
In our previous article, we shared the benefits of mobile access control and compared using a smartphone to open doors with traditional access control methods. We also detailed the steps individuals and organizations can take to regain access when a smartphone is lost or stolen.
In this article, we'll focus on how access control providers securely deliver mobile access apps to smartphones, enabling secure access to company facilities while protecting the privacy of the owner's personal information.

Before we begin, let's recap a few key points from the previous article:
- Smartphones have become the preferred method of secure access control, replacing traditional keys and RFID credentials to give employees access to company buildings.
- Compared with traditional access control tools, mobile access control offers clear advantages, since it's easy to adapt and typically has lower management costs.
- Mobile access control systems allow employees to use a smartphone as an approved credential to enter physical and digital locations. Mobile phones use Near Field Communication (NFC) or Bluetooth Low Energy (BLE) to verify the owner's permission to use the access control system.
- If an employee's smartphone is lost or stolen, the affected employee can contact the company's system administrator to immediately revoke the employee's access control credentials, preventing unauthorized access and protecting company property.
- Companies are advised to implement two-step authentication to ensure that smartphones with mobile access privileges cannot be used by unauthorized individuals — for example, by requiring a personal identification number (PIN) before the mobile access app can be used.

■ Is There a Security Risk to Personal Information When Using Mobile Access Control?
Earlier we discussed what to do if your smartphone is lost or stolen. Now, let's discuss how companies like HID Global® provide a secure mobile access app for your phone.
Companies concerned about vulnerabilities in mobile access control systems are usually worried that if a smartphone is lost or stolen, the mobile access credential could be used by someone else. One important mitigation for this risk is an enterprise-wide policy that requires users to unlock the device and open the app before the credential can be used. For most devices, this means the user must use a PIN or biometrics to unlock the phone, greatly reducing the chance of unauthorized use.
If an even higher level of security is required, this type of access control enforcement can and should also apply to employees using their own devices (BYOD). It works hand in hand with company policy to provide a consistent experience and manage risk. Employees who bring their own phones into the workplace must follow the same protective rules.
To ensure a company's mobile access control system is better protected, the company can use relevant management policies to minimize unauthorized use of employees' phones as much as possible.We understand that employees may be reluctant to install a company app on their phone. This may be because they're worried about being monitored by the company and want to protect their own privacy. For example, some employees may ask why “location services” need to be enabled on the mobile app. They should understand that this is simply to make it easier to pick up the Bluetooth signal, in order to achieve the best phone performance.
It's worth noting that Apple offers a unique feature for its iPhone customers. If you own an iPhone, a feature lets you locate your phone if it's lost or stolen. Part of this feature is the ability to remotely wipe app data, which, once triggered, deletes the mobile access credential. This feature works even if the phone is powered off.
At all times, world-class access control providers go to great lengths to protect your company's access control system and your personal information.
Reliable providers of mobile access apps are extremely careful about protecting all the personal information stored on their platforms. Make sure the provider you choose has a publicly available privacy policy. These kinds of policies detail what limited information is collected, why, and how it is protected and anonymized.
You're advised to seek the protection of local information security policies and regulations. For example, in Europe, the General Data Protection Regulation (GDPR) is a powerful and important piece of legislation covering the personal privacy rights of all citizens. Mobile access control companies must commit to protecting the personal information they collect and maintaining transparent policies. They are obligated to proactively let customers know what data is and isn't collected. These companies can serve as a trusted resource for their business partners when developing mobile access control strategies and when issues arise.

■ What Are the Benefits of a Mobile Access Control System?
Ultimately, it is the phone user's responsibility to protect company access credentials and personal information on their smartphone. Once a smartphone is lost or stolen, it's the owner's responsibility to promptly notify the company's system administrator of the loss. The same holds true for mechanical keys and traditional access cards or fobs.
Administrators using these tools in their systems will prevent unauthorized access to company buildings and systems while protecting both personal and company data. Mobile access control providers must also do their part, ensuring that the workflows and policies of the mobile access control system can support customers and all of their mobile access users.
You can rely on a global access control provider to protect company information and your employees' personal data. They are your partner, helping you solve any access control challenge — a collaborative relationship that works for everyone.
#HIDGlobal #MobileAccessControl #DataPrivacy