Data & Technology

Privacy

Use data that is about people.

Data & Technology

What it studies

Privacy studies use data that concerns individuals — badge logs, camera footage, occupancy sensors that can identify individuals — and the legal conditions under which such data may be collected, retained and used. The field works with data minimisation, purpose limitation and data-subject rights.

Why Facility Management needs it

FM collects a great deal of data in daily operations that formally counts as personal data, often without recognising it as such: who sits where, who enters when, who books which desk. Without privacy knowledge, a GDPR breach can easily arise from purely operational intentions.

Questions it answers

  • Is there a lawful basis for collecting this data, and is it documented before the system goes live?
  • Can this occupancy or access data be traced to an individual, and if so, is that necessary for the purpose?

Evidence sources

  • GDPR (EU Regulation 2016/679); comparable frameworks elsewhere (e.g. UK GDPR, CCPA in the US) — jurisdiction-dependent.

Operating and management implications

  • An occupancy system that stores individual locations instead of aggregated counts requires a separate, explicit lawful basis and retention period.

Related services

  • CAFM & Information Management; Security (camera surveillance)
To the Services Atlas

Related capabilities

  • Data protection impact assessment (DPIA) for facility systems

Related operating models

  • Demand organisation

    The client role must include privacy requirements in the system specification up front; retrofitting them is technically and legally cumbersome.

All operating models

Related standards

  • GDPR (jurisdiction-dependent); ISO/IEC 27701 (privacy information management, an extension of ISO 27001).

The standards section arrives in Part 7.

Common misuse

  • Occupancy data collected at individual level 'in case it is useful later', without a predetermined purpose — a direct breach of purpose limitation.

Current research frontier

The legal qualification of aggregated, anonymised occupancy data remains contested: many supposedly anonymised datasets turn out, in small populations (a half-empty office), to still be traceable to individuals.

Further reading

  • GDPR, Regulation (EU) 2016/679, consolidated text.
  • ISO/IEC 27701:2019, privacy information management.