An architecture firm is, by the very nature of its work, a silent accumulator of personal data: client identification data, land registry extracts, deeds, photographs of the property's existing condition, signed drawings, budgets, works certifications, communications with licensing authorities and, frequently, data on neighbouring residents appearing in surveys and photographs. That concentration stays under the radar until a complaint arrives, an inspection, or simply the need to archive ten years of projects without knowing what can be destroyed and what must be kept.
This guide explains how an architecture firm manages its clients' personal data under GDPR (Regulation (EU) 2016/679) and the LOPDGDD (Spain's Organic Law 3/2018), with emphasis on the points where the sector is most often confused: professional portfolio, third parties appearing in documentation, final delivery and archiving.
The personal data map of a typical engagement
The first step to avoid losing control is to know what data will be processed in an average engagement. A standard residential project generates, over its full lifecycle, the following inventory:
| Block | Typical data | Usual legal basis |
|---|---|---|
| Client identification | Name or company name, tax ID, address, phone, email, IBAN. | Performance of contract (art. 6(1)(b)) |
| Property and ownership | Cadastral reference, land registry extract, title deed, owner data where different from the client. | Performance of contract (art. 6(1)(b)) |
| Existing condition | Photographs, video, 3D scans of the existing state, which may include people and personal belongings of the occupant. | Performance of contract (art. 6(1)(b)) |
| Project and technical documentation | Signed drawings, reports, measurements, budgets, annexes, CAD/BIM files with metadata. | Performance of contract + legal obligation of professional college visa/registration |
| Financial and tax | Fees, certifications, income tax withholdings, invoicing. | Legal obligation (art. 6(1)(c)) |
| Neighbours and surroundings | Cadastral data of adjoining plots, incidental photographs of people and vehicles, communications with the community of owners. | Legitimate interest with limits (art. 6(1)(f)) |
| External suppliers | Structural engineer, MEP engineering, surveyor, accountant, quality control, construction supervision. | Performance of supplier's contract + art. 28 GDPR |
Minimum documentation for the firm
The professional firm, regardless of its size, should have the following documents available before the first engagement:
- Record of Processing Activities (ROPA) with the above blocks identified as processing operations.
- Information clauses differentiated: one for the engagement client, one for job candidates, one for website visitors. The client's clause is built into the engagement letter or delivered as a signed annex.
- Art. 28 GDPR contracts with the usual technical suppliers: structural engineer, services engineering, surveyor, construction supervision, external accounting, collaborative BIM platform.
- Operational security policy: individual strong passwords, two-factor authentication on critical accesses, CAD/BIM licence management, encrypted backups of projects, onboarding and offboarding of staff with archive access.
- Portfolio protocol: how consent to use project images and data on the firm's website, social media and competitions is managed.
- Archiving and destruction policy: how long each block is kept, where and who decides destruction when the period expires.
Professional portfolio: the sector's most common mistake
The portfolio is the central commercial asset of any firm: it showcases completed work on the website, on social media, in sector publications and, occasionally, in award or competition submissions. But it is also the point where GDPR is most frequently breached out of sheer unfamiliarity.
The operating rule is:
- Performance of the services contract (art. 6(1)(b) GDPR) covers drafting the project, professional college visa, supervision of works and delivery to the client. It does not cover the subsequent commercial use of the result through the firm's channels.
- The use of images of the completed project on the website, social media, publications or competitions requires express, written, specific and revocable consent from the client.
- The consent must specify in which channels it will be published (firm website, Instagram, professional platforms, print publications, award submissions) and which specific images will be used.
- Where the project includes inhabited or personalised work by the client (decoration, books on shelves, photos on walls, own furniture), Organic Law 1/1982 also comes into play, and the client may ask for specific images to be removed even though they had authorised general use.
- Consent is revocable: if the client changes their mind, the firm must remove content from channels under its control within a reasonable period.
The professional way to handle this is to build a specific clause into the engagement contract with a tick box separate from the rest of the wording, where the client expressly ticks what they do and do not authorise. Far better than asking at project end, when the commercial relationship may have cooled.
Third parties in the documentation: neighbours, passers-by, previous occupants
One of the sector's worst-handled flanks is the personal data of third parties that incidentally appears in project documentation:
- Existing-condition photographs with neighbours leaning out of windows, washing hanging out, vehicles with visible licence plates, family photos on the previous occupant's walls.
- Surveys of the surroundings with cadastral data of adjoining plots and publicly accessible owner names.
- Drone footage capturing neighbouring properties in detail.
- Reports and annexes with addresses, names and data of those affected by the works (communications to communities of owners, easement certificates).
Good practice:
- Blur faces and licence plates in any documentation leaving the firm's technical environment (public project report, graphic annex for licensing, social media).
- Limit retention of original existing-condition photographs to the time strictly necessary for the project, with subsequent destruction once they no longer add technical value.
- Do not publish on the firm's social media existing-condition photos showing identifiable third-party elements.
- Respect the data minimisation principle (art. 5(1)(c) GDPR) when requesting data: do not ask for more than necessary, do not photograph more than necessary.
"In an architecture firm, personal data is not what gets processed most day to day, but it is what accumulates most over the years. Twenty years of projects without an archiving policy means thousands of personal data items without an active data subject, without a clear legal basis and with nobody who knows what to do with them when a complaint arrives."
Mario P. Talamillo · Managing Partner, Certix®
Metadata in technical files: what CAD and BIM don't tell you
CAD files (.dwg, .dxf) and BIM files (.rvt, .ifc) retain invisible metadata that may contain personal data: name of the file's author, machine it was edited on, full file path on the system (which reveals the firm's internal structure), modification history with the names of the technicians who intervened, internal comments. The same applies to PDFs generated from those files.
Before delivering documentation to the client, to the administration or publishing it on any channel, it is wise to:
- Clean the metadata of final files using the export function or specific utilities.
- Standardise file names and author information so that the firm appears rather than the individual technician.
- Review internal comments that may remain embedded in layers or views and remove them before delivery.
Final delivery: the most critical moment
Final delivery consolidates all project documentation in the client's hands and formalises the close-out of the active phase of the engagement. A reasonable procedure:
- Secure channel: professional file transfer platform with encryption in transit, not standard email for large volumes.
- Signed handover record documenting what files are delivered, in what format, on what date and to which person.
- Clean metadata on all deliverable files.
- Information to the client on how to keep the files and on any third-party personal data they may contain.
- Internal policy for managing the firm's working copies: which are kept, which are destroyed and when.
Minimum checklist for the firm
- ROPA with the seven processing blocks identified.
- Information clause built into the engagement letter, with a separate tick box for commercial use of the project in the portfolio.
- Art. 28 GDPR contracts signed with the usual structural engineer, MEP engineering, surveyor, accountant and construction supervisor.
- Third-party (neighbours, passers-by) handling policy with mandatory blurring before publication.
- Procedure for cleaning metadata in CAD, BIM and PDF before delivery.
- Project file archiving and destruction policy with clear periods by block.
- Final delivery procedure with a signed handover record.
- Annual review of the historical archive to destroy items whose retention period has expired.
Frequently asked questions
What personal data does an architecture firm typically handle about its clients?
Client identification data, cadastral and land registry data on the property, copies of deeds, photographs of the existing condition (which may include people and personal belongings), signed drawings, topographical surveys, financial data, communications with licensing authorities and, frequently, data on neighbouring residents. All of it is personal data under GDPR; the firm is the controller of most of it. Good practice is to map the inventory from the first engagement together with the suppliers it will be shared with.
Does an architect need the client's consent to use the project in their professional portfolio?
Yes. Performance of contract covers drafting, licensing and supervision of works; it does not cover commercial use on the website, social media or publications. It requires express, written, specific and revocable consent, ideally captured in the engagement contract with a separate tick box. Where the work appears inhabited or personalised by the client, Organic Law 1/1982 (right to honour, personal and family privacy and own image) also comes into play.
What about data on neighbouring residents or people appearing in surveys and existing-condition photographs?
It is not covered by the client engagement. Blur faces and licence plates in any documentation leaving the firm's technical environment (public report, graphic annex to the town hall, social media), limit retention of original photographs to what is necessary and do not publish identifiable third-party elements without filtering.
How are final drawings and documentation delivered to the client without compromising personal data?
Channel with encryption in transit (professional platform, not standard email for large volumes), clean metadata in deliverable CAD, BIM and PDF, detailed signed handover record, and controlled deletion of internal working copies respecting the applicable professional retention periods. Careful handling of this moment marks the difference between a professional firm and one with scattered documentation.
This content is for general guidance only and does not constitute specialist legal advice. Application of the rules to any specific case requires individual analysis. Spanish regional sectoral regulations may extend or modify periods and requirements.
Does your firm manage client data on projects in an orderly way?
At Certix we assign you a compliance specialist for the architecture sector. No commercial intermediaries, no generic templates.
Speak to a specialist