Features Pricing Our AI AI Project Plan Generator
Industries Internal projects Use Cases Case Studies
Blog Knowledge library Comparisons PM Templates Free Tools Integrations AI Project Management API & Developers
Login Get started free
Example project plan

Project plan for an access control rollout

Access control and video surveillance process employee data and can monitor behaviour. That is why a data protection impact assessment, signage and a works agreement belong in the plan from the start. This plan shows the rollout at the site of a logistics company with 300 employees.

No sign-up · opens instantly · 14 Weeks · 9 Phases · 49 Tasks · Budget approx. €194,500

This is how the plan looks in PathHub — click through the tabs or tick off tasks.

app.pathhub.ai/try?example=access-enOpen live
Example plan

Electronic Access Control and Video Surveillance Implementation

Implement an electronic access control and video surveillance system at a logistics site serving approximately 300 employees. The project covers requirements definition, vendor selection, privacy impact assessment, works council consultation, detailed engineering, installation, testing and workforce instruction. GDPR Articles 13 and 35 obligations, including purpose limitation, retention rules and signage, must be satisfied before go-live, while any biometric functionality requires a specific Article 9 assessment. Parallel workstreams will support delivery within the 14-week target while minimizing disruption to logistics operations.

Total Progress0%
14Weeks
0/9Phases
0/49Tasks
€194,500Budget
AI Recommendations KIAI Chat KIAI Tools KI

Phases

1

Phase 1: Governance and Mobilization

Pending · 1W · 0/3
Project Manager / Site Operations Lead
0

Establish the decision structure, scope, delivery controls and hard compliance gates for the four-month implementation. The phase ensures that the DPIA, works agreement, signage and go-live decision are treated as mandatory dependencies.

Timeline

Timeline 9 PhasesStart: Oct 6, 2026
Phase / Task
Oct 2026
Nov 2026
Dec 2026
Jan
W 1Oct 6
W 3Oct 20
W 5Nov 3
W 7Nov 17
W 9Dec 1
W 11Dec 15
W 13Dec 29
Governance and MobilizationOct 6 – Oct 12 · 1 wk · 0/3
Governance and Mobilization
Requirements, Site Survey and Process MappingOct 13 – Oct 26 · 2 wk · 0/5
Requirements, Site Survey and Process Mapping
DPIA, Legal Basis and Privacy DesignOct 27 – Nov 9 · 2 wk · 0/6
DPIA, Legal Basis and Privacy Design
Works Agreement and Employee ConsultationNov 10 – Nov 23 · 2 wk · 0/4
Works Agreement and Employee Consultation
Tender and Vendor SelectionNov 17 – Nov 30 · 2 wk · 0/5
Tender and Vendor Selection
Detailed Engineering and ProcurementDec 1 – Dec 14 · 2 wk · 0/6
Detailed Engineering and Procurement
Installation and ConfigurationDec 15 – Dec 28 · 2 wk · 0/10
Installation and Configuration
Acceptance, Signage, Training and ReadinessDec 22 – Jan 4 · 2 wk · 0/6
Acceptance, Signage, Training and Readiness
Go-Live and HypercareJan 5 – Jan 11 · 1 wk · 0/4
Go-Live and Hypercare
PlannedIn progressCompletedBlockedMilestones

Budget

Budget: €194,500
Software, Licenses and Equipment · €79,200Installation, Integration and Testing · €39,600Internal Personnel · €30,000External Privacy, Legal and Procurement Services · €30,000Training, Transparency and Operational Readiness · €15,700
Software, Licenses and Equipment€79,200
ItemQtyUnit priceTotal
Access control and video management software licenses1 Flat rate€14,000€14,000
Network video recorder and compliant storage capacity for approved retention periods1 Flat rate€14,000€14,000
IP surveillance cameras for approved security zones32 Person days€600€19,200
Electronic access card readers16 Person days€850€13,600
Door controllers and access-control panels5 Person days€1,400€7,000
Employee and contractor access badges350 Person days€8€2,800
PoE switches, UPS equipment, firewall adaptation and monitoring console hardware1 Flat rate€8,600€8,600
Installation, Integration and Testing€39,600
ItemQtyUnit priceTotal
Structured cabling, mounting, electrical work and door hardware adaptations1 Flat rate€18,000€18,000
Vendor installation and commissioning labor across operational shifts18 Person days€850€15,300
System configuration, identity integration, role-based access, retention and deletion controls5 Person days€900€4,500
Technical, privacy and operational acceptance testing with defect correction2 Person days€900€1,800
Internal Personnel€30,000
ItemQtyUnit priceTotal
Project Manager / Site Operations Lead16 Person days€900€14,400
IT and Information Security Lead7 Person days€800€5,600
Facilities, Security, Health & Safety and Shift Operations Representatives6 Person days€725€4,350
HR and Learning & Development Lead5 Person days€650€3,250
Procurement and Finance Coordinator4 Person days€600€2,400
External Privacy, Legal and Procurement Services€30,000
ItemQtyUnit priceTotal
DPIA, legal basis, purpose limitation, retention and GDPR Article 9 biometric assessment12 Person days€1,200€14,400
Works agreement negotiation and employee-monitoring legal support6 Person days€950€5,700
Site survey, access-point mapping and operational process analysis6 Person days€900€5,400
Tender preparation, vendor demonstrations and commercial evaluation4 Person days€900€3,600
Independent security architecture and privileged-access review1 Flat rate€900€900
Training, Transparency and Operational Readiness€15,700
ItemQtyUnit priceTotal
GDPR Article 13 information signs: design finalization, production and mounting before go-live40 Person days€120€4,800
Employee shift briefings covering badge use, surveillance purposes, privacy rights and procedures16 Person days€250€4,000
Security administrator and nominated supervisor training2 Person days€900€1,800
Operating procedures, incident handling, handover documentation and first-week hypercare coordination1 Flat rate€5,100€5,100

Risks

High

DPIA or Works Agreement Delay

If the DPIA is not approved by the end of Week 5 or the works agreement remains unresolved after Week 7, the project may be unable to lawfully or organizationally proceed to installation, employee instruction or Week 14 go-live.

Countermeasure: The DPO will begin the DPIA evidence collection in Week 1, and HR will schedule works council sessions in Week 1. The Sponsor will enforce approval gates at the end of Weeks 5 and 7 and prohibit go-live without both approvals.
High

Excessive or Unclear Surveillance Scope

If the site survey or later security requests expand camera coverage to welfare areas, neighboring property, public areas, or broad employee movement tracking after the privacy design is approved, the processing may exceed its defined purpose and require redesign.

Countermeasure: Facilities, Security and the DPO will approve a documented privacy zoning plan by the end of Week 3. The Project Manager will require written DPO approval for any scope change before the Week 10 design freeze.
High

Invalid Article 13 Transparency and Signage

If signs are missing, incomplete, obscured, incorrectly positioned or installed after cameras begin operating, employees, visitors and contractors may not receive the required information before their data is collected.

Countermeasure: The DPO will approve the layered Article 13 notice by Week 5; Facilities will install signs at every relevant entry and surveillance zone by Week 11, at least three weeks before the Week 14 go-live; the Project Manager will record a site-wide signage verification in Week 13.
High

Biometric Feature Creep

If a vendor proposes facial recognition, fingerprint readers, biometric templates or another biometric feature before the Week 10 design freeze, the project may trigger GDPR Article 9 requirements, additional employee consultation and a significant redesign.

Countermeasure: The DPO and IT Security Lead will document the Article 9 decision by Week 5 and prohibit biometric functionality unless separately approved. Procurement will include a no-undisclosed-biometric-feature clause in the contract by Week 8.
High

Hardware or Installation Lead-Time Slippage

If the vendor is not awarded by Week 8, equipment is not confirmed by Week 10, or door hardware, cabling or installation resources are unavailable, the three-week installation window may be insufficient for Week 14 go-live.

Countermeasure: Procurement and Finance will complete the award by Week 8, obtain written delivery commitments by Week 9 and maintain approved alternative equipment. The Vendor and Facilities Lead will complete a readiness review before installation starts in Week 11.
High

Operational Disruption and Unsafe Installation

If installation affects loading bays, shift changes, pedestrian or vehicle routes, emergency exits, or access to operational areas during peak periods in Weeks 11–12, the work may cause safety incidents, shipment delays or unauthorized bypasses.

Countermeasure: Facilities, Health & Safety and Site Operations will approve a phased installation and traffic-management plan by Week 10. The vendor will perform high-disruption work outside peak shifts, maintain temporary access controls and test emergency egress before each affected area is reopened.
High

Cybersecurity or Unauthorized Administrative Access

If default credentials, excessive administrator privileges, insecure remote support, unsegmented camera networks or exposed cloud interfaces remain during configuration or acceptance in Weeks 12–13, attackers or unauthorized staff could access footage or alter entry permissions.

Countermeasure: The IT and Information Security Lead will require MFA, unique accounts, least-privilege RBAC, network segmentation, encrypted communications, restricted vendor access and audit logging before acceptance in Week 13. Security testing and credential review will be mandatory go-live gates.
High

Inadequate Retention and Deletion Controls

If video, access logs, exports or backups are retained beyond the approved periods, automated deletion fails, or administrators can alter retention settings during Weeks 12–13, the project may breach purpose limitation and storage limitation requirements.

Countermeasure: The DPO and IT Lead will define retention and deletion rules by Week 5. The vendor will configure them by Week 12, and IT will execute documented deletion, backup and restoration tests in Week 13 before the Sponsor approves go-live.
Medium

Employee Resistance or Perceived Performance Monitoring

If employees believe access records or video will be used for performance management, or if fewer than 95% of affected employees complete instruction by the end of Week 13, staff may resist the system, share badges or bypass procedures.

Countermeasure: HR, the Works Council and Operations will publish the permitted and prohibited uses by Week 7, provide shift-based training during Weeks 12–13 and track completion. The Site Operations Lead will provide a staffed query and escalation process during the first two weeks after go-live.
Medium

Integration, Reliability or Emergency Access Failure

If access readers fail during network outages, identity synchronization is inaccurate, camera recording is unavailable, or emergency override testing fails during Week 13 acceptance, employees may be locked out or the site may lose security coverage.

Countermeasure: IT, the vendor and Site Operations will define availability, fail-safe and fail-secure requirements by Week 10. They will test offline access, emergency release, backup power, identity synchronization and incident recovery in Week 13, with manual fallback procedures documented before go-live.
Medium

Unplanned Site-Work or Contract Cost Overrun

If surveys identify unexpected cabling, power, door hardware, network or storage requirements after the Week 10 design approval, costs may exceed the EUR 220,000 budget or require scope reductions that weaken security or privacy controls.

Countermeasure: Procurement, Finance and Facilities will complete a measured site survey and costed bill of materials by Week 3, retain the EUR 26,400 reserve for approved changes and require Sponsor approval for any forecast exceeding the approved budget.

Stakeholders

ES

Executive Sponsor / Site Director

Owns the business case, authorizes funding, accepts residual risks and makes the final go-live decision.

Involve: From Phase 1 through governance reviews and final go-live approval
PM

Project Manager / Site Operations Lead

Coordinates the schedule, dependencies, operational constraints, acceptance activities and handover.

Involve: From Phase 1 through hypercare and project closure
WC

Works Council

Represents employee interests and negotiates binding provisions for monitoring, access records, retention and prohibited uses.

Involve: From Phase 1, with intensive involvement during Phases 3–4 and readiness review
DP

Data Protection Officer / Privacy Counsel

Leads the DPIA, confirms the legal basis, defines retention and access controls, prepares Article 13 information and evaluates any biometric processing.

Involve: From Phase 1 through privacy acceptance and post-go-live verification
IA

IT and Information Security Lead

Defines network, identity, storage, logging, cybersecurity, integration and privileged-access requirements.

Involve: From Phase 2 through design, configuration, testing and handover
FS

Facilities, Security and Health & Safety Team

Defines physical security requirements, validates camera and reader locations and protects emergency and logistics operations during installation.

Involve: From Phase 2 through site survey, engineering, installation and acceptance
HA

HR and Learning & Development

Manages employee communications, instructions, administrator training and responses to workforce questions.

Involve: From Phase 4 through training, readiness and hypercare
PA

Procurement and Finance

Runs the tender, evaluates commercial terms, controls purchase orders and confirms affordability and contractual protections.

Involve: From Phase 2 through vendor award and procurement completion
SS

Selected Security Technology Vendor / System Integrator

Designs, supplies, installs, configures, tests and documents the technical solution and provides initial support.

Involve: From Phase 5 through installation, acceptance and hypercare
ES

Employees, Shift Supervisors and Operational Representatives

Validate shift-based access needs, usability, workforce communications and the effect on daily logistics processes.

Involve: From Phase 2 through consultation, testing, instruction and go-live

Compliance

Mandatory

Complete and approve a GDPR Article 35 DPIA for the systematic video surveillance and access-control processing before implementation and go-live; document risks, safeguards, residual risk and approval evidence.

Data Protection Officer / Privacy Counsel Weeks 1–5, with approval before Week 6 and review before Week 14
Mandatory

Define and document the GDPR Article 6 legal basis, specific security purposes, prohibited uses, data fields, access-log use, retention periods and deletion rules for video and access records.

Data Protection Officer / Privacy Counsel with Site Security and IT Weeks 2–5; configure and test in Weeks 9–13
Mandatory

Assess whether facial recognition, fingerprints, templates or other biometric functionality is proposed; prohibit it unless a separate GDPR Article 9 assessment, lawful condition and required safeguards are approved.

Data Protection Officer / Privacy Counsel with Procurement and IT Weeks 3–5; recheck at vendor award and design freeze in Weeks 8–10
Mandatory

Prepare and deploy complete GDPR Article 13 information notices and visible surveillance signs before any recording or monitoring begins, including controller identity, purposes, legal basis, retention, rights and contact details.

Data Protection Officer / Privacy Counsel and Facilities Design in Weeks 4–5; print and install by Week 11; verify in Week 13 before Week 14 go-live
Mandatory

Obtain the approved works agreement and complete employee consultation covering monitoring scope, permitted purposes, access to records, retention, employee rights, escalation and prohibited performance-monitoring uses.

HR / Learning & Development and Works Council Weeks 1–7; conditions incorporated into vendor contract and operating procedures by Week 8
Mandatory

Implement GDPR Article 32 technical and organizational measures, including MFA, least privilege, role-based access, network segmentation, encryption, audit logs, secure remote support, vulnerability management and tested retention/deletion controls; align controls with the internal information-security policy and ISO/IEC 27001 principles where applicable.

IT and Information Security Lead with Vendor Design Weeks 6–10; implementation and testing Weeks 11–13
Optional

Maintain lawful site-operation controls for logistics areas, including emergency egress, fire and evacuation routes, safe installation, temporary access arrangements, visitor/contractor procedures and documented incident and data-subject request handling.

Facilities, Health & Safety, Site Operations and DPO Site survey Weeks 2–3; procedures and testing Weeks 9–13; ongoing after go-live

Milestones

  1. Week 1

    Approved project charter, governance structure and 16-week critical-path plan with DPIA, works agreement and go-live gates identified.

    Depends on: Sponsor appointment, core team availability and initial scope confirmation
  2. Week 3

    Approved site survey, process maps, initial privacy zoning plan and tender-ready requirements baseline.

    Depends on: Approved project charter and access to the site, systems and operational representatives
  3. Week 5

    Approved GDPR Article 35 DPIA, documented legal basis and retention model, Article 13 information design, and recorded Article 9 biometric decision.

    Depends on: Requirements baseline, monitoring purposes, data-flow details and privacy zoning plan
  4. Week 7

    Signed works agreement with no unresolved conditions preventing system installation or employee instruction.

    Depends on: DPIA findings, proposed monitoring scope, retention rules and employee consultation
  5. Week 8

    Approved vendor award, commercial decision record and contract conditions incorporating the DPIA and works agreement.

    Depends on: Tender-ready requirements, vendor submissions and sufficiently settled works-agreement conditions
  6. Week 10

    Approved detailed design, confirmed equipment delivery, installation runbook and printed Article 13 signage available for deployment.

    Depends on: Vendor award, signed contract, approved privacy controls and site engineering data
  7. Week 12

    Installed and configured system, Article 13 signs in place at least three weeks before Week 16 go-live, and documented installation baseline completed.

    Depends on: Approved detailed design, delivered equipment, site access and installation windows
  8. Week 13

    Signed technical, privacy and operational acceptance records; all Article 13 signs verified; employee and administrator instruction completed; go-live approval pack ready.

    Depends on: Installed system, completed testing, approved procedures, signage and training materials
  9. Week 14

    System live for all approved users and zones, first-week operational checks completed, priority defects controlled and formal handover to site operations accepted.

    Depends on: Go-live approval, completed acceptance, trained users and administrators, and operational support readiness

How this plan was created

This plan was created by PathHub AI from a single description: “Introduce an electronic access control system with video surveillance at the site of a logistics company with 300 employees: vendor selection, data protection impact assessment, works agreement, installation and instruction. Go-live in four months.” — without company context. With your departments, approval processes and compliance requirements it becomes much more precise.

Obligations

Obligations with lead time: what many think of too late

These obligations are typically triggered by an access control rollout (example: Germany). PathHub AI schedules them with lead time, warns when the schedule is too tight and shows the rule with its criteria under “Rule & evidence”, which you tick off and back with evidence. Not legal advice.

Carry out a DPIA, define purpose and retention, put up information signs (GDPR Art. 13, 35)
Required 3–6 weeks before go-livestatutory
Rule & evidence

Why: Monitoring strongly affects the privacy of employees and visitors.

Legal basis: GDPR Art. 35: systematic monitoring requires a prior DPIA; signs/information under Art. 13 before going live. Biometric data is specially protected (Art. 9).

Rule from the compliance library
GDPR (General Data Protection Regulation)
Criteria
  • Legal basis for every processing of personal data (consent, contract, legal obligation, legitimate interest)
  • Complete record of processing activities (Art. 30) for all processes
  • Data Processing Agreements (DPA) with all sub-processors
  • Data Protection Impact Assessment (DPIA) for high-risk processing
  • Technical and organisational measures (TOM) documented

If breached: Fines up to €20 million or 4% of global annual revenue — whichever is higher. Plus civil damages claims by affected individuals.

Evidence: In PathHub you tick off the criteria and attach evidence to each item as a file, link or note. Everything exports as a PDF evidence report.
Check and document lawfulness under the BDSG (publicly accessible areas, employee data)
Required 2–4 weeks before go-livestatutory
Rule & evidence

Why: Additional national limits apply to employees and publicly accessible areas.

Legal basis: Sec. 4 BDSG governs video surveillance of publicly accessible areas, Sec. 26 the processing of employee data; covert or permanent performance monitoring is generally not permitted.

Rule from the compliance library
Federal Data Protection Act (BDSG)
Criteria
  • Data protection officer appointed (20+ employees with regular data processing)
  • Employee data protection: data minimisation + purpose limitation in HR
  • Video surveillance with signage and stated purpose
  • Works council involvement for HR data processing

If breached: Fines up to €50,000 for violations of BDSG §§41-43. GDPR fines (up to €20m / 4%) apply in parallel.

Evidence: In PathHub you tick off the criteria and attach evidence to each item as a file, link or note. Everything exports as a PDF evidence report.
Conclude a works agreement on the monitoring technology
Important 6–12 weeks before go-liveguide value
Rule & evidence

Why: Without agreement with the works council the technology must not be used.

Applies: only if a works council exists

Legal basis: Sec. 87(1) No. 6 BetrVG: cameras, tracking and access systems are typical technical monitoring systems.

Rule from the compliance library
Works Constitution Act (BetrVG)
Criteria
  • Enable works council election from 5 eligible employees upward
  • Co-determination on working time, monitoring systems, IT rollouts (§87)
  • Hearing before every dismissal (§102) — written with reasons
  • Balance-of-interests and social plan on operational changes (§111)

If breached: Dismissals without works council hearing are void. Administrative fines up to €10,000 per violation. Criminal liability (§119) for obstructing the works council up to 1 year imprisonment.

Evidence: In PathHub you tick off the criteria and attach evidence to each item as a file, link or note. Everything exports as a PDF evidence report.
All typical initiatives and their obligations: planning internal projects

Frequently asked questions

How long does an access control rollout take?
In the example plan, an access control rollout takes 14 weeks in 9 phases, of which 2 phases partly run in parallel. The actual duration depends on company size, starting point and available resources — with your company context PathHub adjusts the schedule accordingly.
What does an access control rollout cost?
The example plan estimates about €194,500, split into 25 budget line items with quantity and unit price. The largest items are Software, Licenses and Equipment, Installation, Integration and Testing. This is an AI estimate as a starting point, not a quote.
What are the risks of an access control rollout?
The plan lists 11 risks with countermeasures. Rated highest: DPIA or Works Agreement Delay; Excessive or Unclear Surveillance Scope; Invalid Article 13 Transparency and Signage.
Who needs to be involved in an access control rollout?
Among others, the plan includes these people: Executive Sponsor / Site Director, Project Manager / Site Operations Lead, Works Council, Data Protection Officer / Privacy Counsel, IT and Information Security Lead, Facilities, Security and Health & Safety Team. For each role it states why and from when to involve them.
Can I adapt the plan to my company?
Yes. Open the plan in PathHub without signing up, adjust phases and tasks or describe your own initiative — with company context (departments, approval processes, works council, compliance requirements) every further plan gets more precise.

More project plan examples

Adapt this plan to your company

Open the plan in PathHub — no sign-up. Or describe your own initiative and get a complete plan in minutes.

Open plan →