Project plan for an access control rollout
Access control and video surveillance process employee data and can monitor behaviour. That is why a data protection impact assessment, signage and a works agreement belong in the plan from the start. This plan shows the rollout at the site of a logistics company with 300 employees.
No sign-up · opens instantly · 14 Weeks · 9 Phases · 49 Tasks · Budget approx. €194,500
This is how the plan looks in PathHub — click through the tabs or tick off tasks.
Electronic Access Control and Video Surveillance Implementation
Implement an electronic access control and video surveillance system at a logistics site serving approximately 300 employees. The project covers requirements definition, vendor selection, privacy impact assessment, works council consultation, detailed engineering, installation, testing and workforce instruction. GDPR Articles 13 and 35 obligations, including purpose limitation, retention rules and signage, must be satisfied before go-live, while any biometric functionality requires a specific Article 9 assessment. Parallel workstreams will support delivery within the 14-week target while minimizing disruption to logistics operations.
Phases
Phase 1: Governance and Mobilization
Establish the decision structure, scope, delivery controls and hard compliance gates for the four-month implementation. The phase ensures that the DPIA, works agreement, signage and go-live decision are treated as mandatory dependencies.
Phase 2: Requirements, Site Survey and Process Mapping
Document the physical, operational, technical and workforce requirements for the logistics site. The outputs will define the permitted surveillance scope and provide the basis for the DPIA, tender and installation design.
Phase 3: DPIA, Legal Basis and Privacy Design
Complete the GDPR Article 35 assessment and establish the privacy rules that constrain the system design. Purpose limitation, legal basis, retention, access rights, Article 13 information and Article 9 biometric considerations must be resolved before procurement and implementation proceed.
Phase 4: Works Agreement and Employee Consultation
Negotiate the employee-monitoring safeguards and obtain the works agreement required for implementation. The agreement will translate the DPIA and privacy design into binding operational limits for surveillance and access records.
Phase 5: Tender and Vendor Selection
Select a security technology vendor capable of delivering access control and video surveillance within the remaining lead time and approved privacy boundaries. Evaluation will cover functionality, cybersecurity, privacy, delivery capability, support and total cost.
Phase 6: Detailed Engineering and Procurement
Translate the approved requirements into an installable technical design and secure the equipment, services and site access needed for delivery. The design must preserve the approved privacy scope and support a controlled installation with minimal logistics disruption.
Phase 7: Installation and Configuration
Install and configure the physical and digital components while maintaining safe logistics operations. Surveillance and access processing must remain within the approved DPIA and works-agreement boundaries, with Article 13 signs installed before any operational activation.
Phase 8: Acceptance, Signage, Training and Readiness
Validate the system technically, operationally and from a privacy perspective, then prepare all employees and administrators for controlled use. No go-live may occur unless the DPIA conditions, signed works agreement, Article 13 signage and acceptance criteria are all verified.
Phase 9: Go-Live and Hypercare
Launch the access control and video surveillance system under controlled operational monitoring and resolve early defects quickly. The phase transfers ownership to site operations while preserving compliance evidence and support arrangements.
Timeline
Budget
| Item | Qty | Unit price | Total |
|---|---|---|---|
| Access control and video management software licenses | 1 Flat rate | €14,000 | €14,000 |
| Network video recorder and compliant storage capacity for approved retention periods | 1 Flat rate | €14,000 | €14,000 |
| IP surveillance cameras for approved security zones | 32 Person days | €600 | €19,200 |
| Electronic access card readers | 16 Person days | €850 | €13,600 |
| Door controllers and access-control panels | 5 Person days | €1,400 | €7,000 |
| Employee and contractor access badges | 350 Person days | €8 | €2,800 |
| PoE switches, UPS equipment, firewall adaptation and monitoring console hardware | 1 Flat rate | €8,600 | €8,600 |
| Item | Qty | Unit price | Total |
|---|---|---|---|
| Structured cabling, mounting, electrical work and door hardware adaptations | 1 Flat rate | €18,000 | €18,000 |
| Vendor installation and commissioning labor across operational shifts | 18 Person days | €850 | €15,300 |
| System configuration, identity integration, role-based access, retention and deletion controls | 5 Person days | €900 | €4,500 |
| Technical, privacy and operational acceptance testing with defect correction | 2 Person days | €900 | €1,800 |
| Item | Qty | Unit price | Total |
|---|---|---|---|
| Project Manager / Site Operations Lead | 16 Person days | €900 | €14,400 |
| IT and Information Security Lead | 7 Person days | €800 | €5,600 |
| Facilities, Security, Health & Safety and Shift Operations Representatives | 6 Person days | €725 | €4,350 |
| HR and Learning & Development Lead | 5 Person days | €650 | €3,250 |
| Procurement and Finance Coordinator | 4 Person days | €600 | €2,400 |
| Item | Qty | Unit price | Total |
|---|---|---|---|
| DPIA, legal basis, purpose limitation, retention and GDPR Article 9 biometric assessment | 12 Person days | €1,200 | €14,400 |
| Works agreement negotiation and employee-monitoring legal support | 6 Person days | €950 | €5,700 |
| Site survey, access-point mapping and operational process analysis | 6 Person days | €900 | €5,400 |
| Tender preparation, vendor demonstrations and commercial evaluation | 4 Person days | €900 | €3,600 |
| Independent security architecture and privileged-access review | 1 Flat rate | €900 | €900 |
| Item | Qty | Unit price | Total |
|---|---|---|---|
| GDPR Article 13 information signs: design finalization, production and mounting before go-live | 40 Person days | €120 | €4,800 |
| Employee shift briefings covering badge use, surveillance purposes, privacy rights and procedures | 16 Person days | €250 | €4,000 |
| Security administrator and nominated supervisor training | 2 Person days | €900 | €1,800 |
| Operating procedures, incident handling, handover documentation and first-week hypercare coordination | 1 Flat rate | €5,100 | €5,100 |
Risks
DPIA or Works Agreement Delay
If the DPIA is not approved by the end of Week 5 or the works agreement remains unresolved after Week 7, the project may be unable to lawfully or organizationally proceed to installation, employee instruction or Week 14 go-live.
Excessive or Unclear Surveillance Scope
If the site survey or later security requests expand camera coverage to welfare areas, neighboring property, public areas, or broad employee movement tracking after the privacy design is approved, the processing may exceed its defined purpose and require redesign.
Invalid Article 13 Transparency and Signage
If signs are missing, incomplete, obscured, incorrectly positioned or installed after cameras begin operating, employees, visitors and contractors may not receive the required information before their data is collected.
Biometric Feature Creep
If a vendor proposes facial recognition, fingerprint readers, biometric templates or another biometric feature before the Week 10 design freeze, the project may trigger GDPR Article 9 requirements, additional employee consultation and a significant redesign.
Hardware or Installation Lead-Time Slippage
If the vendor is not awarded by Week 8, equipment is not confirmed by Week 10, or door hardware, cabling or installation resources are unavailable, the three-week installation window may be insufficient for Week 14 go-live.
Operational Disruption and Unsafe Installation
If installation affects loading bays, shift changes, pedestrian or vehicle routes, emergency exits, or access to operational areas during peak periods in Weeks 11–12, the work may cause safety incidents, shipment delays or unauthorized bypasses.
Cybersecurity or Unauthorized Administrative Access
If default credentials, excessive administrator privileges, insecure remote support, unsegmented camera networks or exposed cloud interfaces remain during configuration or acceptance in Weeks 12–13, attackers or unauthorized staff could access footage or alter entry permissions.
Inadequate Retention and Deletion Controls
If video, access logs, exports or backups are retained beyond the approved periods, automated deletion fails, or administrators can alter retention settings during Weeks 12–13, the project may breach purpose limitation and storage limitation requirements.
Employee Resistance or Perceived Performance Monitoring
If employees believe access records or video will be used for performance management, or if fewer than 95% of affected employees complete instruction by the end of Week 13, staff may resist the system, share badges or bypass procedures.
Integration, Reliability or Emergency Access Failure
If access readers fail during network outages, identity synchronization is inaccurate, camera recording is unavailable, or emergency override testing fails during Week 13 acceptance, employees may be locked out or the site may lose security coverage.
Unplanned Site-Work or Contract Cost Overrun
If surveys identify unexpected cabling, power, door hardware, network or storage requirements after the Week 10 design approval, costs may exceed the EUR 220,000 budget or require scope reductions that weaken security or privacy controls.
Stakeholders
Executive Sponsor / Site Director
Owns the business case, authorizes funding, accepts residual risks and makes the final go-live decision.
Project Manager / Site Operations Lead
Coordinates the schedule, dependencies, operational constraints, acceptance activities and handover.
Works Council
Represents employee interests and negotiates binding provisions for monitoring, access records, retention and prohibited uses.
Data Protection Officer / Privacy Counsel
Leads the DPIA, confirms the legal basis, defines retention and access controls, prepares Article 13 information and evaluates any biometric processing.
IT and Information Security Lead
Defines network, identity, storage, logging, cybersecurity, integration and privileged-access requirements.
Facilities, Security and Health & Safety Team
Defines physical security requirements, validates camera and reader locations and protects emergency and logistics operations during installation.
HR and Learning & Development
Manages employee communications, instructions, administrator training and responses to workforce questions.
Procurement and Finance
Runs the tender, evaluates commercial terms, controls purchase orders and confirms affordability and contractual protections.
Selected Security Technology Vendor / System Integrator
Designs, supplies, installs, configures, tests and documents the technical solution and provides initial support.
Employees, Shift Supervisors and Operational Representatives
Validate shift-based access needs, usability, workforce communications and the effect on daily logistics processes.
Compliance
Complete and approve a GDPR Article 35 DPIA for the systematic video surveillance and access-control processing before implementation and go-live; document risks, safeguards, residual risk and approval evidence.
Define and document the GDPR Article 6 legal basis, specific security purposes, prohibited uses, data fields, access-log use, retention periods and deletion rules for video and access records.
Assess whether facial recognition, fingerprints, templates or other biometric functionality is proposed; prohibit it unless a separate GDPR Article 9 assessment, lawful condition and required safeguards are approved.
Prepare and deploy complete GDPR Article 13 information notices and visible surveillance signs before any recording or monitoring begins, including controller identity, purposes, legal basis, retention, rights and contact details.
Obtain the approved works agreement and complete employee consultation covering monitoring scope, permitted purposes, access to records, retention, employee rights, escalation and prohibited performance-monitoring uses.
Implement GDPR Article 32 technical and organizational measures, including MFA, least privilege, role-based access, network segmentation, encryption, audit logs, secure remote support, vulnerability management and tested retention/deletion controls; align controls with the internal information-security policy and ISO/IEC 27001 principles where applicable.
Maintain lawful site-operation controls for logistics areas, including emergency egress, fire and evacuation routes, safe installation, temporary access arrangements, visitor/contractor procedures and documented incident and data-subject request handling.
Milestones
- Week 1
Approved project charter, governance structure and 16-week critical-path plan with DPIA, works agreement and go-live gates identified.
Depends on: Sponsor appointment, core team availability and initial scope confirmation - Week 3
Approved site survey, process maps, initial privacy zoning plan and tender-ready requirements baseline.
Depends on: Approved project charter and access to the site, systems and operational representatives - Week 5
Approved GDPR Article 35 DPIA, documented legal basis and retention model, Article 13 information design, and recorded Article 9 biometric decision.
Depends on: Requirements baseline, monitoring purposes, data-flow details and privacy zoning plan - Week 7
Signed works agreement with no unresolved conditions preventing system installation or employee instruction.
Depends on: DPIA findings, proposed monitoring scope, retention rules and employee consultation - Week 8
Approved vendor award, commercial decision record and contract conditions incorporating the DPIA and works agreement.
Depends on: Tender-ready requirements, vendor submissions and sufficiently settled works-agreement conditions - Week 10
Approved detailed design, confirmed equipment delivery, installation runbook and printed Article 13 signage available for deployment.
Depends on: Vendor award, signed contract, approved privacy controls and site engineering data - Week 12
Installed and configured system, Article 13 signs in place at least three weeks before Week 16 go-live, and documented installation baseline completed.
Depends on: Approved detailed design, delivered equipment, site access and installation windows - Week 13
Signed technical, privacy and operational acceptance records; all Article 13 signs verified; employee and administrator instruction completed; go-live approval pack ready.
Depends on: Installed system, completed testing, approved procedures, signage and training materials - Week 14
System live for all approved users and zones, first-week operational checks completed, priority defects controlled and formal handover to site operations accepted.
Depends on: Go-live approval, completed acceptance, trained users and administrators, and operational support readiness
How this plan was created
This plan was created by PathHub AI from a single description: “Introduce an electronic access control system with video surveillance at the site of a logistics company with 300 employees: vendor selection, data protection impact assessment, works agreement, installation and instruction. Go-live in four months.” — without company context. With your departments, approval processes and compliance requirements it becomes much more precise.
Obligations with lead time: what many think of too late
These obligations are typically triggered by an access control rollout (example: Germany). PathHub AI schedules them with lead time, warns when the schedule is too tight and shows the rule with its criteria under “Rule & evidence”, which you tick off and back with evidence. Not legal advice.
Rule & evidence
Why: Monitoring strongly affects the privacy of employees and visitors.
Legal basis: GDPR Art. 35: systematic monitoring requires a prior DPIA; signs/information under Art. 13 before going live. Biometric data is specially protected (Art. 9).
- Legal basis for every processing of personal data (consent, contract, legal obligation, legitimate interest)
- Complete record of processing activities (Art. 30) for all processes
- Data Processing Agreements (DPA) with all sub-processors
- Data Protection Impact Assessment (DPIA) for high-risk processing
- Technical and organisational measures (TOM) documented
If breached: Fines up to €20 million or 4% of global annual revenue — whichever is higher. Plus civil damages claims by affected individuals.
Rule & evidence
Why: Additional national limits apply to employees and publicly accessible areas.
Legal basis: Sec. 4 BDSG governs video surveillance of publicly accessible areas, Sec. 26 the processing of employee data; covert or permanent performance monitoring is generally not permitted.
- Data protection officer appointed (20+ employees with regular data processing)
- Employee data protection: data minimisation + purpose limitation in HR
- Video surveillance with signage and stated purpose
- Works council involvement for HR data processing
If breached: Fines up to €50,000 for violations of BDSG §§41-43. GDPR fines (up to €20m / 4%) apply in parallel.
Rule & evidence
Why: Without agreement with the works council the technology must not be used.
Applies: only if a works council exists
Legal basis: Sec. 87(1) No. 6 BetrVG: cameras, tracking and access systems are typical technical monitoring systems.
- Enable works council election from 5 eligible employees upward
- Co-determination on working time, monitoring systems, IT rollouts (§87)
- Hearing before every dismissal (§102) — written with reasons
- Balance-of-interests and social plan on operational changes (§111)
If breached: Dismissals without works council hearing are void. Administrative fines up to €10,000 per violation. Criminal liability (§119) for obstructing the works council up to 1 year imprisonment.
Frequently asked questions
More project plan examples
Adapt this plan to your company
Open the plan in PathHub — no sign-up. Or describe your own initiative and get a complete plan in minutes.
Open plan →