Skip to content
WelcomeBob
Back to blog
ComplianceWelcomeBobMarch 18, 2026· 4 minAuto-translated

GDPR and your Door Phone: 3 Things Your Board Needs to Know in 2026

GDPR and your Door Phone: 3 Things Your Board Needs to Know in 2026 – WelcomeBob

Modern door phones do more than just make calls and open a door. They record video, store access logs, and in some cases, use facial recognition. This raises questions about personal data that your board should address, regardless of whether you are changing your system or already have one.

Here are three things you need to know.

1. Access Logs are Personal Data

Every time a resident uses a key fob, code, or app to open a door, it is typically recorded in a log. This log contains information about who opened, when, and which door. This is personal data in the GDPR sense, meaning that the association must have a legal basis for storing it, a clear policy for how long it is stored, and a process for deleting it when it is no longer necessary.

In practice, this means: ensure that your supplier can tell you exactly what data is stored, where it is stored, and for how long. Ask for a data processing agreement; it is legally required when an external supplier processes personal data on your behalf.

2. Video Cameras Require Special Attention

If your door phone has video, it records images of everyone who rings the bell, including people who do not live in the property. Datatilsynet has focused on video surveillance in housing associations, and the rules are clear: there must be a legitimate purpose (typically security), it must be proportionate, and residents must be informed.

In practice, this means: put up a sign at the entrance informing that video is being recorded. Ensure that recordings are automatically deleted after a short period, typically 30 days. And avoid board members having free access to review recordings without a legitimate reason.

3. Facial Recognition is High-Risk, and Most Do Not Need It

The EU's AI Regulation (AI Act) classifies biometric access control, including facial recognition, as a high-risk application. This requires impact assessments, human oversight, and documentation. For most housing associations, it is neither necessary nor proportionate.

The good news: most modern access systems, including WelcomeBob, do not use facial recognition at all. Access is via app, key fob, or code, and video is only used for communication (to see who is ringing). This is a much simpler and more GDPR-friendly model.

What Can You Do?

Start by asking your current or future supplier three questions:

  • What personal data does the system collect?
  • Where is the data stored, and who has access?
  • Is there a data processing agreement?

If you do not receive clear answers, you should consider whether the supplier is the right partner for your association.

GDPR compliance is not just a legal requirement; it is a matter of trust with your residents. They have the right to know what is recorded about them, and you are responsible for ensuring it.

We use cookies 🍪

We use cookies and similar technologies to improve your experience, measure traffic and show relevant content. You decide what to accept. Learn more