Visitor sign-in policy: what to include
A short, clear visitor sign-in policy sets expectations, protects people’s privacy and helps you meet your health-and-safety duties. Here is what a good one covers.
Purpose
State why you record visitors: to know who is on site for safety and evacuation, to notify hosts, and to keep an auditable record. Being clear about purpose is also good privacy practice.
What you collect and why
- Name, company and host — to identify the visitor and who is responsible for them.
- Arrival and departure times — for an accurate on-site list and evacuation.
- Any inductions or agreements required for the areas they enter.
- Only what you need — avoid collecting more than the purpose requires.
Privacy and retention
Say how visitor information is stored, who can see it, and how long it is kept before deletion. A digital system keeps each visitor’s details private (unlike a shared paper book) and can purge records automatically after a set period.
Emergencies
Explain that the record is used to account for everyone in an evacuation, and that visitors must sign out when they leave so the on-site list stays accurate.
Frequently asked questions
Is a paper visitor book a privacy risk?▾
It can be — every visitor can read the names, companies and times of those before them. A digital sign-in keeps each entry private to your organisation.
How long should we keep visitor records?▾
Keep them only as long as needed for your stated purpose or as required by law, then delete or de-identify. EntryWatch supports configurable retention with automatic purge.
Related guides
Put this into practice with EntryWatch
Free until 2027 for founding customers.
Create your free organisationThis guide is general information, not legal advice. Check your own obligations and, where needed, take professional advice.