§ Guide

Door Access Swipe Cards And Building Logs

This guide, 'Door Access, Swipe Cards and Building Logs', addresses the use of physical presence evidence derived from access-control systems.

Ref · E-D · 2026 · §LIBClass · ConfidentialJuris · England & WalesStatus · Active

Guide · 17 pages · 21 min read · Published 2026-08-30

This guide, 'Door Access, Swipe Cards and Building Logs', addresses the use of physical presence evidence derived from access-control systems. It details what badge events prove and do not prove, covering the access-control estate, what logs record, and how to read them. The guide discusses attribution - card, credential, and human - and the collection and retention of logs. It explains how to join presence to the digital timeline and identifies where else evidence lives within the source architecture. The content includes worked examples, common mistakes, technical limitations, and questions to ask. It is essential for UK lawyers, litigators, in-house counsel, and investigators dealing with e-discovery, providing insights into the building's diary and its role in constructing a reviewed chronology.

Read this guide on your phone, browse guides by topic or go back to the full PDF library.

§ Credit and source

Published by Computer Forensics Lab on 2026-08-30. Original material of the practice, free to read, cite and download. The authority behind this subject is ICO guide to the UK GDPR, which you should read alongside this guide. See every guide's author and source.

§ Full text of Door Access Swipe Cards And Building Logs

Download the PDF

Prefer a PDF that matches this page exactly? Download the current text as a PDF, generated from the wording shown here, including any later corrections.

Page 1

ACCESS CONTROL EVIDENCE · A GUIDE FOR UK LAWYERS Door Access, Swipe Cards and Building Logs Physical Presence Evidence and What a Badge Event Does and Does Not Prove COMPUTER FORENSICS LAB

§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM TIMELINE CONSTRUCTION CPR PART 35 EXPERT REPORT S FULL CHAIN-OF-CUSTODY DOCUMENTATION

§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: the building keeps a diary 03 The access-control estate: readers, controllers and platforms 04 What the logs record and how to read them 05 Attribution: card, credential and human 06 Collection and retention: getting the logs before they go 07 Joining presence to the digital timeline 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist

§ 01 · ORIENTATION Executive summary THE HEADLINE POINT: BADGELOGSPLACEACREDENTIALPRECISELY: MAKINGTHEM PLACEAPERSONISTHEANALYTICALWORK

§ 02 · FIRST PRINCIPLES The problem in plain English: the building keeps a diary

§ 03 · THEESTATE The access-control estate: readers, controllers and platforms

Page 2

§ 04 · THERECORD What the logs record and how to read them

§ 05 · WHOSE H AND Attribution: card, credential and human

§ 06 · BEFOREITGOES Collection and retention: getting the logs before they go

§ 07 · THEJOIN Joining presence to the digital timeline

§ 08 · THEWIDERMAP Source architecture: where else the evidence lives EVIDENCE TURNSTILES / CONTROLLERS / CCTV DIGITAL TIME & DELETED / PLATFORM LAYER PERIPHERY ATTENDANCE RECOVERABLE LIFTS / VISITORS

§ 09 · IN THE WILD Worked examples EXAMPLE1 · THEOVERTIMETHATBADGEDITSELFOUT EXAMPLE2 · THESERVERROOMAT02: 12, AND WHOSE H AND EXAMPLE3 · THEABSENCETHATPROVEDNOTHING, HONESTLY

Page 3

§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations

§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask your opponent Ask your e Discovery / forensic provider SUGGESTED WORDING · AC CESS - CONTROLLIMBFORTHEPRESER VAT I ON LETTER

§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The access-control checklist Red flags When to involve a digital forensic expert 35. Through e-discovery.uk, the building's diary sits on the same reviewed chronology as everything else the

§ 13 · COMMON QUESTIONS Frequently asked questions How long are swipe logs actually kept? Can badge data alone prove someone was in the building? The logs show no exit for our witness. When did they leave? Our client says a colleague borrowed their card. Hopeless? Is building access data caught by disclosure duties like documents? Can employers freely use this data to investigate staff?

§ 14 · REFERENCE Glossary Sources and authoritative references DISCLAIMER

§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY

§ Common questions

Frequently asked questions

How long are swipe logs actually kept?
Anywhere from weeks to a few years: it is a configuration and platform fact, not a standard: controller-local buffers are shortest, head-end databases longest, and visitor and alarm layers run their own schedules. The only safe assumption is that a window is closing, which is why the census and the ask happen in week one.
Can badge data alone prove someone was in the building?
It proves the credential was: the person follows from corroboration: CCTV at the reader, biometrics, journey coherence, paired device activity: per §5's ladder, and honest findings say which rung they stand on. Example 2 shows the ladder reaching certainty; a lone badge event never does by itself.
The logs show no exit for our witness. When did they leave?
Possibly unknowable from the doors: free-exit design logs entries only: so departure brackets from the estate's other diaries: turnstiles and barriers, alarm set events, last logins and prints, final Wi-Fi as so c i at i on, car park systems. The bracket is often tight enough to plead; the door log alone was never going to be.
Our client says a colleague borrowed their card. Hopeless?
Testable, both ways: lending is common and some time s true: the exam in at i on checks whose rhythm the events match, hunts simultaneity contradictions (the card here, the holder's login there), reads CCTV at the readers, and hears the alleged borrower. Where the ladder's rungs point away from the holder, the defence stands up; where they converge on them, Example 2 is how it ends.
Is building access data caught by disclosure duties like documents?
Fully: it is recorded information within a party's control, disclosable where relevant and preservable from the moment litigation is contemplated: purging it on schedule after that moment invites the adverse-inference conversation. The practical wrinkle is operational: the data often sits with facilities teams or landlords who have never met a disclosure obligation: hence the §11 letter's forwarding limb.
Can employers freely use this data to investigate staff?
Purposefully, proportionately and transparently: presence data is personal data: investigation use needs a lawful basis, honest privacy notices help, minimisation is expected, and pattern analysis brushing sensitive inferences (health, religion, union activity) deserves particular care and usually a DPIA. Well-run investigations use the data confidently inside those rails: the rails are not the obstacle; ignoring them is. cflab. u k · e-disc ove r y. u k ©2026 Computer Forensics Lab Ltd ·cflab.uk ·e-discovery.uk ·info@cflab.uk ·+44 (0)20 7164 6915 Page 15 of 17
§ Related documents
Instruct the practice

Bring us in early. Defensibility is built, not retrofitted.

Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.

WhatsApp