Section 100 of 105
97. Privacy, Consent and Data Minimization
Stable section ID: S05-CON-014-SECTION-100 · 24 content blocks
System05 shall collect and process only the personal or occupant-related data necessary for declared building functions.
Privacy governance shall define:
- Purpose of collection.
- Data categories.
- Legal or authorized basis.
- Consent where required.
- Access rights.
- Retention period.
- Permitted use.
- Sharing restrictions.
- Deletion or anonymization requirements.
- Security protections.
Occupancy, behavior, location, health-related, audio, visual, biometric, and personal preference data shall receive protection proportionate to their sensitivity.
Building safety data and personal data shall remain distinguishable wherever practical. Safety monitoring shall not be used as an undeclared mechanism for surveillance.
Data minimization may include:
- Local processing.
- Aggregation.
- Anonymization.
- Limited sampling.
- Short retention.
- User-controlled features.
- Separation of identity from operational data.
Consent to one function shall not establish consent to unrelated analytics, advertising, profiling, research, or third-party use.
Privacy shall not require deletion of records necessary to preserve life safety, engineering accountability, or lawful asset history. Such retention shall remain limited, protected, and transparent.