Start here
Visitors and identification
What the gate asks a visitor for, what is actually stored when a school collects an ID number, and a correction to what earlier documentation said.
A correction to earlier documentation
An earlier data-protection pack, the kind attached to a service agreement, told schools that the visitor register keeps “only a one-way fingerprint of the ID’s last four digits, never the number itself”.
That is not true wherever a school’s own intake policy asks for a full ID number, and this page exists partly to say so plainly. If your school relied on that sentence when it wrote its privacy notice, the notice needs updating.
The accurate statement is this. A one-way fingerprint of the last four digits is kept, and it is what the ban screening uses. Where the school’s policy collects a full ID number, the number itself is also kept — encrypted at rest, tied to the school that captured it, and never stored in readable form.
How the mistake happened is worth knowing, because it is easy to repeat. The app’s ban-list screen carries an accurate line of its own: “People refused entry at the gate. The full ID number is never stored — only the name and a one-way hash of the last 4 digits.” That is correct about the ban list. It was generalised into a statement about the whole visitor register, which is a different thing.
What the gate asks a visitor for
When somebody signs in at the gate, the officer’s form can ask for the visitor’s name, a phone number, the reason for the visit, an ID number, and a vehicle registration.
Which of those are compulsory is your school’s decision, and the ID number is not required by default. A new school starts with the phone number and the reason compulsory, and the ID number and vehicle registration optional. A school that wants an ID number for every visitor turns that on deliberately.
This is the decision a principal actually has to take. Requiring an ID number is a reasonable choice for a school that wants a defensible register of who was on site. It is also a choice to start holding identity numbers, and it should be written into your privacy notice as one.
What is stored, exactly
Three things, and they behave differently.
The last four digits, as a one-way fingerprint. Whether the visitor gave a full ID or only the last four digits, the last four are turned into a fingerprint that cannot be reversed back into digits. This is what the ban screening compares against, and it is why screening works without anything holding a readable number. The fingerprint is computed with a key and is tied to your school, so the same four digits produce a different fingerprint at a different school.
The full number, encrypted — only if it was collected. If your school’s policy asks for the whole ID and the visitor gives it, that number is encrypted before it is written down. There is no column anywhere holding it in readable form; the encrypted value is the only copy. Each encrypted value is bound to the school that captured it, so a record cannot be lifted into another school’s data and opened there.
Nothing on screen. Having been captured at sign-in, the ID number is not displayed again anywhere in the app. No visitor list, no register view, no report shows it back. It sits encrypted, available to a lawful read, and otherwise out of sight.
If the encryption key is unavailable, the sign-in fails rather than writing the visitor’s details in the clear. A visitor record that quietly downgraded itself to plain text on a bad afternoon would be the worst of both worlds: exposed, and nobody knowing.
The ban list is genuinely different
The ban list — the people your school has refused entry — really does hold only a name and a one-way fingerprint of the last four digits. There is no encrypted full number behind it, because there is no full number: the form asks for four digits, they are turned into a fingerprint immediately, and the digits themselves are never written down.
When the ban list is displayed, an entry does not even show the four digits back. It shows only whether an ID fingerprint is on file at all.
This is deliberate minimisation of a list that is, by its nature, a list of allegations about named people. It is also exactly why the sentence about it should never have been repeated about the register as a whole.
Why hold any of it
Two reasons, and they are the ones to put in a privacy notice.
The first is screening. When a visitor signs in, the name and the fingerprint are checked against the ban list, and a match stops the sign-in and calls for an administrator. A name alone is a weak check; four digits of an ID is a much stronger one, and it can be done without holding a readable number.
The second is the register itself. A school that has to answer “who was on site on the afternoon of the incident” needs a record that identifies people rather than gesturing at them. That is the case for collecting a full ID, and it is also the reason the number has to be protected rather than simply written down.
How long visitor records are kept
Visitor records are kept for two years by default. Your school can shorten that to a minimum of one year, or extend it — up to ten years, which is the one deliberate exception in the whole retention policy. It exists because a school can carry an occupational-health or insurer duty on its visitor register that runs longer than the two years everything else is capped at.
Extending it is a deliberate edit on the school’s privacy screen, not a default somebody inherits. If you extend it, you are choosing to hold visitors’ identity numbers for that long, and that is worth writing down next to the reason.