How long should you keep a visitor's photo? "Forever" is not a retention policy — and under privacy laws such as the EU and UK GDPR, it isn't a defensible one either. Visitor photos are personal data. The right retention period balances what the photo is for against the principle that you shouldn't keep personal data longer than you need it.
This guide covers what the rules expect, how to choose a retention period for visitor photos and logs, and how to apply it automatically. It is general information, not legal advice; your data protection officer or counsel should approve your final policy.
Why visitor photos need a retention policy
A visitor photo on a badge or in a visit record helps staff recognize who belongs on site and helps security review an incident. But it also identifies a person, often alongside their name, company and the time they were in your building.
Under the GDPR, two principles apply directly:
- Data minimization: collect only the personal data you need for your purpose.
- Storage limitation: keep it in a form that identifies people for no longer than that purpose requires.
Neither sets a fixed number of days. Both expect you to decide a period, write it down, and apply it.
Start with the purpose
Decide why you capture photos, because the purpose sets the period:
- Badge identification: the photo's main job is done when the visitor leaves.
- Security review: you may want photos available for long enough to investigate an incident reported after the visit.
- Regulated access: export-controlled or other regulated sites may need visit records — though not necessarily photos — kept for longer to meet their own rules.
If you can't name a purpose for keeping photos beyond the visit, that's a sign the period should be short.
How to set a retention period
- Separate photos from the visit record. Many organizations keep the log entry (name, host, times, documents signed) longer than the photo itself.
- Match the period to the purpose. Long enough to cover how late incidents are typically reported at your site, and no longer.
- Account for legal obligations. Some industries must keep visit records for a set period; check which apply to you.
- Set it per location if your sites differ. A lab handling regulated material may need different rules from a sales office.
- Document the decision. Record the purpose, the period and who approved it, so you can explain it if asked.
- Apply it automatically. A policy that depends on someone remembering to delete files will drift.
Tell visitors what you collect
Visitors should know a photo is being taken, why, and how long it's kept. A short notice on the kiosk welcome screen or in your visitor privacy notice, linked from the pre-registration invite, covers it. Keep it plain: what you collect, why, how long, and who to contact.
Handling deletion and access requests
Visitors can ask what you hold about them and, in some cases, ask you to delete it. Make sure you can find a visitor's records quickly — by name and date in the visitor log — and that someone owns these requests.
Visitor logs need a policy too
Photos get the attention, but the visit log holds personal data too: names, companies, phone numbers, hosts and timestamps. Apply the same thinking — purpose, period, documentation — to the whole record, including signed NDAs and screening results.
How CoReceptionist handles visitor data retention
- Retention policies you set, per location, so visitor data — photos included — is deleted on your schedule.
- Private check-in: each visitor sees only their own entry, unlike an open paper log.
- Role-based access: only the roles you choose can see visitor records and screening results.
- Encryption at rest for stored visitor data.
- Searchable records, so access and deletion requests can be answered quickly.
CoReceptionist hosts customer data in the United States on AWS. If you're subject to the GDPR, include that international transfer in your data protection assessment. Our security overview and security FAQ cover hosting, encryption and access control in more detail.
Frequently asked questions
Is there a legally required retention period for visitor photos? Generally no — the GDPR asks you to set a period that fits your purpose and justify it. Specific industries or regulations may require visit records to be kept for a set time, which is one reason to separate the photo from the log entry.
Do we need consent to photograph visitors? Not always. Many organizations rely on legitimate interests for site security, but you still need to tell visitors about it. Confirm the right legal basis with your data protection officer.
Should photos be printed on badges? It helps staff recognize visitors at a glance. If you print photos, keep the badge design simple and collect badges at check-out where you can.
For more on running a privacy-conscious front desk, see visitor management best practices.


