DC Fire & Security logoDC Fire & Security
Access Control & Door Entry — Expert Guide

Access Control and GDPR: What Door Logs and Biometrics Mean for UK Businesses

By the DC Fire & Security engineering team — installing and maintaining fire and security systems since 2010. Updated June 2026.

SSAIB CCTV, Intruder Alarm & Access Control Certificated
Fast Response Times
15+ Years Experience
500+ Commercial Clients

Quick answer

Door logs tied to named individuals are personal data: you need a purpose (security, safety), staff transparency, a retention period you can defend, and the ability to answer subject access requests. Biometric readers raise the bar — fingerprint and face templates are special category data requiring a DPIA, a lawful basis, and a genuine non-biometric alternative for those who decline.

What in an access system is personal data?

  • Event logs: who opened which door when — the core dataset, and clearly personal data
  • User records: names, photos, departments, credential IDs in the platform
  • Biometric templates: special category data with extra conditions
  • Integration footage: door-triggered CCTV clips inherit video surveillance rules
  • Visitor management entries: sign-in data, often retained far too long by default

The five obligations in practice

Purpose and lawful basis: legitimate interests (security of premises, safety, audit) documented in your record of processing — straightforward for standard door control. Transparency: staff privacy notices must mention access logging; quiet monitoring is where complaints start. Retention: set a defensible log retention (commonly 3–12 months) and configure the platform to enforce it rather than keeping everything forever. Security: admin accounts, role-based access to the platform, audit of who views logs. Rights: be able to extract one person's events for a subject access request — test that you actually can.

Biometrics: the special case

Fingerprint and facial templates are special category biometric data when used to identify individuals: deploying them requires a Data Protection Impact Assessment, an Article 9 condition (in employment contexts, explicit consent only counts if genuinely refusable — so a real alternative like a fob must exist), secure template storage (modern readers store irreversible mathematical templates, not images — say so in your DPIA), and proportionality: the ICO has acted against employers using biometrics where less intrusive options existed. Translation: biometrics for the server room with a documented case — not for clocking everyone through the front door because the reader looked impressive.

Frequently Asked Questions

How long should we keep door access logs?
As long as your stated purpose justifies — 3 to 12 months is the common defensible range, longer only with documented reasons (regulated environments, investigations). 'Forever, by default' is the indefensible answer.
Can staff demand to see their own access records?
Yes — door events about them fall under subject access. Platforms vary in how easily they export per-person history; we configure this capability at setup.
Can we use access logs to check staff timekeeping?
Only if you've told staff that's a purpose — repurposing security logs for performance management without transparency is a classic GDPR failure and an employment relations grenade.
Do fob-only systems avoid GDPR entirely?
No — logs naming individuals are personal data regardless of credential type. Fobs simply avoid the special-category layer that biometrics add.

Sources and further reading

Last updated June 2026.

Need help from a professional installer?

We install and maintain fire and security systems across Bedfordshire, Hertfordshire and London — with fixed written quotes, a 36-month warranty, and certification your insurer will accept.

Request a free survey

Free site visit · No obligation · Response within 24 hours

Photos of the door, panel, alarm, camera position or problem area help us quote more accurately. More details means less guessing and a faster response.

No spam. We'll only use these details to respond to your enquiry.

24-hour response
SSAIB-certificated for CCTV, intruder alarms and access control
500+ commercial clients