DEV Community

Cover image for GDPR-Compliant Access Control: What Your Door Logs Must Contain
Vika Beckerman
Vika Beckerman

Posted on

GDPR-Compliant Access Control: What Your Door Logs Must Contain

Why Door Logs Have Become a GDPR Battleground

Most organizations think of GDPR compliance in terms of HR databases, CRM exports, and cookie banners. Physical access logs rarely make the list — until a data protection audit turns up years of raw entry/exit timestamps sitting in a legacy access control panel with no retention policy, no access restrictions, and no documented lawful basis for processing.

Door logs are personal data. Under GDPR, a record that ties a name or badge ID to a timestamp and a location is squarely in scope, and if your system also captures biometric templates (fingerprint, face, iris), you're dealing with a special category of data under Article 9 that requires explicit consent or another narrow legal basis. Getting this wrong isn't hypothetical — regulators across the EU have already fined companies for excessive retention of employee entry data and for using biometric access control without a valid legal basis.

What a Compliant Door Log Actually Needs to Contain

A GDPR-compliant access log isn't just "who came in when." It needs structure:

1. Minimal necessary fields. Log the badge/credential ID, timestamp, door/zone identifier, and access result (granted/denied). Avoid capturing more than you need — if you don't have a business reason to log which specific meeting room someone entered, don't.

2. A documented retention schedule. GDPR's storage limitation principle means you can't keep entry logs indefinitely "just in case." Most organizations land on 30-90 days for routine logs, longer only for logs tied to an active security investigation, with justification documented.

3. Purpose limitation on record. Write down why you're collecting this data (security, attendance verification, compliance with labor law) and don't repurpose it silently. Using door logs collected for security to build a covert performance-monitoring dataset is exactly the kind of scope creep that draws regulatory attention.

4. Access restrictions on the logs themselves. Ironically, many companies lock down building access tightly but leave the access control software's admin panel wide open to anyone in IT or facilities. Logs containing personal data need role-based access just like any other HR system.

5. A lawful basis for biometric processing, if applicable. Legitimate interest rarely covers biometrics for employee access — you typically need explicit consent, with a genuine non-biometric alternative offered (badge or PIN), or a clear legal obligation.

6. Data subject rights support. Employees have the right to request what door-access data is held about them and to have it corrected or erased where no legal basis for retention exists. If your logs live in disconnected door controller hardware with no central retrieval, answering a subject access request in the required 30 days becomes a scramble.

Where Most Systems Fall Short

Standalone access control panels were built for security, not compliance. They log everything, retain it forever by default, and rarely give IT a clean way to export, anonymize, or purge records tied to a specific employee. When the same building runs a separate time clock system alongside the door controller, you now have two systems capturing overlapping personal data with two different retention rules — doubling your audit exposure.

This is one of the practical reasons more IT and HR teams are consolidating physical access and attendance into a single platform. TimeClock 365 is built around this consolidation: because the same badge, fingerprint, or Apple/Google Wallet tap that opens the door is what generates the attendance record, there's one dataset, one retention policy, and one audit trail — instead of reconciling logs from a door controller and a separate time clock. Customers using TimeClock 365 report 99% time tracking accuracy and a 90% reduction in unauthorized access incidents, largely because there's no gap between "who's in the building" and "who's clocked in."

A Practical Compliance Checklist

Before your next audit, confirm you can answer these:

  • Do you know exactly which fields your door logs capture, and can you justify each one?
  • Is there a written retention period, and is it enforced automatically rather than manually?
  • If you use biometrics, do you have documented consent and a non-biometric alternative on offer?
  • Can you produce or delete one employee's access history within 30 days if asked?
  • Are the logs themselves access-controlled, with an audit trail of who viewed them?

If any of these produce a shrug rather than a confident yes, that's your starting point — not a rebuild of your entire security stack, but a review of retention settings, access permissions, and documentation around whatever system already sits behind your doors.

Get Ahead of the Audit

Unifying access control and attendance doesn't just simplify HR reporting — it closes the gap between what your door hardware captures and what your compliance policy requires. TimeClock 365 gives IT and HR teams one system, one log, and one retention policy to manage instead of two.

Start a free trial and see how a unified access-and-attendance log makes your next GDPR audit dramatically simpler.

Top comments (0)