The front desk is one of the most overlooked places personal data is collected. Here's a practical checklist to bring visitor sign-in in line with India's DPDP Act — without turning reception into a legal department.
Notice & consent
- Show a clear, plain-language notice of what you collect and why.
- Capture consent at the point of check-in, before you process anything.
Collect the minimum
- Capture only name, host, purpose and contact — justify anything more.
- If you verify identity, do it without storing the full Aadhaar number.
Retention & deletion
- Set a retention period and delete records automatically when it lapses.
- Don't keep visitor logs indefinitely 'just in case'.
Access, security & rights
- Restrict who can view and export visitor data; keep an access trail.
- Encrypt data in transit and at rest.
- Be able to find and delete a visitor's records on request.
- Retire the open paper logbook — it leaks one visitor's data to the next.
For the why behind each point, see the DPDP Act and visitor data and why logging isn't verification. Certopact is built consent-first and DPDP-aligned. General information, not legal advice.