Paper visitor book
- Previous entries may be visible if the book is left open at reception.
- Access control depends on where the book is kept.
- Retention and deletion are manual tasks.
GDPR visitor management
Visitor registration always involves personal data. This page explains which GDPR principles matter most when people sign in at your entrance, and which Lobbipad features support organisations in handling that information carefully. It is practical information rather than legal advice — how the GDPR applies to your organisation depends on your own situation.
When someone signs in at your reception, you process personal data: at minimum a name, usually a company and the employee they are visiting, plus the time of arrival and departure. The GDPR asks organisations to be clear about why they collect that information, to collect no more than they need, to keep it no longer than necessary, to limit who can see it and to protect it appropriately.
Visitor registration is a good place to apply these principles, because the purpose is narrow and the data set is small.
Paper vs digital
A paper visitor book is not automatically unlawful or non-compliant. With paper visitor books, access control and retention typically require manual processes, and previous entries may be visible to other visitors if the register is left open at reception.
Digital visitor registration can make access control, retention and deletion easier to manage consistently, because those settings are configured once and applied to every visit. That does not by itself guarantee GDPR compliance — how you configure and use the system still matters.
Data minimisation means asking only for the information the visit genuinely requires. In Lobbipad, first name and last name are required base fields; beyond that, organisations can configure additional custom questions and fields for the check-in flow through the web portal.
That lets you align what visitors are asked with the purpose of the visit, instead of collecting information you never use.
See how the check-in flow works on Visitor Management.
Retention
There is no universal retention period that is correct for every organisation. The appropriate period depends on your purpose for keeping visitor records, your own policies and any other obligations that apply to you.
Lobbipad supports configurable visitor-data retention: your organisation chooses the retention period, and visits older than that period are deleted automatically. The choice of period remains yours.
A visit is registered and stored as a visitor record.
The record is kept for the period your organisation sets.
Visits older than the configured period are deleted automatically.
Lobbipad includes a Recurring Visitors feature for people who visit regularly. Your organisation configures a recurring-visitor period, expressed in months. When a returning visitor enters their first name and the first three characters of their last name, Lobbipad can show a suggestion if a matching earlier visit exists within that period.
If the visitor selects the match, information from their most recent visit is filled in automatically, so repeat check-in is faster. Your organisation controls both the recurring-visitor period and the visitor-data retention period, and should set both in line with its own data-protection requirements.
Pre-registration is a separate feature. Employees can pre-register visitors before they arrive and send them the information they need in advance; a pre-registered visitor can receive a personal QR code that makes check-in on arrival faster.
Pre-registrations can also be created from a calendar invitation using supported calendar workflows. The information involved is the same small set used at check-in, entered by the host rather than at the door.
Lobbipad uses role-based access to visitor information, and administrator rights are granted per host in the web portal.
On Lobbipad's side, access to systems and customer information is restricted according to role and operational need, following the principle of least privilege, and access to production environments is limited to authorised personnel. Which people inside your organisation receive which rights remains your decision.
Lobbipad can present relevant information during registration — for example safety instructions, house rules or documents — as part of the check-in flow, so visitors see them while they sign in.
This is product functionality: what you show, and whether it meets your transparency or consent obligations, is for your organisation to determine.
Data hosting
Lobbipad's infrastructure runs on Amazon Web Services, with data located in AWS Europe (Frankfurt), Germany. Lobbipad does not operate its own data centres.
Connections to Lobbipad are encrypted in transit using HTTPS/TLS. Access follows role-based and least-privilege principles. Retention is configurable and visits are deleted automatically once the configured period passes.
Backups of relevant production data are maintained to support recovery, and infrastructure and applications are monitored for operational and security issues. A Data Processing Agreement is available.
For the full technical picture, see Security & Privacy and the Security Policy.
Where Lobbipad processes personal data on behalf of a customer, the responsibilities for that processing are described in Lobbipad's Data Processing Agreement, which is available and can be incorporated into the Terms of Service for customers who subscribe.
Lobbipad supports permanent deletion of customer data and export requests. The Terms of Service, Privacy Policy and Security Policy are published on this website; additional security and data protection information is available to customers and prospective customers on request.
Checklist
A starting point for evaluating a visitor management system. It is educational, not legal advice, and completing it does not by itself mean your organisation is compliant.
Lobbipad provides features that support GDPR-compliant visitor registration: configurable custom check-in questions on top of the required name fields, configurable retention with automatic deletion of older visits, a configurable recurring-visitor period, role-based access, EU data hosting in AWS Europe (Frankfurt), encrypted transmission, information and documents shown at check-in, and a Data Processing Agreement.
Decisions about what visitor information to collect, which retention period to set, which recurring-visitor period to use, who gets access and what information visitors are shown remain the responsibility of the organisation using Lobbipad. Software supports compliance; it does not create it.
Running check-in on an iPad at the entrance? See iPad visitor management.
Try Lobbipad for 30 days, or let us walk you through the visitor flow and the data settings.