What government requirements must your access security meet?
In the Netherlands, access security must comply with a combination of privacy legislation, occupational health and safety legislation, and sector-specific standards. The GDPR requires organizations to protect personal data processed via access systems, while the Occupational Health and Safety Act sets requirements for workplace safety. For those who want to know how this works in practice, this article provides an overview of all relevant questions. Would you like immediate advice regarding your situation? Feel free to contact us with Sellox.
Which laws and standards apply to access security?
The most important legislation for access security in the Netherlands is the General Data Protection Regulation (GDPR), the Working Conditions Act, and the Network and Information Systems Security Act (Wbni). In addition, there are standards such as ISO 27001 and NEN 7510 that serve as a guideline for establishing secure access security. access control within organizations.
The GDPR applies as soon as an access system processes personal data, such as biometric data, license plates, or employee time registration. The law requires organizations to have a legal basis for this processing and that the data are adequately secured. The Working Conditions Act obliges employers to guarantee a safe working environment, which also relates to who has access to which areas.
ISO 27001 is an international standard for information security that also covers physical access control. Although certification is not legally mandatory for most organizations, it is increasingly requested by clients and contracting parties. NEN 7510 applies specifically to the healthcare sector and sets additional requirements for the security of patient data and access to areas where that data is processed.
What are the minimum requirements for physical access security?
There is no universal statutory minimum standard for physical access security in the Netherlands, but the GDPR requires organizations to take appropriate technical and organizational measures. What is appropriate depends on the nature of the data being processed and the associated risks.
In practice, this means that organizations must consider at least the following elements:
- Restriction of access to sensitive areas based on function or role
- Registration of who had access and when
- Periodic check and updating of access rights
- Procedures for revoking access upon termination of employment
- Security of systems used to manage access
For organizations working with state secrets, critical infrastructure, or special categories of personal data, additional requirements apply under specific laws and regulations. In such cases, certification or a formal security plan may be mandatory.
When is a risk analysis mandatory for access security?
An access security risk analysis is mandatory when the processing of personal data via access systems poses a high risk to the rights and freedoms of data subjects. In that case, the GDPR mandates a Data Protection Impact Assessment (DPIA).
A DPIA is mandatory in any case when using biometric data for identification, such as fingerprints or facial recognition. Large-scale systematic monitoring of employees or visitors also typically falls under this. The Dutch Data Protection Authority has published a list of processing activities for which a DPIA is always required.
Beyond the GDPR obligation, a risk analysis is also advisable from a business perspective. Organizations working with valuable assets, confidential information, or vulnerable groups of people would do well to systematically map out access risks, even if this is not legally required. This helps in taking proportionate measures and demonstrating due diligence in the event of any incidents.
How do regulations differ by sector?
Access security regulations vary by sector because each industry faces its own risks, sensitive data, and regulatory bodies. What suffices for an office environment is insufficient for a hospital, data center, or airport.
Care and welfare
In the healthcare sector, NEN 7510 applies as the dominant standard for information security, including physical access control. Healthcare organizations must demonstrably regulate who has access to areas where patient data is processed or stored. The Health and Youth Care Inspectorate (IGJ) can supervise this.
Vital infrastructure and government
Organizations that are part of vital infrastructure, such as energy companies, drinking water companies, and financial institutions, are subject to the Wbni and the European NIS2 Directive. These regulations require them to implement security measures that also include physical access control and to report incidents to the competent authorities. Government institutions also follow the Government Information Security Baseline (BIO).
What are the consequences of non-compliance with security requirements?
The consequences of non-compliance with security requirements can range from fines and reputational damage to liability in the event of incidents. The Dutch Data Protection Authority can impose fines of up to 20 million euros or four percent of global annual turnover for violations of the GDPR.
In addition to financial sanctions, organizations may face damage claims from victims in the event of a data breach or security incident. If it is found that an organization had taken insufficient measures for access security, this can increase liability. In this regard, regulators look not only at what went wrong but also at whether the organization demonstrably made efforts to mitigate risks.
Reputational damage is often an equally significant, if not greater, consequence. Customers, partners, and employees expect an organization to handle access to buildings and systems with care. An incident that becomes public can damage trust for a long time.
How do you demonstrate that your access security meets the requirements?
You demonstrate that your access security meets the requirements by documenting policies, procedures, and technical measures and evaluating them periodically. Demonstrability is a core requirement of the GDPR and of standards such as ISO 27001.
Concrete steps to demonstrate compliance include:
- Establish an access policy which states who has access to which areas and based on which criteria.
- Record processing operations in a register if you process personal data via access systems.
- Conduct periodic audits apply access rights and record the results.
- Document risk analyses and DPIAs so that you can demonstrate during an audit that risks have been consciously weighed.
- Train employees on the correct handling of access passes, codes, and procedures in the event of loss or theft.
External certification, such as ISO 27001, provides an extra layer of credibility. A certified organization has had its security measures verified by an independent party to meet recognized standards. This can also be an advantage during tenders or contract negotiations.
Do you want to know if your current access security meets the applicable requirements? Contact us contact Sellox for a no-obligation consultation.
Frequently Asked Questions
How often do I need to review my access rights to remain compliant?
It is recommended to check access rights at least once a quarter and adjust them immediately in the event of organizational changes, such as termination of employment, changes in role, or reorganization. The GDPR requires that personal data not be processed for longer than necessary, which means that outdated access rights must be revoked in a timely manner. An automated access management system can significantly simplify this process by automatically generating notifications when rights expire or need to be reviewed.
As an employer, am I allowed to use biometric data for employee access control?
The use of biometric data, such as fingerprints or facial recognition, is in principle prohibited under the GDPR unless strict exceptions are met. In an employment relationship, explicit consent from employees is generally not a valid legal basis, as consent is not considered fully free in a hierarchical relationship. Organizations that nevertheless wish to use biometrics must conduct a DPIA, be able to demonstrate a compelling interest, and verify whether no less intrusive alternatives are available, such as an access card or PIN code.
What should I do if an access card or key is lost or stolen?
In the event of the loss or theft of an access card or key, you must take immediate action: block the card immediately in the access management system and document the incident, including the date, time, and involved employee. Subsequently, check the access logs to assess whether the card was misused in the period between loss and blocking. If there are indications that unauthorized persons have gained access to areas containing sensitive data, this may constitute a data breach that must be reported to the Dutch Data Protection Authority.
Does the reporting obligation to the Dutch Data Protection Authority also apply to a physical security incident?
Yes, the data breach notification obligation under the GDPR also applies to physical security incidents if personal data has been exposed to unauthorized access. Examples include a break-in where files were viewed, or a situation where an unauthorized person gained access to a room containing confidential patient or staff data. Such an incident must be reported to the Dutch Data Protection Authority within 72 hours of discovery, unless it is unlikely that there is a risk to the data subjects.
How do I start drafting an access policy if my organization has no experience with this yet?
Start by inventorying all rooms, systems, and data within your organization and determine, for each component, who requires access based on role and responsibility. Next, draft a simple document outlining the access levels, responsible persons, and procedures for granting and revoking access. It is advisable to involve a security specialist or access system vendor in this process to ensure the policy aligns with the technical capabilities of your existing or desired systems.
What is the difference between access management and access security, and why is that distinction important?
Access management refers to the organizational process of granting, managing, and revoking access rights, while access security encompasses the broader set of technical and physical measures designed to prevent unauthorized access. This distinction is important because both aspects must be addressed separately in your policy and documentation. A good access system without adequate management, such as the timely revocation of rights upon termination, can still create vulnerabilities that entail both legal and operational risks.
Can small businesses also be fined for inadequate access security, or does that only apply to large organizations?
The GDPR makes no distinction based on company size: even small organizations can be fined if they fail to adequately secure personal data via their access systems. However, when imposing sanctions, the Dutch Data Protection Authority does take into account factors such as the size of the organization, the severity of the violation, and the extent to which an organization can demonstrate efforts. For small businesses, it is therefore particularly important to document basic measures, even with limited resources, and to demonstrate that risks have been consciously assessed.