1. Define each purpose
Write down why the school records visits. Common purposes include site security, safeguarding, emergency accountability and investigating an incident. Avoid a single broad statement such as administration because it does not explain the processing clearly.
For each purpose, identify the lawful basis and document the reasoning. Consent is not automatically the best basis simply because a form can include a checkbox.
- Purpose and lawful basis are recorded.
- The process owner and people with access are named.
- Any safeguarding or health information is assessed separately.
- The record appears in the school's record of processing activities.
2. Collect only what is needed
Review every field on the sign-in form. A name, host, organisation, arrival time and departure time may be enough for many visits. Date of birth, home address or an identity-document copy should not be collected by default without a specific need.
If the school records safeguarding checks, separate the minimum status needed at reception from supporting evidence that only authorised staff should access.
3. Give a clear privacy notice
Provide a short notice where the visitor supplies their information, with a link or QR code to the complete notice. It should explain the controller, purposes, lawful basis, recipients, retention, rights and how to contact the school or its data protection officer.
Use plain language that a visitor can read before completing sign-in. A notice hidden after submission does not provide timely transparency.
4. Set access and retention rules
Reception, safeguarding and system administration do not need identical access. Use named accounts, role-based permissions and an audit history. Remove access when responsibilities change.
Set a justified retention period for routine visits and a separate process for records linked to an incident, legal claim or safeguarding matter. Test deletion and backup expiry rather than relying only on a written policy.
5. Check the supplier and incident process
Document hosting locations, subprocessors, international transfers, security controls, deletion assistance and breach notification duties. Put controller-processor obligations into the contract where required.
Staff should know how to correct a record, respond to a rights request and report a suspected disclosure. A procedure that only the system administrator understands is fragile.
- Processing agreement reviewed and signed.
- Hosting and transfer arrangements documented.
- MFA, encryption, backups and access reviews confirmed.
- Rights requests and incidents have named owners.
- The full process is reviewed after material changes.