Planning retention periods for access control data requires carefully weighing security needs against data protection requirements, in particular the GDPR. For every type of data, the specific purpose must be defined and the retention period limited to the absolute minimum necessary. A detailed deletion concept, including technical implementation and regular review, is essential for legal compliance.

A strategic guide for companies on designing access control systems that comply with data protection law

Planning retention periods for data from access control systems is a complex task that requires both technical and legal expertise. Companies face the challenge of striking a balance between security needs and the strict requirements of the General Data Protection Regulation (GDPR). A well-founded deletion concept is essential here, to ensure legal compliance and avoid unnecessary risk.

Key Takeaways

  • A legally compliant deletion concept for access control data is essential to avoid GDPR fines and reputational damage. It requires a precise definition of data types and their processing purposes.
  • Retention periods must be set individually by data type and purpose, with the principle of storage limitation (GDPR Art. 5(1)(e)) always taking priority. Technical implementation and documentation are decisive here.
  • Independent consulting, as offered by PLANATEL®, ensures manufacturer-neutral, tailored and future-proof planning of deletion concepts that guarantee legal compliance and efficiency.

They protect sensitive areas, assets and information. But collecting access data comes with considerable responsibility: handling it in a legally compliant way and, in particular, setting appropriate retention periods. Many companies underestimate the complexity of this task, which goes far beyond simply installing a system. Flawed planning can not only lead to substantial fines but can also lastingly damage the trust of employees and business partners. This article examines the critical aspects of planning retention periods for access control data and shows how companies can master this challenge with independent expertise.

Article image: Access control data retention periods planning - hero

The fundamental importance of legally compliant retention periods

Implementing access control systems is a necessity for many companies, to ensure the security of people, assets and sensitive data. Whether it concerns protecting server rooms, research and development labs or production facilities, collecting access data is an integral part of this protection strategy. But data collection comes with the obligation to comply with strict data protection requirements. The General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG) form the legal framework governing the processing of personal data. A central pillar of this legislation is the principle of storage limitation under Article 5(1)(e) GDPR, which states that personal data may only be stored for as long as necessary for the purposes for which it is processed.

Failing to observe these requirements can have far-reaching consequences. Besides substantial fines, which can amount to up to €20 million or 4% of a company's global annual turnover, reputational damage and loss of trust among employees and customers are also at stake. It is therefore not enough merely to install an access control system; rather, a comprehensive concept must exist for the entire lifecycle of the collected data, one that precisely defines retention periods in particular. This requires a detailed analysis of the respective data types, their processing purposes, and the resulting statutory or operational need for their storage. Forward-looking, legally compliant planning is therefore not only a legal obligation but also a decisive factor for the company's long-term security and integrity.

Setting retention periods for data from access control systems rests on several legal pillars. At the centre is the GDPR, in particular the already-mentioned Article 5(1)(e), which enshrines the principle of storage limitation. In addition, Article 17 GDPR, the "right to erasure" (right to be forgotten), is of great importance. This right allows data subjects to request the deletion of their data where it is no longer necessary for the original purposes or where no other legal basis for storage exists.

The BDSG elaborates on and supplements the GDPR at the national level. For employee data, § 26 BDSG is particularly relevant, governing the processing of personal data within the employment relationship. Here too, the principle of necessity and purpose limitation applies. However, there are no blanket, fixed retention periods that apply equally to all access control data. Rather, companies must take a differentiated approach that takes into account the respective processing purpose of the data. For example, log data used solely for hazard prevention or investigating security incidents can generally only be stored for a very short period, often only a few days to weeks. Data used for time-and-attendance recording or to meet other statutory record-keeping obligations (e.g. under occupational safety law), on the other hand, may require longer periods, but must be clearly separated from pure access data and marked accordingly. The challenge lies in precisely identifying these different requirements and translating them into a coherent deletion concept.

Differentiating data types and their specific retention periods

To develop a legally compliant deletion concept, precise classification of the data collected by access control systems is essential. Not all data serves the same purpose or has the same relevance for security or other operational processes. A rough distinction can be made as follows:

  • Access event data: This is the core information about access events that have occurred (who, when, where). Its main purpose is documenting movements for hazard prevention and investigating security incidents. The shortest retention periods generally apply to this data, often only 72 hours up to a maximum of a few weeks, unless a specific security incident requires longer storage for investigative purposes.
  • Failed-attempt data: Logs of denied access attempts are important for detecting and analysing unauthorised access attempts. Short retention periods are appropriate here too, since the relevance of this data declines quickly.
  • Personal master data: This includes names, employee numbers, and permission profiles. This data is essential to operating the system. It is generally deleted once the person has left the company or no longer needs access authorisation. Employment-law or tax-law retention periods must also be observed here, though these do not directly concern the access events themselves.
  • Video data from surveillance: Where access control systems are coupled with video surveillance, separate, often even shorter, retention periods apply to the video data. The German Data Protection Conference (DSK) generally recommends a maximum retention period of 72 hours for video surveillance data, unless there is a specific reason for longer storage.

The challenge lies in implementing these different periods technically and ensuring that data is not stored for longer than absolutely necessary. Detailed documentation of the respective data types, their purposes, and the resulting retention periods is crucial here and must be reviewed regularly.

Article image: Access control data retention periods planning - mid

Developing a comprehensive deletion concept for access control systems

Creating a deletion concept for access control systems is a multi-stage process that requires interdisciplinary collaboration. It is not solely a task for the IT department, but must integrate the perspectives of data protection, the legal department, HR, and management. A structured approach secures legal compliance and acceptance within the company.

  1. As-is survey and data analysis: First, all data types collected in the access control system must be identified. The exact processing purpose must be defined for each data type (e.g. theft prevention, time-and-attendance recording, proof of working hours, investigation of offences).
  2. Legal assessment: Based on the purposes, a legal review determines which statutory or contractual retention obligations exist and which retention periods follow from the GDPR and the BDSG. The principles of data minimisation and storage limitation must always be observed here.
  3. Defining retention periods: A specific retention period is set for each data type. This should be as short as possible but as long as necessary to fulfil the defined purpose. A detailed justification for each period is essential.
  4. Technical implementation: The concept must describe how deletion is technically realised. This can be done through automated processes within the system or through manual procedures. Being able to prove deletion took place is important.
  5. Documentation: The entire deletion concept, including the as-is survey, the legal assessment, the defined periods, and the technical implementation, must be comprehensively documented. This documentation serves as proof of legal compliance to supervisory authorities.
  6. Training and awareness: Employees who work with the access control system and have access to the data must be trained regularly and made aware of the importance of the retention periods.

This process requires expertise and experience, to take all relevant aspects into account and produce a workable, legally compliant concept.

Technical implementation and integration of retention periods into system landscapes

After conceptually working out the retention periods, the focus shifts to technical implementation. A modern access control system should offer the ability to manage the defined retention periods automatically. This minimises manual sources of error and ensures consistent compliance with the requirements. Integration into the existing IT infrastructure is a critical success factor here.

  • Automated deletion mechanisms: Ideally, the access control system has built-in functions that enable time-controlled, irrevocable deletion of data. This concerns both log data and personal master data, as soon as permissions expire or a person leaves the company.
  • Database management: The underlying databases must be configured to efficiently support the deletion processes. This also includes regularly checking database integrity and ensuring that deleted data does not remain in backups for longer than necessary. Clear retention periods must also be defined for backups, based on the primary system.
  • Interfaces and integration: Where access control data is exchanged with other systems (e.g. time recording, HR management), the deletion concepts must be synchronised across all systems involved. It must be ensured that data deleted in the access control system is not improperly retained in a linked system.
  • Audit trails and logging: The performance of deletion operations should itself be logged, to ensure legal compliance can be proven. These audit trails are essential for internal reviews and in the event of requests from supervisory authorities.
  • Manufacturer independence: When selecting or adapting systems, it is crucial to pay attention to manufacturer independence. Systems that allow flexible configuration of retention periods and offer open interfaces make legally compliant implementation easier and reduce manufacturer dependency. PLANATEL® supports companies in identifying and planning manufacturer-independent solutions that meet individual requirements.

Technical implementation requires deep systems understanding and precise planning, to avoid misconfigurations and the associated data protection risks.

Challenges and common mistakes when planning retention periods

Despite clear legal requirements and the available technical options, challenges and mistakes repeatedly arise when planning and implementing retention periods for access control systems. These can have far-reaching consequences and jeopardise the legal compliance of the entire system.

  • Excessive storage: One of the most common mistakes is storing data beyond the period actually required. Often, out of an exaggerated sense of security need or a lack of knowledge of the legal requirements, data is kept "just in case" for longer. This directly violates the GDPR's principle of storage limitation.
  • Lack of purpose limitation: Data is collected without clearly defining the exact purpose of its storage. Without a precise determination of purpose, however, it is impossible to set an appropriate retention period.
  • Inconsistent application: In larger organisations or when using different systems, inconsistent deletion practices can arise. This leads to uneven data handling and makes it harder to demonstrate legal compliance.
  • Missing documentation: Another problem is inadequate or missing documentation of the deletion concept. Without a written record of the periods, justifications and technical implementations, it is nearly impossible to prove compliance with data protection requirements during an audit.
  • Inadequate technical implementation: Manual deletion processes are error-prone and resource-intensive. If automated deletion mechanisms are missing or misconfigured, data remains stored for longer than permitted.
  • Neglect of backups: It is often forgotten that data contained in backups is also subject to the retention periods. A comprehensive deletion concept must therefore also take the backup strategy and its retention periods into account.
  • Manufacturer dependency: Systems that do not offer flexible retention periods or export options can push companies into manufacturer dependency and make legally compliant implementation harder.

These mistakes show that careful, independent planning is essential, to master the complexity of the subject matter and minimise risk.

The role of independent consulting in planning retention periods

Given the complexity and the potential risks involved in planning retention periods for access control systems, drawing on independent expertise is a decisive advantage. PLANATEL®, as an independent planning and consulting company, has offered comprehensive support in this area since 1992. Our more than 34 years of experience in planning security systems and IT infrastructure enable us to support companies in developing and implementing legally compliant, efficient deletion concepts.

Our core competence lies in manufacturer-neutral and financially independent consulting. This means we receive no commissions from system manufacturers and therefore act exclusively in our clients' interests. We analyse your specific requirements, the existing system landscape, and the relevant legal framework, to develop a tailored deletion concept. This includes:

  • A detailed analysis of the data types collected and their processing purposes.
  • Deriving legally compliant retention periods with regard to the GDPR, the BDSG, and other relevant regulations.
  • Designing technical solutions for automated, verifiable data deletion.
  • Integrating the deletion concept into the existing IT and security infrastructure.
  • Producing comprehensive documentation that serves as proof of legal compliance.
  • Supporting the selection of certified installers for the technical implementation, where required.

Through our independent perspective, we help you avoid manufacturer dependencies and implement solutions that not only meet current requirements but are also future-proof and flexible. We plan maintenance concepts and select certified installers, to ensure the long-term functionality and legal compliance of your systems.

Continuous review and adjustment of the deletion concept

Once created, a deletion concept is not a static document but must be understood as a living instrument that requires continuous review and adjustment. The legal framework, particularly in the field of data protection, is constantly evolving. New court rulings, recommendations from data protection supervisory authorities, or changes in technical standards can make adjusting existing concepts necessary. For example, the recommendations of the Data Protection Conference (DSK) on the retention period for video data can change, which would have direct implications for coupled access control systems.

In addition, a company's internal requirements may also change. An expansion of business areas, the introduction of new processes, or the restructuring of departments can mean that data is processed for new purposes or that existing purposes no longer apply. Such changes must be promptly reflected in the deletion concept, to ensure ongoing legal compliance. Regular internal audits and the involvement of the data protection officer are essential here. PLANATEL® recommends reviewing the deletion concept at least once a year, or in the event of significant changes to the system landscape or the legal framework, and adjusting it where necessary. This includes:

  • Checking the currency of the legal foundations.
  • Assessing the effectiveness of the technical deletion mechanisms.
  • Monitoring compliance with the defined retention periods.
  • Updating the documentation when changes occur.
  • Conducting refresher training for relevant employees.

Only through proactive, ongoing maintenance of the deletion concept can a company ensure the long-term legal compliance of its access control systems and protect itself against potential risks. PLANATEL® also supports you in establishing these review processes and conducting regular audits.

Article image: Access control data retention periods planning - bottom

Next step

Contact us for a no-obligation initial consultation.

PLANATEL®: Independent planning and consulting since 1992
Tel: 040 / 23 73 02-30
Email: info@planatel.de

Frequently asked questions

Why is precise planning of retention periods for access control systems so important?

Precise planning of retention periods is crucial for ensuring legal compliance with the GDPR and the BDSG. It prevents unnecessary accumulation of data, minimises the risk of data protection breaches, and protects the company from substantial fines and reputational damage. It also fosters the trust of employees and business partners by demonstrating responsible handling of personal data. Without a clear concept, data can be stored for an impermissibly long time, which is a permanent risk.

Which data types are typically subject to retention periods in access control?

Typical data types include access event data (who, when, where), failed-attempt data, personal master data (name, permissions), and, where applicable, coupled video data. Specific retention periods must be defined for each of these categories, based on the respective processing purpose. While pure access events are often stored only briefly, master data can remain relevant until the end of the employment relationship or the authorisation.

How can PLANATEL® support the planning of retention periods?

PLANATEL®, as an independent planning and consulting company, offers comprehensive support. We analyse your specific requirements, develop tailored, manufacturer-neutral deletion concepts that take all legal requirements into account, and support the technical implementation. Our expertise ensures you get a legally compliant, efficient and future-proof solution that avoids manufacturer dependencies and optimises costs. We support you from the analysis through to documentation and beyond.

What are the biggest risks of flawed planning of retention periods?

The biggest risks include substantial fines under the GDPR, which can amount to up to €20 million. In addition, there is significant reputational damage, loss of trust among employees and customers, and potential legal disputes. Flawed planning can also lead to unnecessary complexity in data management and impair the efficiency of the security systems. Impermissible storage of data is a permanent data protection risk.

Must backup data from access control systems also be deleted?

Yes, absolutely. The deletion concept must also take into account data contained in backups. It must be ensured that deleted data does not remain in backups for longer than necessary for restoration purposes. This requires careful planning of the backup strategy and its retention periods, which must be synchronised with those of the primary system. Deletion on the active system alone is not sufficient.

How long may access data be stored under the GDPR?

The GDPR does not prescribe fixed periods, but requires that data only be stored for as long as necessary for the original purpose (storage limitation, Art. 5(1)(e)). For purely security purposes, this is often only a few days to weeks, and in exceptional cases up to six months. Longer periods require a specific legal justification, for example for time-and-attendance recording.

What is a deletion concept for access control systems?

A deletion concept is a detailed plan that sets out which data from access control systems is deleted when, how and why. It covers identifying data types, defining retention periods based on legal requirements and purposes, the technical implementation of deletion, and documenting the entire process.

What role does the data protection officer play in planning retention periods?

The data protection officer (DPO) plays a central role in planning retention periods. They advise the company on data protection requirements, review the appropriateness of proposed retention periods, and support the creation of the necessary documentation to ensure legal compliance.

Can access data be used for time-and-attendance recording?

Yes, under certain conditions access data can also be used for time-and-attendance recording. However, this requires a clear determination of purpose, transparent information for the individuals concerned, and often longer retention periods that comply with employment-law requirements. It is important to clearly separate this data from pure security data and to define separate retention periods.

Sources and further information