Blog · CCTV and access control

The school has two hundred keys and nobody knows where they are

Something similar happens in many schools. Over the years, keys are copied for teachers, office staff, cleaning, maintenance, catering, after-school activities or suppliers. Some are returned when someone leaves the school, others are lost and others simply stop being tracked. Eventually there comes a point when the school's leadership knows roughly who should have access to each area, but it is much harder to know who actually has a key that can open it.

A key opens a door, but it does not let you manage who can open it

As long as nothing happens, the key system seems to work. The problem appears when a master key is lost, a contract with a supplier ends, someone leaves the school without returning all their copies or you need to find out who could have entered a particular area outside normal hours. Then an issue that seemed to be purely about locks becomes a management and security problem.

A mechanical key is a simple, reliable way to open a lock. What it does not make easy is changing permissions. If someone has a key that opens twenty doors and stops working at the school, getting that key back depends on them handing it in. If it is lost, there is no way to cancel it: to be certain it can no longer be used, you would have to change the locks concerned and issue new keys to everyone who still needs access.

Nor is there usually any record. A conventional lock cannot tell you who went into a room at seven in the evening, or distinguish between two people who each have a copy of the same key. And the bigger the school, the harder it is to keep an up-to-date inventory linking each key to a person, a door and a given level of access.

That is why the problem does not usually show up at first as a security incident. It appears earlier, as a management question that nobody can answer with certainty: who can currently get into this space?

Far more people come into a school than you might think

The people who need to get into a school are not just teachers and office staff. There are cleaners who may work when the building is practically empty, maintenance technicians who need to reach specific rooms, catering companies, people running after-school activities and, depending on the school, organisations that use certain spaces in the afternoons or at weekends.

Each of these groups needs to get into different places at different times. Cleaning staff may need access to a whole floor between certain hours; an outside company may need nothing more than the plant room; a sports coach may need to get into the sports hall and changing rooms on Saturday, but not into the classrooms or the office area.

With mechanical keys it is hard to achieve that level of precision. People often end up being given a key that opens more doors than strictly necessary because that is the solution available. That is not necessarily a sign of poor management: it is a limitation of the system itself.

There are spaces where that difference matters particularly. The school office and the records archive may hold sensitive documents; the rack or comms cabinet gives access to much of the technology infrastructure; storerooms may hold high-value devices; labs and IT rooms have specialist equipment, and the medical room or first-aid cabinet may contain medication. Not every door in the building needs the same level of control.

What changes when access is managed electronically

With electronic access control, permission no longer depends on a physical key alone. The person uses a credential and the system determines which doors they can open and under what conditions. This makes it possible to withdraw access without changing the lock, to change permissions when someone's responsibilities change or to set time restrictions.

If someone stops working at the school, their credential can be deactivated even if it has not been physically returned. If a supplier needs access for just a few weeks, the permission can be limited to that period. And if the cleaning staff work from seven to nine in the morning, access can be set up for that time slot alone and for the areas they actually need.

The system can also record which credential was used, on which door and at what time. That information makes it possible to reconstruct certain situations that are impossible to know about with a conventional key.

But the system has limits, and they need explaining just as clearly. Access control determines which credential has permission to open a door. It does not stop someone forcing that door physically, or prevent an authorised person from holding it open for someone else. And, unless other additional systems are used, it does not necessarily prove who was carrying the credential at that moment either. What it identifies is the credential used.

The access log contains personal data

Precisely because electronic access control can store information about who opened a door and when, an issue arises that does not exist in the same way with a traditional lock.

If a card is linked to a person and the system logs that the credential opened the archive at 19:40 on a Thursday, that entry tells you something about the activity of an identified person. It is therefore processing of personal data, and Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), applies.

The school must define what it needs that log for, and Article 5 of the Regulation sets the bar: a specified, explicit and legitimate purpose, keeping only the information that purpose requires and setting a retention period. ‘Security’ on its own is not a purpose; controlling access to restricted areas outside school hours is. You also have to decide who can consult the history and for what reason, because a log that anyone looks at out of curiosity is no safeguard.

There is a common misconception about the retention period that needs clearing up. Unlike CCTV recordings, for which Article 22(3) of Organic Law 3/2018 (Spain's data protection act) sets a general maximum of one month, data protection law does not lay down an equivalent single period for access control logs. That does not mean they can be kept indefinitely: the school must set a period appropriate to the purpose and justify it.

The school must inform the people affected in advance, as Article 13 requires, and enter the processing in the record of processing activities under Article 30. An access control installation is therefore not finished when the electronic lock works. There is an organisational and data protection side that has to go with the system.

Controlling access and recording working time are not the same thing

It can be tempting to use the entry and exit information from the doors as a staff working time record as well. After all, the system has dates, times and users. But these are different purposes and it is best not to confuse them.

Access control meets the need to determine who can enter certain spaces. Working time recording has its own obligations: Article 34(9) of Spain's Workers' Statute (Estatuto de los Trabajadores), added by Royal Decree-Law 8/2019 (Spain's working time recording rules), requires employers to ensure a daily record with the specific start and finish times of each employee, keep it for four years and make it available to employees, their legal representatives and the Labour and Social Security Inspectorate.

Opening the building door does not necessarily mean starting work, either, and going out through it does not always mean the working day is over. So if a school wants to use information from access control for other purposes, it must look specifically at how to do so and what additional obligations arise.

When the system affects staff, employment law also comes into play

When access control is applied to employees, data protection law is not the only framework involved. Article 20(3) of the Workers' Statute allows the employer to adopt ‘the monitoring and control measures it considers most appropriate to verify that the worker is fulfilling their employment obligations and duties’, but requires it to do so ‘with due consideration for their dignity in adopting and applying them’ (our translation). It is a power with conditions, not a blank cheque.

Where a school has workers' legal representatives, there are also information and consultation obligations: Article 64(5)(f) gives the works council the right to issue a report, before the decision is implemented, on ‘the introduction and review of systems for organising and monitoring work’ (our translation).

This does not mean that installing an electronic lock is legally complex by definition. It means that, if the system is going to record information linked to employees and that information is going to be used for certain purposes, it is best to define this properly from the start.

Card, mobile phone or biometrics?

The possibility of using biometrics, especially fingerprints or facial recognition, often comes up when access control is being planned. The advantage seems obvious: a fingerprint does not get lost or forgotten, and it cannot be lent as easily as a card.

The problem is that, from a data protection point of view, we are talking about something very different. Biometric data intended to identify a person uniquely is included by Article 9(1) of the GDPR among the special categories, with a general prohibition that is lifted only if one of the circumstances listed in Article 9(2) applies. The Spanish Data Protection Agency (AEPD) also took the view, in its ‘Guía sobre tratamientos de control de presencia mediante sistemas biométricos’ (guide on attendance monitoring using biometric systems) of November 2023, that using biometrics for identification or authentication in attendance monitoring is high-risk processing involving special categories of data.

One warning is needed about that guide, because the situation changed this summer. Spain's National High Court (Audiencia Nacional) annulled it in a judgment of 30 June 2026, upholding the appeal brought by the Asociación Española de Empresas de Seguridad, an association of security companies: it held that, under the guise of a guidance document, the guide set binding criteria for controllers and should therefore have gone through the procedure for a circular, with an opinion from the Council of State and a hearing for interested parties. The judgment annuls it on procedural grounds and does not assess whether the substantive criterion was right; nor is it final, because it can still be appealed in cassation before the Supreme Court. Anyone intending to rely on that document should first check where things stand.

What has not changed is the Regulation, which is where the prohibition lives. In the employment context those circumstances narrow almost to nothing: if lifting the prohibition relies on Article 9(2)(b), there has to be a provision with the rank of law setting out the use of biometric data for that purpose, and there is none. Consent does not lift it there either, because of the imbalance between the employee and the employer. And in any case, a data protection impact assessment under Article 35 would first have to be passed. When we are also talking about pupils, and therefore minors, the analysis must be even more careful.

For that reason, a biometric feature should not be chosen simply because the manufacturer offers it or because it is technically convenient. In many cases, a card, a key fob or a digital credential can meet the school's needs without introducing the legal complexity of using biometric data.

Technology is no substitute for good permissions management

Replacing keys with an electronic system does not achieve much if nobody then keeps the access list up to date. An old permission can stay active for years, just like a key that nobody remembered to get back, with the added problem that it is invisible: nobody sees a file grow.

Before installing anything, you need to define who can authorise new access, who must withdraw it and which situations will automatically trigger that review. A member of staff leaving, the end of a contract with an outside company or a change of responsibilities should all come with a review of the relevant credentials. It is also advisable to review the whole set of permissions periodically to spot those that no longer make sense.

This part is much less visible than the card reader on the door, but it is probably what determines whether the system will still be useful five years from now. Access control needs the same ongoing upkeep as a network's user accounts.

Emergency exit doors have their own rules

There is one issue that takes precedence over the convenience of access control: evacuating the building. A door that forms part of an escape route or emergency exit cannot be locked in such a way that someone needs a key or a credential to get out in an emergency.

Basic Document SI (‘Seguridad en caso de incendio’, on fire safety) of the Spanish Technical Building Code (CTE) sets out, in section SI 3, paragraph 6, specific conditions for these doors and their opening devices: those intended as a floor or building exit and those intended for evacuating more than fifty people must be hinged doors swinging on a vertical axis. On those exits, the locking system must either stay inactive while there is activity in the areas to be evacuated, or allow quick and easy opening from the side the evacuation comes from, ‘without having to use a key and without having to operate more than one mechanism’ (our translation). There are also specific standards, such as UNE-EN 179:2009 and UNE-EN 1125:2009, which apply depending on the type of door and the expected occupancy.

That is why you cannot fit just any electronic locking system to just any door without first studying its role in the building. What applies to each door depends on the calculated occupancy and on the building project, and it is decided by the professional who signed the project, not by the installer. The evacuation plan and fire regulations determine which solution can be installed and how it must behave in a power failure or an emergency.

You do not need to change every door at once

An access control project does not have to mean replacing every lock in the school in a single operation. In many schools it makes more sense to migrate gradually and keep a combination of electronic credentials and traditional keys for years.

The first step is to understand the current situation: which doors there are, which areas are genuinely critical and how the keys are currently distributed. It is the most tedious part of the project and the one that yields the most information. From there it may make sense to start with the perimeter and the main entrances, move on to particularly sensitive spaces and leave the remaining doors with mechanical locks until there is a reason to change them.

Nor are all doors the same. On some it may be enough to replace certain parts of the lock; others need power, cabling or integration with the network. These conditions affect both the cost and the planning of the works, so they need to be checked before a final proposal is prepared.

How we approach access control at PenwinEdu

At PenwinEdu we work with TESA on access control projects for schools. But, as with cameras or the Wi-Fi network, we do not start by choosing a product from a catalogue. First we need to understand which doors the school wants to control, who needs to use them, at what times and what currently happens when staff change or a key is lost.

Our experience working in schools allows us to identify situations that come up again and again in these buildings: cleaning staff who work outside school hours, suppliers who need access to one room and nothing else, after-school activities that use the school once the teaching staff have gone home, or spaces such as the school office and the comms rack that need a different level of control from an ordinary classroom.

From there we can decide together with the school which doors are worth bringing into the system, what type of equipment fits best and how to carry out a phased roll-out. We take care of installing and technically managing the equipment, while decisions relating to data protection, employment law or evacuation need to be properly coordinated with the relevant people at the school.

The aim is not to get rid of keys: it is to regain control

Moving from a traditional lock to electronic access control does not make sense simply because the technology is more modern. It makes sense when it lets the school give clear answers to questions that become harder and harder to answer with a bunch of keys: who can get in, where, at what times and how that permission is withdrawn when it is no longer needed.

Sources

  1. Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los derechos digitales (LOPDGDD), artículo 22.3 (in Spanish)
  2. Reglamento (UE) 2016/679, General de Protección de Datos (RGPD) (in Spanish)
  3. Agencia Española de Protección de Datos, «Guía sobre tratamientos de control de presencia mediante sistemas biométricos» (noviembre de 2023), anulada por la Audiencia Nacional (in Spanish)
  4. Audiencia Nacional, Sala de lo Contencioso-Administrativo, sentencia 367/2026, de 30 de junio de 2026, que anula la guía anterior por defecto de procedimiento (sentencia no firme, susceptible de recurso de casación) (in Spanish)
  5. Real Decreto Legislativo 2/2015, de 23 de octubre, por el que se aprueba el texto refundido de la Ley del Estatuto de los Trabajadores, artículos 20.3, 34.9 y 64.5.f) (in Spanish)
  6. Real Decreto-ley 8/2019, de 8 de marzo, de medidas urgentes de protección social y de lucha contra la precariedad laboral en la jornada de trabajo (in Spanish)
  7. Código Técnico de la Edificación, Documento Básico SI «Seguridad en caso de incendio», sección SI 3, apartado 6 (Real Decreto 314/2006, de 17 de marzo, en su texto consolidado tras el Real Decreto 164/2025) (in Spanish)
  8. Normas UNE-EN 179:2009 y UNE-EN 1125:2009, sobre dispositivos de apertura para salidas de emergencia (in Spanish)

At PenwinEdu we bring our experience in schools to managing access in this way. We design access control projects around how each school really works, prioritising the doors where the change adds value and allowing the roll-out to happen gradually. Because the aim is not to replace two hundred keys with two hundred electronic locks: it is for the school to know once again exactly who can get in where, and to be able to change that whenever it needs to. The initial assessment is free and comes with no obligation.