GDPR and the visitor book
Your visitor book shows the last twenty people’s details to the twenty-first
Names, companies, car registrations, who they came to see, sometimes a mobile number. Open on a counter, at the one point in your building where you have least control over who is stood there. That is the part of the paper book that is genuinely difficult to defend, and it is not the part most people worry about.
General information about published law, not legal advice. Sources at the bottom of the page.
The short answer
No, a paper book is not illegal. That is the wrong question.
Every page you will find on this subject is written by somebody who sells visitor management software, this one included. So here is the honest version first, and you can weigh the rest of it knowing where we stand.
- No law bans a paper visitor book. There is no clause anywhere in the UK GDPR or the Data Protection Act 2018 that says a register has to be electronic. Anybody telling you a book is illegal is selling something.
- It is still personal data, and it is in scope. The regulation covers manual records that form part of a filing system — a structured set accessible by specific criteria. A bound book with the same six columns on every line, ordered by date, is about as structured as paper gets. And the moment a name is typed into a spreadsheet, a badge or an email to the host, it is automated processing and the argument ends.
- So the question is not lawful or unlawful. It is whether you can run a book in a way that satisfies the principles, day after day, at a busy reception, with agency staff covering the desk. Some sites genuinely can. Most discover otherwise the first time somebody asks a hard question about it.
- The trigger is usually somebody else asking. A customer security questionnaire, an ISO auditor, a prime contractor pushing requirements down the chain, or one visitor who noticed their name was readable and put it in writing. Nobody replaces a book for its own sake.
Where it strains
Five principles, and how a reception book meets each one
The UK GDPR does not have a rule about visitor books. It has principles that apply to everything, and a book happens to sit awkwardly against five of them. In roughly the order they cause trouble.
Article 5(1)(f)
Integrity and confidentiality
The one that breaks first. An open book shows the previous twenty entries — names, companies, car registrations, sometimes mobile numbers — to the twenty-first person to pick up the pen. That is a disclosure of other people’s personal data to a stranger, and there is no purpose it serves.
Article 5(1)(c)
Data minimisation
Adequate, relevant and limited to what is necessary. Most books ask for a car registration and a mobile number because the column was printed on the page, not because anyone decided the site needed them. Every field you cannot justify is one you should not be collecting.
Article 5(1)(e)
Storage limitation
Kept no longer than necessary. Filled books go in a drawer, and the drawer has no end date. If somebody asks how long you keep visitor data and why, “there are eleven of them in the cupboard” is not a retention policy.
Article 5(2)
Accountability
The principle that turns the other four into work: you have to be responsible for compliance and able to demonstrate it. Not able to believe it, or to describe it on a call. A book gives you a stack of paper and a memory of what you meant to do with it.
Articles 13 and 15
Telling people, and finding it again
You have to say what you are collecting and why at the point you collect it, and you have to be able to produce one person’s data on request. Getting one visitor’s entry out of a paper page means photocopying and redacting everybody else who signed that day.
None of these is a fine waiting to happen. What they are is five questions you would rather have an answer to before a customer, an auditor or an annoyed visitor asks one of them.
If the open book has to go
Five things you can do instead, cheapest first
If you arrived here about to order a “GDPR compliant” visitor book, this is the list worth two minutes first. Two of the five are free, and the one we sell is the most expensive, so you can weigh what follows accordingly.
| Option | What it fixes | What it leaves | What it costs |
|---|---|---|---|
| A “GDPR” visitor book with peel-off or carbon slips | The next visitor reading the last one’s details, which is the most visible problem. | Retention, finding one person’s record, the privacy notice, nobody signing out, and a roll call that is inside the building. | More than a plain book, and bought again when it is full. |
| Printed sheets that reception fills in | Disclosure, because the visitor never reads the page, and the privacy notice, because it is printed at the top with a retention period on it. | The shredding is still somebody’s job, the register still has to be carried out in a fire, and finding one person means reading sheets. | Free. Ours are on this site, with no form to fill in. The printable sheets |
| A QR code and Microsoft Forms | Disclosure, handwriting and searching: a typed, time stamped row per visitor in a spreadsheet you can filter. | Nobody signs out, the roll call is a workbook on a phone, anyone with access can edit the record, and deletion is manual. | Free, if your business already has Microsoft 365. About an hour to build. The eight step guide |
| A self serve visitor app on your own tablet | What a dedicated system is for: sign in and out on a screen, records kept and deleted by rule rather than by memory. | You buy, mount, configure and support the hardware, and you own the rollout. | Sign In App publishes its entry tier at £415 a site a year, hardware separate. Less than a third of our price. Our comparison, including where they win |
| A managed kiosk, which is what we sell | The same, with the iPad and stand included, installed and configured on your site, a live fire roll call on any phone, and somebody to ring. | It costs the most of the five, and we are one person rather than a support desk. | £150 a month plus VAT, setup from £599. Every price, in public |
Sign In App’s price is their published list price, checked September 2026; check it against their own pricing page before you rely on it. Which of the five is right depends mostly on who, if anybody, is asking you to prove what the record says.
What changes on a screen
The same details, collected in a way you can account for
A kiosk does not make you compliant. What it does is remove the four failure modes above from the list of things a person at a busy desk has to get right every time.
One visitor at a time
The screen clears between arrivals. Nobody signing in can read who came before them, because there is nothing on the glass to read.
A notice at the point of collection
Your privacy wording is shown on the screen where the details are asked for, and acknowledged as part of signing in. That is Article 13 done at the moment it applies, rather than a laminated sheet nobody reads.
Deletion that happens on its own
You set the retention period once. Records past it are deleted automatically, so storage limitation is a setting rather than a job somebody is supposed to remember.
One person’s record, found in seconds
Search by name or date, export what you need. Answering a subject access request stops involving a photocopier and a marker pen.

The kiosk in fullISO 27001 visitor accessWhy sign out matters for roll callWhere the data goes once it is off paper
The questionnaire
Five questions customers ask, and where the answers come from
These arrive as a spreadsheet from a customer’s procurement or security team, usually with a deadline. Every one of them is answerable about reception specifically.
- What personal data do you collect from visitors, and why?The sign in questions themselves, which are configured per site and can be listed straight off the kiosk.
- What is your lawful basis?Yours to determine, but for site security and safety it is normally legitimate interests under Article 6(1)(f) — the same basis the ICO relies on for visitors to its own offices. Consent is usually the wrong answer, because a visitor who declines still has to be accounted for in a fire.
- How long is it retained, and how is it destroyed?The retention period you set, with automatic deletion on expiry rather than a manual purge.
- Where is the data held, and who processes it?AWS eu-west-1 on ISO 27001 infrastructure, under the EU-UK adequacy decision. Noon Elite Ltd is the processor, ICO registered, with a data processing agreement provided as standard.
- Can a visitor see, or ask you to delete, their own record?Search, export and delete a single record from the dashboard, without touching anybody else’s.
Before you ask
The questions that come up on every call about this
Is a paper visitor book illegal under GDPR?
No. Nothing in the UK GDPR or the Data Protection Act 2018 requires a visitor register to be electronic. A paper book is lawful. The difficulty is that an open book on a counter discloses previous visitors’ personal data to the next person to sign in, which is hard to reconcile with the integrity and confidentiality principle in Article 5(1)(f), and that filled books tend to be kept indefinitely with no retention period, which is hard to reconcile with Article 5(1)(e).
Does UK GDPR apply to paper records at all?
It applies to manual records that form part of a filing system, meaning a structured set of personal data accessible according to specific criteria. A bound visitor book with the same fields on every line, ordered by date, is structured in exactly that way. In practice the point is rarely reached anyway, because visitor details are almost always typed into something else as well — a spreadsheet, a badge, an email to the host — and that is automated processing beyond argument.
What is the lawful basis for collecting visitor details?
For most sites it is legitimate interests under Article 6(1)(f): knowing who is in the building for security and for fire safety. The ICO relies on the same basis for visitors to its own offices. Consent is usually a poor fit, because a visitor who withheld it would still need to be accounted for in an evacuation, which means the processing was never genuinely optional.
How long should we keep visitor records?
There is no period set in law. You decide it, write it down, and apply it consistently. Sites commonly land somewhere between three months and two years depending on what else the record is used for — a customer security requirement or a contractual obligation may pull it longer. The failure is not picking the wrong number, it is having no number and a cupboard full of books.
Do we need a privacy notice at reception?
You need to tell people what you are collecting, why, on what basis and for how long, at the point you collect it. A kiosk can show that wording on the screen where the details are entered and record that it was shown. A framed notice behind the desk is better than nothing but is harder to evidence.
Is a “GDPR compliant” visitor book with peel-off labels good enough?
It fixes one problem and leaves the others. Covering the previous entry stops the casual disclosure, which is the most visible issue. It does nothing about retention, nothing about finding a single person’s record without exposing everyone else on the page, nothing about the privacy notice, and nothing about the fact that nobody signs out. Whether that is good enough depends on who is asking you.
Being straight with you
What this page is not
- We are not data protection lawyers and this is not legal advice. Your lawful basis, your retention period and your privacy notice wording are yours to decide, ideally with someone qualified.
- A kiosk is a processor, not a compliance certificate. It makes the principles easier to hold to; it does not hold to them for you.
- If your visitor data is also going into a spreadsheet, a WhatsApp group and a badge printer nobody has mapped, the book is not your biggest problem.
- Screening out the fields you do not need is free, and worth doing whether or not you ever buy anything from us.
Sources
Check any of this yourself
- UK GDPR Article 5, principlesMinimisation, storage limitation, and integrity and confidentiality, in the words the regulation uses.
- UK GDPR Article 6, lawfulness of processingIncluding 6(1)(f), legitimate interests, which is where most visitor logs sit.
- Data Protection Act 2018, section 3The definition of a filing system, which is what brings structured paper records into scope.
- ICO, a guide to lawful basisHow to choose one and why “necessary” means targeted and proportionate rather than merely useful.
- ICO, visitors to the officeThe regulator’s own reception privacy notice. Worth reading as a worked example of what yours should say.
- ICO, right to be informedWhat has to be told to people, and when, at the point their details are collected.
General information about published law, not legal advice. If the answer matters to a contract, take it to someone qualified.
Also asked of sites like yours
The other things somebody may ask you to evidence
Each of these is a page about one standard, one duty or one visitor, written the same way as this one: what it actually asks for, what an iPad at reception records towards it, and where it does not help.
- CMMC physical security
- ISO 27001 visitor access
- AEO visitor access control
- BRCGS visitor control
- Fire roll call
- Contractor management
- HSE inspection records
- ISO 45001 contractor control
- Sign in sheet template
- Visitor health questionnaire template
- Contractor induction template
- Permit to work template
- Hot work permit template
- Fire drill record template
Next step
Tell us what your book asks for
Fifteen minutes on the phone. Read us the columns printed on your visitor book and we will tell you which ones you probably should not be collecting — whether or not you ever buy anything from us.
Book a 15 minute callNo site visit needed and nothing to install. If it is not a fit we will say so on the call.
Would rather email? [email protected]
Not the person who signs it off? Send them the one page business case