor data you currently collect — name, phone, company, purpose of visit, ID type, photograph — and ask whether each field is actually necessary.
  • Check who can currently see or export that data, and whether that list matches the people who genuinely need it for their job.
  • Decide your retention period, keeping the one-year floor in mind, and make sure old entries are actually erased rather than sitting in a folder indefinitely.
  • Write down, in plain terms, what a visitor is told at the gate about why their data is being collected — this is your consent notice, and it needs to be specific, not a generic sign.

None of this requires new hardware overnight, and a phased move — starting with the highest-traffic gate, then extending to contractor entries and material gates — is a realistic way to handle it across a multi-shift, multi-contractor site. If you want to see how the permission structure, export controls and audit trail work against your specific gate setup, a walkthrough is the fastest way to check whether it fits, and pricing is transparent enough that you can work out the cost against a single-gate or multi-site rollout without a sales call first. For the safety-and-compliance side of visitor and contractor management on the factory floor, DGFASLI's guidance at dgfasli.gov.in is a useful companion reference alongside your DPDP planning.

DPDP questions buyers ask

Do we need a visitor's consent before recording their name, phone number and photograph at the gate?

Yes — under the DPDP Act, collecting a visitor's name, phone number and photograph counts as processing personal data, and processing needs a stated purpose and the visitor's awareness of it before it happens. In practice this means the gate can't just silently write details into a register; the person signing in needs to see what's being collected and why. VizPass handles this by showing a consent and purpose notice on the digital check-in screen at the gate, so the visitor agrees to specific fields — name, phone, photo, company — rather than a guard filling in a blank column with no context. The notice can be worded to match your own privacy policy, since the Act doesn't prescribe exact language, only that purpose be disclosed. This also creates a record that consent was captured, which matters more than the register entry itself if you're ever asked to show how a visitor's data was obtained. For broader guidance on what counts as valid notice under the Act, the Ministry of Electronics & IT publishes explanatory material at https://www.meity.gov.in. Getting the notice right at the point of entry is simpler than trying to reconstruct consent after the fact.

How long can we legally keep visitor log data under DPDP?

You should keep visitor log data only as long as you have a genuine purpose for it, not indefinitely just because a spreadsheet or drawer never gets cleared out. The DPDP Act's storage limitation principle means data collected for a gate visit should be erased once that purpose — usually safety, access control or a short audit trail — no longer applies, and the exact retention period is a decision each site has to make and document rather than one fixed by the Act itself. VizPass lets an admin set a retention period in the platform's features settings, so visitor records are automatically purged once that window closes instead of sitting in an old file or a register nobody revisits. This also solves the reverse problem: proving you don't still hold data you said you'd delete, which is much harder to demonstrate with paper records that could still be sitting in a drawer somewhere. The right period depends on what the data is used for — a warehouse tracking deliveries may need a shorter window than a site running longer contractor engagements — but whatever you choose, it needs to be a deliberate, written decision, not a default of "we've never gotten around to deleting it."

Is a paper visitor register or Excel sheet still allowed once DPDP Rules 2025 take effect?

A paper register or Excel sheet isn't automatically illegal under DPDP, but it's much harder to control who sees it, how long it's kept, and whether it gets deleted properly. The Act doesn't ban specific formats — it requires that personal data be protected against unauthorised access and kept only as long as needed, and a register sitting open at a gate or a spreadsheet emailed between shifts makes both of those hard to demonstrate. Access can't easily be restricted to one column, and there's no way to prove the file wasn't copied or forwarded. A digital system like VizPass addresses this by keeping visitor records in one place with role-based access, so only the people who need to see gate data — security head, HR, admin — can open it, and an audit trail shows who accessed what and when. This matters for industries like manufacturing and warehousing where multiple shifts and contractors pass through the same gate, since a paper register changes hands constantly. You can technically stay on paper and still comply, but you'll need to build the same controls — locked storage, defined access, a deletion schedule — manually, which is harder to maintain consistently across shifts than a system that enforces it automatically.

Do we need to appoint a Data Protection Officer just to cover gate visitor data?

Not necessarily — the DPDP Act requires a Data Protection Officer only for organisations classified as "significant data fiduciaries," a status based on the volume and sensitivity of personal data processed across the whole company, not just gate visitor logs at one plant. Most single-site visitor and contractor data on its own is unlikely to trigger that threshold, but the company overall might already carry that obligation for other data it processes, in which case the same DPO also covers visitor records. Even without a formal DPO, someone at the plant — usually the admin or security head — should be named as the internal point of contact for visitor data questions, since "the guard collected it" isn't a valid answer if the Data Protection Board asks who's accountable. VizPass supports this by keeping a single, exportable record of visitor entries and consent per site, so whoever is designated can actually produce an answer instead of piecing it together from a register and a phone log. If you're not sure whether your organisation cr

Getting the register out of a notebook

Most plants don't need a new process, they need the existing one made defensible. If your gate currently runs on a bound register or a shared Excel file, the fix isn't a policy document — it's putting the same three fields (name, phone, photo) inside a system where you can say, with evidence, who saw them and for how long. That's the practical starting point, and it's worth doing before 13 May 2027 rather than in the weeks before it, when every vendor's implementation queue fills up. A phased rollout — one gate, one shift, then the rest of the industries or units you run — surfaces problems like poor connectivity at a remote gate or a guard shift that hasn't been trained, while the stakes are still low.

Where plants get this wrong

The common mistake isn't malice, it's convenience. A few patterns show up repeatedly on Indian shop floors:

  • A visitor's photo or phone number gets forwarded on WhatsApp to save time when a host isn't reachable — outside any system, unrecoverable, untraceable.
  • The register export sits in a shared drive because "someone in HR asked for it once," long after the reason for asking has been forgotten.
  • A contract guard is given the same login as the security supervisor, so there's no way to know who actually pulled a record.
  • Old registers are kept indefinitely "just in case," well past the point the Rules ask you to erase data whose purpose has been served.

None of these need bad intent to become a breach-notification problem. They need a system that doesn't allow the shortcut in the first place — which is closer to what features like role-based export controls and view restrictions are built to prevent.

What to check, not just what to install

A working register is one you can interrogate, not just one that logs entries. Periodically ask:

  • Who exported the register in the last quarter, and did each export have a business reason?
  • Can a guard see anything beyond today's gate list — and if so, why?
  • Are corrections visible as corrections, or does the record just look edited?
  • How old is the oldest entry still sitting in the system, and does it need to be there?

This is where VizPass earns its place: exports are permission-controlled and the guard role cannot export at all, ID images and phone numbers stay visible only to roles that actually need them, and a wrong entry is reversed with a reason rather than deleted — so an audit sees the correction, not a gap. It's a small design choice that answers a large question when the Data Protection Board asks it.

What this doesn't cover

VizPass gives you the register controls a data fiduciary needs to show — it does not give you legal advice, and there is no DPDP certification to hand an auditor, because none exists yet. If your plant handles visitor data alongside other personal data — HR records, CCTV footage, contractor KYC — you'll still need counsel to map obligations across all of it; the Ministry of Electronics & IT is the right place to track how the Rules are interpreted as they take effect. For the gate itself, see use-cases or book a walkthrough to see how the controls hold up against your own register.

Know who is on your site

Free for 7 days. Add a gate, invite your hosts, and check your first visitor in this afternoon.