Architecture and engineering
Data protection for
architects and technical studios
Architecture studios manage data relating to clients, developers, builders and subcontracted technical professionals on projects that may span several years. Subcontracting and administrative files create complex data processing relationships.
10 years
civil liability — architect (Building Act)
Art. 28
GDPR — technical subcontracting
Art. 6.1.b
GDPR — performance of contract
24 h
personalised proposal
Sector challenges
General obligations for architects and technical studios
Client data in projects
Identity, contact and property data of the client commissioning the project must be processed on a valid legal basis, with the data subject informed and retained for the duration of potential liability periods.
Subcontracting to technical professionals
Quantity surveyors, engineers, surveyors and other technical professionals who access client data in the context of the project may act as data processors or as independent controllers. The precise legal relationship depends on the access and context; it should be analysed and documented in each case.
Administrative files
Planning permits, college visas and cadastral procedures include data of the developer or property owner that the studio submits to public authority systems.
Plans and technical documentation
Project plans and reports may include personal data of the client (name, address, property data). Their storage and access must be controlled.
Data of builders and subcontractors
Managing quotations, contracts and communications with builders, installers and subcontractors involves processing personal data of natural persons.
Retention of completed projects
The Building Act establishes liability periods of up to 10 years for the architect. Technical documentation must be retained during that period, which includes any personal data linked to it.
The service
What is included in the service for your architecture studio
Record of Processing Activities
Tailored RoPA (Record of Processing Activities): clients, employees, subcontracted technical professionals, builders and public authorities.
Information clauses
Texts for the services contract with clients and web forms.
Privacy policy and legal notice
Legal documentation for the studio's website.
Data Processing Agreements (DPA)
DPAs for subcontracted technical professionals, project management software and storage platforms.
Data breach protocol
Incident response procedure with notification within 72 hours.
Data subject rights management
Documented procedure for handling requests from clients, technical professionals and builders.
Document management platform
Access to a private platform with documents and electronic signature.
Ongoing support
Unlimited queries. Updates in response to regulatory changes.
External DPO (where applicable)
As a general rule, architecture studios are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis. Separate contract.
Do you need a proposal for your studio?
Tell us the size of the studio and the type of projects you handle. Proposal in under 24 hours.
FAQ
Frequently asked questions about data protection in architecture
What personal data does an architect typically process?
An architect processes identity and contact data of clients, property data and financial information about the buildings involved, data relating to builders and subcontractors, and data relating to developers included in administrative files for planning permits and college visas.
Are quantity surveyors and other subcontracted technical professionals data processors?
It depends on the access they have to data. If a quantity surveyor or engineer accesses personal data belonging to the studio's client in order to carry out part of the project, they act as a data processor and must sign a Data Processing Agreement (DPA). If they act entirely independently as a data controller in their own right, the relationship is between controllers.
Does a planning application file include personal data of the developer?
Yes. Municipal planning permission files, college visas and other administrative procedures include identity data, property data and, on occasion, financial data relating to the developer. The architecture studio processes this data and must inform the client that it will be included in administrative files.
How long must an architecture studio retain completed projects?
There is no single retention period. Claims for civil liability against the architect prescribe after 10 years from the completion of the building (Building Act, art. 18). During that period, it is advisable to retain the technical documentation. Personal data of clients may be blocked once potential liabilities have been extinguished.
How should data relating to builders and subcontractors be managed?
Data relating to builders and subcontractors (companies and self-employed individuals) with whom the studio works must be processed in accordance with GDPR: legal basis for the processing (performance of contract or legitimate interests), information clause and retention periods. Where natural persons are involved, the obligations are the same as for any other data subject.
Does accessing government platforms with client data create additional obligations?
Yes. Accessing government platforms (Cadastre electronic office, planning permit portals, professional colleges) using client data must be reflected in the studio's RoPA. In these cases, the public authority typically acts as an independent data controller for its own purposes, without prejudice to the studio's obligations regarding the data it submits to the files. The exact legal nature of each relationship must be analysed individually.
Sector resources
Learn more
Architects
Client data in architecture firms: project files, drawings and data protection
How an architecture firm manages client personal data: project files, signed drawings, current-state photographs, professional portfolio, neighbouring properties and final handover.
8 min·Read article
Architects
Architect as processor: when Art. 28 GDPR applies
When an architect is controller and when processor: direct work with end client, technical subcontracting, collaborative BIM platforms and Art. 28 GDPR contracts.
8 min·Read article
Architects
Retention of architecture projects and permits: statutory periods vs. the GDPR
How long to retain architecture projects: LOE, civil prescription, Commercial Code, General Tax Act and professional college rules against the GDPR storage-limitation principle.
8 min·Read article
Free tool
Data protection self-check
Check in 5 minutes your overall adaptation level in personal data protection.
No email · Anonymous · No commitment
Architecture and engineering
GDPR compliance
for your studio.
An expert analyses your practice and proposes the appropriate solution. No intermediaries.
Proposal within 24 h · info@certix.es
Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.