When your business registers visitors, you collect personal data. That means GDPR applies – regardless of whether you use a paper-based visitor book or a digital system. Here's a practical walkthrough of what the law requires, and what you should do to stay on the right side of it.

What does GDPR say about visitor registration?

GDPR (General Data Protection Regulation) is the EU's data protection regulation, which applies in full in Norway through the EEA Agreement. The regulation sets clear requirements for all processing of personal data – and visitor registration is no exception. When you note down a name, company, and who a guest is there to see, you're processing personal data under GDPR Article 4.

This means that as the data controller (the party that determines the purpose of the registration), you must have a legal basis, comply with the processing principles, and safeguard data subjects' rights. Many businesses aren't aware that these requirements also apply to visitor registration – but the Norwegian Data Protection Authority confirms that they do.

What is the legal basis for visitor registration?

You need a legal basis under GDPR Article 6 to register visitors. For most businesses, the most relevant basis is one of these two:

  • Legitimate interest (Art. 6(1)(f)): You have a legitimate business reason – such as security, access control or health and safety – that outweighs the visitor's privacy interest. This is the most common basis for visitor registration.
  • Contract (Art. 6(1)(b)): The registration is necessary to carry out a scheduled meeting. This can be used in combination with legitimate interest.

Consent (Art. 6(1)(a)) is usually not the right basis for visitor registration, because the consent isn't freely given when the visitor can't enter without registering.

Practical tip: Document your choice of legal basis in your records of processing activities (GDPR Art. 30). The Data Protection Authority may ask to see this during an inspection.

Duty to inform – you must tell guests what you're doing

GDPR Article 13 requires you to inform data subjects at the time of collection. For visitor registration, that means you must disclose:

  • Who the data controller is (the business's name and contact details)
  • What the data is used for (e.g. access control and health and safety)
  • The legal basis for the processing
  • How long the data is stored
  • What rights the visitor has (access, rectification, erasure)

You don't need to read out a long text to every guest. A brief notice on the check-in screen, a QR code linking to the privacy policy, or a plaque in reception is enough. What matters is that the information is easily accessible before the registration takes place.

How long can you store visitor data?

The GDPR principle of storage limitation (Art. 5(1)(e)) states that personal data must not be stored for longer than necessary for the purpose. There's no fixed statutory deadline for visitor registration, but the Data Protection Authority recommends considering a retention period of 30–90 days for a standard visitor log.

Some situations can justify a longer retention period:

  • Industry security requirements (e.g. critical infrastructure, defence)
  • Insurance requirements that call for documentation of who was in the building
  • Documentation of workplace accidents (health and safety legislation)

Either way, you should set a specific retention period and enforce it. With a digital visitor system, this can be automated – in Gjestin, data is deleted automatically after 90 days (or sooner if you set it that way).

Note: Many businesses forget to delete old data from the visitor book. A paper-based book from 2019 that's still sitting in a drawer is a GDPR breach – even if no one is looking at it.

Is a paper-based visitor book GDPR-compliant?

A paper-based visitor book is rarely GDPR-compliant in practice. Here are the most common problems:

  • Lack of confidentiality: Every new visitor can see who has been there before – names, companies and times. This is an obvious privacy risk.
  • Difficult to delete: You can't automatically delete data after the retention period. It requires manual review and shredding.
  • No access control: Anyone passing through reception can read the book.
  • Hard to fulfil the right of access: If someone requests access to what you've registered about them, it can be time-consuming to find.

A digital visitor system solves all of these problems. Data is encrypted, only authorised users have access, deletion happens automatically, and you can easily retrieve data for a subject access request.

Data processing agreement – when do you need one?

If you use an external provider for your visitor system (like Gjestin), the provider processes personal data on your behalf. That makes the provider a data processor under GDPR Article 28, and you're legally required to enter into a data processing agreement (DPA).

A data processing agreement regulates, among other things:

  • What the data processor can do with the data
  • Security requirements and procedures in the event of a security breach
  • Deletion of data when the agreement ends
  • Use of sub-processors (e.g. an SMS provider)

Gjestin offers a data processing agreement to all customers. Get in touch at post@gjestin.no to have it signed.

Data subjects' rights

Visitors have the same rights as any other data subject under GDPR. The most common rights that may become relevant are:

  • Access (Art. 15): The right to know what you've registered about them
  • Rectification (Art. 16): The right to have inaccurate data corrected
  • Erasure (Art. 17): The "right to be forgotten" – they can demand deletion if there's no longer a basis for the processing
  • Restriction (Art. 18): The right to restrict processing in certain situations

In practice, it's rare for visitors to exercise these rights – but you must have procedures in place to handle them within the one-month deadline (GDPR Art. 12).

Summary – checklist for GDPR-compliant visitor registration:

  • Establish the legal basis and document it
  • Give guests easily accessible information at check-in
  • Set a specific retention period (e.g. 90 days)
  • Ensure automatic deletion after the retention period
  • Enter into a data processing agreement with the system provider
  • Have procedures for handling subject access requests

How Gjestin helps you with GDPR

Gjestin is built to make GDPR compliance easy for Norwegian businesses. The system automatically displays a privacy notice to every guest at check-in, deletes data automatically after your chosen period, and all data is stored in Norway. We offer a data processing agreement to all customers, and the admin panel gives you full control over what data has been registered.

Want to know more about how the Gjestin visitor system works, or see what it costs? Feel free to get in touch – we're happy to help.

Try Gjestin risk-free for 30 days

GDPR-compliant visitor system with automatic deletion, a data processing agreement, and Norwegian support.

Get in touch →
← Back to All articles Read next → Why Your Business Should Switch to a Digital Visitor System