Last Updated on 9. October 2026
In many public agencies and businesses, homegrown Access databases still support important processes, often outside the view of central IT. They show how much business units can achieve on their own. Given rising demands for security, data protection, and digital sovereignty, however, now is the time to put these applications to the test. This article shows how organizations can modernize their Access databases and move them to a future-proof solution in four steps.
Access: Between Pioneering Achievement and Shadow IT
When a public agency searches its network drives for Access files, it often uncovers a second, unofficial application landscape: deadline tracking in regulatory offices, grant management, application registers, and much more. Caseworkers built many of these solutions themselves years ago to solve a specific problem quickly. Today, processes that matter for day-to-day operations depend on these files. Yet they are rarely managed centrally or documented thoroughly.
The picture in businesses is similar. Whether it’s quote calculation in sales, complaint management in quality assurance, or reporting in controlling, Access has been the tool business units have used for decades to close the gaps between ERP, CRM, and Excel. Especially in mid-sized companies, business-critical applications have grown this way over the years, and often nobody has a complete overview of them anymore.
That said, Access deserves real credit. Long before low-code platforms existed, it enabled employees to build their own digital solutions quickly, pragmatically, and close to actual needs. By today’s standards, many of these applications are outdated. But they demonstrated what public administrations and business units can achieve on their own. This very principle is at the heart of low code and the idea of citizen developers today, including in the public administration of the future.
At the same time, this approach has created shadow IT in many places, meaning applications that business units build and run without approval from central IT. Access comes with many Office suites and is therefore instantly available. An Access database is essentially just a file: anyone with access to the drive can copy it or send it by email. As a result, it often doesn’t show up in the application inventories maintained by agency or company leadership.
Where Access Reaches Its Limits Today
- Information security. Anyone who can open the file can usually see all records, and access is typically not logged. This makes it difficult to meet requirements such as BSI IT-Grundschutz (the German Federal Office for Information Security’s baseline protection standard) or ISO 27001.
- Data protection. Many databases contain personal data, such as the names and bank details of applicants or customers. They are often missing from the record of processing activities, and there is frequently no deletion policy. The GDPR, however, requires organizations to be able to demonstrate lawful processing.
- Stability. Access is designed for small workgroups. When many people work in a database at the same time, or when the file approaches the two-gigabyte limit, the risk of data loss increases. Regularly tested backups are often missing.
- Knowledge retention. Often, only the person who built an application knows how it works. According to the German Civil Service Federation (dbb), more than 1.3 million public-sector employees will retire by 2030, and businesses are feeling the effects of demographic change as well. Valuable knowledge risks leaving with them.
- Traceability. If an official decision or a business decision relies on an undocumented query, it is hard to explain during an audit. Versioning and systematic archiving are usually not part of such solutions.
- Accessibility. Homegrown Access forms generally do not meet the requirements of BITV 2.0, Germany’s accessibility regulation for public-sector IT.
- Integration. Standalone Access solutions can hardly be connected to portals, registers, electronic case files, or modern enterprise systems. This limits their compatibility with the goals of the German Online Access Act (OZG) and registry modernization.
Digital Sovereignty as a Strategic Driver
For public agencies, and increasingly for businesses in Germany and Europe, digital sovereignty is becoming a key criterion when selecting software. The goal is to reduce dependence on individual vendors and retain control over data, applications, and one’s own IT strategy. For example, the Center for Digital Sovereignty of Public Administration (ZenDiS) offers openDesk as an open alternative to conventional Office suites, and the first German states are already actively moving to open source workplaces.
The end of support for Windows 10 in October 2025 recently showed how dependent organizations are on product roadmaps and licensing models. For some agencies, it meant replacing existing hardware or switching to a different operating system. This applies to Access solutions in particular. While Access continues to ship with Microsoft 365 and is still maintained, support periods are ending for certain perpetual-license versions. For Office 2021 and Access 2021, support ends on October 13, 2026. Above all, however, Access applications are tightly tied to Windows and Microsoft Office. Organizations that want to make their workplaces more sovereign cannot simply take them along.
Replacing Access is therefore less a reaction to a vendor’s support roadmap than a strategic opportunity: organizations can move their business applications to open, independent technologies while deliberately developing their employees’ skills.
How to Replace Access Successfully
1. Inventory. IT works with business units to search network drives for Access files and talks to the teams that use them. For each application, they document its purpose, user group, data, and owners.
2. Assessment. Depending on importance and protection requirements, each application is either shut down, consolidated, migrated to an existing system, or redeveloped. Applications containing personal data should take priority.
3. Target architecture. If no existing business application, no standard software, or, in public administration, no “One for All” (EfA) solution can take over the task, a dedicated low-code platform is a good fit. This allows organizations to carry the skills of experienced Access power users into a modern framework while benefiting from consistent standards, security, and the platform’s reusability.
4. Migration. The project team and the business unit model the new application together, clean up data, transfer the rules embedded in the legacy application’s queries, and align them with each other. After acceptance, documentation, and training, the old database is archived.
Moving the business logic of applications that have grown over time into new applications requires the knowledge of the people who built them. Those who developed and maintained their Access solutions over the years are therefore the most important partners in the project. Involving them early not only preserves their expertise but also makes them co-creators of the new solution. With the right training, they can continue developing applications on the new platform themselves. Replacing Access is thus also a change process that needs clear project leadership, well-defined responsibilities, and open communication.
Successfully Replacing Access-Based Business Applications
The German state of Schleswig-Holstein shows how an Access replacement can succeed. The state administration is gradually replacing more than 100 Access-based business applications. To do so, it relies on the A12 AI Low Code Platform, whose source code is available as open source on openCode and GitHub, an important building block for greater digital sovereignty. The result is modern web applications that other administrations can reuse as well. A statewide low-code competence center ensures that the administration will also be able to develop new applications on its own. The platform runs in Dataport data centers, so other member states can build on it.
Talks on Replacing Access at SCCON 2026
Wed., October 14, 2026, 11:00–11:30 a.m.
“A12 Low Code in the Open Source State of Schleswig-Holstein: The Access Replacement Project”
Speakers: Florian Christian Weber, Project Lead, State Chancellery of Schleswig-Holstein, and Jan Samek, Business Development Manager, mgm
Wed., October 14, 2026, 4:00–4:15 p.m.
“Statewide Access Replacement: Schleswig-Holstein’s Success Story Thanks to Open Source and Low Code”
Speakers: Hamarz Mehmanesh, Managing Director, mgm, and Jan Samek, Business Development Manager, mgm
More information:
- Website: A12 AI Low Code Platform
- Website: State of Schleswig-Holstein: Digitalization (German)
Are you working on the digital transformation of public administration? Learn more about our public sector work and how to get in touch: https://a12.ai/public-sector
FAQ
Why should organizations modernize their Access databases now?
Homegrown Access applications often fall short of today’s requirements for information security, data protection, accessibility, and integration. In addition, they are tightly tied to Windows and Microsoft Office, which conflicts with the goal of digital sovereignty.
What are the biggest risks of Access-based shadow IT?
Typical risks include unrestricted access to all records, missing access logs, personal data outside the record of processing activities, data loss as files grow, and knowledge that only a single person holds.
How do you replace Access applications step by step?
A proven approach has four steps: take an inventory of all Access files, assess each application, define the target architecture, and migrate the business logic and data together with the business unit.
What role do the original Access developers play in a migration?
They are the most important partners in the project. Their knowledge of the business logic is essential, and with the right training they can continue developing applications on the new platform themselves.





