Checking Out Who's Checked In
The ubiquitousness of paper logbooks means even solutions that are intended to prevent this from happening, such as 'discreet sheets' or 'peel off systems' are imperfect, and can be easily tampered with. Under GDPR, organisations should ensure that the names of those who have previously signed in are not visible to the next individual.
"There is a myth that paper falls outside of GDPR, but that's not the case," says Gregory Blondeau, Founder and co-CEO of Proxyclick. "Any form of structured processing of personal data falls inside the scope of GDPR. GDPR is technologically neutral, which means that any kind of processing of personal data - either electronic or manual - in a structured and consistent manner has to comply."
Making paper logbooks GDPR-compliant is possible, but it's not easy, he adds. "If the logbook is safely stored, if the data cannot be disclosed to third parties (other than receptionists), if it is destroyed in the shredder on a regular basis, and if all other GDPR requirements are complied with, it may be argued that a logbook might indeed be GDPR compliant."
Meanwhile the research reveals that a third of people feel uncomfortable about providing personal data during check-in - 35% of people are still nervous about the idea of signing in via fingerprint, facial recognition or voice recognition software - with the main reasons being a feeling that it's unnecessary for the level of their visit (85%) and not wanting personal data being stored by the company they're visiting (73%). This demonstrates that many visitors need to be reassured about how these new technologies are using and storing their data before they'll feel comfortable using them, adds Blondeau.
Through the independent research firm OnePoll, Proxyclick surveyed 2,000 US and UK office workers in summer 2018 about their experiences in corporate lobbies. The research reveals that 40 per cent of office workers have experienced a negative corporate welcome when coming into a building. Over 70 per cent (71.48%) cited unfriendly receptionists, followed by over half (53.78%) naming a lacklustre welcome as top reasons for their bad experience.
"The results demonstrate that human beings are inherently nosey - we want to know who's been there before us, whether for personal interest or commercial gain. But under GDPR, this is not allowed. Organisations need to ensure that their visitors' data is kept private and secure, however it is recorded," concludes Blondeau.