
Access
Part of Coworking member onboarding
Issuing secure access without unnecessary personal data
A practical credential process for coworking operators, from authorisation and minimum data collection to testing and revocation.
To issue coworking access, confirm who is entitled to enter, assign an individual credential for approved spaces and dates, and test it. The Privacy Act 1988 (Cth) contains the Australian Privacy Principles (APPs); the Office of the Australian Information Commissioner (OAIC) is Australia’s privacy regulator. For an operator covered by the APPs, collect only information reasonably necessary for its functions or activities—not a full identity-document copy, date of birth or biometric by default.
Define the access decision first
Record the member or employer authorisation, start and end dates, permitted hours and areas. Decide who may approve changes.
A private office, shared desk area and after-hours entrance may require different permissions. Give each person an individual credential where the system supports it; a shared team code makes it harder to remove one person’s access without disrupting everyone else.
Choose a proportionate way to verify that the credential is going to the right person, based on the agreement, building arrangements and risk. If a justified reason requires an identity document, sight it and consider recording the result instead of keeping an image, if that is sufficient.
APP 3 allows an organisation that is an APP entity to collect personal information only where it is reasonably necessary for its functions or activities. Collection must be lawful and fair, and information should be collected from the individual unless that is unreasonable or impracticable; sensitive information has stricter conditions, including consent unless an exception applies.
APP 5 requires reasonable steps, before or at collection or as soon as practicable afterwards, to tell people or ensure they know the operator’s identity and contact details, the circumstances and purposes of collection, whether it is required or authorised by law, and the consequences of not providing it. The notice must also cover usual disclosures, the privacy policy and likely overseas disclosures, including countries where practicable.
Check OAIC small-business guidance if you are unsure whether the Privacy Act obligations apply to the operator.
Issue, test and recover
Use a short credential lifecycle:
- Approve:match the request to a current membership and the named user.
- Configure:set the spaces, hours and expiry that match the entitlement.
- Deliver:provide activation instructions through a channel appropriate to the credential; avoid posting a reusable code in a group message.
- Test:ask the member to enter through the door they will normally use, including any after-hours route they are entitled to use.
- Recover:provide a clear process for a lost phone, card or failed credential, including who can help when reception is closed.
- Revoke:remove access when the entitlement ends or the person leaves the team, then confirm the change took effect.
Keep staff accounts that grant or override access individual, limit their permissions and remove access promptly when no longer needed. Consider multi-factor authentication for online administration; it is separate from how a member opens a physical door.
If an access-system incident is an eligible data breach likely to cause serious harm, assess it quickly under the Notifiable Data Breaches scheme and notify affected individuals and the OAIC.
Keep an accountable record
An access record needs the person or credential identifier, entitlement, approver, activation and revocation status, and enough detail to investigate a failed entry. Avoid adding unrelated profile details, and check that contractors, guests and former members cannot inherit standing access through an old team account.
APP 11 requires reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. It also requires reasonable steps to destroy or de-identify information once it is no longer needed for a permitted APP purpose, unless it is part of a Commonwealth record or a law or court order requires retention.
When an identity image is no longer needed for its purpose, destroy or de-identify it; record the verification result instead only if that is sufficient. Apply the same necessity test to access logs, and protect any personal information they contain.
A successful handover is specific: the authorised person can use the correct entrance at the correct time, staff can explain a denial, and a lost or expired credential can be disabled promptly.



