Physical access control

Data protection glossary · 1 minute read

Physical access control prevents unauthorised persons from physically entering premises and facilities in which personal data is processed.

Typical measures

  • locking systems with key or card management
  • secured server rooms with restricted access
  • visitor rules and escort requirements
  • alarm systems and, where appropriate, video surveillance

Classification

Physical access control comes from the catalogue of control objectives in the former BDSG and is still used today to structure technical and organisational measures. In more recent catalogues, such as Section 64(3) BDSG, it is covered by access control for processing equipment.

It also remains relevant for cloud services: here, the provider must demonstrate how its data centres are physically secured.

Art. 32 GDPR
Security of processing.
Section 64(3) BDSG
Catalogue of control objectives as guidance.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.