A card access control system is an electronic system that controls who may pass through a door, turnstile or barrier, and when, using a credential issued to each person — usually an RFID card, sometimes a QR code. When a card is presented, the system checks the holder's permissions, releases or refuses the lock, and logs the time, date and door.
Set up well, the same card read can also feed time and attendance records and canteen meal counts.
This guide covers the building blocks, why keys and sign-in books stop working as a site grows, the questions to settle before you buy, and the data protection side — including what applies if you operate in Türkiye.
How does a card access control system work?
Five components work together at every entry point. The weakest one sets the reliability of the whole system.
| Component | What it does | What to check |
|---|---|---|
| Credential | Represents the person: RFID card, key fob, time-limited QR code or biometric template | How hard is it to clone? How quickly can it be revoked when lost? |
| Reader | Reads the card or QR code and passes the identity on | Compatibility with the card technology, suitability for outdoor use |
| Controller | Applies the rules and tells the lock to open or stay shut | Where the rules are stored, how it talks to the central system |
| Lock / turnstile / barrier | Provides the physical barrier | Behaviour in a fire or emergency, throughput at peak times |
| Software | Manages people, permissions, zones and reports | How readable the rules are, how reports reach HR and payroll |
The flow itself is simple: the card is presented, the identity reaches the controller, the controller checks whether that person may enter that zone at that time, a decision is made and the event is logged. The difference lies in how clearly the rules are written. The anti-passback rule that stops card sharing is part of the same rule set.
Why the card technology matters
Many sites still run 125 kHz proximity cards, which typically carry nothing more than a fixed number that is relatively easy to copy. 13.56 MHz smart cards support mutual authentication with the reader and give a far more secure foundation. For visitors and contractors, a QR code valid for a set period avoids the familiar problem of cards that never come back. We compare the two card types in detail in our 125 kHz vs 13.56 MHz guide.
Why keys, sign-in books and a guard stop being enough
As a site grows, keys and a visitor book run into three problems:
- Keys get copied and cannot be recalled. A key held by a former employee stays valid until the lock is changed. A card can be switched off centrally in one step.
- A book cannot tell you who is inside. During a fire drill — or a real evacuation — handwritten lists are rarely up to date.
- The rules are not written anywhere. "Only the warehouse team enters the warehouse during their shift" lives in a guard's memory; it cannot be audited or reported on.
Organisations are investing to close these gaps. A private market research firm forecasts that the global access control market will grow from USD 10.62 billion in 2025 to USD 15.80 billion by 2030 (MarketsandMarkets Access Control Market report). The European picture points the same way:
According to Eurostat, 29% of EU enterprises with 10 or more employees used Internet of Things devices in 2021, and 72% of those used them to secure their premises. (Eurostat — Use of Internet of Things in enterprises)
There is also a personal data angle. Access logs show who was where, and when — that is personal data. In Türkiye, the Personal Data Protection Authority (KVKK) received 12,512 complaints and reports in 2025 alone (KVKK 2025 Annual Report).
Types of card access control system
Systems are usually built at one of three scales:
- Standalone, single door. Reader and controller share one unit and the log stays on the device. Fine for a small office, but reporting and central management are limited.
- Networked, single site. Every door connects to central software; permissions are granted in one place and activity is monitored live. This is the norm in factories, hospitals and office buildings, and school campus access control follows the same pattern.
- Multi-site with central management. Each site keeps its own records while head office receives consolidated reports. A good fit for groups and chains; we cover the model in detail in our multi-site access control guide.
The type of entry point matters too: the right turnstile type for staff entrances, barrier and parking systems for vehicles, and for high-security rooms a combination of card and biometric verification such as fingerprint access.
Seven questions to settle before choosing a system
Settle these before requesting quotes:
- Which zones exist, and who needs to enter each one? List the gatehouse, production, warehouse, offices, server room and the roles that use them. Our examples of zone-based access in factories and data centre access control show how such a map is drawn.
- Are the rules written in language a manager can read? If permissions only make sense to the installer, explaining them to an auditor becomes hard.
- What happens when two rules conflict? When "production may enter the warehouse" meets "the warehouse is closed at weekends", you should be able to see which rule wins.
- How will visitors and contractors get in? Permanent card or QR code visitor access? Both should follow the same permission rules.
- Will attendance and the canteen need separate devices? If one person taps three different terminals a day, the data ends up in three different places. We explain how a time and attendance system works separately.
- What happens in an emergency? You should be able to lock every door in one action and pull a zone-by-zone list of who is on site right now — in practice, an emergency muster report.
- How long are logs kept, and who sees them? Retention, anonymisation and an audit trail need to be designed in from the start.
We look at how each of these choices affects the budget in our access control system cost guide.
Data protection: what to watch for
Access logs fall under data protection law wherever you operate. In Türkiye that is Law No. 6698 on the Protection of Personal Data, known as KVKK — broadly comparable in spirit to the GDPR. In practice, four principles matter most: logs are visible only to people with a legitimate need, a retention period is defined and expired records are destroyed or anonymised, changes to records are traceable, and employees are properly informed. Biometric data such as fingerprints or facial templates counts as a special category of personal data and needs extra care; we summarise the regulator's current position in our biometric attendance and data protection article. Handling this through data protection compliance consultancy while the system is being installed is far easier than retrofitting it later.
How we deliver card access projects at Digital Bridge
We do not sell a boxed package and walk away. A card access control project with us follows these steps:
- Needs analysis and site survey. We review zones, the number and type of entry points (turnstiles, barriers, door locks), cabling and network, on site or remotely.
- Permission map. Together we write down which role may enter which zone and when; this document becomes the draft rule set.
- Written proposal. Scope, phases and fees are set out clearly.
- Installation and commissioning. Because software and hardware come from the same team, responsibility for making readers, controllers and software work together stays in one place.
- Integration. When attendance data needs to reach HR or payroll, our system integration team takes it on.
- Support. We work remotely and on site across all 81 provinces of Türkiye, with technical support available 24/7.
SmartPass: door, attendance and canteen in a single card read
SmartPass, our own product, combines access control, time and attendance and canteen meal counting in one system. Here is what a typical morning looks like:
At 07:52 a production worker taps their card at the gatehouse turnstile. One read opens the turnstile, creates the attendance record and starts their timesheet according to the shift plan. At lunch, they tap the same card in the canteen and, if they are entitled to a meal that day, the meal is deducted. A supplier arriving the same morning uses a time-limited QR code instead of a permanent card — and that QR code is bound by exactly the same permission rules as an employee card.
What SmartPass brings:
- 13.56 MHz RFID cards and time-limited QR codes on the same terminal. Permanent cards for staff, single-use QR codes for visitors.
- Rules in plain language. For example, "The production team may enter the Warehouse zone during working hours". When two rules conflict, the system states clearly which one applies, and a rule simulator lets you see the effect.
- Zone hierarchy and live monitoring. Gatehouse, production, warehouse, offices and more. In an emergency, every door can be locked in one action and you get a zone-by-zone list of who is inside.
- No separate attendance device. Timesheets follow the shift plan and reports can be exported to payroll.
- Designed with data protection in mind. Card numbers are never stored in plain text; records past their retention period are anonymised; an audit trail keeps old and new values; the auditor role is read-only.
- Built for multiple sites. Each organisation runs on its own subdomain and database; a group can see consolidated reports while sites cannot see each other's records.
Next step
Put three things on a single page: how many entry points you have, who needs to go where, and how attendance is recorded today. Get in touch with that list and we will run the needs analysis with you and show how SmartPass would work with your own rules.