Skip to main content
CoReceptionist
Schedule a demo
Resources / Blog / GDPR retention for visitor photos
COMPLIANCE · FEB 20, 2026 · 6 MIN READ

GDPR retention for visitor photos

How long is too long? Setting photo and data retention that satisfies both counsel and CISO.

MC
Maya ChenHead of Security Research, CoReceptionist

How long is too long? Visitor photos are personal data, and “forever” is not a retention policy. The right answer balances security value against data-minimization principles.

Retention per site, deletion on schedule

Set retention policies per location, and let visitor data — photos included — delete on your schedule, not ours. Counsel gets the policy; the CISO gets the audit trail.

Keep reading

Make your visitor log audit-ready