Access Management & Intrusion Detection15 min read
GDPR and Access Control: What Companies Must Consider for Legal Compliance
Modern access control systems are indispensable for company security, but also raise data protection challenges. This article examines the key aspects of GDPR in the context of access control and shows how to make your system legally compliant.
For GDPR-compliant access control, companies must base the processing of personal data on a legal basis, implement appropriate technical and organisational measures (TOM), carry out a data protection impact assessment (DPIA), uphold data subject rights, and establish clear deletion concepts. Independent specialist planning is essential here to avoid dependency on manufacturers and ensure long-term legal compliance.
Comprehensive planning and implementation of access control systems in line with the General Data Protection Regulation
Modern access control systems are indispensable for company security, but also raise data protection challenges. This article examines the key aspects of GDPR in the context of access control and shows how to make your system legally compliant.
Key Takeaways
- GDPR-compliant access control requires a clear legal basis for data processing and the consistent implementation of technical and organisational measures (TOM).
- Carrying out a data protection impact assessment (DPIA) is often mandatory for access control systems, particularly those using biometric data, in order to identify and minimise risks at an early stage.
- Independent specialist planning by experts such as PLANATEL® ensures manufacturer-independent selection, cost optimisation and long-term legal compliance for your access control solution.
The physical security of company buildings, sensitive areas and data processing systems is of the utmost importance for every organisation. Access control systems play a central role here by controlling who is granted access, when and where. However, capturing access data also brings far-reaching obligations regarding the protection of personal data. The General Data Protection Regulation (GDPR) sets clear and strict requirements here, and non-compliance can have significant legal and financial consequences. Companies therefore face the challenge of implementing high-performance access control systems that also fully comply with data protection requirements. Sound planning is the key to a legally compliant, efficient solution.

GDPR fundamentals in the context of access control
Implementing access control is inextricably linked to the processing of personal data. This typically includes names, employee IDs, and access times and locations. Under Article 4(1) GDPR, all of this is information relating to an identified or identifiable natural person and is therefore subject to the scope of protection of the GDPR. The central question is always which legal basis permits this processing. Article 6(1) GDPR offers various options here. The controller's legitimate interest (Art. 6(1)(f) GDPR) is frequently relevant, for example to ensure building security and protect company assets. Companies must carry out a careful balancing of interests here, weighing their own protective interests against the fundamental rights and freedoms of the data subjects. Another legal basis can be a legal obligation (Art. 6(1)(c) GDPR), for example arising from employment law or industry-specific security regulations.
Particular caution is required when biometric data such as fingerprints or facial recognition are used. These fall under the special categories of personal data under Article 9(1) GDPR, the processing of which is generally prohibited unless one of the exceptions in Article 9(2) applies. In an employment relationship, the processing of biometric data is only permissible under very strict conditions, owing to the dependent relationship between employer and employee, usually only with the explicit, voluntary and informed consent of the data subject (Art. 9(2)(a) GDPR) or where it is strictly necessary to fulfil employment-law obligations and no less intrusive means are available. Choosing the correct legal basis is fundamental and must be carefully documented from the outset in order to ensure the legal compliance of the entire access control system.
Technical and organisational measures (TOM) for access control systems
Article 32 GDPR requires the implementation of appropriate technical and organisational measures (TOM) to ensure a level of protection appropriate to the risk of the processing. For access control systems, this means a range of precautions covering both the physical security of the data processing facilities and the logical security of the data itself. Technical measures include, for example, the use of automatic access control systems with chip cards, transponders or biometric features, security locks, alarm systems, and securing servers in lockable server cabinets. DIN EN 60839-11-1 defines detailed requirements for electronic access control systems and their components, including the logging and control of information.
Organisational measures complement the technical precautions and include, among other things, clear key management, keeping a visitor log or issuing visitor badges, accompanying visitors by staff, and carefully selecting cleaning and security services. A central aspect is access control to the IT systems that manage the access data. Here, measures such as user credentials with passwords, biometric login procedures, lockouts after failed attempts and encryption of data carriers are essential. Access permission management, in turn, regulates which authorised user may access and process which specific data within the system, based on a differentiated roles and permissions concept. Documenting all these TOM is not only an obligation but also evidence of due diligence towards the supervisory authorities.
The role of the record of processing activities and the data protection impact assessment (DPIA)
Under Article 30 GDPR, every company that processes personal data is obliged to keep a record of processing activities. For access control systems, this means that all relevant information on the collection, storage and use of access data must be documented in detail. This includes, among other things, the purposes of the processing, the categories of data subjects and data, the recipients of the data, the storage period, and a description of the technical and organisational measures. This record serves not only as an internal overview but also as evidence of legal compliance to the supervisory authorities.
An even more far-reaching instrument is the data protection impact assessment (DPIA) under Article 35 GDPR. A DPIA is always required where a type of processing, in particular using new technologies, is likely, given its nature, scope, context and purposes, to result in a high risk to the rights and freedoms of natural persons. Access control systems, particularly those with biometric features or extensive logging, often fall into this category. The DPIA must be carried out before processing begins and includes a systematic description of the planned processing operations, an assessment of necessity and proportionality, a risk assessment for the rights and freedoms of data subjects, and the planned measures to mitigate these risks. A properly conducted DPIA is a decisive step in identifying and addressing potential data protection risks at an early stage, before a system is put into operation. PLANATEL® supports companies in preparing these important documents, to ensure seamless legal compliance.

Data subject rights and their implementation
The GDPR significantly strengthens data subjects' rights. Companies operating access control systems must ensure that these rights can be upheld and exercised at all times. The most important rights include the right of access (Art. 15 GDPR), the right to rectification (Art. 16 GDPR), the right to erasure (Art. 17 GDPR), the right to restriction of processing (Art. 18 GDPR), the right to data portability (Art. 20 GDPR) and the right to object (Art. 21 GDPR). For access data, this means, for example, that a person has the right to find out what data about their access is stored, for what purpose it is processed, and how long it is retained.
Practical implementation of these rights requires corresponding processes and technical capabilities within the access control system. The system must, for example, be able to provide information about the stored data on request from a data subject, or correct or delete it where necessary. The right to erasure is particularly important here once the purpose of storing the data no longer applies. Companies must define clear procedures for how they respond to requests from data subjects and process them within the required deadlines. This also includes informing data subjects of their rights, for example through transparent privacy notices or notices on display. Early involvement of the works council, as set out in Section 87 of the Betriebsverfassungsgesetz (Works Constitution Act), is also of great importance when introducing access systems that can monitor employee behaviour or performance, in order to uphold co-determination rights and reach a works agreement.
Storage periods and deletion concepts for access data
A central principle of the GDPR is storage limitation (Art. 5(1)(e) GDPR), which states that personal data may not be stored for longer than is necessary for the purposes for which it is processed. For access data, this means that companies must develop and implement clear deletion concepts. The storage period must be tied to the purpose and proportionate. Once the original purpose of the data processing no longer applies, there is generally an obligation to delete the data, unless statutory retention obligations or other legal grounds justify longer storage.
Typical purposes for storing access data are ensuring security, the traceability of incidents, or compliance with working-time regulations. A commonly recommended maximum storage period for video recordings in the security field is 72 hours, provided no security-relevant incidents have been identified. For access event data, the period can vary depending on the risk and purpose, but should be kept as short as possible. Longer storage is only permissible where there is a specific reason, for example in the case of a security incident requiring further investigation. In such cases, the relevant data may be retained until the matter is resolved or handed over to the authorities. Companies must define an appropriate storage period for each category of personal data and document this. This includes setting deletion deadlines, justifying these deadlines, and documenting the technical and organisational deletion processes. Automated deletion once deadlines have expired is best practice here, to avoid manual errors and ensure legal compliance.
Selecting and planning legally compliant access control systems
Selecting and planning an access control system is a strategic decision with far-reaching implications for a company's security and legal compliance. PLANATEL® places the greatest importance here on manufacturer-independent, financially independent consulting, in order to find the optimal solution for the individual requirements of the client. This begins with a detailed as-is survey and needs analysis, in which not only security needs but also data protection requirements are precisely captured. Consideration is given to which groups of people will use the system, which spatial zones need to be secured, and how the security requirements correspond with escape routes.
When it comes to system architecture, it is crucial to choose solutions that build in data minimisation and data security from the ground up. This can involve choosing between different identification media such as RFID cards, transponders, PIN codes or biometric methods. While biometric systems can offer a high level of security, they require particular data protection review and consent owing to the sensitivity of the data. Integrating the access control system into existing IT infrastructure and security management systems must also be carefully planned, to avoid interface problems and security gaps. Standards such as DIN EN 60839-11-1 provide important guidance here on the requirements for systems and devices. PLANATEL® supports the creation of target concepts, detailed planning and tender documents, to ensure that the chosen system is not only technically capable but also legally compliant and economical in the long term.
Common mistakes and best practices in implementation
Implementing access control systems frequently gives rise to mistakes that jeopardise legal compliance and lead to unnecessary risks. One of the most common mistakes is inadequate documentation of the processing activities and the technical and organisational measures taken. Without complete documentation, it is difficult to demonstrate compliance with the GDPR and to respond to requests from supervisory authorities or data subjects. Another mistake is over-dimensioning the system, collecting more data or storing it for longer than is necessary for the actual purpose. This violates the principle of data minimisation (Art. 5(1)(c) GDPR) and storage limitation.
Best practices, by contrast, include proactive, precise planning that integrates data protection aspects from the outset. This includes carrying out a comprehensive risk analysis and, where applicable, a data protection impact assessment before implementation. Regular training for employees working with the system is essential, to raise awareness of data protection requirements and avoid operating errors. Implementing a role-based access concept, ensuring that employees can only access the data they need for their tasks, is also an important best practice. In addition, regular reviews and audits of the system should be carried out to continuously ensure its functionality, security and legal compliance. Logging access to applications, particularly when entering, changing and deleting data, is essential here to ensure traceability and prevent manipulation.
The importance of independent specialist planning for your access control
The complexity of GDPR requirements, combined with the technical diversity of modern access control systems, makes independent specialist planning essential. Since 1992, PLANATEL® has offered manufacturer-independent, financially independent consulting services that ensure the client's interests always come first. Without ties to particular manufacturers, we can objectively select the best systems and technologies, tailored precisely to your needs while meeting the highest standards of legal compliance and security.
Our expertise covers the entire project chain: from the initial needs analysis and the creation of a tailored security concept, through detailed planning and the preparation of tender documents, to accompanying implementation and system acceptance. We help you minimise potential risks, optimise costs, and ensure the long-term legal compliance of your access control solution. Independent planning by PLANATEL® protects you from unnecessary investment, dependency on manufacturers, and the potential pitfalls of inadequate data protection implementation. With over 34 years of experience in planning and optimising security systems, we are your reliable partner in making your access control not only secure but also future-proof and data-protection compliant.

Next step
Contact us for a no-obligation initial consultation.
PLANATEL®: Independent planning and consulting since 1992
Tel: 040 / 23 73 02-30
Email: info@planatel.de
Frequently asked questions
Which legal bases are relevant for processing access data?
Processing access data must be based on a valid legal basis under Article 6 GDPR. The controller's legitimate interest (Art. 6(1)(f) GDPR) in ensuring building security, or a legal obligation (Art. 6(1)(c) GDPR), are frequently relevant. When using biometric data, the explicit consent of the data subject (Art. 9(2)(a) GDPR) or another specific exception under Article 9 GDPR is generally required. The choice of legal basis must be carefully examined and documented to ensure legal compliance.
What is the difference between physical access control, system access control and data access control?
The terms physical access control, system access control and data access control are often confused, but have different meanings in the context of data protection. Physical access control refers to the physical control of entry to buildings, rooms or premises where data processing takes place. System access control prevents unauthorised persons from using IT systems, for example through passwords or biometric logins. Data access control governs which authorised user may access and process which specific data within an IT system, based on a permissions concept.
What role does DIN EN 60839-11-1 play in GDPR-compliant access control?
DIN EN 60839-11-1 is an important standard for electronic access control systems. It defines system and component requirements for physical access control systems in and around buildings and protected areas. Although it contains no direct data protection provisions, it provides essential technical requirements for functionality, performance and test methods that are relevant to implementing appropriate technical and organisational measures (TOM) under Article 32 GDPR. Compliance with this standard therefore contributes indirectly to data security and hence to legal compliance.
Must the works council be involved when introducing access control?
Yes, introducing and managing access control, particularly where it involves technical systems capable of monitoring employee behaviour or performance, is subject to the co-determination rights of the works council under Section 87(1) No. 6 of the Betriebsverfassungsgesetz (BetrVG, Works Constitution Act). Early involvement of the employee representative body is therefore essential in order to reach a works agreement and avoid legal conflicts. This ensures that employees' interests are appropriately taken into account.
How can PLANATEL® support the GDPR-compliant planning of access control systems?
As an independent planning and consulting company, PLANATEL® provides comprehensive support in designing your access control systems in a GDPR-compliant way. We carry out needs analyses, develop tailored security concepts, prepare detailed plans and tender documents, and accompany implementation through to acceptance. Our manufacturer-independent expertise ensures that you receive a technically optimal, economical and long-term legally compliant solution tailored specifically to your company's needs, avoiding dependency on manufacturers. With over 34 years of experience, we minimise your risks and optimise your investments.
What data is captured by access control?
Access control typically captures personal data such as name, employee ID, access time, access location and, where applicable, biometric features. This data is used to identify and authenticate individuals and to log access events.
When is a data protection impact assessment necessary for access control?
A data protection impact assessment (DPIA) is required for access control systems where the processing is likely to result in a high risk to the rights and freedoms of natural persons. This is particularly the case with extensive processing of sensitive data (e.g. biometrics) or the systematic monitoring of areas.
How long may access data be stored?
Under the GDPR, access data may only be stored for as long as is necessary for the respective processing purpose (storage limitation). This requires clear deletion concepts. A commonly recommended maximum storage period for video recordings is 72 hours, provided there is no specific security incident.
What are technical and organisational measures (TOM) in access control?
Technical and organisational measures (TOM) in access control include physical security precautions such as automatic locking systems and alarm systems, as well as logical measures such as user authentication, encryption and role-based access concepts. They serve to protect personal data against unauthorised access and misuse.
Sources and further information
- fm-connect.com
- dsgvo-gesetz.de
- datenschutz-notizen.de
- recogtech.com
- datenschutz-praxis.de
