Physical access control prevents unauthorised persons from physically entering premises and facilities in which personal data is processed.
Typical measures
- locking systems with key or card management
- secured server rooms with restricted access
- visitor rules and escort requirements
- alarm systems and, where appropriate, video surveillance
Classification
Physical access control comes from the catalogue of control objectives in the former BDSG and is still used today to structure technical and organisational measures. In more recent catalogues, such as Section 64(3) BDSG, it is covered by access control for processing equipment.
It also remains relevant for cloud services: here, the provider must demonstrate how its data centres are physically secured.
Legal provisions
- Art. 32 GDPR
- Security of processing.
- Section 64(3) BDSG
- Catalogue of control objectives as guidance.