Visitor management compliance: what UK premises need to record
No UK law says you must keep a visitor book. That surprises people, because almost every premises has one. The duty is real, but it comes from three separate places rather than one, and the way most organisations meet it, an open paper book on the reception desk, now creates a data protection problem of its own. This guide sets out what the law actually requires, what you should and should not record, and how long to keep it.
This article is for informational purposes only and does not constitute legal advice. Duties vary by premises type and sector, and you should take qualified health and safety or data protection advice for your specific circumstances.
Is a visitor book a legal requirement in the UK?
Not by name. No piece of UK legislation refers to a visitor book, a sign-in sheet or a visitor log as a specific requirement. If you search for the law that mandates one, you will not find it.
What exists instead are three duties that, taken together, make a visitor record the only practical way to comply. Understanding which duty you are meeting matters, because it tells you what to record and how the record needs to behave in an emergency.
The three duties in short
1. Fire safety. You must be able to account for everyone on the premises during an evacuation.
2. Health and safety. You owe a duty of care to people who are not your employees.
3. Data protection. Whatever you record about visitors is personal data, and UK GDPR applies to it.
Duty one: fire safety and accounting for people
In England and Wales, the Regulatory Reform (Fire Safety) Order 2005 places duties on the “responsible person” for non-domestic premises. Those duties cover employees and, separately, people who are not employees: the Order requires fire precautions that are reasonably required to ensure the premises are safe for them too.
The Order does not tell you to keep a list. It requires a fire risk assessment, and it requires you to have procedures in place for evacuation. In practice, almost every fire risk assessment concludes the same thing: you cannot confirm that a building is clear unless you know who was in it. That is where the visitor record comes from. If the fire service arrives and asks whether anyone is still inside, “we think that’s everyone” is not an answer.
The Management of Health and Safety at Work Regulations 1999 reinforce this, requiring employers to establish procedures for serious and imminent danger, which includes evacuation and accounting for people.
Scotland and Northern Ireland have their own equivalent regimes rather than the 2005 Order, so if you operate across the UK, check which applies to each site.
The practical test is simple: in an evacuation, can somebody standing at the assembly point produce an accurate list of everyone who should be there? If your answer depends on a book behind a reception desk nobody can now reach, or a PC that has lost power, the record exists but it does not work. This is exactly the gap a fire roll call system closes, by putting the live on-site list on a mobile device outside the building.
Duty two: health and safety towards non-employees
Section 3 of the Health and Safety at Work etc. Act 1974 requires employers to conduct their business so that people who are not their employees are not exposed to risks to their health or safety, so far as is reasonably practicable. Visitors, contractors and delivery drivers all sit under that duty.
This shapes what a good sign-in process does beyond simply capturing a name. It is the point at which you can confirm a visitor has been told what to do if the alarm sounds, where the assembly point is, and any site-specific hazards. For contractors, it is where you check they have seen the site induction and hold the permits they need.
Construction sites have a further layer under the Construction (Design and Management) Regulations 2015, which require site inductions and control over who is on site. Schools, care settings and other regulated environments have their own safeguarding and identity-check requirements on top of everything here.
Duty three: visitor data is personal data
Everything you write in a visitor record is personal data, and UK GDPR applies to it in full. This is the duty most often overlooked, partly because a paper book feels informal in a way a database does not. Data protection law is technology neutral: a name written in ink is treated the same as a name in a system.
That has two consequences. First, you need a lawful basis for collecting it, which for most premises is legitimate interests, covering site safety and security, with a legitimate interests assessment recorded. Second, the data protection principles apply, including data minimisation and the requirement to keep personal data secure.
The same principles cover employee attendance data, and our guide to UK GDPR and time and attendance data goes into the lawful basis question in more depth.
The open visitor book problem
Here is where a lot of published advice overstates the position, so it is worth being precise.
You will read that “GDPR requires visitor books to hide previous visitors’ names.” No provision of UK GDPR says that. What the law does say is that personal data must be processed in a way that ensures appropriate security, including protection against unauthorised access, and that you should collect no more than you need.
An open book where each visitor can read the names, employers and hosts of everyone before them does disclose personal data to unrelated third parties. That is hard to justify against those principles, and it is a real risk rather than a theoretical one: anyone can walk into a reception, glance at the page and learn which suppliers, candidates or competitors have visited you. The book is also easy to lose, and it offers no practical way to honour an erasure request without scribbling out a line.
So the honest framing is not “paper books are illegal.” It is that a standard open book is difficult to defend, and there are straightforward fixes:
- A book with concealed panels, so each visitor sees only their own line
- Keeping the book behind the desk, completed by reception staff rather than by visitors
- A digital system, which shows each visitor a blank form and keeps everything else private
A digital approach also solves the erasure problem, gives you a searchable record, and produces the live on-site list that a fire evacuation actually needs. That combination is what visitor management software is built to handle.
What to record, and what to leave out

Data minimisation means collecting what you need for your stated purpose, and nothing more. For most premises that comes down to a short list.
| Field | Record it? | Why |
|---|---|---|
| Name | Yes | Needed to account for people in an evacuation |
| Organisation | Yes | Identifies the visitor and their reason for being on site |
| Host being visited | Yes | Someone can confirm whether they are still on site |
| Time in and time out | Yes | Without a sign-out, your on-site list is wrong |
| Contact number | Often | Useful if you need to reach someone after they leave |
| Vehicle registration | Only if needed | Justified where you manage parking or site access, not by default |
| Home address | Rarely | Hard to justify for a site visit |
| Reason for visit, in detail | Careful | Can reveal sensitive information, for example in a clinical or HR setting |
The sign-out is the field that fails most often. A record of arrivals with no departures does not tell you who is in the building, which defeats the fire safety purpose entirely. Any process you adopt needs to make signing out as easy as signing in, or people simply will not do it.
How long should you keep visitor records?
There is no statutory retention period for visitor logs. That means the storage limitation principle applies: keep them only as long as you have a genuine purpose, then delete them.
For routine visits, many organisations settle on somewhere between one and three months. That is long enough to cover evacuation checks, security queries and any incident that surfaces shortly afterwards. Where a visit is connected to an accident or an investigation, that record may need to be kept longer as part of the relevant file, and the reason should be documented.
What matters is that you have decided a period, written it down, and actually apply it. A visitor book from 2019 sitting in a cupboard is personal data you have no reason to hold, and it is the kind of thing that turns a minor incident into a reportable one.
Check your own visitor process
Work through the questions below to see where your current process stands. Nothing is recorded or sent anywhere, this runs entirely in your browser.
Bringing it together
The duties behind visitor records are not complicated once you separate them. Fire safety tells you that you must be able to account for everyone on site. Health and safety tells you that you owe those people a duty of care while they are there. Data protection tells you to collect only what you need, keep it secure, and not hold it forever.
The reason a paper book struggles is that it is asked to do all three jobs and does none of them especially well. It exposes data to whoever is standing at the desk, it is difficult to search or erase, and it is often the one thing nobody grabs when the alarm sounds.
A digital process handles the same duties without those trade-offs, and connects the visitor record to the fire roll call so the list at the assembly point is accurate and current. If you would like to see how that works in practice, our team can walk you through it.
See visitor management and fire roll call working together