Regulatory compliance and data protection

How LabKey applies GDPR principles and the requirements of the NIS2 Directive in the design of the platform.

Privacy by design: only the necessary data, for the necessary time

LabKey is configured to collect exclusively the data functional to attesting presence and to access control, with no scope for further processing beyond these purposes and without requiring the data subject’s consent as a precondition for operation.

Personal data processed: first and last name (the only mandatory fields), email address and phone number (optional). The platform does not process biometric data or other special categories of data, and does not introduce any personal monitoring features beyond the mere attestation of presence at the installed device.

Each managed facility has a logically distinct database, consistent with the principles of data minimization and purpose limitation. All access credentials are masked and encrypted.

Privacy by design

Encryption of identifiers

The identification code of each NFC card is never exposed in plain text: the system generates an encrypted identifier starting from the tag’s physical UID. Simply consulting the data stored on the management panel side makes it impossible in any way to trace back to the corresponding physical card, structurally reducing the risk of cloning or improper association.

Multi-facility logical segregation

The architecture provides for a unique and permanent association between each access control device and the facility where it is installed. To reduce the margin for human error during configuration, the platform supports:

  • pre-configured access groups per facility, so that the operator assigns the user to an already-constrained group, without needing to act on individual access rights;
  • restriction of card enrollment permissions to administrative profiles only;
  • on request, logically separate management panels for each individual facility, with the list of NFC tags not shared between different facilities.

Retention and traceability

Log typeRetention periodMethod
Attendance logs (access events)90 daysAutomatic deletion
System and application logs6 monthsAutomatic rotation (log rotation)
Operator activity logsAccessible to authorized technical personnelRecords operator identity, data changed, date/time

Traceability logs cannot be modified, newly created, or deleted by operators: they are generated exclusively and automatically in response to the physical event of a badge read. Time accuracy is guaranteed by continuous synchronization via the NTP protocol, which cannot be altered by the operator.

It is also possible to automate the periodic export of logs to an external repository, with digital signature and timestamp applied, to give the logs enhanced evidentiary value.

A configurable alerting engine

The platform includes an alerting module capable of notifying, in real time — via email, instant messaging, or integration with third-party software — circumstances such as:

  • an access attempt by a user not authorized for that facility or time slot;
  • use of a badge not registered on the platform;
  • prolonged non-use of a badge, with the option of automatic deactivation as a precautionary measure;
  • duplicate access occurrences on the same badge within a short time interval.

Each alert is a technical data point requiring human evaluation before it produces any administrative consequences, consistent with the principle of proportionality.

Alignment with the NIS2 Directive

LabKey is developed and operated by LabKey taking into account the obligations arising from Directive (EU) 2022/2555 (“NIS2”) and the relevant national implementing legislation (Italian Legislative Decree No. 138 of 4 September 2024), applicable to LabKey in its capacity as a digital service provider.

  • Supply chain risk management (Art. 21(2)(d)): LabKey owns its own Autonomous System, registered with RIPE NCC, and directly manages the routing of traffic to its own systems, eliminating dependencies on third-party connectivity providers.
  • Risk management measures for system security (Art. 21(2)(c)): a documented Business Continuity Plan and Disaster Recovery Plan govern service recovery procedures in the event of critical incidents.
  • Strong authentication (Art. 21 and Art. 32 GDPR): two-factor authentication (2FA) is available for accessing the management panel, alongside “Operator” profiles with role-differentiated rights.

NIS2

Support for DPIAs and privacy roles

As a technology provider, LabKey supplies its customers with all the technical elements needed to carry out a Data Protection Impact Assessment (Art. 35 GDPR), including internal risk assessment documentation. LabKey is also available to take on the role of Data Processor under Art. 28 GDPR for activities carried out on behalf of the Data Controller.


To learn more about the infrastructure architecture, physical device security, and the certifications obtained, continue with Physical security, infrastructure, and certifications.