Legally compliant planning of access control systems requires compliance with the General Data Protection Regulation (GDPR) and the Federal Data Protection Act (BDSG). This includes defining clear legal bases, implementing suitable technical and organisational measures (TOMs), carrying out a data protection impact assessment (DPIA) where the risk is high, and ensuring data minimisation as well as transparent information obligations toward data subjects.

Legally compliant implementation of access control systems in practice

Modern access control systems are essential for the security of businesses, yet they also carry significant data protection challenges. Careful, legally compliant planning is crucial to avoiding fines and securing the trust of employees and partners.

Key Takeaways

  • Legally compliant planning of access control systems is essential to avoid substantial fines and secure the trust of employees and partners.
  • Selecting the legal basis, implementing suitable technical and organisational measures (TOMs), and carrying out a data protection impact assessment (DPIA) are core components of the planning.
  • Manufacturer-neutral consulting and comprehensive documentation are decisive for ensuring tailored, future-proof, and demonstrably GDPR-compliant solutions.

Access control systems play a central role in protecting company assets, sensitive data, and the safety of employees. But implementing such systems is complex, particularly where it involves complying with the strict requirements of the General Data Protection Regulation (GDPR). Companies must ensure that their access systems not only effectively protect against unauthorised access but also guarantee the responsible handling of personal data. Forward-looking, legally compliant planning is the key to success here, and to avoiding considerable legal and financial risk.

Article image: Access control GDPR-compliant planning - hero

GDPR and access control fundamentals: why legally compliant planning is decisive

Since it came into force in May 2018, the General Data Protection Regulation (GDPR) has significantly tightened the requirements for processing personal data across the European Union. For companies using access control systems, this means a comprehensive review and adjustment of their processes. Access control systems typically collect and process identification data such as names, personnel numbers, and company affiliation, as well as access data such as timestamps and room numbers. This information counts as personal data and is therefore subject to the GDPR's strict rules.

The need for legally compliant planning follows from several GDPR articles, in particular Article 32, which establishes the obligation to protect personal data through "appropriate technical and organisational measures" (TOMs). A GDPR violation can not only lead to substantial fines but can also lastingly damage the trust of employees and customers. Planning must therefore incorporate the principles of data minimisation, purpose limitation, and transparency from the outset. This means that only the absolutely necessary data may be collected, processed only for clearly defined purposes, and data subjects must be comprehensively informed about the data processing. Forward-looking planning that integrates these aspects is essential, to ensure both physical security and data protection while minimising legal risk.

Selecting the correct legal basis is a fundamental step in planning GDPR-compliant access control. Under Article 6 GDPR, processing personal data is only lawful if at least one of the conditions listed there is met. For access control systems, two legal bases primarily come into consideration: the legitimate interest of the controller (Art. 6(1)(f) GDPR) and the performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR).

The legitimate interest lies, for example, in protecting property, infrastructure and employee safety. This requires a careful balancing of interests between the company's protective interests and the fundamental rights of data subjects. For employees, § 26 of the Federal Data Protection Act (BDSG) can also serve as a legal basis, provided the data processing is necessary for carrying out the employment relationship. When collecting data, the principle of data minimisation (Art. 5(1)(c) GDPR) must also be observed: only data absolutely necessary for the respective purpose may be collected. This typically covers identification features and access times. Biometric data, such as fingerprints or facial scans, counts as a special category of personal data (Art. 9 GDPR) and generally requires the explicit consent of the data subject as well as a mandatory data protection impact assessment. PLANATEL® supports you in precisely defining these legal bases and setting out the required data categories, to create a solid foundation for your access control system.

Technical and organisational measures (TOMs) for access control

Implementing suitable technical and organisational measures (TOMs) is a core requirement under Article 32 GDPR for the security of processing personal data. When planning access control systems, TOMs must aim to ensure the confidentiality, integrity and availability of the data. These include measures for physical access control (physical entry to rooms), logical access control (use of IT systems), and authorisation control (permissions within systems).

Examples of technical measures:

  • Use of automated access control systems with chip cards or transponders.
  • Encryption of transmission and storage data.
  • Regular security audits and penetration tests.
  • Implementation of two-factor authentication for access to systems.
  • Securing servers and network technology in lockable server cabinets.

Examples of organisational measures:

  • Clear key policies and key registers.
  • Keeping a visitor book or digital visitor logs.
  • Regular review and updating of access permissions.
  • Training employees in handling access media and data protection guidelines.
  • Producing work instructions on locking office rooms when unattended.

The selection and combination of these measures must be risk-based and reflect the state of the art. PLANATEL® supports you in analysing your specific requirements and designing a tailored TOM catalogue that ensures the legal compliance and security of your access control systems.

Article image: Access control GDPR-compliant planning - mid

The role of the data protection officer and the data protection impact assessment (DPIA)

The data protection officer (DPO) plays a central role in the legally compliant planning and implementation of access control systems. They advise management and the specialist departments on all data-protection-relevant questions and monitor compliance with the GDPR. Involving them early is crucial, to identify and minimise potential data protection risks already during the design phase.

Another critical requirement is carrying out a data protection impact assessment (DPIA) under Article 35 GDPR. A DPIA is always mandatory when a new processing activity, such as introducing an access control system, is likely to result in a high risk to the rights and freedoms of natural persons. This is particularly the case when processing special categories of personal data (e.g. biometric data) or with extensive systematic monitoring of publicly accessible areas.

The DPIA covers a detailed description of the planned processing operations, an assessment of the necessity and proportionality of the measures, a risk assessment for the rights and freedoms of data subjects, and a description of the planned remedial measures. One example would be introducing a fingerprint scanner, where the risks to the biometric data and the proportionality of the measure must be carefully assessed. PLANATEL® accompanies you through the DPIA process and ensures that all relevant aspects are taken into account and the results transparently documented.

Retention periods and deletion concepts: data minimisation in practice

The principle of storage limitation (Art. 5(1)(e) GDPR) is a central pillar of the GDPR, stating that personal data may only be stored for as long as necessary for the purposes for which it is processed. This applies to a particular degree to data from access control systems. Blanket, indefinite storage without a specific reason is not permissible and can lead to significant data protection problems.

Setting appropriate retention periods requires carefully weighing the company's security interests against the rights of data subjects. While only short-term storage is often necessary for purely operational purposes (e.g. permission checks), longer periods may be justified when investigating security incidents or meeting statutory record-keeping obligations. For example, log data for access management is stored for 7 days in some cases, but can be retained for longer where there is a specific suspicion of an incident, provided this is clearly documented and justified. For master data in identification systems in security-relevant areas, such as airports, a retention period of up to ten years may be permissible, but this too must be justified.

A structured deletion concept is therefore essential. It must define which data categories are collected, what purposes they serve, how long they are stored, and when and how they are deleted, whether automatically or manually. This requires implementing technical mechanisms for automated deletion and organisational processes for monitoring the retention periods. PLANATEL® supports you in developing and implementing such concepts, to effectively achieve data minimisation in your access control.

Manufacturer-neutral planning and system selection: independence as a success factor

Selecting the right access control system is a strategic decision with far-reaching implications for a company's security, efficiency and legal compliance. In this process, manufacturer neutrality is of decisive importance. Many access control system vendors offer integrated solutions that are often tied to specific hardware or software. Independent planning, as PLANATEL® has practised for more than 34 years, ensures that the choice of system is based exclusively on the customer's individual requirements and not on the interests of a particular manufacturer.

PLANATEL® acts as an independent planning and consulting company and receives no commissions whatsoever from manufacturers or installers. This enables an objective assessment of the various systems and technologies on the market. We analyse your specific needs and assess the technical possibilities and data protection implications of different solutions. In doing so, we take into account aspects such as scalability, integration capability with existing infrastructure, ease of maintenance, and, of course, compliance with all relevant data protection standards. A manufacturer-neutral tender and award process also ensures that you receive the best possible solution on fair terms and that unnecessary manufacturer dependency is avoided. This is particularly important for ensuring long-term flexibility and being able to respond to future technological developments as well as changing legal requirements.

The GDPR places great emphasis on accountability (Art. 5(2) GDPR), meaning that companies must not only act in a legally compliant manner but must also be able to prove this at any time. This is of immense importance when planning and operating access control systems. Comprehensive, up-to-date documentation is key to being able to demonstrate compliance with data protection rules in the event of a review by supervisory authorities or requests from data subjects.

The documentation should cover the following elements:

  • Record of processing activities: A detailed description of all processing operations relating to access control, including the purposes, data categories, legal bases, recipients, and retention periods.
  • Data protection concept: A comprehensive concept that clearly sets out the data protection framework, the implemented TOMs, and the responsibilities.
  • Data protection impact assessment (DPIA): Where required, the complete documentation of the DPIA, including the risk analysis and the remedial measures taken.
  • Works agreements: Where employees are affected, the relevant works agreements on introducing and using the access control system.
  • Training records: Documentation of the training provided to employees on data protection and the use of the system.
  • Logs: Regular logging of access attempts, system changes, and maintenance work.

These documents must be reviewed and updated regularly, to reflect changes in system configuration, legal requirements, or operational processes. PLANATEL® supports you in creating and maintaining this documentation, to comprehensively fulfil your accountability obligations and ensure complete demonstrability of legal compliance.

Article image: Access control GDPR-compliant planning - bottom

Next step

Contact us for a no-obligation initial consultation.

PLANATEL®: Independent planning and consulting since 1992
Tel: 040 / 23 73 02-30
Email: info@planatel.de

Frequently asked questions

For processing access data, the legitimate interest of the controller (Art. 6(1)(f) GDPR) in protecting property and safety, as well as the performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR), are primarily relevant. For employee data, § 26 BDSG can also be applied, provided the processing is necessary for the employment relationship. A careful balancing of interests is always required.

What are the most important technical and organisational measures (TOMs) for access control systems?

Important TOMs include technical aspects such as the use of chip cards or transponders, data encryption, regular security audits, and securing servers. Organisational measures include clear key policies, visitor logs, regular review of permissions, and employee training. The goal is to ensure the confidentiality, integrity and availability of the data and to prevent unauthorised access.

How can manufacturer dependency be avoided when planning access control systems?

Manufacturer dependency is avoided through independent, manufacturer-neutral planning. An experienced consultant such as PLANATEL® analyses the company's specific requirements and objectively assesses different systems, without being tied to particular products. This enables a tailored solution matched to the customer's needs and ensures long-term flexibility and cost efficiency. A transparent tender and award process is essential here.

What role does the works council play in introducing access control systems?

Under § 87(1) No. 6 of the Works Constitution Act (BetrVG), the works council has co-determination rights when introducing and applying technical devices intended to monitor employee behaviour or performance. Early involvement of the works council in the planning is therefore essential, to find a legally compliant, accepted solution and to conclude a works agreement.

What are the consequences of GDPR violations involving access control systems?

GDPR violations can have significant consequences. These include substantial fines, which can amount to up to €20 million or 4% of a company's global annual turnover, whichever is higher. In addition, there is a risk of reputational damage, loss of trust among employees and customers, and possible damages claims from data subjects. Legally compliant planning is therefore of the utmost importance.

What data may access control systems store?

Access control systems may only store the personal data absolutely necessary for the defined purpose of access management. This typically includes identification data (name, personnel number) and access events (timestamp, location). The principle of data minimisation must be strictly observed here.

Is a data protection impact assessment always necessary for access control?

A data protection impact assessment (DPIA) is not always necessary, but is often required, in particular where the access control system carries a high risk to the rights and freedoms of data subjects. This is the case when processing biometric data or with extensive systematic monitoring.

How long may access data be stored?

The retention period for access data must be limited to the absolute minimum necessary. Blanket storage over weeks or months without a specific reason is not permissible. In the event of security incidents, temporarily longer storage can be justified, but must be clearly defined and documented.

What is the difference between access control and logical access control?

Access control (physical) refers to physical entry to buildings, rooms or premises. Logical access control, by contrast, governs access to IT systems, networks or applications. Both are essential components of a comprehensive security concept.

Sources and further information