Data access control

Data protection glossary · 1 minute read

Data access control ensures that authorised persons can only access the data they need for their tasks.

Distinction

Physical access control concerns physical entry to premises, system access control concerns logging on to systems. Data access control comes next and governs which data a logged-in user may read, change or delete.

Implementation

  • authorisation concept based on the need-to-know principle
  • role-based assignment of rights
  • regular review and withdrawal of rights no longer needed
  • logging of access to sensitive data

The catalogue in Section 64(3) BDSG, which directly applies only to the police and judiciary, is often used in practice as guidance for such control objectives.

Art. 32(1)(b) GDPR
Ensuring confidentiality.
Art. 25(2) GDPR
Limiting accessibility through default settings.
Section 64(3) BDSG
Catalogue of control objectives, including data access control.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.