Section 86 of 101
85. Privacy and Data Protection
Stable section ID: S05-CON-006-SECTION-86 · 35 content blocks
The Building BIOS shall collect, process, retain, and disclose only the data necessary for its authorized engineering, operational, safety, security, and lifecycle functions.
Data shall be classified as:
public technical data;
building operational data;
confidential engineering data;
security-sensitive data;
commercially restricted data;
personal data;
highly sensitive occupant data;
- emergency-access data.
- The BIOS shall distinguish building engineering identity from occupant identity wherever practical.
Privacy-sensitive sources may include:
occupancy sensors;
access records;
cameras;
microphones;
health-related devices;
behavioral data;
room-use patterns;
location tracking;
energy-use patterns linked to individuals.
Privacy controls shall provide:
data minimization;
purpose limitation;
role-based access;
local processing where practical;
defined retention;
deletion or anonymization where permitted;
consent and visibility where required;
export and ownership-transfer procedures;
security of stored and transmitted data.
The BIOS shall not require continuous audio or video collection merely to provide ordinary configuration management.
AI services shall not receive unrestricted historical or occupant-sensitive data simply because they are connected to the building.
Emergency access may expose defined safety information without ordinary authorization where delay would create greater risk. Such access shall remain limited and auditable.
Deletion of personal data shall not destroy engineering evidence required for safety, certification, maintenance, or lifecycle accountability. These data categories shall be separated where possible.