Data access control ensures that authorised persons can only access the data they need for their tasks.
Distinction
Physical access control concerns physical entry to premises, system access control concerns logging on to systems. Data access control comes next and governs which data a logged-in user may read, change or delete.
Implementation
- authorisation concept based on the need-to-know principle
- role-based assignment of rights
- regular review and withdrawal of rights no longer needed
- logging of access to sensitive data
The catalogue in Section 64(3) BDSG, which directly applies only to the police and judiciary, is often used in practice as guidance for such control objectives.
Legal provisions
- Art. 32(1)(b) GDPR
- Ensuring confidentiality.
- Art. 25(2) GDPR
- Limiting accessibility through default settings.
- Section 64(3) BDSG
- Catalogue of control objectives, including data access control.