DPDP Compliance for Co-working and Physical Access Platforms
Biometric access gates, visitor logs and CCTV footage turn a shared workspace into a continuous data-collection environment for members and guests alike.
Biometric access control is a distinct, higher-stakes collection
Fingerprint or facial-recognition access gates used at co-working spaces collect biometric templates that are considerably harder to reissue than a lost keycard if the underlying database is ever compromised. The notice given to members at sign-up should clearly separate biometric enrolment as its own consent point, distinct from the general membership agreement, and should say plainly whether the raw biometric image is stored or only a derived template — the two carry very different risk profiles.
Where a co-working operator runs multiple locations under one membership, a member's biometric data enrolled at one site is often synced across all sites for portability, which means the security safeguards and access logging need to cover that entire multi-site database, not just the single premises where enrolment happened.
Visitor logs and CCTV cover people who never signed up
Guests, delivery personnel, and interview candidates visiting a co-working space get logged at the front desk and captured on CCTV without ever having agreed to the operator's membership terms, which means the operator needs a separate, visible notice at the entrance covering what is recorded and why, since these are data principals with no other relationship to the platform. CCTV footage retention should be tied to a specific, reasonable purpose — security incident investigation, typically — rather than kept indefinitely simply because storage is inexpensive.
Shared reception and access logs sometimes get reused for purposes beyond security, like tracking which member companies bring the most visitor traffic for account-management conversations, and that secondary use needs its own basis rather than riding on the original security-driven collection.
Third-party building management and shared infrastructure
Many co-working operators lease space inside larger commercial buildings that run their own building-wide access and security systems, meaning a member's access data may be visible to both the co-working operator and the building's separate security provider. Members should be told when a second, independent party operates the underlying access infrastructure, since a request to correct or delete access data may need to be routed to that building operator rather than resolved entirely within the co-working platform's own systems.
Meeting-room booking systems and shared amenity platforms (printers, cafés, parking) integrated into a co-working app add further small data flows — usage logs tied to individual members — that are easy to overlook in a broader compliance review but still count as personal data requiring the same basic notice discipline.
Where to go next
The Retention Planner is a practical next step for setting explicit limits on CCTV footage and access-log retention, since “keep it just in case” is the default failure mode for this kind of continuously generated data. A Data Flow Mapper exercise can also help clarify where the co-working operator's own systems end and a building-wide security provider's systems begin.