Access Management & Intrusion Detection17 min read
Access Control GDPR Requirements: Legally Compliant Planning for Businesses
Implementing access control systems is essential for businesses, yet it brings complex data protection challenges. Legally compliant implementation under GDPR is crucial to protect sensitive data and minimise legal risks. We examine the key requirements and show how independent planning supports this process.
GDPR places high demands on access control systems, since they process personal data. Businesses must establish legal grounds for the data processing, implement technical and organisational measures (TOMs), ensure data minimisation and purpose limitation, uphold data subject rights, and meet documentation obligations as well as, where applicable, data protection impact assessments (DPIAs). Independent specialist planning is essential for this.
Comprehensive expertise for data-protection-compliant access control systems
Implementing access control systems is essential for businesses, yet it brings complex data protection challenges. Legally compliant implementation under GDPR is crucial to protect sensitive data and minimise legal risks. We examine the key requirements and show how independent planning supports this process.
Key Takeaways
- Access control systems process personal data and are therefore fully subject to GDPR. A well-founded legal basis and comprehensive technical and organisational measures (TOMs) are mandatory.
- The principles of data minimisation and purpose limitation must be consistently implemented. This affects the type of data collected, its retention period and its exclusive use for the defined purpose.
- Independent planning and consulting is crucial to avoid manufacturer dependency, to factor in all GDPR requirements from the outset, and to implement a future-proof, legally compliant solution.
Modern access control systems are a cornerstone of physical security in companies, authorities and organisations. They govern who is granted access when and where, protecting buildings, IT infrastructure and sensitive company areas from unauthorised access. At the same time, however, these systems capture personal data, which places them directly within the scope of the General Data Protection Regulation (GDPR). Designing such systems in a legally compliant way is therefore not an option but an imperative, to safeguard company assets, protect the privacy of data subjects, and avoid substantial fines. Sound planning is the key to successfully meeting these complex requirements.

Fundamentals of access control and its relevance for GDPR
Access control systems are designed to govern and log physical entry to specific areas or buildings. This ranges from simple mechanical locking systems to complex electronic systems using biometrics, chip cards or transponders. Regardless of the technology involved, these systems generally capture personal data. This typically includes identification data such as name, personnel number or company affiliation, as well as access data such as timestamps, door and room number, or the precise location of the access event.
The collection, storage and processing of this data is subject to the strict requirements of the General Data Protection Regulation (GDPR). Article 32 GDPR obliges companies to take appropriate technical and organisational measures (TOMs) to ensure the security of processing and to protect personal data against unauthorised access, loss or alteration. A breach of these principles can not only lead to significant legal consequences but can also permanently damage the trust of employees and business partners. The distinction between Zutrittskontrolle (physical access), Zugangskontrolle (digital access to IT systems) and Zugriffskontrolle (permissions within a system) is essential here, even though all three aspects are relevant to data protection within a comprehensive security concept.
Careful planning of an access control system must therefore take the data protection implications into account from the very start. This means not only meeting the company's security requirements, but also consistently implementing the GDPR principles of data minimisation, transparency and accountability. Independent consulting, as PLANATEL® has offered for over 34 years, is invaluable here in developing a manufacturer-independent, legally compliant solution tailored to the company's specific needs.
Legal grounds for processing access data under GDPR
Any processing of personal data in an access control system requires a valid legal basis under Article 6 GDPR. Without such a basis, the data processing is unlawful and can lead to substantial fines. The most relevant legal grounds in the context of access control are:
- Consent (Art. 6(1)(a) GDPR): The data subject has given their voluntary, informed and unambiguous consent to the processing of their data for one or more specific purposes. This is often the seemingly simplest but, in practice, the most difficult legal basis, since voluntariness in an employment relationship can often be called into question.
- Performance of a contract (Art. 6(1)(b) GDPR): The processing is necessary for the performance of a contract to which the data subject is party, or to take steps prior to entering into a contract. This could be relevant, for example, for service providers contractually entitled to access certain areas.
- Legal obligation (Art. 6(1)(c) GDPR): The processing is necessary for compliance with a legal obligation to which the controller is subject. This may arise from specific laws or regulations that prescribe certain security measures.
- Legitimate interest (Art. 6(1)(f) GDPR): The processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. This is the most commonly used legal basis for access control systems in companies, to safeguard property, trade secrets or the safety of employees. A careful balancing of interests is mandatory here.
Particular caution is required when biometric data (e.g. fingerprints, iris scans) are processed. These fall under the "special categories of personal data" pursuant to Article 9 GDPR and require additional, stricter legal grounds, such as explicit consent or a legal provision permitting it. PLANATEL® supports companies in identifying the appropriate legal basis for their specific access control system and in preparing the required documentation to ensure legal compliance from the outset.
Technical and organisational measures (TOMs) for GDPR-compliant access control
Article 32 GDPR requires the implementation of suitable technical and organisational measures (TOMs) to ensure a level of protection appropriate to the risk. In the context of access control, these measures are varied and cover both physical and digital aspects. The aim is to permanently ensure the confidentiality, integrity, availability and resilience of the systems and services.
Key technical measures include:
- Encryption and pseudonymisation: Sensitive access data should, wherever possible, be encrypted or pseudonymised to make it harder to identify the data subjects.
- Access controls: Implementation of role and permission concepts that ensure only authorised personnel can access the access control systems and the data they contain. This also includes logging of access.
- Automated deletion mechanisms: Access logs and other personal data may only be stored for as long as necessary for the defined purpose. Automated deletion concepts are essential for this.
- Secure system architecture: The entire system architecture must be designed for security, including firewalls, anti-virus software and regular security updates.
Organisational measures complement the technical precautions:
- Key and media management: Structured management of access media (chip cards, transponders) and keys, including loss-reporting processes.
- Staff training: Regular training of personnel on using the access control system and on data protection requirements.
- Visitor policies: Clear processes for registering, accompanying and documenting visitors.
- Contingency plans: Concepts for the rapid restoration of data and system availability in the event of physical or technical incidents.
PLANATEL® supports companies in developing and implementing a comprehensive TOM concept, tailored individually to the risk assessment and the specific requirements of the company. In doing so, we always factor in the state of the art and current legal requirements.

Data minimisation and purpose limitation as core GDPR principles
The principles of data minimisation (Art. 5(1)(c) GDPR) and purpose limitation (Art. 5(1)(b) GDPR) are cornerstones of GDPR and are of particular importance for access control systems. Data minimisation means that only personal data strictly necessary for the respective purpose may be collected and processed. This also covers the retention period: data must be deleted once the purpose for which it was collected has ceased to apply.
In the context of access control, this means, for example:
- Minimal data volume: Only the data strictly necessary to control and log access should be captured. Does the full name really need to be stored, or is an anonymised ID sufficient?
- Purpose-bound storage: Access logs must not be retained indefinitely. The retention period must be clearly defined and justified, e.g. for investigating criminal offences, meeting legal evidentiary obligations, or asserting, exercising or defending legal claims. A retention period of a few days or weeks is often sufficient, unless specific statutory requirements or a concrete incident call for longer retention.
- No unnecessary linking: Access control data should not be linked to other data sets (e.g. working hours, performance data) without a compelling reason, if this does not serve the original purpose.
The principle of purpose limitation requires that personal data may only be processed for the explicitly and legitimately defined purposes for which it was originally collected. A later change of purpose is only permissible under narrow conditions. For access control systems, this means that the primary purpose, ensuring physical security, must be clearly communicated and adhered to. Using the data to monitor employee performance or conduct is generally impermissible, unless there is an explicit legal basis and comprehensive information for the data subjects. PLANATEL® supports companies in formulating clear purpose definitions and planning technical solutions that effectively implement these principles.
Data subject rights and their implementation in access control systems
GDPR significantly strengthens the rights of data subjects. Companies operating access control systems must be able to guarantee these rights at all times and respond to relevant requests within the statutory deadlines. The most important data subject rights include:
- Right to information (Art. 15 GDPR): Data subjects have the right to be informed whether and which personal data concerning them is being processed, for what purposes, to whom it is disclosed, and how long it is stored.
- Right to rectification (Art. 16 GDPR): Data subjects can request the rectification of inaccurate data or the completion of incomplete data.
- Right to erasure ("right to be forgotten", Art. 17 GDPR): Under certain conditions, data subjects can request the deletion of their data, e.g. if the data is no longer necessary for the purposes for which it was collected.
- Right to restriction of processing (Art. 18 GDPR): In certain cases, data subjects can request the restriction of processing of their data, e.g. if the accuracy of the data is contested.
- Right to object (Art. 21 GDPR): Data subjects can object to the processing of their data, in particular where processing is based on a legitimate interest.
- Right to data portability (Art. 20 GDPR): Data subjects have the right to receive their data in a structured, commonly used and machine-readable format and to transmit it to another controller.
Implementing these rights requires clear internal processes and technical capability within the access control system. For example, companies must be able to quickly and completely provide information on a person's access history, or delete their data on request. This can be a challenge, particularly with older or complex systems. PLANATEL® advises on the design of systems that take these requirements into account from the outset, and supports the development of policies and processes for the legally compliant handling of data subject requests.
Documentation obligations and data protection impact assessment (DPIA)
GDPR places great importance on the accountability of the controller (Art. 5(2) GDPR). This means that companies must not only comply with GDPR, but must also be able to demonstrate this compliance at all times. The record of processing activities (Art. 30 GDPR) and the data protection impact assessment (DPIA) under Article 35 GDPR play a central role here.
The record of processing activities must contain detailed information on all data processing operations within the company, including the purposes of processing, the categories of data subjects and data, the recipients, the retention period and the applied TOMs. Access control systems must be listed here as a distinct processing activity.
A data protection impact assessment (DPIA) is always required when a planned processing operation is likely to result in a high risk to the rights and freedoms of natural persons. This is particularly the case for:
- Systematic and extensive evaluation of personal aspects (including profiling) that produces legal effects.
- Large-scale processing of special categories of data (e.g. biometric data) or data relating to criminal convictions.
- Systematic, large-scale monitoring of publicly accessible areas.
The use of biometric access control systems generally requires a DPIA. Extensive video surveillance combined with access control can also make a DPIA necessary. The DPIA must be carried out before processing begins and should be understood as a dynamic instrument that is reviewed and updated regularly. If the DPIA reveals a high residual risk that cannot be contained by the measures taken, the competent data protection supervisory authority must be consulted before processing begins (Art. 36 GDPR).
PLANATEL® supports companies in preparing the record of processing activities and in carrying out DPIAs for access control systems. Our expertise helps identify potential risks early and plan suitable measures to ensure legal compliance.
Selecting and planning GDPR-compliant access control systems, the role of independent consulting
Selecting and planning an access control system that meets both security requirements and GDPR provisions is a complex task. Companies face the challenge of finding the right solution among a multitude of technologies and manufacturers. Here, independent, manufacturer-independent consulting is of decisive importance in ensuring an objective assessment and making an optimal, future-proof investment.
PLANATEL® has operated as an independent planning and consulting company since 1992. Our role is to guide our clients through the entire process of system selection and planning, without being tied to particular manufacturers or products. This guarantees that recommendations are based solely on the client's individual needs and the best possible technical and data-protection suitability. We begin with a detailed as-is analysis and requirements assessment, to understand the company's specific security risks and data-protection-relevant requirements. Building on this, we develop a target concept that takes all aspects of GDPR-compliant data processing into account.
Our services include, among others:
- Risk analysis and protection-needs assessment: Assessment of the protection required for data and areas.
- Design of TOMs: Development of tailored technical and organisational measures.
- Specification of system requirements: Definition of the functional and non-functional requirements for the access control system, taking GDPR into account.
- Preparation of tender documents: Formulation of clear, data-protection-compliant specifications of services for awarding contracts to installers.
- Support during the award process: Assistance in selecting qualified installers and evaluating bids.
- Acceptance and invoice review: Ensuring that the implemented solution meets the planned requirements and GDPR.
Through this comprehensive and independent planning, we ensure that the implemented access control system is not only technically capable but also permanently legally compliant, thereby strengthening data subjects' trust and minimising legal risks.
Common mistakes and best practices when implementing access control
Implementing an access control system is a complex project in which mistakes can easily occur, with far-reaching data protection consequences. Forward-looking planning and adherence to best practices are therefore essential.
Common mistakes:
- Insufficient legal basis: Processing access data without a clear, documented legal basis is a frequent and serious violation.
- Missing or inadequate TOMs: Failing to implement appropriate technical and organisational measures can lead to data breaches and undermine the security of the system.
- Insufficient data minimisation: Collecting and storing more data than strictly necessary, or an excessively long retention period, are direct violations of GDPR.
- Ignoring data subject rights: Inadequate processes for handling information or erasure requests can lead to complaints to supervisory authorities and claims for damages.
- Missing DPIA in high-risk cases: Especially with biometric systems or extensive monitoring, a missing or inadequate data protection impact assessment is a significant risk.
- Lack of transparency: Data subjects are not adequately informed about the data processing.
- Manufacturer dependency: Excessive reliance on a single manufacturer can limit flexibility in adapting to new data protection requirements.
Best practices:
- "Privacy by design" and "privacy by default": Data protection should be integrated into the system's planning from the outset (Art. 25 GDPR). Systems should have the most privacy-friendly settings by default.
- Regular review: The effectiveness of the TOMs and compliance with GDPR should be reviewed and assessed regularly.
- Clear responsibilities: Define clear responsibilities for data protection in connection with access control.
- Comprehensive documentation: Keep a complete record of processing activities and document all decisions and measures for GDPR-compliant implementation.
- Staff training: Raise awareness and regularly train all relevant staff on handling personal data and the systems.
- Independent consulting: Bring in independent experts such as PLANATEL® early on to ensure an objective assessment and planning, avoiding mistakes from the outset. Our more than 34 years of experience in manufacturer-independent consulting are a decisive advantage here.

Next Step
Contact us for a no-obligation initial consultation.
PLANATEL®: Independent planning and consulting since 1992
Tel: 040 / 23 73 02-30
Email: info@planatel.de
Frequently Asked Questions
Which legal grounds apply to the processing of access data?
Various legal grounds under Art. 6 GDPR can be used for the processing of access data. These include the data subject's consent, the performance of a contract, a legal obligation, or the legitimate interest of the controller. For biometric data, the requirements under Art. 9 GDPR are stricter and usually require explicit consent or a specific legal provision. A careful assessment of each individual situation is essential.
How long may access logs be stored?
The retention period for access logs must follow the principle of data minimisation and be purpose-bound. Data may only be stored for as long as necessary for the original purpose (e.g. investigating criminal offences, evidentiary obligations). Indefinite, blanket storage is impermissible. A few days or weeks are often sufficient, unless there are specific circumstances or statutory requirements justifying longer retention. Automated deletion concepts are essential here.
Must employees be informed about access control?
Yes, under GDPR's information obligations (Art. 13, 14), data subjects, including employees, must be comprehensively informed about the data processing involved in access control. This includes the purpose of processing, the legal basis, the categories of data processed, the retention period, the recipients of the data and their rights as a data subject. This information must be transparent and easily accessible, ideally before the system is implemented.
What role does DIN VDE 0833 play for access control systems in the context of GDPR?
DIN VDE 0833 is a national series of standards that governs the planning, installation, extension, modification and operation of hazard warning systems, which can also include access control systems. Although it primarily defines technical requirements, compliance with these standards contributes to ensuring data security by guaranteeing a high level of technical protection. This supports the implementation of the technical and organisational measures (TOMs) under Art. 32 GDPR and thus the legal compliance of the system.
How can PLANATEL® support the GDPR-compliant planning of access control systems?
PLANATEL®, as an independent planning and consulting company, has offered manufacturer-independent expertise since 1992. We support companies with the as-is analysis, requirements assessment, development of target concepts, and specification of system requirements, all taking GDPR requirements into account. This includes identifying the appropriate legal grounds, designing TOMs, carrying out data protection impact assessments, and preparing tender documents. Our goal is to plan a tailored, legally compliant and future-proof solution.
When is a data protection impact assessment (DPIA) necessary for access control?
A DPIA is required when the access control is likely to pose a high risk to the rights and freedoms of natural persons. This is particularly the case with extensive processing of special categories of data (e.g. biometric data) or systematic, large-scale monitoring of publicly accessible areas.
Which data may be stored in an access control system?
Only personal data strictly necessary for the defined purpose of access control may be stored (data minimisation). This typically includes identification data (e.g. name, personnel number) and access data (timestamp, location). The retention period must also be purpose-bound and minimal.
What is the difference between Zutrittskontrolle, Zugangskontrolle and Zugriffskontrolle?
Zutrittskontrolle governs physical access to buildings or rooms. Zugangskontrolle protects digital access to IT systems. Zugriffskontrolle manages a user's permissions within a system to carry out specific actions or functions. All three are relevant to data protection.
What role do technical and organisational measures (TOMs) play in access control?
They comprise technical precautions such as encryption and access controls, as well as organisational measures such as key management and staff training, to protect data against unauthorised access.
Sources and further information
- fm-connect.com
- simons-voss.com
- juraforum.de
- weka.de
- gfos.com
