{"id":1257,"date":"2026-09-25T07:21:00","date_gmt":"2026-09-25T07:21:00","guid":{"rendered":"https:\/\/qudify.co\/blogs\/?p=1257"},"modified":"2026-09-26T10:26:41","modified_gmt":"2026-09-26T10:26:41","slug":"visitor-management-policy-india-2026-2","status":"publish","type":"post","link":"https:\/\/qudify.co\/blogs\/2026\/09\/25\/visitor-management-policy-india-2026-2\/","title":{"rendered":"Visitor Management Policy for Indian Offices: The 2026 Framework That Survives an Audit"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"1257\" class=\"elementor elementor-1257\">\n\t\t\t\t<article class=\"elementor-element elementor-element-cef4b1d e-con e-atomic-element e-flexbox-base e-098764d \" data-id=\"cef4b1d\" data-element_type=\"e-flexbox\" data-e-type=\"e-flexbox\" data-interaction-id=\"cef4b1d\">\n    \t\t\t<h1 data-interaction-id=\"b39bf61\" class=\"e-b39bf61-b44191d e-heading-base\"><strong>Visitor Management Policy for Indian \tOffices: The 2026 Framework That Survives an Audit<\/strong><\/h1>\n\t\t\t\t<div class=\"elementor-element elementor-element-570296d elementor-widget elementor-widget-image\" data-id=\"570296d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/1-8.png\" class=\"attachment-full size-full wp-image-1259\" alt=\"Qudify header graphic featuring the company logo, headline India Visitor Management Policy: 2026 Audit Framework, and an illustration of two professionals shaking hands in front of a giant signed document clipboard.\" srcset=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/1-8.png 1920w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/1-8-300x169.png 300w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/1-8-1024x576.png 1024w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/1-8-768x432.png 768w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/1-8-1536x864.png 1536w\" sizes=\"(max-width: 1920px) 100vw, 1920px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-7980e23-cc867f3 e-divider-base\" data-interaction-id=\"7980e23\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"5311e1a\" class=\"e-5311e1a-225b666 e-heading-base\"><strong>Key Takeaways<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-1833b0c elementor-widget elementor-widget-text-editor\" data-id=\"1833b0c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A visitor management policy is a governance document. The software enforces it; the policy decides what gets enforced and who is accountable.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Imported templates fail in India because they carry no DPDP notice, consent, retention or erasure architecture, and no POSH route for non-employees.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/static.pib.gov.in\/WriteReadData\/specificdocs\/documents\/2025\/nov\/doc20251117695301.pdf\"><span style=\"font-weight: 400;\">India&#8217;s DPDP Rules<\/span><\/a><span style=\"font-weight: 400;\"> were notified in November 2025. Notice, consent, security, rights and penalties all bite in mid-May 2027.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The Data Protection Board exists, but its inquiry and penalty powers are not yet in force. Nobody is being fined for a visitor register in 2026.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/www.seclore.com\/fundamentals\/dpdp-rules-2025-compliance-guide\/\"><span style=\"font-weight: 400;\">Rule 6(1)(e)<\/span><\/a><span style=\"font-weight: 400;\"> sets a one-year floor on logs and personal data, which cuts against the standard &#8220;delete visitor data after 90 days&#8221; advice.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A never-digitised paper register sits outside DPDP. Photograph or type one entry and the whole practice comes into scope.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Visitors fall inside the <\/span><a href=\"https:\/\/en.wikipedia.org\/wiki\/Sexual_Harassment_of_Women_at_Workplace_(Prevention,_Prohibition_and_Redressal)_Act,_2013\"><span style=\"font-weight: 400;\">POSH Act&#8217;s<\/span><\/a><span style=\"font-weight: 400;\"> definition of an aggrieved woman, so your policy needs a complaint route for non-employees.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">In shared buildings, lobby security and your reception are separate data fiduciaries collecting twice. Write the boundary into the policy.<\/span><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e3f5ecf elementor-widget elementor-widget-text-editor\" data-id=\"e3f5ecf\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Most Indian offices already have a visitor policy. It runs to about two pages; it was adapted from a template written for a company in Ohio, and it says something close to: <\/span><i><span style=\"font-weight: 400;\">all visitors must sign in at reception, wear a badge at all times, and be accompanied by their host.<\/span><\/i><span style=\"font-weight: 400;\"> It has never failed, because nothing has ever tested it.<\/span><\/p><p><span style=\"font-weight: 400;\">Three things are about to test it. The Digital Personal Data Protection Rules are notified and running on a clock. Your <\/span><a href=\"https:\/\/cybersigmacs.com\/blog\/iso-27001-certification-process-india\/\"><span style=\"font-weight: 400;\">ISO 27001<\/span><\/a><span style=\"font-weight: 400;\"> auditor has started asking to see the visitor log for a specific Tuesday rather than glancing at the register. And a growing share of Indian offices no longer own the front door they are writing rules about.<\/span><\/p><p><span style=\"font-weight: 400;\">That last one is worth a number. Flexible space operators took<\/span><a href=\"https:\/\/www.business-standard.com\/industry\/news\/india-s-office-mkt-posts-record-quarterly-leasing-on-gcc-flex-demand-cbre-126070600781_1.html\"> <span style=\"font-weight: 400;\">27% of gross office leasing in Q2 2026<\/span><\/a><span style=\"font-weight: 400;\"> on CBRE&#8217;s count, against a record 24.6 million sq ft for the quarter;<\/span><a href=\"https:\/\/www.jll.com\/en-in\/newsroom\/india-office-leasing-dips-3-point-9-percent-to-379m-sf-gccs-strong\"> <span style=\"font-weight: 400;\">JLL&#8217;s sector cut for the same quarter<\/span><\/a><span style=\"font-weight: 400;\"> puts flex at 28.4%, just behind technology; and Colliers expects operators to account for<\/span><a href=\"https:\/\/www.colliers.com\/en-in\/news\/press-release-india-office-outlook-2026\"> <span style=\"font-weight: 400;\">20\u201325% of full-year leasing<\/span><\/a><span style=\"font-weight: 400;\">. Different methodologies, same conclusion: roughly a quarter of new Indian office space is being taken by companies whose actual business is running somebody else&#8217;s front door.<\/span><\/p><p><span style=\"font-weight: 400;\">This guide is about the document itself: what belongs in it, what the law now requires it to say, and where the standard templates quietly leave you exposed.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-2b567e7-3135bf3 e-divider-base\" data-interaction-id=\"2b567e7\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"af7fb76\" class=\"e-af7fb76-7f8c5dd e-heading-base\"><strong>What Is A Visitor Management Policy?<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-f91e23d elementor-widget elementor-widget-text-editor\" data-id=\"f91e23d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">A visitor management policy is the written rule set that defines who may enter your premises, what personal data you collect from them, who approves and escorts them, what they may and may not do inside, how long their records are retained, and who is accountable when any of that fails. It is the governance layer that sits above your reception desk and your visitor management software.<\/span><\/p><p><span style=\"font-weight: 400;\">The distinction matters more than it sounds, because four separate artefacts routinely get collapsed into one and the gaps show up during audit.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-198f040 elementor-widget elementor-widget-text-editor\" data-id=\"198f040\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<table><tbody><tr><td><p><b>Artefact<\/b><\/p><\/td><td><p><b>What it does<\/b><\/p><\/td><td><p><b>Who owns it<\/b><\/p><\/td><td><p><b>Who reads it<\/b><\/p><\/td><\/tr><tr><td><p><b>Visitor management policy<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Sets the rules and the accountability<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">HR \/ Admin \/ Security, board-approved<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Employees, auditors, counsel<\/span><\/p><\/td><\/tr><tr><td><p><b>Front-desk SOP<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Tells reception and guards what to do, step by step<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Facilities or security lead<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Reception, guards, shift supervisors<\/span><\/p><\/td><\/tr><tr><td><p><b>Visitor privacy notice<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Tells the visitor what you collect and why, before you collect it<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Legal \/ DPO<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">The visitor, at the point of check-in<\/span><\/p><\/td><\/tr><tr><td><p><a href=\"https:\/\/qudify.co\/blogs\/2026\/06\/26\/what-is-a-visitor-management-system-and-why-every-indian-office-needs-one-in-2026\/\"><b>Visitor management system (VMS)<\/b><\/a><\/p><\/td><td><p><span style=\"font-weight: 400;\">Enforces the policy and produces the evidence<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">IT \/ Admin<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Nobody reads software; it just has to behave<\/span><\/p><\/td><\/tr><\/tbody><\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-83c4df1 elementor-widget elementor-widget-text-editor\" data-id=\"83c4df1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Write only the SOP and you have instructions with no authority behind them. Buy only the software, and you have a well-instrumented process that nobody has agreed to. The policy is what makes the other three defensible.<\/span><\/p><p><b>The short version of the difference:<\/b><span style=\"font-weight: 400;\"> the policy is a decision, the system is an enforcement mechanism. A VMS can capture consent, expire a pass and run a deletion job, but only after someone has decided what consent text to show, how long a pass lives and when data goes. That decision is the policy, and no software makes it for you.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-528cddb-ee95c8c e-divider-base\" data-interaction-id=\"528cddb\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"0437ea4\" class=\"e-0437ea4-e6738a6 e-heading-base\"><strong>Why Imported Visitor Policy Templates Fail In India<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-03aefa8 elementor-widget elementor-widget-image\" data-id=\"03aefa8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/2-8.png\" class=\"attachment-full size-full wp-image-1260\" alt=\"Infographic featuring the headline Why Imported Visitor Policies Fail in India, an illustration of a woman checking items on a large policy clipboard, and a man inspecting binders with a magnifying glass.\" srcset=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/2-8.png 1920w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/2-8-300x169.png 300w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/2-8-1024x576.png 1024w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/2-8-768x432.png 768w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/2-8-1536x864.png 1536w\" sizes=\"(max-width: 1920px) 100vw, 1920px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f064f43 elementor-widget elementor-widget-text-editor\" data-id=\"f064f43\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Search for a workplace visitor policy template, and you will find a dozen good ones. They are almost all written against US or UK assumptions, and they break in four predictable places once you apply them to an Indian office.<\/span><\/p><p><b>They treat visitor data as an etiquette question, not a legal one:<\/b><span style=\"font-weight: 400;\"> The typical template devotes a paragraph to badges and nothing to consent, notice, lawful basis, retention or erasure. Under India&#8217;s framework, those are not best practices. They are obligations.<\/span><\/p><p><b>Their retention advice is wrong for India: <\/b><span style=\"font-weight: 400;\">&#8220;Keep visitor logs for 90 days&#8221; is the standard line. India&#8217;s notified Rules impose a minimum retention floor on logs and personal data that runs longer than that. Deleting on a 90-day cycle without reconciling the two is a documented decision to under-retain.<\/span><\/p><p><b>They have no POSH hook:<\/b><span style=\"font-weight: 400;\"> Section 2(a) of the Sexual Harassment of Women at Workplace Act, 2013 defines an aggrieved woman as a woman of any age, <\/span><i><span style=\"font-weight: 400;\">whether employed or not,<\/span><\/i><span style=\"font-weight: 400;\"> which, as<\/span><a href=\"https:\/\/www.shrm.org\/topics-tools\/employment-law-compliance\/debunking-myths-about-india-posh-act\"> <span style=\"font-weight: 400;\">SHRM&#8217;s summary of the Act&#8217;s common myths<\/span><\/a><span style=\"font-weight: 400;\"> sets out, expressly reaches clients, customers and others who are not on your payroll. A visitor can be a complainant. A visitor can be a respondent. Almost no imported template gives either one a route.<\/span><\/p><p><b>They assume you control the building:<\/b><span style=\"font-weight: 400;\"> Most Indian offices sit inside a multi-tenant tower or a managed flex facility with its own security layer at the ground-floor lobby. A policy that says &#8220;all visitors sign in at reception&#8221; without saying <\/span><i><span style=\"font-weight: 400;\">which<\/span><\/i><span style=\"font-weight: 400;\"> reception is describing a workflow that does not exist.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-7884ac3-63a315a e-divider-base\" data-interaction-id=\"7884ac3\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"392444a\" class=\"e-392444a-75e2729 e-heading-base\"><strong>What Indian Law Actually Requires At Your Front Desk<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-85430d0 elementor-widget elementor-widget-text-editor\" data-id=\"85430d0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Five instruments do the real work. None of them mandates a visitor management system by name; together they make an undocumented, unconsented, indefinitely retained paper register very hard to defend.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"7c7e354\" class=\"e-7c7e354-2b40f44 e-heading-base\"><strong>The DPDP clock, and what is actually switched on<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-37c765f elementor-widget elementor-widget-text-editor\" data-id=\"37c765f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">The Digital Personal Data Protection Rules, 2025 were notified in November 2025, alongside the notifications commencing parts of the Act and establishing the Data Protection Board. Enforcement is staggered across three tranches under G.S.R. 843(E),<\/span><a href=\"https:\/\/www.amsshardul.com\/insight\/enforcement-of-the-dpdp-act-and-notification-of-the-dpdp-rules\/\"> <span style=\"font-weight: 400;\">analysed here by Shardul Amarchand Mangaldas<\/span><\/a><span style=\"font-weight: 400;\">:<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5723e3f elementor-widget elementor-widget-text-editor\" data-id=\"5723e3f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<table><tbody><tr><td><p><b>Tranche<\/b><\/p><\/td><td><p><b>Approx. date<\/b><\/p><\/td><td><p><b>What comes into force<\/b><\/p><\/td><td><p><b>What it means at your front desk<\/b><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Commencement<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">13 Nov 2025 (gazetted 14 Nov)<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Definitions; constitution of the Data Protection Board (ss.18\u201326); ss.35, 38\u201343<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">The Board exists institutionally. Its powers to inquire and penalise are <\/span><b>not<\/b><span style=\"font-weight: 400;\"> in this tranche<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Twelve months<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Mid-Nov 2026<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">s.6(9), s.27(1)(d) and Rule 4 all Consent Manager provisions<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Little direct effect on visitor data<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Eighteen months<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Mid-May 2027<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">ss.3\u20135, most of s.6, ss.7\u201317, most of s.27, ss.28\u201334 (including s.33, penalties), s.44(2)<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Notice, consent, purpose limitation, security safeguards, breach reporting, data principal rights and the penalty regime. This is the date your check-in form is written for<\/span><\/p><\/td><\/tr><\/tbody><\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f1ac431 elementor-widget elementor-widget-text-editor\" data-id=\"f1ac431\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Two points of precision that most published timelines get wrong.<\/span><\/p><p><b>The Board cannot yet act on a complaint:<\/b><span style=\"font-weight: 400;\"> Sections 18 to 26 constitute the Board and are in force. Section 27, which sets out its powers and functions, sits in the eighteen-month tranche apart from clause (d) of sub-section (1). Through 2026, no Chairperson or Members had been appointed, a gap<\/span><a href=\"https:\/\/www.livelaw.in\/articles\/india-data-protection-board-established-law-543751\"> <span style=\"font-weight: 400;\">LiveLaw examined in August 2026<\/span><\/a><span style=\"font-weight: 400;\">. If a vendor tells you the Board is hearing visitor-data complaints today, they have not read the notification.<\/span><\/p><p><b>The exact date is 13 or 14 May 2027, and it depends on how you count:<\/b><span style=\"font-weight: 400;\"> The notification is dated 13 November 2025 and was published in the Gazette on 14 November. Reputable sources are split. Do not build an implementation plan whose margin is one day.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"85dfb83\" class=\"e-85dfb83-b4f25ea e-heading-base\"><strong>What the penalties actually are<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-a746167 elementor-widget elementor-widget-text-editor\" data-id=\"a746167\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">The way this is usually explained to buyers is that a paper register attracts fines of \u20b9250 crore. That is wrong twice over, and repeating it makes the rest of your compliance argument easy to dismiss.<\/span><\/p><p><span style=\"font-weight: 400;\">The Schedule to the Act sets seven categories, each a ceiling rather than a tariff:\u00a0<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">up to \u20b9250 crore for failing to take reasonable security safeguards to prevent a breach (s.8(5))<\/span><span style=\"font-weight: 400;\"><br \/><br \/><\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">up to \u20b9200 crore each for failing to notify a breach (s.8(6)) and for breaching children&#8217;s data obligations (s.9)<\/span><span style=\"font-weight: 400;\"><br \/><br \/><\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">up to \u20b9150 crore for a Significant Data Fiduciary&#8217;s additional obligations (s.10)<\/span><span style=\"font-weight: 400;\"><br \/><br \/><\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">up to \u20b910,000 on an individual for breach of a data principal&#8217;s duties (s.15)<\/span><span style=\"font-weight: 400;\"><br \/><br \/><\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">the amount applicable to the underlying breach where a voluntary undertaking is broken (s.32)<\/span><span style=\"font-weight: 400;\"><br \/><br \/><\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">\u00a0and up to \u20b950 crore as the residual category covering everything else. A defective consent or notice practice at a reception desk sits in that last bucket.<\/span><\/li><\/ul><p>\u00a0<\/p><p><span style=\"font-weight: 400;\">And section 33, which carries the penalty regime, is itself in the eighteen-month tranche. Nobody is being fined for a visitor register in 2026. The ceilings are large enough without inflating either the number or the timing.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"893bd97\" class=\"e-893bd97-660bef3 e-heading-base\"><strong>The paper register paradox<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-e16c4dd elementor-widget elementor-widget-text-editor\" data-id=\"e16c4dd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Here is the part that surprises most admin heads. The DPDP Act applies to digital personal data collected in digital form, or collected on paper and digitised afterwards. A handwritten register that is never scanned, photographed or typed into a spreadsheet sits outside the Act&#8217;s material scope, as<\/span><a href=\"https:\/\/www.dlapiperdataprotection.com\/?t=law&amp;c=IN\"> <span style=\"font-weight: 400;\">DLA Piper&#8217;s India chapter<\/span><\/a><span style=\"font-weight: 400;\"> notes.<\/span><\/p><p><span style=\"font-weight: 400;\">That is not a defence. It is a trap, for three reasons.<\/span><\/p><p><b>The condition rarely holds:<\/b><span style=\"font-weight: 400;\"> Somebody photographs the page for the daily security report, or an executive assistant types the week&#8217;s entries into Excel for the MIS. At that moment, the whole practice is inside the Act, with retrospective obligations you have no consent record for.<\/span><\/p><p><b>The other regime has an expiry date:<\/b><span style=\"font-weight: 400;\"> Section 43A of the <\/span><a href=\"https:\/\/indiankanoon.org\/doc\/76191164\/\"><span style=\"font-weight: 400;\">Information Technology Act, 2000<\/span><\/a><span style=\"font-weight: 400;\"> and the SPDI Rules, 2011 framed under it still apply today. <\/span><a href=\"https:\/\/www.dpdpa.com\/dpdpa2023\/chapter-9\/section44.html\"><span style=\"font-weight: 400;\">Section 44(2)<\/span><\/a><span style=\"font-weight: 400;\"> of the DPDP Act omits section 43A, and s.44(2) is itself in the eighteen-month tranche. So the sensitive-data rules some organisations still rely on and the DPDP obligations that replace them change places in mid-2027 rather than overlapping indefinitely. Meanwhile your ISO 27001 certification, your customers&#8217; vendor security questionnaires and your own contractual commitments are unaffected by DPDP&#8217;s scope carve-out either way.<\/span><\/p><p><b>And it fails on its own terms:<\/b><span style=\"font-weight: 400;\"> An open register shows every subsequent visitor the name, company and mobile number of everyone before them. No statute is required to see the problem. That single design flaw is the clearest argument for<\/span><a href=\"https:\/\/qudify.co\/blogs\/2026\/08\/08\/how-digitising-visitor-logs-improves-security-and-compliance\/\"> <span style=\"font-weight: 400;\">digitising the visitor log<\/span><\/a><span style=\"font-weight: 400;\">, and it holds regardless of which commencement date you are counting to.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"a1955c7\" class=\"e-a1955c7-efb5073 e-heading-base\"><strong>ISO 27002 control 7.2: what your auditor is testing<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-9d986f9 elementor-widget elementor-widget-text-editor\" data-id=\"9d986f9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">If you hold ISO\/IEC 27001:2022, physical entry is control 7.2, and the<\/span><a href=\"https:\/\/www.isms.online\/iso-27001\/annex-a-2022\/7-2-physical-entry-2022\/\"> <span style=\"font-weight: 400;\">supporting guidance<\/span><\/a><span style=\"font-weight: 400;\"> is unusually specific for a standard that normally avoids prescription. Authenticate visitor identity by an appropriate means. Record date and time of both entry and departure. Grant access only for a specific authorised purpose, with instructions on the area&#8217;s security requirements and emergency procedures. Supervise visitors unless an explicit exception has been granted.<\/span><\/p><p><span style=\"font-weight: 400;\">Read that list against your current policy. Most fail on the second and fourth items: departure times and the escort exception, and those are exactly the two an auditor can test in ninety seconds by pulling a single day&#8217;s log.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"c40dcba\" class=\"e-c40dcba-8473796 e-heading-base\"><strong>POSH: visitors are inside the definition, in both directions<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-4e9cf45 elementor-widget elementor-widget-text-editor\" data-id=\"4e9cf45\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">The <\/span><a href=\"https:\/\/en.wikipedia.org\/wiki\/Sexual_Harassment_of_Women_at_Workplace_(Prevention,_Prohibition_and_Redressal)_Act,_2013\"><span style=\"font-weight: 400;\">POSH Act<\/span><\/a><span style=\"font-weight: 400;\"> has not been replaced by a 2026 statute, despite what a few sites now claim. What has changed is the evidence expectation around it. Employers are increasingly registering <\/span><a href=\"https:\/\/dst.gov.in\/internal-complaints-committee-icc-women\"><span style=\"font-weight: 400;\">Internal Committees on the Ministry of Women<\/span><\/a><span style=\"font-weight: 400;\"> and <\/span><a href=\"https:\/\/www.pib.gov.in\/PressReleasePage.aspx?PRID=2247562&amp;reg=48&amp;lang=2\"><span style=\"font-weight: 400;\">Child Development&#8217;s SHe-Box portal<\/span><\/a><span style=\"font-weight: 400;\">, and complaints routed through it come back to the employer for action, which means your internal process has to be able to receive one.<\/span><\/p><p><span style=\"font-weight: 400;\">Two things follow for a visitor policy. First, a visitor who is harassed on your premises is an aggrieved woman under s.2(a), and your policy has to tell her where to go which means the Internal Committee&#8217;s contact details need to be available at reception and inside the visitor notice, alongside the display obligation you already carry under s.19. Second, in <\/span><a href=\"https:\/\/indiankanoon.org\/doc\/184184467\/\"><i><span style=\"font-weight: 400;\">Dr Sohail Malik v. Union of India<\/span><\/i><span style=\"font-weight: 400;\"> (2025)<\/span><\/a><span style=\"font-weight: 400;\">, the Supreme Court confirmed that the Internal Committee at the aggrieved woman&#8217;s workplace may have jurisdiction even where the respondent works somewhere else. That is exactly the visitor scenario: your employee complaining about a vendor&#8217;s engineer, or a client&#8217;s executive complaining about your employee. A complaint should not be waved off because the other person is on somebody else&#8217;s payroll.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"366b4f1\" class=\"e-366b4f1-facfeb0 e-heading-base\"><strong>Contractors: the governing law changed in November 2025<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-acb21c6 elementor-widget elementor-widget-text-editor\" data-id=\"acb21c6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Most visitor policies still cite the <\/span><a href=\"https:\/\/clc.gov.in\/clc\/acts-rules\/contract-labour-regulation-abolition-act-1970\"><span style=\"font-weight: 400;\">Contract Labour (Regulation and Abolition) Act<\/span><\/a><span style=\"font-weight: 400;\">, 1970 by name. That reference is now stale. All four labour codes were brought into force on<\/span><a href=\"https:\/\/www.pib.gov.in\/PressReleseDetailm.aspx?PRID=2192463&amp;reg=3&amp;lang=2\"> <span style=\"font-weight: 400;\">21 November 2025<\/span><\/a><span style=\"font-weight: 400;\">, and the Occupational Safety, Health and Working Conditions Code, 2020 consolidates thirteen statutes including the Contract Labour Act and the Factories Act. The codes are in force; the central and state rules that operationalise them were still being notified through 2026.<\/span><\/p><p><span style=\"font-weight: 400;\">Practically, that means two things. Write your contractor clauses against the OSH Code rather than the 1970 Act, and write them so a state rule notification does not force a rewrite: reference the obligation, not the rule number. And treat the reference itself as a freshness signal: an auditor who sees a 1970 citation in a 2026 policy will assume, usually correctly, that nothing else in the document has been reviewed either.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"87290fc\" class=\"e-87290fc-dcf0152 e-heading-base\"><strong>Evacuation: a real obligation with no national form<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-9c99dc2 elementor-widget elementor-widget-text-editor\" data-id=\"9c99dc2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">There is no central statute telling an Indian office how to log visitors for fire safety. Fire services and building safety are state subjects; the operative duties sit in state fire service legislation and municipal building bye-laws, most of which adopt Part 4 of the National Building Code of India, 2016 by reference.<\/span><\/p><p><span style=\"font-weight: 400;\">What those instruments consistently require of an occupier is a workable means of escape and a rehearsed drill. Neither works without an accurate count of who is inside. That is the honest way to state it: the roll-call is not a prescribed statutory form; it is the thing every evacuation obligation quietly assumes you can produce.<\/span><\/p><p><span style=\"font-weight: 400;\">This article is a practitioner&#8217;s guide, not legal advice. Have your final policy and your visitor privacy notice reviewed by counsel before adoption.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-b266c4f-6854635 e-divider-base\" data-interaction-id=\"b266c4f\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"c13ca47\" class=\"e-c13ca47-526786a e-heading-base\"><strong>The Twelve Sections Every Visitor Management Policy Needs<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-2eb5251 elementor-widget elementor-widget-image\" data-id=\"2eb5251\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/3-8.png\" class=\"attachment-full size-full wp-image-1261\" alt=\"Infographic featuring an ascending sequence of ten red translucent panels representing sequential visitor management policy stages: 1. Host accountability, 2. Scope &amp; definition, 3. Visitor categories, 4. Pre-registration, 5. Notice &amp; consent, 6. ID verification, 7. Conduct, 8. Zones &amp; escorting, 9. Roll-call &amp; checkout, 10. Retention &amp; vendors, 11. Incidents &amp; exceptions, and 12. Ownership.\" srcset=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/3-8.png 1920w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/3-8-300x169.png 300w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/3-8-1024x576.png 1024w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/3-8-768x432.png 768w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/3-8-1536x864.png 1536w\" sizes=\"(max-width: 1920px) 100vw, 1920px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-202073b elementor-widget elementor-widget-text-editor\" data-id=\"202073b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">What follows is the structure we see holding up best in Indian offices, grouped four ways: accountability and scope, entry controls, data, and operations. Each section states the decision you actually have to make and gives a sample clause you can adapt.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"5e6dce2\" class=\"e-5e6dce2-173b2c7 e-heading-base\"><strong>1. Start with host accountability; it is the highest-leverage clause you will write<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-24c5a75 elementor-widget elementor-widget-text-editor\" data-id=\"24c5a75\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Most policies bury this. Put it near the top, because it is the single change that improves the largest number of downstream outcomes at zero cost.<\/span><\/p><p><span style=\"font-weight: 400;\">Name the host as accountable for the visit, not the security guard. The guard controls a gate; the host knows why the person is there, whether they should be in a restricted area, and when they left. Every unclosed checkout, every unescorted wander and every stale badge traces back to an unnamed owner.<\/span><\/p><p><i><span style=\"font-weight: 400;\">Sample:<\/span><\/i><span style=\"font-weight: 400;\"> Every visitor must have a named employee host. The host is accountable for approving the visit, receiving the visitor at the entry point, supervising them in non-public areas, and confirming departure. A visit without an identified host will not be approved.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"322f367\" class=\"e-322f367-800339b e-heading-base\"><strong>2. Purpose, scope and who counts as a visitor<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-546eb88 elementor-widget elementor-widget-text-editor\" data-id=\"546eb88\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Define the premises the policy covers, including parking, loading bays, terraces and any leased space in a shared building. Then define &#8220;visitor&#8221; broadly enough that nobody argues about it later: clients, candidates, auditors, vendors, contractor workers, delivery and courier personnel, employee family members, alumni, and employees from other locations who lack local access credentials.<\/span><\/p><p><span style=\"font-weight: 400;\">State the exclusions explicitly too. If a courier who never crosses the lobby line is not a visitor for policy purposes, say so, and say where the line is.<\/span><\/p><p><span style=\"font-weight: 400;\">If you operate more than one office, decide here whether this is one policy or several. One policy with site-specific annexures is almost always right: the accountability, data and retention rules should be identical across Chennai and Gurugram, while entry points, zone maps and building operators plainly are not.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"2698c39\" class=\"e-2698c39-19d01a2 e-heading-base\"><strong>3. Visitor categories and differentiated entry rules<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-83a11c2 elementor-widget elementor-widget-text-editor\" data-id=\"83a11c2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">One flow for everyone is why check-in queues form. Categories let you collect less from most people and more from the few who need it.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2b7bab6 elementor-widget elementor-widget-text-editor\" data-id=\"2b7bab6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<table><tbody><tr><td><p><b>Category<\/b><\/p><\/td><td><p><b>Pre-approval<\/b><\/p><\/td><td><p><b>Identity check<\/b><\/p><\/td><td><p><b>Data collected<\/b><\/p><\/td><td><p><b>Escort<\/b><\/p><\/td><td><p><b>Extras<\/b><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Guest\/client<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Host invite<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Name confirmation<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Name, mobile, company, host, purpose<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">In non-public areas<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">\u2014<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Interview candidate<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">HR schedule<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Name confirmation<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Name, mobile, host<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">To and from interview room<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Candidate data goes to HR retention, not visitor retention<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Vendor\/auditor<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Host invite<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Photo ID sighted, not stored<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Standard set<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Full escort<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">NDA acknowledgement<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Contractor worker<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Contractor supervisor<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">ID verified against contractor roster<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Standard set + firm name<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Zone-restricted<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Safety induction, work permit<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Courier\/delivery<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">None<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">None at lobby line<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Name, firm, recipient<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Not beyond drop point<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">\u2014<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">VIP \/ executive<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Named approver, usually EA or CXO office<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Discreet, by recognition or invite match<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Minimum set; no photograph unless agreed<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Personally received<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Protocol note; discretion is a security requirement, not a courtesy<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Repeat \/ long-term vendor<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Standing approval<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">On first visit<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Standard set + firm name<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Zone-restricted<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Pass validity end date, mandatory<\/span><\/p><\/td><\/tr><\/tbody><\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-deed1ed elementor-widget elementor-widget-text-editor\" data-id=\"deed1ed\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Two rows deserve a note.<\/span><\/p><p><b>VIP visits are where policies get suspended,<\/b><span style=\"font-weight: 400;\"> which is precisely when they need to hold. The realistic answer is not to exempt VIPs but to give them a category with a named approver, minimal data capture, and a person rather than a queue. Write it down and the exception stops being improvised.<\/span><\/p><p><b>Long-term passes are where most offices leak.<\/b><span style=\"font-weight: 400;\"> They get issued and never expire. Every one must carry an end date written into the policy, not left to whoever issues it.<\/span><\/p><p><b>After-hours and weekend visits<\/b><span style=\"font-weight: 400;\"> need their own rule rather than an assumption. State the standard visiting window, name who can authorise entry outside it at a level, not a person and require that the authorisation is recorded against the visit rather than given verbally at the gate. Most after-hours incidents are not intrusions; they are ordinary visits that nobody could account for afterwards.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"8ea79f2\" class=\"e-8ea79f2-5655b69 e-heading-base\"><strong>4. Pre-registration as the default, walk-ins as the exception<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-bffda51 elementor-widget elementor-widget-text-editor\" data-id=\"bffda51\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">This is the operational decision that determines whether the rest of your policy is enforceable, and almost no template addresses it.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-eb0fab6 elementor-widget elementor-widget-text-editor\" data-id=\"eb0fab6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<table><tbody><tr><td>\u00a0<\/td><td><p><b>Pre-registered<\/b><\/p><\/td><td><p><b>Walk-in<\/b><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Host approval<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Before arrival, in writing<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">At the door, under time pressure<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Notice and consent<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Shown with the invite and again at check-in<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Only at check-in, in a queue<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Identity<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Name matched against an invite<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Nothing to match it against<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Check-in time<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Seconds<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Minutes, with a queue forming behind<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Denial of entry<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">A decision made calmly, in advance<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">A confrontation at reception<\/span><\/p><\/td><\/tr><\/tbody><\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-685fb45 elementor-widget elementor-widget-text-editor\" data-id=\"685fb45\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Host accountability only works if approval happens before the person is standing in your lobby. Once they have arrived, the host approves under social pressure, and the record you keep is of a decision that was never really made.<\/span><\/p><p><i><span style=\"font-weight: 400;\">Sample:<\/span><\/i><span style=\"font-weight: 400;\"> Visits by clients, vendors, auditors, candidates and contractor personnel must be pre-registered by the host. Walk-in entry is permitted only where [named role] authorises it; the authorisation and its reason are recorded on the visit record.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"ef091d9\" class=\"e-ef091d9-4f8cd57 e-heading-base\"><strong>5. Identity verification, kept proportionate<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-e306698 elementor-widget elementor-widget-text-editor\" data-id=\"e306698\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Decide what you verify and what you <\/span><i><span style=\"font-weight: 400;\">store<\/span><\/i><span style=\"font-weight: 400;\">, and write both down. Those are different decisions, and conflating them is how offices end up with a folder of Aadhaar photocopies at reception.<\/span><\/p><p><span style=\"font-weight: 400;\">For a routine business guest, confirming a name against a host-issued invite is proportionate. For a contractor entering a plant room, checking a photo ID against the contractor&#8217;s roster is proportionate. Retaining a scan of a government identity document for either is usually not, and it converts your reception desk into a high-value target.<\/span><\/p><p><b>Aadhaar deserves its own line, and the useful line is narrower than most policies assume.<\/b><span style=\"font-weight: 400;\"> The 2022 UIDAI advisory telling private entities not to hold Aadhaar photocopies was<\/span><a href=\"https:\/\/www.tribuneindia.com\/news\/nation\/no-caution-just-routine-prudence-govt-withdraws-aadhaar-photocopy-warning-after-netizens-flay-uidai-advisory-399245\"> <span style=\"font-weight: 400;\">withdrawn days later<\/span><\/a><span style=\"font-weight: 400;\">, which is why the position feels muddy. It is less muddy than it feels. Aadhaar authentication by a private entity is not open season: it runs through the Aadhaar Authentication for Good Governance Rules, which require a proposal to the relevant ministry, a reference to UIDAI, and central government approval for a specified purpose. A reception desk verifying a vendor is not that. Separately, UIDAI has approved a<\/span><a href=\"https:\/\/www.outlookmoney.com\/news\/uidai-approves-rule-mandating-registration-for-entities-to-seek-aadhaar-verification\"> <span style=\"font-weight: 400;\">registration requirement for entities seeking Aadhaar-based verification<\/span><\/a><span style=\"font-weight: 400;\">, with QR- and app-based checks intended to replace paper copies; as of mid-2026, the formal notification was still pending. The current instruments sit on the<\/span><a href=\"https:\/\/uidai.gov.in\/en\/about-uidai\/legal-framework\/regulations.html\"> <span style=\"font-weight: 400;\">UIDAI legal framework page<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p><p><span style=\"font-weight: 400;\">The defensible policy line does not depend on how that resolves: do not make Aadhaar your default visitor ID, never photocopy it, and if a visitor offers it, sight it and move on.<\/span><\/p><p><b>Biometrics and facial recognition need a decision, not a default.<\/b><span style=\"font-weight: 400;\"> A face template is personal data. Collecting one requires the same notice and consent as a phone number, and it is harder to justify on minimisation grounds, because the point of a visitor system is that most visitors come once. The question to ask your vendor is what happens to the template after the visit ends. If the answer is &#8220;we keep it so check-in is faster next time&#8221;, that is a second purpose, and it needs its own consent rather than riding on the first.<\/span><\/p><p><i><span style=\"font-weight: 400;\">Sample:<\/span><\/i><span style=\"font-weight: 400;\"> Government identity documents may be sighted for verification where the visitor category requires it. Images or copies of identity documents will not be captured, uploaded or retained except where a specific legal or contractual obligation requires it and the DPO has approved it in writing. Biometric identifiers, including facial templates, will not be collected from visitors without a documented purpose, a separate consent, and a defined deletion trigger.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"5f940a0\" class=\"e-5f940a0-bc32535 e-heading-base\"><strong>6. Notice and consent at the point of collection<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-d029087 elementor-widget elementor-widget-text-editor\" data-id=\"d029087\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">This is the section that does not exist in imported templates, and the one your policy will be judged on after mid-May 2027.<\/span><\/p><p><span style=\"font-weight: 400;\">Rule 3 of the DPDP Rules sets out what the notice has to be. It must stand on its own and be understandable without reference to any other document; you cannot point at a privacy policy on your website. It must be in clear, plain language. It must give an <\/span><i><span style=\"font-weight: 400;\">itemised<\/span><\/i><span style=\"font-weight: 400;\"> description of the personal data being collected and the specific purposes. It must give a working link and means by which the person can withdraw consent as easily as they gave it, exercise their rights, and complain to the Board. And it must be available in English or any language in the Eighth Schedule to the Constitution, at the person&#8217;s option, not a requirement to publish all twenty-two at once. The Rules themselves are on<\/span><a href=\"https:\/\/www.meity.gov.in\/documents\/act-and-policies\/digital-personal-data-protection-rules-2025-gDOxUjMtQWa?pageTitle=Digital-Personal-Data-Protection-Rules-2025\"> <span style=\"font-weight: 400;\">MeitY&#8217;s DPDP Rules page<\/span><\/a><span style=\"font-weight: 400;\">. Rule 9 separately requires you to publish the contact details of a person who can answer questions about the processing which, for a visitor, means a name and a route rather than a generic inbox.<\/span><\/p><p><span style=\"font-weight: 400;\">A pre-printed line at the top of a register saying &#8220;by signing below you consent to our data policy&#8221; satisfies none of this. Consent has to be free, specific, informed, unconditional and unambiguous, given by clear affirmative action, and limited to the data necessary for the stated purpose.<\/span><\/p><p><span style=\"font-weight: 400;\">Your policy should require three things: that the notice is shown before any field is captured, that the notice version shown is logged with a timestamp, and that a visitor who declines is offered an alternative, usually a manually escorted, minimal-data visit rather than being turned away.<\/span><\/p><p><i><span style=\"font-weight: 400;\">Sample visitor notice, adapt with counsel:<\/span><\/i><span style=\"font-weight: 400;\"> We collect your name, mobile number, organisation, host name, purpose of visit and entry\/exit times, to verify your identity at entry, notify your host, maintain a security record of who is on the premises, and account for everyone present during an emergency. We do not use this data for marketing. Records are retained per our published schedule and then deleted. To withdraw consent, access or correct your record, or raise a complaint, contact [DPO name, email, phone]. You may also complain to the Data Protection Board of India.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"716cdac\" class=\"e-716cdac-9d7ccc9 e-heading-base\"><strong>7. Escorting, zones and what a badge actually authorises<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-82f6f81 elementor-widget elementor-widget-text-editor\" data-id=\"82f6f81\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">A badge is a claim about authorisation, so define what it authorises. Map your premises into zones: public (lobby, meeting rooms off the lobby), general work floor, restricted (server room, records room, plant room, labs) and state which categories may enter which, and under what supervision.<\/span><\/p><p><span style=\"font-weight: 400;\">Then handle the exception honestly. ISO 27002 contemplates unescorted access as an <\/span><i><span style=\"font-weight: 400;\">explicitly granted exception<\/span><\/i><span style=\"font-weight: 400;\">, not as a default that emerges because everyone is busy. Name who can grant it, for whom, and for how long. If your badges drive physical doors rather than just being visual, the zone map and the reader groups have to agree, which is a systems question as much as a drafting one, and the failure mode is covered in our guide to<\/span><a href=\"https:\/\/qudify.co\/blogs\/2026\/08\/18\/access-control-integration-with-vms-a-step-by-step-guide\/\"> <span style=\"font-weight: 400;\">integrating a VMS with access control<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"9c968c2\" class=\"e-9c968c2-e22939a e-heading-base\"><strong>8. Conduct: NDA, photography, POSH and removal<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-c57253a elementor-widget elementor-widget-text-editor\" data-id=\"c57253a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Cover four things and resist the urge to write a code of conduct.<\/span><\/p><p><b>Confidentiality:<\/b><span style=\"font-weight: 400;\"> which categories sign an NDA or acknowledge one digitally at check-in, and where that record lives. <\/span><b>Photography and recording:<\/b><span style=\"font-weight: 400;\"> where it is prohibited, and that this includes visitors&#8217; phones. <\/span><b>Harassment:<\/b><span style=\"font-weight: 400;\"> that visitors are both protected and bound, with the Internal Committee&#8217;s contact details available at reception and in the visitor notice, and a stated position that a complaint is not dismissed because one party works for a different organisation. <\/span><b>Removal:<\/b><span style=\"font-weight: 400;\"> who has authority to deny entry or ask someone to leave, and that the decision is logged with a reason.<\/span><\/p><p><span style=\"font-weight: 400;\">The denial-of-entry clause is the one people skip and then improvise under pressure. Write it before you need it.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"61675bb\" class=\"e-61675bb-9141a94 e-heading-base\"><strong>9. Retention, erasure and who else touches the data<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-79d5af9 elementor-widget elementor-widget-text-editor\" data-id=\"79d5af9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">The schedule itself is set out in full in the next section. Three things belong in the policy clause rather than the schedule.<\/span><\/p><p><b>Deletion runs on a schedule, not on request.<\/b><span style=\"font-weight: 400;\"> If erasure only happens when someone asks, you cannot demonstrate a practice, only a favour.<\/span><\/p><p><b>Your VMS vendor is a data processor, and that has a contract consequence.<\/b><span style=\"font-weight: 400;\"> If visitor check-in runs on somebody&#8217;s software, you are the data fiduciary, and they are almost certainly a processor. Rule 6(1)(f) requires the contract between you to carry appropriate provisions for reasonable security safeguards a drafting obligation, not just a diligence one. Three things belong in that contract and are usually missing: where the data is hosted, how long the vendor retains it after you delete it at your end, and what happens to it on termination. Section 8(1) keeps the fiduciary responsible for processing done on its behalf, which means a vendor&#8217;s failure is your exposure.<\/span><\/p><p><b>Breach has a procedure, and you should name it.<\/b><span style=\"font-weight: 400;\"> If your visitor database is exposed, Rule 7 requires you to inform affected individuals without delay and the Board without delay, with a detailed report within 72 hours unless extended. Say who declares a breach, who notifies, and who writes the report. A visitor database is a small target with a lot of mobile numbers in it, which is a common combination in the ones that get sold.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"f82802b\" class=\"e-f82802b-fc52df6 e-heading-base\"><strong>10. Emergency roll-call and the checkout problem<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-99e4622 elementor-widget elementor-widget-text-editor\" data-id=\"99e4622\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">State the requirement plainly: at any moment, an authorised person must be able to produce a list of everyone currently on the premises, and that list must be accurate.<\/span><\/p><p><span style=\"font-weight: 400;\">Which means checkout is not an administrative nicety. It is the input to the roll-call. A visitor record with no exit time is indistinguishable from a person still inside the building, and an evacuation list that over-reports sends fire wardens back into a building for someone who left at eleven.<\/span><\/p><p><span style=\"font-weight: 400;\">Your policy should therefore assign responsibility for closing open records, normally the host, with a defined auto-close rule and a note on the record showing it was system-closed rather than confirmed. Test it during your drill, not after.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"f23a720\" class=\"e-f23a720-48a7bad e-heading-base\"><strong>11. Incidents, exceptions and deactivation<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-7705d14 elementor-widget elementor-widget-text-editor\" data-id=\"7705d14\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Three things happen constantly and are documented almost nowhere, which is why they surface as audit findings.<\/span><\/p><p><b>Incidents:<\/b><span style=\"font-weight: 400;\"> Define what counts as a denied entry, an unescorted visitor found in a restricted zone, a tailgating event, a lost badge, a refused consent that escalated, a harassment complaint involving a visitor. Give each a log entry with date, people, decision and the person who made it. The value is not the incident record; it is that the pattern becomes visible before it becomes a finding.<\/span><\/p><p><b>Exceptions:<\/b><span style=\"font-weight: 400;\"> Every unescorted-access grant, every walk-in override, every after-hours authorisation is an exception to your own rule. Log them in one place with an expiry. An exception register that is empty is not a compliant organisation; it is an organisation that is not recording exceptions.<\/span><\/p><p><b>Deactivation:<\/b><span style=\"font-weight: 400;\"> Long-term vendor passes, contractor rosters and standing approvals all need an off-switch with an owner. State that a pass is deactivated on the earlier of its end date, the end of the contract, or notification by the contractor that the person has left and that the contractor is contractually obliged to give that notification. This is the visitor-side equivalent of employee offboarding, and it fails for the same reason: nobody owns the end of the relationship.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"b18b197\" class=\"e-b18b197-2f71417 e-heading-base\"><strong>12. Ownership, review and enforcement<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-a3fdc0b elementor-widget elementor-widget-text-editor\" data-id=\"a3fdc0b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Name a policy owner by role. Set a review cadence annually, plus on any change to premises, entry points, building operator, or applicable law. State what happens when an employee bypasses the policy, because a rule that cannot be breached is a suggestion. Version the document and record approvals.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-74abf30-c8a5165 e-divider-base\" data-interaction-id=\"74abf30\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"5352a18\" class=\"e-5352a18-d486ef1 e-heading-base\"><strong>How Long Should You Keep Visitor Records In India?<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-7751739 elementor-widget elementor-widget-image\" data-id=\"7751739\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/4-7.png\" class=\"attachment-full size-full wp-image-1262\" alt=\"Graphic featuring the headline Shared Spaces: The Hidden Boundary and an illustration of a man working on a laptop on a couch, alongside a man and woman working on laptops at a shared office desk.\" srcset=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/4-7.png 1920w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/4-7-300x169.png 300w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/4-7-1024x576.png 1024w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/4-7-768x432.png 768w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/4-7-1536x864.png 1536w\" sizes=\"(max-width: 1920px) 100vw, 1920px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4c4d17b elementor-widget elementor-widget-text-editor\" data-id=\"4c4d17b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">If your office is inside a commercial tower or a managed flex facility, a visitor is very likely registered twice: once by building security at the ground-floor lobby, and again by your reception on your floor. Two collections. Two sets of purposes. Two organisations deciding what to do with the data.<\/span><\/p><p><span style=\"font-weight: 400;\">The building operator determines the purpose and means of its own lobby collection. You determine the purpose and means of yours. Neither becomes the other&#8217;s processor by virtue of sharing a building. That has practical consequences a template will never surface for you:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>You cannot rely on the building&#8217;s notice:<\/b><span style=\"font-weight: 400;\"> Your collection needs your notice, naming you, with your DPO&#8217;s contact details.<\/span><span style=\"font-weight: 400;\"><br \/><br \/><\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>You cannot rely on the building&#8217;s log for your roll-call:<\/b><span style=\"font-weight: 400;\"> Lobby registration proves someone entered the tower, not that they reached or left your floor.<\/span><span style=\"font-weight: 400;\"><br \/><br \/><\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>You inherit their retention practice by accident:<\/b><span style=\"font-weight: 400;\"> Ask the operator, in writing, what they collect, how long they keep it and whether they photograph identity documents. If their practice is weak, your visitors&#8217; data is still exposed, and your visitors will not distinguish between you.<\/span><span style=\"font-weight: 400;\"><br \/><br \/><\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Your policy needs a boundary clause:<\/b><span style=\"font-weight: 400;\"> One paragraph stating which entry point is governed by whose policy, what data flows between the two, if any, and on what basis.<\/span><\/li><\/ul><p>\u00a0<\/p><p><span style=\"font-weight: 400;\">The same logic runs across sites. If you operate in four cities, the risk is not that each office does something different; it is that nobody can say which office does what. Keep one policy, one retention schedule and one consent text; vary only the annexure that describes entry points, zones and the local building operator. Then make sure whatever system you use can show you all four sites from one screen, because a policy you cannot audit centrally is four policies wearing the same cover page.<\/span><\/p><p><span style=\"font-weight: 400;\">This is a conversation with the landlord or operator, not a drafting exercise. Have it before you publish, and record the outcome in the policy itself.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-2efa98f-44a533d e-divider-base\" data-interaction-id=\"2efa98f\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"039909a\" class=\"e-039909a-d3e950c e-heading-base\"><strong>The Audit-Ready Control Framework<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-4136491 elementor-widget elementor-widget-text-editor\" data-id=\"4136491\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">The title of this article promises a framework that survives an audit, so here is the actual mapping: what the policy has to define, and what someone can ask you to produce.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-df4a002 elementor-widget elementor-widget-text-editor\" data-id=\"df4a002\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<table><tbody><tr><td><p><b>Control area<\/b><\/p><\/td><td><p><b>What the policy must define<\/b><\/p><\/td><td><p><b>Evidence you should be able to produce<\/b><\/p><\/td><td><p><b>Where the expectation comes from<\/b><\/p><\/td><\/tr><tr><td><p><b>Identification<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Which categories are verified, how, and what is stored versus sighted<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Visitor records for a named date<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">ISO 27002 7.2; DPDP minimisation<\/span><\/p><\/td><\/tr><tr><td><p><b>Approval<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Who may host; who may approve exceptions and walk-ins<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Host approval and invite records<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Internal control<\/span><\/p><\/td><\/tr><tr><td><p><b>Notice &amp; consent<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">What the visitor sees, before which field is captured<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Notice text, version and timestamp per visitor<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">DPDP Rule 3<\/span><\/p><\/td><\/tr><tr><td><p><b>Access &amp; zones<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Which categories enter which zones, escorted or not<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Badge\/zone records; escort exception register<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">ISO 27002 7.2<\/span><\/p><\/td><\/tr><tr><td><p><b>Retention &amp; erasure<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Period per record type and the deletion mechanism<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Deletion job schedule plus immutable deletion log<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">DPDP s.8(7), Rule 6, Rule 8<\/span><\/p><\/td><\/tr><tr><td><p><b>Data security<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Who can read visitor data and how that list is reviewed<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Admin access list with last review date<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">DPDP Rule 6(1)(b), (c)<\/span><\/p><\/td><\/tr><tr><td><p><b>Processors<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Who processes on your behalf, and on what terms<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Signed contract carrying the security clause<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">DPDP Rule 6(1)(f); s.8(1)<\/span><\/p><\/td><\/tr><tr><td><p><b>Breach<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Who declares, who notifies, who reports<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Breach register; drill or incident record<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">DPDP Rule 7<\/span><\/p><\/td><\/tr><tr><td><p><b>Rights &amp; grievances<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">How a visitor asks what you hold, and by when you answer<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Published request route and response period<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">DPDP Rule 14<\/span><\/p><\/td><\/tr><tr><td><p><b>Emergency<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Who produces the on-premises list, and how fast<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Roll-call output plus drill reconciliation<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">State fire rules; NBC 2016 Part 4<\/span><\/p><\/td><\/tr><tr><td><p><b>Contractors<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Roster verification, induction, permits, zone limits<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Induction and permit records<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">OSH Code, 2020<\/span><\/p><\/td><\/tr><tr><td><p><b>Conduct &amp; incidents<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">NDA, photography, POSH route, denial of entry<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Incident log with reasons and decision-makers<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">POSH Act ss.2(a), 19<\/span><\/p><\/td><\/tr><tr><td><p><b>Ownership<\/b><\/p><\/td><td><p><span style=\"font-weight: 400;\">Named owner, review cadence, approval route<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Versioned policy with approver and date<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Governance<\/span><\/p><\/td><\/tr><\/tbody><\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-73982fc elementor-widget elementor-widget-text-editor\" data-id=\"73982fc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">This is a working control map, not a compliance guarantee. Auditors scope differently; a customer&#8217;s security questionnaire is not an ISO audit, and neither is a regulatory inquiry. Use it to find your gaps, not to certify their absence.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<h3 data-interaction-id=\"a7085eb\" class=\"e-a7085eb-b3cdea8 e-heading-base\"><strong>The six-artefact spot check<\/strong><\/h3>\n\t\t\t\t<div class=\"elementor-element elementor-element-940080c elementor-widget elementor-widget-text-editor\" data-id=\"940080c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">If you want the fast version, these six are what get asked for most often. If you cannot produce all six today, that list is your implementation plan.<\/span><\/p><ol><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The approved, versioned policy, with the date and the approver.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A visitor log for a named date, showing entry <\/span><i><span style=\"font-weight: 400;\">and<\/span><\/i><span style=\"font-weight: 400;\"> exit times against a named host.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The consent and notice record for one specific visitor, showing what they saw and when.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Evidence that deletion ran on schedule, and the deletion log proving it.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The list of people with administrative access to visitor data, and when that list was last reviewed.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The roll-call output from your last evacuation drill, with the reconciliation of any discrepancy.<\/span><\/li><\/ol>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-82be8d2-7b254ce e-divider-base\" data-interaction-id=\"82be8d2\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"f037ede\" class=\"e-f037ede-8009336 e-heading-base\"><strong>Rolling It Out In 30 Days<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-3e56b0b elementor-widget elementor-widget-text-editor\" data-id=\"3e56b0b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<ol><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Days 1\u20135: <\/b><span style=\"font-weight: 400;\">Count what you actually collect at every entry point, including the building&#8217;s lobby. Most offices discover a field or two nobody can justify.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Days 6\u201310: <\/b><span style=\"font-weight: 400;\">Draft the categories table and the retention schedule first. These two decisions constrain everything else in the document.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Days 11\u201315: <\/b><span style=\"font-weight: 400;\">Write the visitor notice, and send it and the retention schedule to counsel together.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Days 16\u201320: <\/b><span style=\"font-weight: 400;\">Have the landlord conversation. Get the boundary clause right before you publish.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Days 21\u201325:<\/b><span style=\"font-weight: 400;\"> Configure the system to match the policy categories, notice display, consent capture, pass validity, auto-close, deletion job. If your platform cannot express a rule the policy requires, change the platform or change the rule, but do not publish a policy you cannot enforce.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Days 26\u201330:<\/b><span style=\"font-weight: 400;\"> Brief hosts and reception, run one drill against the roll-call, and publish with a review date.<\/span><\/li><\/ol><p>\u00a0<\/p><p><span style=\"font-weight: 400;\">The order matters. Teams that configure software first end up with a policy written backwards from whatever the tool happened to support.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-5b918e3-c28d19d e-divider-base\" data-interaction-id=\"5b918e3\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"f678731\" class=\"e-f678731-fa68f16 e-heading-base\"><strong>Where Qudify Fits<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-6c0426e elementor-widget elementor-widget-image\" data-id=\"6c0426e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/5-6.png\" class=\"attachment-full size-full wp-image-1263\" alt=\"&quot;Qudify website homepage featuring the company logo, top navigation links, headline Digitalising usage of future ready workspaces, subtext about enhancing workspace efficiency via digital meeting room and desk booking, a red &apos;Book Demo&apos; button, and a smartphone mockup displaying a QR code with the text Qudify.co and Scan QR &amp; Try It Yourself\" srcset=\"https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/5-6.png 1920w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/5-6-300x169.png 300w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/5-6-1024x576.png 1024w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/5-6-768x432.png 768w, https:\/\/qudify.co\/blogs\/wp-content\/uploads\/2026\/09\/5-6-1536x864.png 1536w\" sizes=\"(max-width: 1920px) 100vw, 1920px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b1fdf4a elementor-widget elementor-widget-text-editor\" data-id=\"b1fdf4a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">A policy is only worth the enforcement behind it, and most of the clauses above map to specific system behaviour: showing a standalone notice before the first field is captured, logging which notice version a visitor saw, expiring long-term vendor passes automatically, closing open records, running scheduled deletion, and producing a live on-premises list during a drill.<\/span><\/p><p><span style=\"font-weight: 400;\">Qudify was built around that mapping for Indian offices specifically. Visitors check in by scanning a QR code on their own phone, hosts approve over WhatsApp, and there is no kiosk, badge printer or app install in the path, which matters when your policy says a visitor who declines something must still have a workable route in. Multi-site operations run from one dashboard with office-wise admin controls, which is the practical answer to the multi-tenant and multi-city boundary problem.<\/span><\/p><p><span style=\"font-weight: 400;\">Qudify reports 500+ live sites, 400+ client organisations and over 64,000 monthly active users. Those are self-reported figures and are not independently audited; treat them as you would any vendor&#8217;s.<\/span><\/p><p><span style=\"font-weight: 400;\">If you are earlier in the process, our<\/span><a href=\"https:\/\/qudify.co\/blogs\/2026\/07\/01\/best-visitor-management-systems-in-india-2026-a-practical-fact-checked-comparison\/\"> <span style=\"font-weight: 400;\">fact-checked comparison of the leading platforms in India<\/span><\/a><span style=\"font-weight: 400;\"> covers the selection question, and<\/span><a href=\"https:\/\/qudify.co\/blogs\/2026\/08\/10\/contactless-visitor-management-in-india-why-its-no-longer-optional\/\"> <span style=\"font-weight: 400;\">contactless visitor management in India<\/span><\/a><span style=\"font-weight: 400;\"> covers why the check-in method itself is now a policy decision. For the surrounding controls, see<\/span><a href=\"https:\/\/qudify.co\/blogs\/2026\/07\/11\/office-security-best-practices-for-indian-enterprises-the-complete-2026-guide\/\"> <span style=\"font-weight: 400;\">office security best practices for Indian enterprises<\/span><\/a><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p><p><span style=\"font-weight: 400;\">A<\/span><a href=\"https:\/\/qudify.co\/visitor-management\"> <span style=\"font-weight: 400;\">demo<\/span><\/a><span style=\"font-weight: 400;\"> is available if you want to see the check-in flow against your own front desk.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n<hr class=\"e-46b70ef-e3a45a4 e-divider-base\" data-interaction-id=\"46b70ef\"   \/>\n\t\t\t\t\t<h2 data-interaction-id=\"1238384\" class=\"e-1238384-77e5b45 e-heading-base\"><strong>Frequently Asked Questions<\/strong><\/h2>\n\t\t\t\t<div class=\"elementor-element elementor-element-27214eb elementor-widget elementor-widget-n-accordion\" data-id=\"27214eb\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;default_state&quot;:&quot;expanded&quot;,&quot;max_items_expended&quot;:&quot;one&quot;,&quot;n_accordion_animation_duration&quot;:{&quot;unit&quot;:&quot;ms&quot;,&quot;size&quot;:400,&quot;sizes&quot;:[]}}\" data-widget_type=\"nested-accordion.default\">\n\t\t\t\t\t\t\t<div class=\"e-n-accordion\" aria-label=\"Accordion. Open links with Enter or Space, close with Escape, and navigate with Arrow Keys\">\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-4100\" class=\"e-n-accordion-item\" open>\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"1\" tabindex=\"0\" aria-expanded=\"true\" aria-controls=\"e-n-accordion-item-4100\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> What is a visitor management policy? <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-4100\" class=\"elementor-element elementor-element-9dcb9e9 e-con-full e-flex e-con e-child\" data-id=\"9dcb9e9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1358aae elementor-widget elementor-widget-text-editor\" data-id=\"1358aae\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">It is the written rule set defining who may enter your premises, what data you collect from them, who approves and escorts them, how long records are kept, and who is accountable when something fails. It governs the front desk; it is not the same thing as the software running it.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-4101\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"2\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-4101\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> What should a visitor management policy include? <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-4101\" class=\"elementor-element elementor-element-4d0462a e-flex e-con-boxed e-con e-child\" data-id=\"4d0462a\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-277eb90 elementor-widget elementor-widget-text-editor\" data-id=\"277eb90\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Twelve sections in four groups. Accountability and scope: host accountability, purpose and definitions, visitor categories. Entry controls: pre-registration versus walk-ins, identity verification limits, notice and consent, escorting and zones. Conduct and data: NDAs, photography, POSH, removal, retention and processors. Operations: emergency roll-call and checkout, incidents and deactivation, and named ownership with a review cadence.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-4102\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"3\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-4102\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> What is the difference between a visitor policy and a visitor management system?  <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-4102\" class=\"elementor-element elementor-element-ade8ae9 e-flex e-con-boxed e-con e-child\" data-id=\"ade8ae9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-df5c6f5 elementor-widget elementor-widget-text-editor\" data-id=\"df5c6f5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">The policy is a decision; the system is an enforcement mechanism. Software can capture consent, expire a pass and run a deletion job, but only after someone has decided what the consent says, how long the pass lives and when data goes. Buying a VMS without a policy gives you a well-instrumented process nobody has agreed to.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-4103\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"4\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-4103\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> Is a visitor management policy legally required in India? <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-4103\" class=\"elementor-element elementor-element-9284aed e-flex e-con-boxed e-con e-child\" data-id=\"9284aed\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4065517 elementor-widget elementor-widget-text-editor\" data-id=\"4065517\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">No statute names the document. But the DPDP Act and Rules impose notice, consent, security, retention and rights obligations on any organisation collecting visitor data digitally, and ISO 27001, POSH and state fire-safety obligations attach to people on your premises regardless. The policy is how you evidence all of it in one place.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-4104\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"5\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-4104\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> Does the DPDP Act apply to visitor data?  <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-4104\" class=\"elementor-element elementor-element-3917c1d e-flex e-con-boxed e-con e-child\" data-id=\"3917c1d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3fa882f elementor-widget elementor-widget-text-editor\" data-id=\"3fa882f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Yes, where the data is digital. A name, mobile number, organisation and entry time collected through a tablet, kiosk or QR form is digital personal data; you are the data fiduciary, and the notice, consent, purpose-limitation, security and erasure obligations apply from mid-May 2027. Paper collected and then digitised is also covered.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-4105\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"6\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-4105\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> Is a paper visitor register illegal under the DPDP Act? <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-4105\" class=\"elementor-element elementor-element-ac4900c e-flex e-con-boxed e-con e-child\" data-id=\"ac4900c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-a0c54e4 elementor-widget elementor-widget-text-editor\" data-id=\"a0c54e4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Not directly. The Act covers digital personal data and data digitised after collection, so a register that is never scanned or typed up falls outside its scope. In practice, that condition rarely holds, and a shared open register still exposes every visitor&#8217;s details to the next one.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-4106\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"7\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-4106\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> What information should offices collect from visitors? <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-4106\" class=\"elementor-element elementor-element-33faa54 e-flex e-con-boxed e-con e-child\" data-id=\"33faa54\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f637ab7 elementor-widget elementor-widget-text-editor\" data-id=\"f637ab7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">For a routine guest: name, mobile number, organisation, host name, purpose and entry\/exit times. That set supports identification, host notification, security records and emergency roll-call, which are the four purposes you can actually justify. Anything beyond it ID images, biometrics, vehicle details, health data needs a stated purpose of its own.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-4107\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"8\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-4107\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> How long should visitor data be retained in India? <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-4107\" class=\"elementor-element elementor-element-db47c23 e-flex e-con-boxed e-con e-child\" data-id=\"db47c23\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-2d466dd elementor-widget elementor-widget-text-editor\" data-id=\"2d466dd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Long enough to satisfy the one-year floor Rule 6(1)(e) places on logs and personal data, and no longer than the purpose requires. Twelve months for the entry\/exit log is a defensible default, with contractor and candidate records moved onto their own schedules and CCTV kept under its own policy. Confirm the specifics with counsel.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-4108\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"9\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-4108\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> What should a visitor sign-in process look like?  <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-4108\" class=\"elementor-element elementor-element-282140e e-flex e-con-boxed e-con e-child\" data-id=\"282140e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-5667fe7 elementor-widget elementor-widget-text-editor\" data-id=\"5667fe7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Pre-registration by the host; a standalone privacy notice shown before the first field; consent captured by an affirmative action and logged with the notice version; minimal fields; identity confirmed against the invite rather than stored; host notified; a pass with a stated validity and zone; and a checkout that actually closes the record.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-4109\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"10\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-4109\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> How do you prepare visitor records for an audit? <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-4109\" class=\"elementor-element elementor-element-22e4cdc e-flex e-con-boxed e-con e-child\" data-id=\"22e4cdc\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-5f88518 elementor-widget elementor-widget-text-editor\" data-id=\"5f88518\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Be able to produce six things: the versioned policy with its approver, a full day&#8217;s log with entry and exit times against named hosts, one visitor&#8217;s consent record showing what they saw and when, proof that deletion ran on schedule, the admin access list with its last review date, and the roll-call output from your most recent drill with any discrepancy reconciled.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-41010\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"11\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-41010\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> Should we use Aadhaar or facial recognition to verify visitors? <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-41010\" class=\"elementor-element elementor-element-26fbf8f e-flex e-con-boxed e-con e-child\" data-id=\"26fbf8f\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3cd90bb elementor-widget elementor-widget-text-editor\" data-id=\"3cd90bb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Neither should be your default. Private-entity Aadhaar authentication runs through an approval route that a reception desk does not sit in, and copies should not be retained. Facial templates are personal data and are hard to justify for people visiting once. Sight a photo ID where the category warrants it, store a confirmation rather than an image, and keep biometrics for a documented purpose with its own consent.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-41011\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"12\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-41011\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> Who owns the visitor management policy: HR, IT, or facilities? <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-41011\" class=\"elementor-element elementor-element-09a3d19 e-flex e-con-boxed e-con e-child\" data-id=\"09a3d19\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4fe476b elementor-widget elementor-widget-text-editor\" data-id=\"4fe476b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Facilities or admin usually operate it, and IT configures the system, but the policy needs a single named owner with authority to enforce it, and legal or the DPO must sign off on the notice and retention sections. Split ownership without a named owner is why these documents go stale.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-41012\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"13\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-41012\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> Does the policy apply to contractors and delivery personnel?  <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-41012\" class=\"elementor-element elementor-element-f7ffe67 e-flex e-con-boxed e-con e-child\" data-id=\"f7ffe67\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-70a23c3 elementor-widget elementor-widget-text-editor\" data-id=\"70a23c3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Yes, with different rules. Contractors typically need roster verification, a safety induction, zone restrictions and permits, now framed by the OSH Code, 2020 rather than the repealed Contract Labour Act. Delivery personnel who stop at a defined drop point usually need minimal data and no escort. Define both categories explicitly rather than treating everyone as a guest.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-41013\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"14\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-41013\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> What happens if a visitor refuses to give their data?  <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-41013\" class=\"elementor-element elementor-element-6ea7e3e e-flex e-con-boxed e-con e-child\" data-id=\"6ea7e3e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-5961191 elementor-widget elementor-widget-text-editor\" data-id=\"5961191\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Your policy needs a documented alternative, normally a minimal-data, fully escorted visit because consent given under threat of refused entry is difficult to characterise as free. Turning people away by default is the outcome you want to avoid designing into the process.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-41014\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"15\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-41014\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> How does a visitor policy work in a shared or coworking office? <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-41014\" class=\"elementor-element elementor-element-0ba24e7 e-flex e-con-boxed e-con e-child\" data-id=\"0ba24e7\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-03eebd3 elementor-widget elementor-widget-text-editor\" data-id=\"03eebd3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Building security and your reception are separate collections by separate organisations. You need your own notice, your own retention practice and your own on-floor record for roll-call. Add a boundary clause naming which entry point is governed by whose policy, agreed with the operator in writing.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-41015\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"16\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-41015\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><span class=\"e-n-accordion-item-title-text\"> How often should a visitor management policy be reviewed?  <\/span><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-41015\" class=\"elementor-element elementor-element-6430f23 e-flex e-con-boxed e-con e-child\" data-id=\"6430f23\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-aedacd8 elementor-widget elementor-widget-text-editor\" data-id=\"aedacd8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Annually at minimum, plus on any change to your premises, entry points, building operator, visitor volume or applicable law. Given the mid-May 2027 DPDP date and the labour codes commencing in November 2025, most Indian offices should schedule a review in 2026 rather than waiting.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t<script type=\"application\/ld+json\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is a visitor management policy?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"It is the written rule set defining who may enter your premises, what data you collect from them, who approves and escorts them, how long records are kept, and who is accountable when something fails. It governs the front desk; it is not the same thing as the software running it.\"}},{\"@type\":\"Question\",\"name\":\"What should a visitor management policy include?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Twelve sections in four groups. Accountability and scope: host accountability, purpose and definitions, visitor categories. Entry controls: pre-registration versus walk-ins, identity verification limits, notice and consent, escorting and zones. Conduct and data: NDAs, photography, POSH, removal, retention and processors. Operations: emergency roll-call and checkout, incidents and deactivation, and named ownership with a review cadence.\"}},{\"@type\":\"Question\",\"name\":\"What is the difference between a visitor policy and a visitor management system?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"The policy is a decision; the system is an enforcement mechanism. Software can capture consent, expire a pass and run a deletion job, but only after someone has decided what the consent says, how long the pass lives and when data goes. Buying a VMS without a policy gives you a well-instrumented process nobody has agreed to.\"}},{\"@type\":\"Question\",\"name\":\"Is a visitor management policy legally required in India?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No statute names the document. But the DPDP Act and Rules impose notice, consent, security, retention and rights obligations on any organisation collecting visitor data digitally, and ISO 27001, POSH and state fire-safety obligations attach to people on your premises regardless. The policy is how you evidence all of it in one place.\"}},{\"@type\":\"Question\",\"name\":\"Does the DPDP Act apply to visitor data?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes, where the data is digital. A name, mobile number, organisation and entry time collected through a tablet, kiosk or QR form is digital personal data; you are the data fiduciary, and the notice, consent, purpose-limitation, security and erasure obligations apply from mid-May 2027. Paper collected and then digitised is also covered.\"}},{\"@type\":\"Question\",\"name\":\"Is a paper visitor register illegal under the DPDP Act?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Not directly. The Act covers digital personal data and data digitised after collection, so a register that is never scanned or typed up falls outside its scope. In practice, that condition rarely holds, and a shared open register still exposes every visitor&#8217;s details to the next one.\"}},{\"@type\":\"Question\",\"name\":\"What information should offices collect from visitors?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"For a routine guest: name, mobile number, organisation, host name, purpose and entry\\\/exit times. That set supports identification, host notification, security records and emergency roll-call, which are the four purposes you can actually justify. Anything beyond it ID images, biometrics, vehicle details, health data needs a stated purpose of its own.\"}},{\"@type\":\"Question\",\"name\":\"How long should visitor data be retained in India?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Long enough to satisfy the one-year floor Rule 6(1)(e) places on logs and personal data, and no longer than the purpose requires. Twelve months for the entry\\\/exit log is a defensible default, with contractor and candidate records moved onto their own schedules and CCTV kept under its own policy. Confirm the specifics with counsel.\"}},{\"@type\":\"Question\",\"name\":\"What should a visitor sign-in process look like?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Pre-registration by the host; a standalone privacy notice shown before the first field; consent captured by an affirmative action and logged with the notice version; minimal fields; identity confirmed against the invite rather than stored; host notified; a pass with a stated validity and zone; and a checkout that actually closes the record.\"}},{\"@type\":\"Question\",\"name\":\"How do you prepare visitor records for an audit?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Be able to produce six things: the versioned policy with its approver, a full day&#8217;s log with entry and exit times against named hosts, one visitor&#8217;s consent record showing what they saw and when, proof that deletion ran on schedule, the admin access list with its last review date, and the roll-call output from your most recent drill with any discrepancy reconciled.\"}},{\"@type\":\"Question\",\"name\":\"Should we use Aadhaar or facial recognition to verify visitors?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Neither should be your default. Private-entity Aadhaar authentication runs through an approval route that a reception desk does not sit in, and copies should not be retained. Facial templates are personal data and are hard to justify for people visiting once. Sight a photo ID where the category warrants it, store a confirmation rather than an image, and keep biometrics for a documented purpose with its own consent.\"}},{\"@type\":\"Question\",\"name\":\"Who owns the visitor management policy: HR, IT, or facilities?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Facilities or admin usually operate it, and IT configures the system, but the policy needs a single named owner with authority to enforce it, and legal or the DPO must sign off on the notice and retention sections. Split ownership without a named owner is why these documents go stale.\"}},{\"@type\":\"Question\",\"name\":\"Does the policy apply to contractors and delivery personnel?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Yes, with different rules. Contractors typically need roster verification, a safety induction, zone restrictions and permits, now framed by the OSH Code, 2020 rather than the repealed Contract Labour Act. Delivery personnel who stop at a defined drop point usually need minimal data and no escort. Define both categories explicitly rather than treating everyone as a guest.\"}},{\"@type\":\"Question\",\"name\":\"What happens if a visitor refuses to give their data?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Your policy needs a documented alternative, normally a minimal-data, fully escorted visit because consent given under threat of refused entry is difficult to characterise as free. Turning people away by default is the outcome you want to avoid designing into the process.\"}},{\"@type\":\"Question\",\"name\":\"How does a visitor policy work in a shared or coworking office?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Building security and your reception are separate collections by separate organisations. You need your own notice, your own retention practice and your own on-floor record for roll-call. Add a boundary clause naming which entry point is governed by whose policy, agreed with the operator in writing.\"}},{\"@type\":\"Question\",\"name\":\"How often should a visitor management policy be reviewed?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Annually at minimum, plus on any change to your premises, entry points, building operator, visitor volume or applicable law. Given the mid-May 2027 DPDP date and the labour codes commencing in November 2025, most Indian offices should schedule a review in 2026 rather than waiting.\"}}]}<\/script>\n\t\t\t\t\t\t\t<\/div>\n\t\t\n<\/article>\n\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Visitor Management Policy for Indian Offices: The 2026 Framework That Survives an Audit Key Takeaways A visitor management policy is a governance document. The software enforces it; the policy decides what gets enforced and who is accountable. Imported templates fail in India because they carry no DPDP notice, consent, retention or erasure architecture, and no [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1259,"comment_status":"open","ping_status":"open","sticky":false,"template":"elementor_header_footer","format":"standard","meta":{"footnotes":""},"categories":[35],"tags":[],"class_list":["post-1257","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-access-control-integration"],"_links":{"self":[{"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/posts\/1257","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/comments?post=1257"}],"version-history":[{"count":4,"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/posts\/1257\/revisions"}],"predecessor-version":[{"id":1266,"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/posts\/1257\/revisions\/1266"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/media\/1259"}],"wp:attachment":[{"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/media?parent=1257"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/categories?post=1257"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qudify.co\/blogs\/wp-json\/wp\/v2\/tags?post=1257"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}