Privacy
Use data that is about people.
What it studies
Privacy studies use data that concerns individuals — badge logs, camera footage, occupancy sensors that can identify individuals — and the legal conditions under which such data may be collected, retained and used. The field works with data minimisation, purpose limitation and data-subject rights.
Why Facility Management needs it
FM collects a great deal of data in daily operations that formally counts as personal data, often without recognising it as such: who sits where, who enters when, who books which desk. Without privacy knowledge, a GDPR breach can easily arise from purely operational intentions.
Questions it answers
- Is there a lawful basis for collecting this data, and is it documented before the system goes live?
- Can this occupancy or access data be traced to an individual, and if so, is that necessary for the purpose?
Evidence sources
- GDPR (EU Regulation 2016/679); comparable frameworks elsewhere (e.g. UK GDPR, CCPA in the US) — jurisdiction-dependent.
Operating and management implications
- An occupancy system that stores individual locations instead of aggregated counts requires a separate, explicit lawful basis and retention period.
Related services
- CAFM & Information Management; Security (camera surveillance)
Related capabilities
- Data protection impact assessment (DPIA) for facility systems
Related operating models
- Demand organisation
The client role must include privacy requirements in the system specification up front; retrofitting them is technically and legally cumbersome.
Related standards
- GDPR (jurisdiction-dependent); ISO/IEC 27701 (privacy information management, an extension of ISO 27001).
The standards section arrives in Part 7.
Common misuse
- Occupancy data collected at individual level 'in case it is useful later', without a predetermined purpose — a direct breach of purpose limitation.
Current research frontier
The legal qualification of aggregated, anonymised occupancy data remains contested: many supposedly anonymised datasets turn out, in small populations (a half-empty office), to still be traceable to individuals.
Further reading
- GDPR, Regulation (EU) 2016/679, consolidated text.
- ISO/IEC 27701:2019, privacy information management.