Certix

Architecture and engineering

Data protection for
architects and technical studios

Architecture studios manage data relating to clients, developers, builders and subcontracted technical professionals on projects that may span several years. Subcontracting and administrative files create complex data processing relationships.

10 years

civil liability — architect (Building Act)

Art. 28

GDPR — technical subcontracting

Art. 6.1.b

GDPR — performance of contract

24 h

personalised proposal

Sector challenges

General obligations for architects and technical studios

Client data in projects

Identity, contact and property data of the client commissioning the project must be processed on a valid legal basis, with the data subject informed and retained for the duration of potential liability periods.

Subcontracting to technical professionals

Quantity surveyors, engineers, surveyors and other technical professionals who access client data in the context of the project may act as data processors or as independent controllers. The precise legal relationship depends on the access and context; it should be analysed and documented in each case.

Administrative files

Planning permits, college visas and cadastral procedures include data of the developer or property owner that the studio submits to public authority systems.

Plans and technical documentation

Project plans and reports may include personal data of the client (name, address, property data). Their storage and access must be controlled.

Data of builders and subcontractors

Managing quotations, contracts and communications with builders, installers and subcontractors involves processing personal data of natural persons.

Retention of completed projects

The Building Act establishes liability periods of up to 10 years for the architect. Technical documentation must be retained during that period, which includes any personal data linked to it.

The service

What is included in the service for your architecture studio

Record of Processing Activities

Tailored RoPA (Record of Processing Activities): clients, employees, subcontracted technical professionals, builders and public authorities.

Information clauses

Texts for the services contract with clients and web forms.

Privacy policy and legal notice

Legal documentation for the studio's website.

Data Processing Agreements (DPA)

DPAs for subcontracted technical professionals, project management software and storage platforms.

Data breach protocol

Incident response procedure with notification within 72 hours.

Data subject rights management

Documented procedure for handling requests from clients, technical professionals and builders.

Document management platform

Access to a private platform with documents and electronic signature.

Ongoing support

Unlimited queries. Updates in response to regulatory changes.

External DPO (where applicable)

As a general rule, architecture studios are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis. Separate contract.

Do you need a proposal for your studio?

Tell us the size of the studio and the type of projects you handle. Proposal in under 24 hours.

Request a proposal

FAQ

Frequently asked questions about data protection in architecture

What personal data does an architect typically process?

An architect processes identity and contact data of clients, property data and financial information about the buildings involved, data relating to builders and subcontractors, and data relating to developers included in administrative files for planning permits and college visas.

Are quantity surveyors and other subcontracted technical professionals data processors?

It depends on the access they have to data. If a quantity surveyor or engineer accesses personal data belonging to the studio's client in order to carry out part of the project, they act as a data processor and must sign a Data Processing Agreement (DPA). If they act entirely independently as a data controller in their own right, the relationship is between controllers.

Does a planning application file include personal data of the developer?

Yes. Municipal planning permission files, college visas and other administrative procedures include identity data, property data and, on occasion, financial data relating to the developer. The architecture studio processes this data and must inform the client that it will be included in administrative files.

How long must an architecture studio retain completed projects?

There is no single retention period. Claims for civil liability against the architect prescribe after 10 years from the completion of the building (Building Act, art. 18). During that period, it is advisable to retain the technical documentation. Personal data of clients may be blocked once potential liabilities have been extinguished.

How should data relating to builders and subcontractors be managed?

Data relating to builders and subcontractors (companies and self-employed individuals) with whom the studio works must be processed in accordance with GDPR: legal basis for the processing (performance of contract or legitimate interests), information clause and retention periods. Where natural persons are involved, the obligations are the same as for any other data subject.

Does accessing government platforms with client data create additional obligations?

Yes. Accessing government platforms (Cadastre electronic office, planning permit portals, professional colleges) using client data must be reflected in the studio's RoPA. In these cases, the public authority typically acts as an independent data controller for its own purposes, without prejudice to the studio's obligations regarding the data it submits to the files. The exact legal nature of each relationship must be analysed individually.

Free tool

Data protection self-check

Check in 5 minutes your overall adaptation level in personal data protection.

No email · Anonymous · No commitment

Start the test

Architecture and engineering

GDPR compliance
for your studio.

An expert analyses your practice and proposes the appropriate solution. No intermediaries.

INFORMACIÓN BÁSICA DE PROTECCIÓN DE DATOS: De conformidad con las normativas de Protección de Datos, le facilitamos la siguiente información del tratamiento: Responsable: Certificación y Gestión Normativa S.L.U. Finalidad: atender su solicitud y contactarle para ofrecerle la información solicitada. Derechos: acceso, rectificación, portabilidad, supresión, limitación y oposición, así como otros derechos detallados en la información adicional. + info: Puedes encontrar información más detallada en nuestra Política de privacidad.

Or tell us your full case →

Proposal within 24 h · info@certix.es

Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.