In the architecture sector, personal data flows rarely stay within a single office. A typical project mobilises the lead architect, one or more structural engineers, the services engineering firm, the surveyor, the geotechnical study, the construction supervisor, the health and safety coordinator, and the accountant. Across that chain move data on the client, on the property, occasionally on the occupants and always on the technical team itself. Each actor in the chain holds a specific role under GDPR (Regulation (EU) 2016/679): controller, processor or, in some cases, independent controller. Knowing how to tell them apart determines which contract must be signed, what obligations are assumed and who answers if something goes wrong.
This guide explains how the roles are shared in a professional operation under GDPR and the LOPDGDD (Spain's Organic Law 3/2018), with emphasis on the three scenarios that generate the most confusion in the sector: architect engaged by another entity to serve its clients, regular technical subcontracting on a project and cloud-based collaborative BIM platforms.
The three GDPR roles applied to architecture
- Controller: the party that decides the purposes and means of the processing of personal data. The central figure of GDPR: signs the contract with the data subject (or directly relates to them), defines what data is collected and why, assumes the obligations of art. 24 GDPR.
- Processor: natural or legal person who processes personal data on behalf of the controller. Does not decide their own purposes; executes what the controller instructs. Governed by art. 28 GDPR through a mandatory contract.
- Independent controller: the party that, over the same data, simultaneously decides its own purposes distinct from those of the first controller. Exists in complex flows where several actors process the same data for their own ends.
The most common mistake in the sector is to assume that where there is technical subcontracting all roles are automatically "controller" because each professional signs with their own responsibility. In reality, professional technical responsibility is independent of the GDPR role: a structural engineer can be fully responsible for their calculations and, at the same time, a processor over the client's personal data received from the lead architect.
Scenario 1: architect working directly with end client
This is the most common situation and the simplest in terms of GDPR role. The architect signs an engagement letter with an individual, a company or a public body to draft a project, supervise works or carry out an expert appraisal. The relationship is bilateral and the architect:
- Decides what personal data is requested from the client (identification, registry, financial).
- Decides what purposes it pursues with that data (drafting the project, professional college visa, licence processing, invoicing).
- Decides which suppliers it engages for complementary technical services.
It is therefore the controller. Its art. 13 GDPR information duty is discharged by delivering the information clause to the client at first contact, ideally built into the engagement letter.
Scenario 2: architect engaged by another entity to serve its clients
Here the situation changes. An architect may act as processor when working for another entity that maintains the principal relationship with the end client. The typical cases:
- Technical architect for a property developer: the developer captures the buyers, manages marketing and maintains the relationship with them; the architect drafts the projects on behalf of the developer. Over the buyers' data the architect receives to personalise the project (layout changes, finishes chosen), they typically act as processor of the developer.
- Architect collaborating with another firm: when a firm engages another firm or a freelance architect for a specific stage (preliminary design, execution stage, supervision of works), the second works on the first firm's client data as a processor.
- In-house architect of a construction company or large corporate: in projects for external clients, the in-house architect acts as the company's staff, not as direct controller in relation to the client.
In these scenarios, the architect must sign with the principal entity an art. 28 GDPR contract governing the processing of data on its behalf, with the minimum content of art. 28(3).
Scenario 3: regular technical subcontracting on a project
This is the reverse scenario: the architect leading the project, who is controller in relation to the end client, subcontracts one or more specialist technicians. Those technicians are processors of the main firm over the client data transferred to them.
| Supplier | What client data they receive | GDPR role |
|---|---|---|
| Structural engineer | Property data, owner, occasionally the client. | Processor (art. 28) |
| MEP / services engineering | Property drawings, owner data. | Processor (art. 28) |
| Surveyor | Cadastral data, occasionally owner and adjoining plots. | Processor (art. 28) |
| Geotechnical study | Property data, owner. | Processor (art. 28) |
| Construction supervisor | Full project and client data during the works. | Processor (art. 28) |
| Health and safety coordinator | Site data, contractor companies and workers. Dual plane. | Processor (project data) + own controller (PRL data) |
| External accountant | Firm and client financial data for invoicing. | Processor (art. 28) |
| Cloud BIM platform | Full project model and associated data. | Processor (art. 28) + international transfers if applicable |
Collaborative BIM platforms: the technological sub-processor
Cloud BIM platforms (Autodesk BIM 360, Trimble Connect, Bimplus, Bentley ProjectWise, Graphisoft BIMcloud) process personal data on behalf of the firm: client data embedded in the model, multiple technicians' accesses, version metadata, internal team comments. The platform is a processor and must offer the firm a Data Processing Agreement with the content of art. 28(3) GDPR.
What the firm needs to review:
- Platform sub-processors: the cloud it uses (AWS, Azure, GCP), monitoring and support providers. Each one must be listed and there must be a right to object to changes.
- International transfers: most BIM platforms have parent companies or servers in the United States. It is necessary to verify whether the provider is adhered to the Data Privacy Framework or whether the operation relies on Standard Contractual Clauses (SCC) and a Transfer Impact Assessment (TIA).
- Deletion and export functionality: the firm's client has the right to obtain a copy of their data and, where applicable, to request its erasure. The platform must allow the firm to comply with those rights.
- Handover of models to the client at close-out: the contract must allow delivery of the full BIM model to the end client in a neutral format (IFC) where appropriate, without contractual restrictions preventing it.
"The architect's GDPR role changes with who they contract: direct with the client makes them controller; integrated in the chain of a firm or developer may make them processor. The practical consequence: the art. 28 contract is not optional; it is the central piece of professional collaboration when personal data travels."
Mario P. Talamillo · Managing Partner, Certix®
Health and safety coordinator: the dual plane
The health and safety coordinator deserves a separate mention because they simultaneously occupy two GDPR roles:
- Over the project data received from the lead architect (drawings, client data, project features), they act as processor of the main firm.
- Over the occupational risk prevention data they generate by virtue of their function (data on contracting companies, on workers involved, accident reports, coordination meetings), they act as independent controller based on the legal obligation arising from Spanish Royal Decree 1627/1997 (health and safety in construction sites).
The contract with the coordinator must reflect that duality: governing the processor role for project data and recognising the independent controller responsibility for PRL (occupational risk prevention) data.
Minimum content of the art. 28 GDPR contract
For any technical supplier acting as processor, the contract must include the content of art. 28(3) GDPR:
- Subject matter, duration, nature and purpose of the processing.
- Types of data and categories of data subjects.
- Obligations of the controller and the processor.
- Confidentiality of the processor's personnel, including after termination of the contract.
- Appropriate security measures: encryption in transit and at rest where appropriate, access control, activity logging.
- Sub-processor regime (general or specific authorisation, accessible list and mechanism for notifying changes).
- Assistance with data subject rights.
- Breach notification within a reasonable period.
- Return on termination of the service (art. 28(3)(g) GDPR): the processor returns the data to the controller before destroying it.
Engagement and collaboration checklist
- Prior analysis of the GDPR role for each new client: direct, via developer, via firm?
- Information clause adapted to each role, built into the engagement letter of the direct client or, where applicable, received from the main firm.
- Art. 28 GDPR contract signed with each regular technical collaborator (structural engineer, MEP engineering, surveyor, construction supervisor, health and safety coordinator).
- Art. 28 GDPR contract with the collaborative BIM platform and annual review of sub-processors and transfers.
- Documented procedure for secure transfer of data to collaborators and return at close-out.
- Documented procedure for handling breaches notified by collaborators or platforms.
- Up-to-date inventory of suppliers with their GDPR role, contract date and expiry.
Frequently asked questions
When is an architect a controller and when a processor under GDPR?
Controller when working directly with an end client (individual, company, public body). Processor when engaged by another entity (developer, another firm, construction company) to serve that entity's clients. Each case requires analysis: the key is to identify who decides purposes and means over the data. Where in doubt, reflect the role expressly in the engagement contract.
If I'm an architect and I subcontract a structural engineer, am I controller or processor in relation to them?
The lead architect is the controller and the structural engineer is the art. 28 GDPR processor. The relationship must be governed by contract with the minimum content of art. 28(3): subject matter, types of data, confidentiality, security measures, sub-processors, assistance with rights, breaches and return. It is sensible to have a standard annex for regular technical collaborators.
And are collaborative BIM platforms processors of the firm?
Yes. Cloud BIM platforms (Autodesk BIM 360, Trimble Connect, Bimplus, Bentley ProjectWise) process personal data on behalf of the firm and must offer a Data Processing Agreement with the content of art. 28(3) GDPR. Review in particular sub-processors (cloud, support) and international transfers where servers are outside the EEA (Data Privacy Framework or Standard Contractual Clauses).
What happens to the client's data when a collaboration with an external engineer ends?
Art. 28(3)(g) GDPR requires the processor to return the data to the controller before destroying it. The engineer must hand back to the main firm calculations, models and client data at the close of the collaboration, before any destruction. Document the handover in writing for evidence. The supplier will retain on its side only what its own professional retention rules require (civil liability, tax).
This content is for general guidance only and does not constitute specialist legal advice. Application of the rules to any specific case requires individual analysis. Spanish regional sectoral regulations may extend or modify periods and requirements.
Have you regulated the chain of technical collaborations under Art. 28 GDPR?
At Certix we assign you a compliance specialist for the architecture sector. No commercial intermediaries, no generic templates.
Speak to a specialist