Regulations for Site Access Control in the UK Construction Industry

Site access control in the UK construction industry is mainly governed by the Construction (Design and Management) Regulations 2015. Regulation 13 requires the principal contractor to provide a suitable site induction and take the necessary steps to prevent unauthorised access, and Regulation 15 stops contractors starting work until reasonable steps are in place. Any access control system must also keep emergency exits usable and handle personal data in line with UK GDPR.

As a UK site security company, we install access control systems on construction sites nationwide, and this guide covers the rules every principal contractor needs to follow. If you are new to the technology, start with our guide on how an access control system works.

UK Site Access Control Regulations at a Glance

Regulation

What it requires

How access control helps

CDM 2015, Regulation 13

Principal contractor must provide a site induction and prevent unauthorised access

Only inducted, authorised people are given credentials

CDM 2015, Regulation 15

Contractors must not start work until reasonable steps prevent unauthorised access

Controlled gates and turnstiles in place from mobilisation

CDM 2015, Regulations 30 to 32

Emergency procedures, clear emergency routes and exits, fire detection

Fail-safe release and live headcounts for roll call

UK GDPR and Data Protection Act 2018

Lawful, secure and proportionate use of personal data

Controlled data retention, access rights and audit logs

Immigration, Asylum and Nationality Act 2006

Employers must check workers have the right to work in the UK

Credentials issued only after checks are recorded

CDM 2015: The Main Law Behind Construction Site Access

CDM 2015 applies to almost every construction project in Great Britain and is enforced by the Health and Safety Executive (HSE), whose guidance on protecting the public explains how site boundaries and entry points should reflect the level of risk. It does not name a specific technology, so a padlocked gate is not automatically compliant and a turnstile is not automatically required. What the law expects is control that matches the level of risk on the site.

Principal Contractor Duties Under Regulation 13

Under Regulation 13 of CDM 2015, the principal contractor must ensure that a suitable site induction is provided, that the necessary steps are taken to prevent access by unauthorised persons, and that welfare facilities meeting Schedule 2 are in place throughout the construction phase.

In practice, this means you need to know who is on site, confirm they have been inducted and stop anyone else getting in. Access control systems that link credentials to induction records turn that duty into something you can prove.

Contractor Duties Under Regulation 15

Every contractor, not just the principal contractor, must not begin work unless reasonable steps have been taken to prevent unauthorised access. On multi-contractor sites, this duty sits alongside the principal contractor controlling the main entrance.

What Counts as Reasonable Steps

HSE takes a risk-based view. A small residential job in a quiet area may need a lockable gate and a sign-in process. A large urban site with plant, deep excavations and public footfall will usually need controlled entry points, visitor management and monitoring. The key is that controls are maintained and reviewed as the site changes, not set once at mobilisation.

Emergency Exits and Fire Evacuation Rules

Regulations 30 to 32 of CDM 2015 cover emergency procedures, emergency routes and exits, and fire detection and fire-fighting. Access control must never trap people on site. That means:

  • Turnstiles and gates must allow safe exit during an emergency, either through fail-safe release or dedicated emergency egress gates.
  • Locking devices should be linked to the fire alarm so escape routes open automatically when an alarm is triggered.
  • Emergency routes must stay clear of access control hardware, queues and barriers.

A good access control system also helps with evacuation by providing a live list of who is on site for the fire roll call.

UK GDPR and Data Protection Rules for Access Control Systems

Every card swipe, PIN entry and face scan creates personal data. Under UK GDPR and the Data Protection Act 2018, the site operator must have a lawful basis for collecting it, tell workers how it is used, keep it secure and delete it when it is no longer needed.

Cards, Fobs and PIN Codes

Standard credentials are personal data but not special category data. Keep retention periods clear, restrict who can view access logs and remove credentials when a worker leaves the project.

Biometric Access Control

Fingerprint and facial recognition create special category biometric data. ICO guidance on biometric recognition says explicit consent is likely to be the most appropriate condition in most cases, and a data protection impact assessment (DPIA) will usually be needed before the system goes live.

Because consent from workers is hard to prove as freely given, the ICO recommends offering an alternative, such as a PIN or card, that is no less favourable. On construction sites, this means biometric turnstiles should always have a non-biometric option.

CCTV Linked to Access Events

Linking access events to CCTV footage strengthens security and evidence, but the combined data must also meet UK GDPR. Display clear signage and document why the recording is necessary.

Right to Work and Competency Checks

Under the Immigration, Asylum and Nationality Act 2006, employers face civil penalties for employing people who do not have the right to work in the UK. Access control does not replace these checks, but issuing credentials only after checks are recorded closes the gap where an unchecked worker walks through the gate.

Competency cards such as CSCS are not a legal requirement in themselves. However, most major contractors require them, and CDM 2015 does require workers to have the right skills, knowledge and training. Linking card status to site access makes this easier to enforce.

Standards and Good Practice for Access Control in the UK

Beyond the law, these sources shape how access control in the UK is designed and installed:

  • BS EN 60839-11-1 sets system and component requirements for electronic access control systems.
  • HSE guidance on protecting the public sets out how boundaries and entry points should match the surrounding area.
  • The principal contractor’s construction phase plan should record how site access is controlled, reviewed and updated.

Site Access Control Compliance Checklist

  • Every worker and visitor is inducted before receiving a credential.
  • Entry points are controlled, and no unmanned gaps are left open.
  • Turnstiles and locks release safely when the fire alarm activates.
  • A live headcount is available for fire roll call.
  • A DPIA is completed for any biometric or combined CCTV system.
  • A non-biometric alternative is offered to workers.
  • Credentials are revoked the day a subcontractor finishes.
  • Access logs are retained for a defined period and stored securely.
  • Access arrangements are reviewed at each new phase of the build.

How PAP Ltd Helps Construction Sites Stay Compliant

Platinum Asset Protection designs, installs and manages access control for construction sites and commercial premises nationwide from our headquarters in Morley, Leeds.

For construction projects, we provide:

  • Construction site turnstile hire, with full height and waist height turnstiles installed at mobilisation and removed at handover.
  • Time-limited contractor credentials linked to induction status, which are revoked automatically when a contract ends.
  • Cloud-managed access control with remote permissions, multi-site control and a full audit trail.
  • Integration with fire alarms, CCTV and remote monitoring from our in-house control room.
  • A free site survey to review entry points and risks before any system is recommended.

Choosing Access Control Companies in the UK

When comparing access control companies in the UK for a construction project, check that they:

  • Understand CDM 2015 and site induction workflows, not just office door entry.
  • Offer hire options for temporary projects.
  • Can integrate access control with fire alarms and CCTV.
  • Build UK GDPR requirements, including DPIAs for biometrics, into the design.
  • Install using their own engineers and provide ongoing support

Frequently Asked Questions

No specific system is required by law. However, CDM 2015 requires the necessary steps to prevent unauthorised access, and on most commercial sites controlled entry is the practical way to meet that duty.

The principal contractor is responsible for preventing unauthorised access and providing site inductions. Every contractor must also make sure reasonable steps are in place before starting work.

Yes, but you will usually need a DPIA, explicit consent and a non-biometric alternative such as a card or PIN, in line with ICO guidance.

Emergency routes and exits must stay usable under CDM 2015. Linking turnstiles and locks to the fire alarm, or providing emergency egress gates, is the standard way to achieve this.

UK GDPR does not set a fixed period. Keep records only as long as needed for security, safety and contractual purposes, and set that period in your data protection policy.

Share:

More Posts

Send Us A Message

Protect Your Business with Trusted Security Solutions

Whether you need CCTV, manned guarding, mobile patrols, access control, or alarm response, our experienced team is here to help. Get expert advice and a free, no-obligation quote tailored to your security requirements.