Restricting access to your systems and data to only those who truly need it is a requirement under the GDPR, regardless of the size of your company. We offer a policy for access and identity management policythat’s ready to be customized, covering both the assignment of permissions and user access control, system security, and password security.
What are access management and identity management?
Access management involves defining, assigning, and controlling the access rights granted to each user (employee, intern, executive, contractor, etc.) to your information systems and data.
It is often associated with identity management, which involves creating, modifying, and deleting accounts (usernames, profiles) as employees join, leave, or change positions. Together, identity management and access management form what cybersecurity professionals call IAM (Identity and Access Management).
It is based on a simple principle: a user should have access only to the data strictly necessary for performing their duties, whether that data is internal (e.g HR files, payroll) or external (e.g data on your clients, prospects, and partners).
For example, only members of the HR department, the accounting department, managers, and executive management can access a team’s salaries. Other employees in departments unrelated to payroll management (e.g marketing) do not have access to this information.
In practice: When an employee joins the company: Set up their access based on their authorization profile, using a unique and personal username—never a shared account used by multiple people. When an employee leaves (or changes positions): Immediately revoke access to tools, email accounts, and Drive storage, without waiting for the next scheduled review.
Why is access management a GDPR requirement GDPR
In accordance with Article 32 of GDPR, you must implement measures to ensure data confidentiality, which means restricting access to your systems to only those individuals authorized to process the data as part of their duties. In this regard, the CNIL (National Commission for Information Technology and Civil Liberties) defining authorization profiles tailored to each position, as part of a comprehensive information systems security policy.
The CNIL (National Commission for Information Technology and Civil Liberties) fact sheet CNIL (National Commission for Information Technology and Civil Liberties) access rights management specifies, in particular, that access rights should be reviewed regularly—at least once a year—to identify and delete unused accounts, and to promptly revoke temporary authorizations or accounts belonging to individuals who have left the organization.
Strict access control thus makes it possible to:
- Reduce the risk of personal data breaches and data leaks;
- Demonstrate your GDPR security and GDPR compliance in the event of an audit by the CNIL (National Commission for Information Technology and Civil Liberties)
- Ensure traceability in the event of an incident (who has access to what, and when);
- Strengthen your company's overall cybersecurity by reducing the number of vulnerable entry points to your systems.
What resources should you use to secure access to your systems and tools?
Beyond technical tools, access security also relies on internal resources: an up-to-date access rights registry, a formalized procedure for revoking access, and a password management policy shared with all your employees, in accordance with CNIL (National Commission for Information Technology and Civil Liberties) recommendations CNIL (National Commission for Information Technology and Civil Liberties) passwords. These resources and measures significantly reduce the risk of unauthorized access to your data.
Download your access management policy template for free
Why is access management a strategic issue for your company?
Poorly managed access control is not just a theoretical risk: it exposes your company to real-world consequences—legal, financial, and operational—regardless of its size.
An audit risk that isn't limited to large companies: In 2024, the CNIL (National Commission for Information Technology and Civil Liberties) 87 penalties, including 69 through the simplified procedure—a process specifically designed for cases that do not present particular difficulties, with fines capped at €20,000. Data security, including access rights management, is among the violations addressed under this framework. In other words, this is not an issue limited to large companies: inadequate access management can be found in any organization.
An increased risk due to the proliferation of tools and remote work. The cloud, collaboration tools, remote access: the more entry points a company creates to its systems, the greater its exposure to human error and intrusion attempts.
A challenge in internal coordination. Access management typically involves several people (executive, IT administrator, DPO), who must share a common understanding of current access permissions. Without a centralized registry, it becomes difficult to know who has access to what, which delays the detection of anomalies and complicates the response in the event of an incident.
A matter of trust with your clients partners. Demonstrating structured access management is one of the concrete elements expected during a compliance audit or certification process (e.g ISO 27701), and it reassures your clients how their data is protected within your organization.
Dipeeo Advice
Your access management policy should be aligned with your IT policy, which sets out the rules for using digital tools for all your employees; the two documents complement each other without one replacing the other.
FAQ: Access Management Policy
Who is responsible for access management in a company?
Accountability generally shared among management, the IT department, and the DPO, who ensures compliance and controls access to the company's systems.
What is the recommended frequency for reviewing security clearances?
There is no legally mandated frequency: it must be tailored to the sensitivity of the data and the risks identified by your DPO (quarterly, semiannual, or annual, as appropriate).
What are the risks for a company if it mismanages access?
Poor access management increases the risk of a personal data breach, which may result in a notification to the CNIL (National Commission for Information Technology and Civil Liberties), notification of the individuals concerned, and a penalty in the event of a serious violation of GDPR.
Does access management apply only to computer data?
No. It applies equally to physical access (premises, paper archives) and access to digital data (information systems, file-sharing tools, email accounts, clients databases).
What is the difference between a company's access to internal and external resources?
Access to internal resources refers to your company’s own tools and data (servers, intranet, HR files), while access to external resources refers to data belonging to your clients, prospects, or partners; both fall under the same access management framework.