
Site access control in the UK construction industry is mainly governed by the Construction (Design and Management) Regulations 2015. Regulation 13 requires the principal contractor to provide a suitable site induction and take the necessary steps to prevent unauthorised access, and Regulation 15 stops contractors starting work until reasonable steps are in place. Any access control system must also keep emergency exits usable and handle personal data in line with UK GDPR.
As a UK site security company, we install access control systems on construction sites nationwide, and this guide covers the rules every principal contractor needs to follow. If you are new to the technology, start with our guide on how an access control system works.
Regulation | What it requires | How access control helps |
|---|---|---|
CDM 2015, Regulation 13 | Principal contractor must provide a site induction and prevent unauthorised access | Only inducted, authorised people are given credentials |
CDM 2015, Regulation 15 | Contractors must not start work until reasonable steps prevent unauthorised access | Controlled gates and turnstiles in place from mobilisation |
CDM 2015, Regulations 30 to 32 | Emergency procedures, clear emergency routes and exits, fire detection | Fail-safe release and live headcounts for roll call |
UK GDPR and Data Protection Act 2018 | Lawful, secure and proportionate use of personal data | Controlled data retention, access rights and audit logs |
Immigration, Asylum and Nationality Act 2006 | Employers must check workers have the right to work in the UK | Credentials issued only after checks are recorded |
CDM 2015 applies to almost every construction project in Great Britain and is enforced by the Health and Safety Executive (HSE), whose guidance on protecting the public explains how site boundaries and entry points should reflect the level of risk. It does not name a specific technology, so a padlocked gate is not automatically compliant and a turnstile is not automatically required. What the law expects is control that matches the level of risk on the site.
Under Regulation 13 of CDM 2015, the principal contractor must ensure that a suitable site induction is provided, that the necessary steps are taken to prevent access by unauthorised persons, and that welfare facilities meeting Schedule 2 are in place throughout the construction phase.
In practice, this means you need to know who is on site, confirm they have been inducted and stop anyone else getting in. Access control systems that link credentials to induction records turn that duty into something you can prove.
Every contractor, not just the principal contractor, must not begin work unless reasonable steps have been taken to prevent unauthorised access. On multi-contractor sites, this duty sits alongside the principal contractor controlling the main entrance.
HSE takes a risk-based view. A small residential job in a quiet area may need a lockable gate and a sign-in process. A large urban site with plant, deep excavations and public footfall will usually need controlled entry points, visitor management and monitoring. The key is that controls are maintained and reviewed as the site changes, not set once at mobilisation.
Regulations 30 to 32 of CDM 2015 cover emergency procedures, emergency routes and exits, and fire detection and fire-fighting. Access control must never trap people on site. That means:
A good access control system also helps with evacuation by providing a live list of who is on site for the fire roll call.
Every card swipe, PIN entry and face scan creates personal data. Under UK GDPR and the Data Protection Act 2018, the site operator must have a lawful basis for collecting it, tell workers how it is used, keep it secure and delete it when it is no longer needed.
Standard credentials are personal data but not special category data. Keep retention periods clear, restrict who can view access logs and remove credentials when a worker leaves the project.
Fingerprint and facial recognition create special category biometric data. ICO guidance on biometric recognition says explicit consent is likely to be the most appropriate condition in most cases, and a data protection impact assessment (DPIA) will usually be needed before the system goes live.
Because consent from workers is hard to prove as freely given, the ICO recommends offering an alternative, such as a PIN or card, that is no less favourable. On construction sites, this means biometric turnstiles should always have a non-biometric option.
Linking access events to CCTV footage strengthens security and evidence, but the combined data must also meet UK GDPR. Display clear signage and document why the recording is necessary.
Under the Immigration, Asylum and Nationality Act 2006, employers face civil penalties for employing people who do not have the right to work in the UK. Access control does not replace these checks, but issuing credentials only after checks are recorded closes the gap where an unchecked worker walks through the gate.
Competency cards such as CSCS are not a legal requirement in themselves. However, most major contractors require them, and CDM 2015 does require workers to have the right skills, knowledge and training. Linking card status to site access makes this easier to enforce.
Beyond the law, these sources shape how access control in the UK is designed and installed:
Platinum Asset Protection designs, installs and manages access control for construction sites and commercial premises nationwide from our headquarters in Morley, Leeds.
For construction projects, we provide:
When comparing access control companies in the UK for a construction project, check that they:
Enjoyed this article?
★ Add Platinum Asset Protection as a Preferred SourceNo specific system is required by law. However, CDM 2015 requires the necessary steps to prevent unauthorised access, and on most commercial sites controlled entry is the practical way to meet that duty.
The principal contractor is responsible for preventing unauthorised access and providing site inductions. Every contractor must also make sure reasonable steps are in place before starting work.
Yes, but you will usually need a DPIA, explicit consent and a non-biometric alternative such as a card or PIN, in line with ICO guidance.
Emergency routes and exits must stay usable under CDM 2015. Linking turnstiles and locks to the fire alarm, or providing emergency egress gates, is the standard way to achieve this.
UK GDPR does not set a fixed period. Keep records only as long as needed for security, safety and contractual purposes, and set that period in your data protection policy.
Whether you need CCTV, manned guarding, mobile patrols, access control, or alarm response, our experienced team is here to help. Get expert advice and a free, no-obligation quote tailored to your security requirements.
We use cookies to improve your experience, analyse website traffic, and store preferences. You can accept or manage cookies anytime through your browser settings.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
These cookies are needed for adding comments on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
Clarity is a web analytics service that tracks and reports website traffic.
Service URL: clarity.microsoft.com (opens in a new window)