
Choosing an access badge to secure professional premises is not just about buying readers and distributing cards. The communication protocol between the badge and the reader, the legal obligations related to GDPR, and the system’s ability to evolve determine the actual robustness of the device. Comparing these technical parameters before any purchase avoids heavy migration costs in the medium term.
OSDP Protocol and AES Encryption: the Technical Foundation of a Reliable Access Badge
The majority of systems installed in recent years still rely on the Wiegand protocol, an unencrypted link between the badge reader and the controller. Data is transmitted in clear text, making the system vulnerable to interception or badge cloning.
New installations are moving towards the OSDP (Open Supervised Device Protocol), which is encrypted and supervised. This protocol is now considered the main security gain in a modernization project. Specifically, a solid specification outlines three elements: 13.56 MHz badge, AES encryption with diversified keys, and OSDP communication between the reader and the controller.
The difference between these two approaches can be measured by specific criteria. The table below summarizes the discrepancies.
| Criterion | Wiegand (old standard) | OSDP (recommended standard) |
|---|---|---|
| Data encryption | None (clear transmission) | AES 128 bits, diversified keys |
| Reader supervision | No (fault detection impossible) | Yes (alert in case of tampering or sabotage) |
| Direction of communication | Unidirectional (reader to controller) | Bidirectional (remote reader updates) |
| Badge cloning risk | High (unprotected 125 kHz frequency) | Low (mutual authentication badge/reader) |
| Scalability | Complete rewiring necessary | Compatible with existing RS-485 cabling |
For any company wishing to implement a secure access badge, requiring the OSDP protocol in the specifications is the first structuring decision. Overlooking this point means installing a system that is already obsolete at the time of its commissioning.

GDPR Obligations and Consultation with the CSE Before Access Control Deployment
A badge system records each passage: identity of the bearer, time, access point. These logs constitute personal data within the meaning of GDPR. Three obligations must be met before commissioning, and non-compliance exposes one to sanctions from the CNIL.
- Prior consultation with the CSE: any device that can indirectly control employees’ activities must be submitted to the social and economic committee. The minutes of this consultation serve as proof of compliance in case of an audit.
- Individual and collective information for employees: each employee receives a notice specifying the purposes of the processing, the categories of data collected, the retention period of access logs, and the rights they have (access, rectification, opposition).
- Limitation of the retention period for logs: access logs cannot be stored indefinitely. The CNIL recommends limiting this retention to a few months, unless specific sectoral obligations apply.
A common mistake is to treat these formalities as a simple checkbox after installation. In reality, the consultation with the CSE should occur before ordering the equipment, as an unfavorable opinion can change the project’s scope (covered areas, data collected, traceability hours).
Processing Register and Legal Basis
Access control by badge is part of the company’s processing register. The most commonly retained legal basis is the legitimate interest of the employer to protect its premises and assets. However, the CNIL specifies that this legal basis does not allow the use of badge data to monitor individual working hours, unless a separate legal basis justifies it.
Zone Segmentation and Access Rights Management by Profile
Distributing the same level of access to all employees negates the system’s purpose. Segmentation is based on a simple principle: each badge only opens the doors strictly necessary for its holder’s function.
A typical tertiary site is divided into three levels. Common areas (lobby, cafeteria, restrooms) remain accessible to all active badges. Work areas (offices, meeting rooms) are restricted to the relevant teams. Sensitive areas (servers, archives, management) are accessible only to a limited number of specifically identified individuals.
This mapping is constructed before the physical installation of the readers. Placing a reader on a door without having defined the profile of authorized users generates cascading modification requests, with a significant recabling cost.
Managing the Lifecycle of a Badge in the Company
A badge is not a static object. Its lifecycle includes several events that require an immediate response from the system:
- Arrival of an employee or contractor: creation of the badge with rights corresponding to the profile validated by the area manager.
- Internal job change: updating rights in the management software, removing access to the old area, adding new ones.
- Loss or theft of the badge: immediate deactivation via the central software, even before issuing a replacement badge.
- Permanent departure: deletion of the badge and purging of associated rights within a short period, ideally on the same day.
The speed of deactivation of a lost badge or an employee who has left is the real test of the system’s maturity. A delay of several days between reporting and deactivation creates a window of exposure that encryption alone cannot fill.

NFC Mobile Badge and Dematerialized Credentials: What Changes for Companies
The alternative to the physical badge is progressing. Mobile credentials, stored on smartphones via NFC, allow employees to badge with their phones. This approach eliminates the cost of card production and reduces incidents related to lost badges.
However, the mobile badge introduces a dependency on the employee’s personal phone. In case of a dead battery or forgotten phone, access to the site is blocked without a fallback solution if no physical backup badge is provided. The coexistence of both formats (physical badge and mobile credential) remains the most realistic configuration for sites where continuity of access is non-negotiable.
The choice of protocol, compliance with social and GDPR obligations, granularity of rights by area, and rigorous management of the badge lifecycle form an inseparable whole. An access control system is only as strong as the weakest link in this chain, whether technical, organizational, or legal.