Phone: 0 (552) 380 25 25  |  Weekdays 10:00–18:00 · Technical support 24/7

🇹🇷 TR

Digital Bridge Blog

Access Control & Attendance

Mobile Access Control with NFC, Bluetooth and QR: How to Let Staff Open Doors with Their Phones

How does mobile access control work? We compare NFC, Bluetooth and QR credentials, explain iPhone limits and Turkish data rules, and plan a safe rollout.

9 min read  · Digital Bridge Engineering Team
Mobile Access Control with NFC, Bluetooth and QR: How to Let Staff Open Doors with Their Phones

Mobile access control is an access control setup in which an employee's or visitor's smartphone replaces the access card for opening doors, turnstiles and barriers. The phone is tapped on the reader via NFC, brought close over Bluetooth (BLE), or shows a short-lived QR code. Whichever method you choose, the central access system, not the phone, decides who gets in.

Why everyone is asking about phone-based entry

Every organisation that runs card access knows the small daily frictions: the employee who left their card at home, the contractor waiting for a replacement, the visitor who walks off with a badge. Printing, issuing and collecting cards is an invisible workload. The phone, meanwhile, is the one device people almost never leave behind.

Phone ownership is not a barrier in Türkiye either. According to BTK's Quarterly Market Data Report for Q1 2026, the Turkish telecoms regulator counted 85.96 million real mobile users excluding M2M at the end of March 2026, a penetration rate of about 100.3%. The market is moving the same way: MarketsandMarkets' access control forecast expects the global access control market to grow from USD 10.62 billion in 2025 to USD 15.80 billion by 2030, driven by IoT-based security and cloud platforms.

So "can we open the doors with our phones?" now comes up in nearly every access project. It is a fair question, but the answer is not a single technology. Mobile access touches the reader hardware, the phone operating systems, network connectivity and data protection rules all at once. If you have not yet pinned down the building blocks of card access, start with our card access control system guide; mobile credentials sit on top of that structure.

The cost of getting mobile access wrong

The first cost is technical, and it comes from assuming the phone behaves the same everywhere. The iPhone is the clearest example. Apple has opened NFC card emulation to third-party apps, including corporate badges, through its "NFC & SE Platform". However, the list of eligible territories on Apple's NFC & SE Platform developer page does not currently include Türkiye, so an NFC scenario that works on Android may not work for the managers carrying iPhones.

The second cost is legal. Türkiye's data protection law, KVKK, is broadly modelled on EU data protection law, and its Board has listed examples of methods employers can use for attendance instead of biometrics:

In its public announcement on principle decision 2026/921, the Turkish Personal Data Protection Authority lists alternatives such as "encrypted card or PIN-based systems", traditional signed paper timesheets, "RFID/NFC ID cards" and manual entry under supervision. (KVKK announcement on decision 2026/921)

This suggests that, for attendance, card credentials are seen as a less intrusive option than fingerprints. Phone-based methods that process no biometric data can be assessed in the same way; we cover the detail in biometric attendance and data protection. Phones still generate personal data, though. A log of which device was used at which door, and when, falls under KVKK and must be limited to its purpose and kept proportionate.

The third cost is operational and usually surfaces after go-live. Mobile access without a defined fallback means queues at the turnstile at shift change: flat batteries, apps that will not open and permissions wiped by an update all land on the security desk. Swapping card handouts for "my phone won't read" calls is a common disappointment with mobile access.

Mobile access control methods compared: NFC, BLE, QR and remote unlock

There are four ways to build phone-based entry. They differ in how the phone talks to the reader and how much they depend on the network.

MethodHow it worksStrengthWatch out for
NFC (phone as card)Phone is tapped on the reader; an app emulates the card credentialClosest to the card habit, fastiPhone regional and contractual limits; reader must support it
Bluetooth (BLE)App sends the credential when the phone approaches the readerEntry without taking the phone outPoorly tuned range can open doors unintentionally; battery and permission settings
Time-limited QRA short-lived QR on screen is read by the terminal's cameraWorks on any phone, no app requiredNeeds short expiry and single-use rules against screenshot sharing
Remote unlockA button in the app opens the door via the serverAn authorised person can open the door from elsewhere (e.g. for a delivery or a waiting guest)Needs internet; does not prove the person is at the door

The practical conclusion is to choose by user group rather than lock into one method. Staff can keep the card as the primary credential, with the phone as a second one. For visitors and contractors, a time-limited QR is usually the lowest-friction route, as we show in our QR code visitor access guide. How plates and driver credentials work together at the vehicle gate is covered in our vehicle access control system guide.

For NFC, the reader's frequency and card type matter too. Phone NFC runs at 13.56 MHz, so older 125 kHz readers will not see the phone at all. The difference is explained in 125 kHz vs 13.56 MHz cards. The cloning weakness of older cards is covered in access card cloning risk.

Seven steps to a safe mobile access rollout

  1. Separate your user groups. Decide which credential applies to permanent staff, shift workers, contractors, visitors and managers. Not every phone is company-owned, and using a personal phone should be voluntary and needs a clear privacy notice under KVKK. How this split works where guests and staff share one building is described in hotel staff access control.
  2. Audit your readers. List each reader's frequency, whether it reads QR codes and whether it supports Bluetooth. The number of readers to replace is often one of the biggest budget lines.
  3. Define the fallback first. Nobody should be stuck at the door because of a flat battery, a lost phone or an app that will not start. A card, a PIN or a temporary QR issued by security should be a written fallback.
  4. Test offline behaviour. Know which methods keep working when the network drops; this is why rule sets should be held on the terminal. See access control offline mode for the detail.
  5. Make sharing hard. QR codes should be short-lived and single-use, and the same credential should not be able to enter twice in a row. That rule is called anti-passback.
  6. Extend account security to the door. The phone app is an extension of the corporate account; a weak screen lock or password means a weak door. We cover the basics in business password security.
  7. Start with a small pilot. Run a two- to three-week trial on one door with one team, and measure read speed, failed entries and user complaints before rolling out further.

If you are building the phone app yourselves, there is also a platform decision: separate Android and iOS apps, or one shared codebase? We compare the options in native vs cross-platform apps.

How we deliver mobile access at Digital Bridge

We treat mobile access as part of the access system rather than an app install. Because software and hardware are built by the same team, you have one point of contact from reader to dashboard.

  • Discovery and requirements. We walk every door, turnstile and barrier, record which credentials the existing readers support and map your user groups. If your current card access control hardware can be kept, we say so in writing; the technical feasibility assessment for hardware is free of charge.
  • Choosing the method. Together we settle which credential each group uses, the fallback route and offline behaviour, then prepare a written proposal covering scope, phases and cost.
  • Where an app is needed. If you need a bespoke mobile credential or remote-unlock app, our mobile app development team designs it around the access system's permission rules.
  • Pilot and integration. We pilot on a single door, then connect HR, visitor and identity systems through system integrations. For retention periods and privacy notices we support you through data protection compliance consultancy.

SmartPass: cards and phones under the same rules

Our own product, SmartPass, reads 13.56 MHz RFID cards and time-limited QR codes on the same terminal. A typical setup: staff use a permanent card, while a visitor or day contractor enters with a single-use QR sent to their phone. Both follow the same permission rules, so a visitor's QR is valid only for the zone and time window defined for them.

Rules are written in plain language, such as "The production team may enter the Warehouse zone during working hours." When two rules conflict, SmartPass states clearly which one wins, and a rule simulator lets you test a change before it goes live. In an emergency every door can be locked in a single action, with a zone-by-zone list of who is inside at that moment.

SmartPass never stores card numbers in plain text, only an irreversible hash. Records past their retention period are anonymised, and every change is written to an audit trail with old and new values. The same card read that opens the door also creates the attendance record, so no separate time clock is needed. For the criteria to use when picking attendance software, see choosing time and attendance software.

On the phone side, SmartPass currently offers the time-limited QR. If your organisation requires phones to be read like NFC cards, or Bluetooth entry, we assess that as a separate item during discovery and share a written feasibility view.

Next step

Before you get in touch, note three things: the number of doors and readers, your user groups, and the rough Android/iPhone split among your staff. Then reach us through our contact page and we will check together whether your existing readers can work with phones. For more guides on card access, attendance and visitor management, visit our Access Control & Attendance hub.

Let us look at your case

Tell us about your process; after a needs analysis we send a written proposal with scope, phases and cost.

Request a Quote +90 552 380 25 25
Questions we hear most often

Frequently Asked Questions

Is mobile access control secure?

Set up properly, it need not be any weaker than a card; if the app requires the phone to be unlocked, that adds a barrier a card does not have. Security depends less on the phone itself than on rules being enforced centrally, QR codes being short-lived and single-use, and a lost device's permissions being revoked immediately. Remote unlock should be used sparingly, as it does not prove the person is at the door.

Can an iPhone open doors over NFC in Türkiye?

Apple has opened NFC corporate badges to third-party apps in selected countries, subject to an agreement with Apple and a security review, and Türkiye is not currently on that list. For iPhone users in Türkiye, time-limited QR codes or Bluetooth-based methods therefore give more predictable results. Check the Android/iPhone split among your users before deciding on a method.

What happens if an employee's phone battery dies?

Every mobile access project needs a written fallback. The most common answer is for staff to keep carrying their card as a backup credential, or for security to issue a short-lived QR code on the spot. What matters is that the fallback follows the same permission rules and that every use is logged, so the exception does not become a loophole.

Will my existing card readers work with phones?

It depends on the reader. Phone NFC operates at 13.56 MHz, so 125 kHz readers cannot read a phone. QR codes need a camera-equipped or QR-capable terminal, and Bluetooth needs a BLE module. During discovery each reader's model and supported credentials are listed, and the number of readers to replace follows directly from that list.

Can we require staff to install an app on their personal phones?

Offering it as an option is healthier than making it compulsory. Using a personal phone should be left to the employee's choice and backed by a clear privacy notice under KVKK, and a card should always remain valid for anyone who prefers not to use their phone. The app should process only the data needed for entry and avoid collecting extras such as location.

Have a different question? Ask Us

Talk to an Engineer

Tell us what you need to solve. We'll come back with a written proposal.