Why Access Control Data Is Personal Data Under UK GDPR
Access control systems hold more than fob numbers. Typical data includes fob IDs, user records, door events, controller logs, anti‑passback flags and visitor entries. If a fob ID can be linked to a name, shift pattern, location, or CCTV timecode, it is personal data. Audit trails and controller diagnostics also count where they single out a person or can reasonably be linked back.
Employers and landlords act as controllers and must meet UK GDPR duties. Homeowners using simple domestic systems have fewer obligations, but privacy and safety still matter. For a broader view of system value, see our guides to the advantages of access control systems and the top 5 benefits to access control systems.
Choose The Right Lawful Basis (And When Consent Is Wrong)
Match the basis to the purpose and context:
- Legitimate interests: most workplaces use this for security, safety and incident investigation. Complete a Legitimate Interests Assessment.
- Contract: can apply for residents’ fobs in blocks or paid memberships.
- Legal obligation: may apply for safeguarding, Health and Safety, or where specific regulations require logging.
- Public task: for public bodies performing official functions.
- Consent: rarely appropriate for employees due to the imbalance of power.
Biometrics (face, fingerprint, vein) are special category when used to uniquely identify a person. You must:
- Identify an Article 9 condition and a Schedule 1 DPA 2018 condition (e.g., employment, social protection, or substantial public interest where applicable).
- Complete a DPIA and maintain an Appropriate Policy Document.
- Offer a reasonable alternative where consent cannot be freely given (e.g., card or PIN).
Keep it simple: define the purpose, assess necessity, balance risks, add safeguards, and document your LIA. Schools and universities have specific risks; see our education sector overview.
Set Sensible Retention Periods For Fobs, Logs And Visitors
Use risk‑based windows and document the rationale:
- Routine door events: 30–90 days.
- High‑security areas: longer if justified by risk (e.g., 6–12 months), reviewed regularly.
- Visitor logs: 7–30 days.
- Fob assignment data: keep while active plus a short period after de‑provisioning, then delete or anonymise.
Automate deletion with log rotation and scheduled purges. Align controller storage with server retention and ensure backups expire on the same timetable. Pause deletion only under a documented legal hold for an active investigation. For multi‑site estates, use one schedule and track exceptions. Our PPM template for multi‑site estates can help you embed retention into maintenance.

This image was generated with AI and may not always represent the product or service exactly.
Be Transparent: Privacy Notices, Signage And Onboarding
Provide clear, layered information:
- At entrances: concise signage stating who is responsible, what is collected, purpose (security/safety), a link or QR to the full notice, and contact details.
- In onboarding: explain what is logged, how long you keep it, who can see it, and how to make a SAR.
- Online: a full privacy notice with purposes, lawful basis, retention, recipients, international transfers, rights and contact details.
If you use kiosks, QR passes or analytics, explain any tracking and retention. Keep notices short at the door and detailed online in your policy. Review your cookie policy and consider touchless door options that improve hygiene and accessibility.
Responding To Subject Access Requests (SARs) For Access Logs
Build a repeatable process:
- Locate all sources: controllers, access servers, visitor apps and, where relevant, the VMS for CCTV alignment.
- Filter by person, fob ID and time range. Verify the requester’s identity.
- Redact third‑party data and any sensitive notes that are not about the requester.
- Record the search, dates, decisions and any exemptions relied upon.
Deliver securely within one month. You may extend by up to two months for complex cases, but inform the requester and explain why. For mixed datasets (e.g., access + CCTV), explain the scope and provide timecodes so footage can be located or reviewed safely.
Configure Systems To Be Compliant And Usable
- Data minimisation: use unique IDs and minimal naming; avoid adding personal details to labels and notes.
- Access controls: apply role‑based access, MFA for admins, and keep an audit of admin actions.
- Security basics: remove default passwords, restrict admin access by IP/VPN, encrypt data in transit and at rest where supported.
- Time accuracy: time‑sync controllers to reliable NTP sources to avoid inaccurate trails.
- Safety integration: set door schedules that respect fire egress and lockdown rules; integrate the fire alarm so doors fail safely while still recording events.
- Tuning: adjust anti‑passback and failed‑auth alerts to reduce false positives.
Read our guide on how to align access control with your fire strategy.
Accessibility And Equality: DDA‑Aligned Access Control
Design for inclusion in line with the Equality Act 2010 and good practice (e.g., BS 8300, Building Regulations Part M):
- Avoid short unlock windows, heavy closers or high‑mounted readers that disadvantage some users.
- Provide alternatives such as longer timeouts, remote release, proximity triggers or automatic/sliding doors.
- Choose inclusive hardware: touchless activators, compliant handles, clear wayfinding and suitable mounting heights.
- Keep profiles fair; do not restrict routes for protected groups without a lawful, necessary reason supported by risk assessment.
Access Automation designs systems that support independence and safe movement for everyone.

This image was generated with AI and may not always represent the product or service exactly.
Visitor Management That Protects Privacy And User Flow
- Collect only what you need: name, company and host. Avoid unnecessary fields (e.g., personal contact details) unless justified.
- Hide previous entries on paper or digital sign‑in and avoid printing excess personal data on badges.
- Apply short retention for visitor logs and auto‑expire temporary passes; revoke access at the stated end time.
- For contractors, use pre‑registration, induction prompts and clear expiry times.
- Design the lobby to minimise queuing; pair a privacy‑screened tablet with staffed reception at peak times.
Match door type to demand so entries stay safe and accessible during surges, especially where deliveries and wheelchairs share the space.
Sharing Logs With Police, Insurers And Investigators
- Verify the request is lawful and genuine; record who asked, why, and the legal basis (e.g., legal obligation, legitimate interests, or court order).
- Scope the export to the minimum necessary; redact unrelated names and notes.
- Use secure transfer with encryption and keep an audit of what was shared and when.
- When CCTV is involved, align door events and camera timecodes and state any clock offsets.
Keep a simple playbook for security events, with roles, approvals and post‑incident reviews to improve controls and retention decisions.
End‑Of‑Life, Firmware And Controller Disposal
- Decommission securely: factory reset devices, wipe storage, and destroy or recycle controllers that held fob lists or cached logs.
- Reclaim readers and remove site data before disposal. Revoke credentials and close old admin accounts at the same time.
- Keep firmware current to patch vulnerabilities; plan updates with rollback and out‑of‑hours windows to avoid lockouts.
- Ensure backups follow your retention rules so deleted data does not reappear after a restore; verify media sanitisation.
Keep Records: RoPA And DPIAs For Monitoring
- Run a DPIA when using biometrics, large‑scale monitoring or working with vulnerable people. Describe purposes, necessity, risks and mitigations.
- Maintain Article 30 (RoPA) records: categories of data and subjects, recipients, retention, security measures and international transfers.
- For biometrics, keep an Appropriate Policy Document and link it to retention and security controls.
- In multi‑site estates, use templates and name owners for each building or campus. Review at least annually or after system changes.
Link records to training, signage and maintenance so privacy sits alongside safety and uptime.
When To Call In An Engineer (And What We Do On Site)
- Health checks: time sync, storage health, audit trails, controller alerts and firmware status.
- Safety tests: fail‑safe and fail‑secure logic, fire integrations and emergency overrides.
- Usability checks: signage, reader heights, unlock timings and accessibility against your policy and risk profile.
- Common fixes: clock drift, storage full, loose cabling, misaligned readers, noisy alerts.
Planned maintenance reduces nuisance alarms and supports retention targets. Access Automation provides clear reports and practical fixes that keep your system safe, usable and compliant.
FAQs
Do We Need Employee Consent To Log Fob Use?
No. Most employers rely on legitimate interests for security and safety. Explain this in your privacy notice and put clear signage at entrances.
How Long Should We Keep Door Access Logs?
Typically 30–90 days for routine events. Keep longer only if you can justify the risk and purpose, and automate deletion.
Can We Use Facial Recognition For Access?
Yes, but it is special category data when used for unique identification. You must meet an additional legal condition, run a DPIA and offer alternatives where appropriate.
What Should Our Access Control Privacy Notice Include?
Purposes, lawful basis, retention, who sees data, data sharing, international transfers (if any), SAR rights and contact details. Keep signage short and link to full online details.
How Fast Must We Reply To A SAR On Access Logs?
Within one month of receipt. You can extend by up to two months for complex cases, but you must tell the requester.
Who Should Have Admin Rights To Logs?
Only trained staff with a clear need. Use role‑based access, MFA and admin audit trails to prevent misuse.