GDPR compliance starts at the front desk.
Every visitor who signs in at your reception is sharing personal data. GDPR requires you to collect it with consent, store it securely, retain it only as long as necessary, and delete it automatically when that period expires. Vizitor handles all of it, built into the check-in flow from day one.
What is GDPR?
The General Data Protection Regulation (GDPR) is the European Union's comprehensive data privacy law. It governs how organisations collect, store, use, and delete the personal data of individuals in the EU and European Economic Area. GDPR applies to any organisation that processes EU residents' personal data, regardless of where that organisation is based.
What is a GDPR compliant visitor management system?
A GDPR compliant visitor management system replaces paper sign-in sheets, which expose visitor data to every person who approaches the desk, with a digital platform that captures consent at check-in, stores data with AES-256 encryption, enforces configurable retention periods, supports right-to-erasure requests, and maintains a tamper-proof audit trail. Every stage of the visitor lifecycle is documented and deletable on demand.
How Vizitor maps to GDPR
| GDPR requirement | What it asks for | How Vizitor helps |
|---|---|---|
| Art. 6 — Lawful basis & consent | A documented basis + notice before collection | Privacy notice + timestamped acknowledgment at check-in |
| Art. 5 & 13 — Minimisation, retention, transparency | Collect only what's needed; tell visitors; keep only as long as needed | Configurable fields, on-screen notice, automatic deletion |
| Art. 17 — Right to erasure & SAR | Delete or export a person's data on request | Search + delete/export a record in minutes, logged |
| Art. 25 — Privacy by design & default | Protection built in, not bolted on | Minimal-by-default fields, first-name badges, optional photos |
| Art. 28 & 32 — Processor duties & security | A contract + real technical safeguards | AES-256 / TLS 1.2 + role-based access + audit trail |
| Art. 30 — Records of processing | Auditable records you can produce | Exportable visitor logs for any date range or location |
| Chapter V — International transfers | Safeguards when data leaves the EEA | Contact the Vizitor team for data transfer details |
How Vizitor addresses each GDPR requirement for visitor management
Article 6 — Lawful Basis and Consent
Automated consent collection at every check-in
GDPR requires a lawful basis before processing personal data. For most organisations, this is legitimate interest in building security, but the basis must be documented and communicated to visitors at the point of collection.
With Vizitor, you configure your visitor registration flow to display your organisation's privacy notice at the start of check-in. Visitors acknowledge and accept the notice before any data is stored. The acknowledgment is logged with a timestamp, creating a documented, auditable consent record for every visit.
You control exactly what data is collected, which agreements are presented, and how consent is recorded. Whether visitors check in at a kiosk tablet, via QR code on their own phone, or through pre-registration, consent capture is always part of the workflow.
Article 5 — Data Minimisation and Storage Limitation
Collect only what you need. Delete it automatically when the purpose expires.
GDPR's data minimisation principle requires that personal data is adequate, relevant, and limited to what is necessary for the stated purpose. Its storage limitation principle requires that personal data is kept no longer than necessary.
Vizitor lets administrators configure exactly which fields appear in the check-in form, and which are mandatory versus optional. Different visitor types collect different data proportionate to their purpose. A delivery driver does not need to provide the same information as a board-level client.
For retention, administrators configure automatic deletion periods, 30 days, 90 days, one year, or any period that aligns with your organisation's data protection policy. When a visitor record reaches its configured retention limit, it is automatically purged. No manual action. No risk of indefinite data accumulation.
Article 13 — Transparency at Point of Collection
Visitors are told what you collect, why, and how long you keep it, before they check in.
GDPR Article 13 requires that individuals are provided with specific information at the time their personal data is collected, including the purpose of processing, the lawful basis, the retention period, and their rights.
Vizitor displays your privacy notice on the kiosk screen before the visitor completes any form. The notice is configurable per location and per visitor type. The visitor's acknowledgment is timestamped and stored as part of their visit record, available for export if a compliance query requires evidence of transparency.
For organisations that require additional legal acknowledgment at check-in, NDAs, confidentiality agreements, site safety declarations, Vizitor's digital document signing serves a dual purpose. The visitor signs the document on the kiosk screen before entering the building, and the signed document is stored with a timestamp against their visit record. The NDA becomes both a legal agreement and a documented record of informed consent, satisfying Article 13's transparency requirement and your legal team's requirements in a single step.
Article 17 — Right to Erasure
Data subject requests fulfilled in minutes, not days.
Any visitor can exercise their right to erasure, requesting that their personal data be deleted. Organisations must respond within 30 days. With a paper logbook, that process involves physical searching, manual redaction, and no audit trail. With Vizitor, it takes under two minutes.
Vizitor's admin dashboard is fully searchable by visitor name, date, location, and host. A specific visitor's record is located, individually deleted, and the deletion is logged with a timestamp, without affecting any surrounding records. The same process handles Subject Access Requests (SARs) for data export.
Article 25 — Privacy by Design and by Default
GDPR compliance built into the visitor workflow, not added on top.
Article 25 requires that data protection is considered from the point of system design, not retrofitted after the fact. Vizitor is configured to collect minimal data by default. Additional fields require explicit administrator enablement.
Badge printing can be configured to show only first name, keeping full identity private from other visitors and staff. Photo capture is configurable and can be restricted to specific visitor types. Every privacy control is configurable per location, giving your data protection team full flexibility over how visitor data is handled across the organisation.
Article 28 and Article 32 — Data Processor Obligations and Security
Enterprise-grade security. Documented data processing agreements.
GDPR Article 32 requires appropriate technical and organisational measures to ensure security against unauthorised access, accidental loss, or damage. Vizitor stores visitor data with AES-256 encryption at rest and TLS 1.2 in transit. Role-based access controls restrict visibility of visitor records to authorised administrators only.
Vizitor is ISO 27001 certified, independently audited annually, covering the information security management framework that GDPR's Article 32 security requirement expects. A Data Processing Agreement (DPA) meeting GDPR Article 28 requirements is available for all enterprise deployments, documenting Vizitor's obligations as a data processor.
Every data access action, check-in, export, deletion, is logged in a tamper-proof audit trail.
Article 30 — Records of Processing Activities
Audit-ready evidence of compliance, exportable in under 60 seconds.
GDPR Article 30 requires organisations to maintain records of processing activities, including the purposes of processing, categories of data subjects, and retention periods. Demonstrating compliance requires documentation that can be produced for a regulator on request.
Vizitor's complete visitor log for any date range or location is exportable in under 60 seconds, formatted for regulatory review, internal audit, or Data Protection Officer reporting. Every action in the system is logged: check-in time, consent record, data access, export, and deletion.
The certifications behind Vizitor's GDPR compliance
ISO 27001 Certified
Vizitor's information security management system is independently certified to ISO 27001, the international standard covering the technical and organisational security measures that GDPR Article 32 requires. Audited annually by independent third parties.
AES-256 Encryption at Rest · TLS 1.2 in Transit
All visitor personal data is encrypted at rest with AES-256 and in transit with TLS 1.2. The encryption standards expected by GDPR's Article 32 technical measures requirement, documented and independently verified.
VAPT — Independent Penetration Testing
Vizitor's systems are regularly tested by independent third-party security assessors through Vulnerability Assessment and Penetration Testing. Active adversarial testing verifies that the technical safeguards protecting visitor personal data hold up under real-world attack conditions, going beyond what certification alone can demonstrate.
Data Processing Agreement (Article 28)
A GDPR-compliant Data Processing Agreement is available for all enterprise deployments. The DPA documents Vizitor's obligations as a data processor, covers sub-processor relationships, and meets the contractual requirements of GDPR Article 28.
Frequently Asked Questions
Yes. A visitor's name paired with a timestamp, a company name, or a host name is personal data under GDPR. Any information that can identify a natural person, directly or indirectly, qualifies. Every organisation that collects visitor names and arrival times at check-in is handling regulated personal data subject to GDPR requirements.
For most organisations, legitimate interest in building security is the lawful basis for collecting and processing visitor data at check-in. This must be documented in the organisation's records of processing activities (Article 30) and communicated to visitors in the privacy notice at check-in before any data is collected.
GDPR does not prescribe a specific retention period. Article 5(1)(e) requires that data is kept no longer than necessary for the purpose it was collected. For building security purposes, 30 to 90 days is the most defensible window for most organisations. Vizitor's configurable retention periods allow organisations to set and enforce their own policy, with automatic deletion when the period expires.
Yes. Vizitor is built for GDPR compliance with consent capture at check-in, configurable automated data retention, individual right-to-erasure support within the 30-day response window, AES-256 encryption at rest, TLS 1.2 in transit, role-based access controls, tamper-proof audit logs, ISO 27001 certification, and a Data Processing Agreement available for enterprise deployments.
Yes. A GDPR-compliant Data Processing Agreement meeting the requirements of Article 28 is available for enterprise deployments. Contact the Vizitor team to request the DPA documentation.
Yes. Visitor records are searchable by name, date, location, and host in the Vizitor admin dashboard. An individual visitor record can be located, exported for a Subject Access Request, or individually deleted, within minutes, and within GDPR's 30-day response requirement. The deletion is logged in the audit trail without affecting surrounding records.
Yes. GDPR applies to any organisation that processes the personal data of EU residents, regardless of where the organisation is based. If your organisation receives visitors from EU member states, or operates offices in the EU, GDPR applies to your visitor management process.
A GDPR compliant front desk. From the free plan.
Every Vizitor plan, including the free plan, includes consent capture at check-in, configurable data retention with automatic deletion, right-to-erasure support, AES-256 encryption, and a tamper-proof audit trail. GDPR compliance is not a premium tier at Vizitor. It is the foundation.