GDPR visitor management

GDPR and visitor registration.

Visitor registration always involves personal data. This page explains which GDPR principles matter most when people sign in at your entrance, and which Lobbipad features support organisations in handling that information carefully. It is practical information rather than legal advice — how the GDPR applies to your organisation depends on your own situation.

What GDPR means for visitor management

When someone signs in at your reception, you process personal data: at minimum a name, usually a company and the employee they are visiting, plus the time of arrival and departure. The GDPR asks organisations to be clear about why they collect that information, to collect no more than they need, to keep it no longer than necessary, to limit who can see it and to protect it appropriately.

Visitor registration is a good place to apply these principles, because the purpose is narrow and the data set is small.

  • Collect only what you need
  • Control who has access
  • Define how long data is kept

Paper vs digital

Paper visitor books and visitor privacy

A paper visitor book is not automatically unlawful or non-compliant. With paper visitor books, access control and retention typically require manual processes, and previous entries may be visible to other visitors if the register is left open at reception.

Digital visitor registration can make access control, retention and deletion easier to manage consistently, because those settings are configured once and applied to every visit. That does not by itself guarantee GDPR compliance — how you configure and use the system still matters.

Paper visitor book

  • Previous entries may be visible if the book is left open at reception.
  • Access control depends on where the book is kept.
  • Retention and deletion are manual tasks.

Digital visitor record

  • Each visit is a separate record rather than a shared page.
  • Access is role-based.
  • Retention is configured once and applied to every visit.

Collect only the visitor information you need

Data minimisation means asking only for the information the visit genuinely requires. In Lobbipad, first name and last name are required base fields; beyond that, organisations can configure additional custom questions and fields for the check-in flow through the web portal.

That lets you align what visitors are asked with the purpose of the visit, instead of collecting information you never use.

See how the check-in flow works on Visitor Management.

Retention

How long visitor records are kept

There is no universal retention period that is correct for every organisation. The appropriate period depends on your purpose for keeping visitor records, your own policies and any other obligations that apply to you.

Lobbipad supports configurable visitor-data retention: your organisation chooses the retention period, and visits older than that period are deleted automatically. The choice of period remains yours.

  1. 01

    Check-in

    A visit is registered and stored as a visitor record.

  2. 02

    Configured retention period

    The record is kept for the period your organisation sets.

  3. 03

    Automatic deletion

    Visits older than the configured period are deleted automatically.

Returning visitors and repeat check-in

Lobbipad includes a Recurring Visitors feature for people who visit regularly. Your organisation configures a recurring-visitor period, expressed in months. When a returning visitor enters their first name and the first three characters of their last name, Lobbipad can show a suggestion if a matching earlier visit exists within that period.

If the visitor selects the match, information from their most recent visit is filled in automatically, so repeat check-in is faster. Your organisation controls both the recurring-visitor period and the visitor-data retention period, and should set both in line with its own data-protection requirements.

Pre-registration and visitor data

Pre-registration is a separate feature. Employees can pre-register visitors before they arrive and send them the information they need in advance; a pre-registered visitor can receive a personal QR code that makes check-in on arrival faster.

Pre-registrations can also be created from a calendar invitation using supported calendar workflows. The information involved is the same small set used at check-in, entered by the host rather than at the door.

Who can access visitor information

Lobbipad uses role-based access to visitor information, and administrator rights are granted per host in the web portal.

On Lobbipad's side, access to systems and customer information is restricted according to role and operational need, following the principle of least privilege, and access to production environments is limited to authorised personnel. Which people inside your organisation receive which rights remains your decision.

Showing information and documents during check-in

Lobbipad can present relevant information during registration — for example safety instructions, house rules or documents — as part of the check-in flow, so visitors see them while they sign in.

This is product functionality: what you show, and whether it meets your transparency or consent obligations, is for your organisation to determine.

Data hosting

Where Lobbipad data is hosted

Lobbipad's infrastructure runs on Amazon Web Services, with data located in AWS Europe (Frankfurt), Germany. Lobbipad does not operate its own data centres.

Data hosting
AWS Europe (Frankfurt), Germany
Transmission
HTTPS/TLS
Access
Role-based
Retention
Configurable
Deletion
Automatic after configured retention period
DPA
Available

Security controls relevant to visitor data

Connections to Lobbipad are encrypted in transit using HTTPS/TLS. Access follows role-based and least-privilege principles. Retention is configurable and visits are deleted automatically once the configured period passes.

Backups of relevant production data are maintained to support recovery, and infrastructure and applications are monitored for operational and security issues. A Data Processing Agreement is available.

For the full technical picture, see Security & Privacy and the Security Policy.

Data Processing Agreement and documentation

Where Lobbipad processes personal data on behalf of a customer, the responsibilities for that processing are described in Lobbipad's Data Processing Agreement, which is available and can be incorporated into the Terms of Service for customers who subscribe.

Lobbipad supports permanent deletion of customer data and export requests. The Terms of Service, Privacy Policy and Security Policy are published on this website; additional security and data protection information is available to customers and prospective customers on request.

GDPR & Data ProtectionPrivacy Policy

Checklist

A practical GDPR checklist for visitor management

A starting point for evaluating a visitor management system. It is educational, not legal advice, and completing it does not by itself mean your organisation is compliant.

  1. 01Define why you register visitors and what you do with the records.
  2. 02Collect only the information you actually need for the visit.
  3. 03Define a retention period that matches your purpose and policies.
  4. 04Check that expired visitor records are actually deleted.
  5. 05Restrict who can see the visitor register, and review those rights periodically.
  6. 06Give visitors the relevant information during check-in.
  7. 07Avoid a register in which previous visitors' entries are exposed to others.
  8. 08Know where the data is hosted and who processes it.
  9. 09Put appropriate processor documentation, such as a DPA, in place.
  10. 10Decide internally who handles access, correction and deletion requests.

How Lobbipad supports GDPR-conscious visitor registration

Lobbipad provides features that support GDPR-compliant visitor registration: configurable custom check-in questions on top of the required name fields, configurable retention with automatic deletion of older visits, a configurable recurring-visitor period, role-based access, EU data hosting in AWS Europe (Frankfurt), encrypted transmission, information and documents shown at check-in, and a Data Processing Agreement.

  • Configurable check-in fields
  • Configurable retention & automatic deletion
  • Recurring visitor controls
  • Role-based access
  • EU data hosting — AWS Europe (Frankfurt)
  • DPA available

Decisions about what visitor information to collect, which retention period to set, which recurring-visitor period to use, who gets access and what information visitors are shown remain the responsibility of the organisation using Lobbipad. Software supports compliance; it does not create it.

Running check-in on an iPad at the entrance? See iPad visitor management.

GDPR visitor management FAQs

It means treating visitor sign-in data as personal data: a clear purpose, only the information you need, a defined retention period, limited access and appropriate security. Visitor registration is a small, well-defined process, so these principles are relatively easy to apply.

A paper visitor book is not automatically unlawful. In practice, access control and retention require manual processes, and previous entries may be visible to other visitors if the register is left open at reception. Whether your own logbook is acceptable depends on how you use and protect it.

Only what the visit requires. In Lobbipad, first name and last name are required base fields, and organisations can configure additional custom questions in the web portal to match their own purpose.

There is no universal period. It depends on your purpose for keeping the records, your own policies and any other obligations that apply. Lobbipad lets your organisation configure the retention period.

Yes. Your organisation configures its visitor-data retention period, and visits older than that configured period are deleted automatically.

Yes. Organisations can configure a recurring-visitor period. When a returning visitor enters their first name and the first three characters of their last name, Lobbipad can suggest a matching recent visit. If the visitor selects the match, information from their most recent visit is filled in automatically. The organisation controls the period during which this functionality is available.

Yes. Employees can pre-register visitors in advance, and a pre-registered visitor can receive a personal QR code for faster check-in. Pre-registration is separate from the Recurring Visitors feature.

Access is role-based, and administrator rights are granted per host in the web portal. Lobbipad's own access to systems and customer information is restricted by role and operational need, following least-privilege principles.

On Amazon Web Services, in AWS Europe (Frankfurt), Germany.

Connections to Lobbipad are encrypted in transit using HTTPS/TLS. Passwords are not stored in plaintext and are securely hashed.

Yes. Safety instructions, house rules or documents can be presented as part of the check-in flow. Whether that satisfies your transparency obligations is for your organisation to assess.

Yes. A Data Processing Agreement is available and can be incorporated into the Terms of Service for subscribing customers.

Through configurable check-in questions, configurable retention with automatic deletion, a configurable recurring-visitor period, role-based access, EU hosting, encrypted transmission, information shown at check-in and a DPA. Configuration and organisational responsibility remain with the customer.

See how visitor registration works in practice.

Try Lobbipad for 30 days, or let us walk you through the visitor flow and the data settings.

Related:Visitor ManagementPricingSecurity & Privacy