Alessandro AleddaInsider Threat and Risk

INTRA/DP/DP016Physical access control

The division of premises into areas by what each one holds, and the rules governing who may enter one.

Pillar
DP  |  Data and asset protection
Sources cited
2
Added
1 SEPTEMBER 2026
Updated
1 SEPTEMBER 2026
ControlJurisdictionSourceWhat it establishesPrerequisite or recommendation
DP016/EUMandatoryEuropean UnionDirective (EU) 2022/2557 on the resilience of critical entities, articles 13 and 14European Parliament and Council · read 1 Sep 2026The conditions on which a critical entity may ask for a background check, on whom, and what the check has to cover at a minimum. Also the duty to set out which categories of personnel exercise critical functions and to establish their access rights to premises.Employee security management is to set out the categories of personnel who exercise critical functions and to establish their access rights to premises, to critical infrastructure, and to sensitive information. The physical protection asked for alongside it names fencing, barriers, perimeter monitoring, detection equipment, and access controls.
RecommendedEuropean Unionwhere writtenSecure personal dataEuropean Data Protection Board · read 1 Sep 2026What controlling access to a building is taken to consist of, area by area, and what the Board says is owed before access to those areas is recorded.The building is divided into areas according to risk, and for each area a list is kept of the individuals, or the categories of individual, permitted to enter it. Rules and means are established for visitors, at a minimum that a visitor is accompanied by someone from the organization once outside the public areas. The keys and the alarm codes are themselves protected.