The short version
- Record name, company, host, arrival and departure times, and purpose; drop any field you cannot justify.
- Set a fixed retention period, document it, and make sure deletion actually happens on schedule.
- Visitors can make a subject access request for their own entries, so you must be able to search by name.
- Missing sign-outs and the open sign-in book are the two failures that undo everything else.
A visitor log must record enough to answer three questions at any moment: who is in the building, why they are here, and who is responsible for them. In practice that means full name, company, host, arrival time, departure time and the purpose of the visit. Add anything your insurer, auditor or fire risk assessment specifically requires, such as a vehicle registration or a signed NDA acknowledgement, and stop there. Every extra field is personal data you now have to protect for no real benefit.
Retention is the second half of the job, and it is where most offices slip. Data protection law in the UK and Europe says you keep personal data no longer than you need it, and US state privacy laws are heading the same way. That means setting a fixed retention period, deleting entries on schedule, and being able to show an inspector, an auditor or the visitor themselves exactly what you hold. Here is what belongs in the log, how long to keep it, who has a right to see it, and the mistakes that catch office managers out.
What must a visitor log record?
There is no single statute that dictates the fields, but fire safety duties, security audits and data protection rules converge on a core set. A defensible visitor management record captures:
- Full name. Initials or first names alone are useless in an evacuation roll call or an incident investigation.
- Company or organisation. Essential for contractors and supplier audits.
- Host. The employee responsible for the visitor while they are on site. This is the field people forget, and the one security teams need most.
- Date and arrival time. Timestamped automatically if the system allows it.
- Departure time. A log without sign-out is half a log. If you cannot say who is still in the building, the record fails at its primary job.
- Purpose of visit. A short category is enough: meeting, delivery, contractor works, interview.
- Badge or pass number, if you issue them, so unreturned passes can be traced and deactivated.
Some sites also need agreement records, such as health and safety inductions or confidentiality terms, and regulated environments may require photo capture. Treat these as additions justified by a specific requirement, not defaults. Under GDPR the test is data minimisation: if you cannot explain why a field exists, remove it.
How long should you keep visitor log records?
Neither GDPR nor the UK Data Protection Act sets a fixed number of days. The rule is storage limitation: keep records only as long as you have a genuine purpose, then delete them. You decide the period, document it, and stick to it.
A sensible approach for most offices is a short default with defined exceptions. Routine visit records rarely need to survive beyond a few months, because their purposes, evacuation accountability and short-term security queries, expire quickly. Records tied to something longer-lived deserve longer: contractor attendance that evidences work under a contract, entries connected to an incident or investigation, or records an auditor has asked you to preserve. Whatever you choose, write it into your privacy notice and retention schedule so front of house is not making it up entry by entry.
Two practical tests keep you honest. First, could you justify the period to a regulator in one sentence? Second, does deletion actually happen? A policy that says 90 days while the system quietly holds three years of names is worse than no policy, because it proves you knew.
| Record type | Retention approach | Why |
|---|
| Routine visit records | Short default, a few months at most | Evacuation accountability and security queries expire quickly |
| Contractor attendance | Longer, tied to the contract | Evidences work carried out under a contract |
| Incident or investigation entries | Longer, until the matter closes | Connected to an incident or investigation |
| Records flagged by an auditor | Preserve until released | An auditor has asked you to keep them |
Who may ask to see your visitor log?
Several parties have a legitimate claim, and knowing them in advance stops the reception desk from either refusing a fire officer or handing the book to a stranger.
- Fire and safety officers. During an inspection, a drill or a real evacuation, they can expect an accurate account of everyone on site. Your emergency evacuation checklist should name the visitor log as one of the documents grabbed on the way out, or better, available on a phone.
- Auditors. ISO 27001 assessors, client security auditors and insurers routinely sample visitor records to test physical access controls. Gaps in sign-out data are a standard finding.
- Police and authorities. With a lawful basis, such as an investigation. Verify the request and record what was disclosed rather than handing over the whole log.
- The visitors themselves. Under GDPR and UK law, any visitor can make a subject access request for their own entries. You normally have one month to respond, so you need to be able to search by name.
- Internal teams. Facilities, security and HR, for defined purposes only.
One group has no right at all: other visitors. Which leads directly to the most common failure.
What are the most common visitor log mistakes?
The open sign-in book
A paper book on the reception desk shows every arriving visitor the names, companies and hosts of everyone who came before them. That is a personal data disclosure, and in competitive industries it is also commercial intelligence given away at the door. Regulators have flagged open sign-in sheets for years. If you keep paper, use tear-off slips at minimum.
No sign-out discipline
If visitors sign in but drift out unrecorded, your evacuation list is fiction. The front of house team ends up accounting for people who left hours ago while a fire marshal waits. Make departure capture as easy as arrival, or automate it.
Run a live headcount test. Ask reception to name everyone currently in the building. If the answer takes more than a minute or includes people who left hours ago, fix your sign-out process before a fire drill or an auditor finds the gap for you.
Keeping everything forever
Old visitor books in a cupboard are not an archive, they are liability. Every page is personal data you are holding without purpose, discoverable in the event of a breach or a subject access request.
Collecting too much
Asking every visitor for email, phone, home address and signature when the visit purpose needs none of it fails data minimisation and slows the desk down.
Not logging the regulars
Cleaners, engineers and delivery drivers who “everyone knows” walk past the book daily. They are exactly the people an auditor or investigator will ask about. If they are on site, they are in the log.
Does a digital visitor log make compliance easier?
Yes, mainly because it removes the human failure points. A digital system keeps each entry private from the next visitor, timestamps arrivals and departures, enforces retention automatically, and answers a subject access request with a search instead of an afternoon of page-turning. It also gives you a live on-site list during an evacuation rather than a book left on a burning desk. This is why visitor records sit inside HybridHero, a workplace management platform covering desk booking, meeting room booking, visitor management and parking, used in around 40 countries and built ISO 27001 and GDPR ready.
HybridHero visitor management: sign-in, badges and a live visitor logIf you are tightening up visitor records as part of a wider review of how your building actually gets used, the Workplace Visibility Report sets benchmarks from 1,500+ workplace teams and is a useful yardstick for where your operation stands.
The short version: record name, company, host, times and purpose. Set a retention period you can defend and delete on schedule. Know in advance who can lawfully see the log. And close the two gaps that undo everything else, missing sign-outs and the open book on the desk.