GDPR could be regarded as a way to discourage organisations and individuals from allowing data to be where it shouldn't be. In this case I would count Students having access to pigeon holes a potential breach waiting to happen. Our pigeon holes are in a corridor that is used by many students regularly, no lock on the door at all. I think this needs to change. If the money is there for it, we'll push to get a card reader lock installed (which we use elsewhere)
I think the OPs setup is okay, but they should think about the security of the room, too. Perfect world = Authorised access only on the pigeon holes themselves, all logged. Never going to happen, though. There's an element of trust placed on the staff, so securing the room should be adequate. djrscally is right.