Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Practical Steps And Common Mistakes
- 1. Map your data properly
- 2. Match your privacy notices to real collection points
- 3. Put proper data processing clauses in your contracts
- 4. Review CCTV and monitoring practices carefully
- 5. Secure phones, tablets and onsite records
- 6. Set realistic retention periods
- 7. Prepare for data subject requests and breaches
- 8. Check whether a DPIA is needed
- 9. Train managers and site leads
- 10. Align privacy with wider business documents
- Key Takeaways
Facilities management businesses often collect far more personal data than they first realise. Access logs, CCTV footage, contractor sign in sheets, tenant complaints, helpdesk recordings, body worn device footage, lone worker apps and smart building systems can all trigger privacy obligations. Common mistakes include relying on a vague privacy notice, keeping data for too long, and sharing information with landlords, clients or subcontractors without being clear about who is responsible for what.
For UK facilities management companies, the main legal question is not just whether you collect personal data, but why you collect it, who controls it, how long you keep it and what you tell people about it. That can become messy quickly when you work across multiple sites and use several suppliers.
This guide explains what privacy data collection rules for facilities management company operations look like in the UK, when the issue tends to arise, and the practical steps that help you avoid the common compliance traps before you sign a contract or spend money on setup.
Overview
UK facilities management companies usually handle personal data under the UK GDPR and the Data Protection Act 2018. The legal position depends on the kind of data you collect, your reason for collecting it, whether you act as a controller or processor, and the promises you make in your client and supplier contracts.
- Map what personal data you collect across sites, systems and services.
- Work out whether your business is a controller, joint controller or processor for each activity.
- Identify a lawful basis for each type of collection, such as security monitoring, visitor management or helpdesk support.
- Give clear privacy information to staff, visitors, tenants, contractors and customers where required.
- Set retention periods for CCTV, access records, incident reports and complaint files.
- Put written data processing terms in place with clients, software providers and subcontractors.
- Review security controls for mobile devices, cloud systems, building tech and shared portals.
- Prepare a process for data subject requests, breaches and high risk monitoring.
What Privacy Data Collection Rules for Facilities Management Company Means For UK Businesses
For UK businesses in facilities management, privacy compliance means turning everyday operational data collection into something lawful, documented and limited to what you genuinely need.
Many FM businesses think privacy law only applies if they run a marketing database or process payroll. In practice, facilities management can involve regular handling of personal information in buildings, estates, workplaces, schools, healthcare settings, residential developments and industrial sites. That includes data about occupiers, visitors, employees, contractors and members of the public.
What counts as personal data?
Personal data is any information that identifies a person directly or indirectly. In facilities management, this often includes names, contact details, flat numbers, staff IDs, location records, incident reports, voice recordings, vehicle registration numbers and CCTV images.
Some FM businesses also handle special category data, which carries extra obligations. That can happen where records reveal health details, disability adjustments, trade union membership, biometric data used for access control, or information about religious practices from room use or accommodation arrangements.
Why facilities management creates extra privacy risk
The main risk is volume and overlap. A single contract might involve security services, cleaning, maintenance scheduling, reception management, smart access systems and out of hours support. Each function can collect different personal data, often through different tools.
This is where founders often get caught. They sign a client contract that assumes the FM provider is responsible for operational compliance, then onboard software, surveillance systems and subcontractors without sorting out who controls the data and who only processes it on someone else’s instructions.
Controller or processor?
This distinction matters because it changes your legal obligations. A controller decides why and how personal data is used. A processor handles data on behalf of a controller, following instructions.
An FM company may be a controller for some activities and a processor for others. For example:
- You may be a processor where you manage a client’s visitor booking system strictly under their instructions.
- You may be a controller where you keep your own HR records, supplier contacts and internal health and safety incident logs.
- You may be a controller for your own CCTV at your office or depot.
- You may be a joint controller in some shared security or site management arrangements, depending on how decisions are made.
You cannot safely rely on labels in a contract if the real arrangement says something different. The actual decision making and purpose of collection matter.
What lawful basis usually applies?
Every collection and use of personal data needs a lawful basis. Consent is not always the right answer, and many FM businesses overuse it.
Common lawful bases in this sector include:
- Legitimate interests, for site security, visitor logging, fraud prevention, building management and basic service delivery, where your interests are balanced against people’s rights.
- Contract, where processing is needed to deliver a service or manage a customer relationship.
- Legal obligation, where records are required for health and safety, employment law or other statutory duties.
- Vital interests, in rare emergency situations affecting someone’s life.
If you process special category data, you usually need an additional condition as well, not just a standard lawful basis.
Transparency and privacy notices
People should not be left guessing about what happens to their data. A facilities management company may need different privacy notices for different groups, depending on the service model.
That might include:
- an employee privacy notice
- a website and enquiries privacy notice
- a visitor or site user notice
- a CCTV notice with supporting privacy information
- a contractor or supplier contact notice
The wording should match your actual operations. Copying a generic website privacy policy rarely solves site level data collection issues.
Security and accountability
UK privacy law expects businesses to use appropriate technical and organisational measures to protect data. For FM companies, that often means looking closely at practical weak spots rather than policy documents alone.
Typical pressure points include:
- shared devices used by onsite teams
- photos taken on personal phones
- portable radios and call recordings
- paper logbooks left at reception
- subcontractor access to client systems
- remote access to smart building platforms
- email chains containing incident details
You also need records that show how your business approaches privacy. Smaller businesses do not get a free pass on the basics just because the operation is busy or site based.
When This Issue Comes Up
Privacy data collection rules for facilities management company operations usually become urgent when a contract, site rollout or incident exposes gaps that were easy to miss earlier.
Most businesses do not review privacy in isolation. The issue tends to appear at moments where commercial pressure is high and decisions are being made quickly.
When tendering for a new client
Many tenders ask detailed questions about data protection, security standards, CCTV use, subcontracting and incident handling. If your documentation is thin, you may lose the opportunity or sign terms that create obligations you are not ready to meet.
Before you sign a contract, check whether the client expects:
- specific retention periods
- named security controls
- data processing terms
- restrictions on offshore hosting or support
- audit rights
- mandatory breach reporting timeframes
When introducing building technology
Smart lockers, desk booking systems, occupancy sensors, access apps, QR visitor systems and integrated CCTV can all increase privacy risk. The legal issue is not just the technology itself, but whether the collection is proportionate, explained properly and limited to a genuine need.
If a system tracks individual movement, creates behaviour profiles or links data across multiple sources, a more careful assessment may be needed before rollout.
When using CCTV and surveillance
CCTV is one of the most common flashpoints in facilities management. Businesses often install cameras for broad security reasons but fail to define coverage, retention, access rights and response procedures.
Extra care is needed if surveillance could be viewed as intrusive, such as staff monitoring in break areas, audio recording, body worn cameras, covert monitoring or cameras covering neighbouring spaces.
When subcontractors are involved
Cleaning teams, maintenance engineers, concierge services, alarm response contractors and specialist security providers may all come into contact with personal data. If those suppliers access systems, records or footage, your contracts should reflect that.
A handshake arrangement or purchase order is rarely enough where personal data is involved.
When a person makes a complaint or request
A tenant may ask for CCTV footage. An employee may request records about monitoring. A visitor may complain that they were not told data was being collected. These moments reveal whether your business can identify the right data, locate it quickly and respond within the legal timeframe.
When there is a breach
A lost phone, misaddressed email, exposed visitor log or hacked building management platform can all amount to a personal data breach. Once that happens, your business needs a clear response process, not an improvised discussion between operations and IT.
Practical Steps And Common Mistakes
The best approach is to build privacy into contracts, systems and site procedures early, not after a complaint lands on your desk.
Facilities management businesses usually need a mix of legal documents, operational controls and internal training. Here’s what to sort out first.
1. Map your data properly
You need a practical record of what your business collects and why. That means more than listing software names.
Your mapping should cover:
- what data is collected
- who it relates to
- where it comes from
- why you use it
- who can access it
- where it is stored
- how long it is kept
- whether it is shared with clients or suppliers
Common mistake: treating CCTV or site logs as operational records rather than personal data.
2. Match your privacy notices to real collection points
Your notices should reflect the actual journey people have with your business. A website privacy policy on its own will not explain surveillance, visitor logs or onsite reporting tools.
Think about each audience separately. Staff, visitors, occupiers and client contacts may need different wording and different delivery methods.
Common mistake: using one generic privacy notice for every service line and every site.
3. Put proper data processing clauses in your contracts
If you process data for clients, your service agreement should deal with the data protection position clearly. If your suppliers process data for you, your supplier agreements should do the same.
Good contract drafting usually covers:
- who is controller and who is processor
- the subject matter and duration of processing
- the type of personal data and categories of people involved
- security expectations
- subprocessor approval rules
- breach notification obligations
- return or deletion of data at the end of the contract
- audit and information rights where appropriate
Common mistake: assuming a client’s standard terms deal with all of this fairly or accurately.
4. Review CCTV and monitoring practices carefully
If your business uses surveillance, document why it is needed and whether a less intrusive option would work. Make sure signage and supporting privacy information are aligned with what the system actually does.
You should also decide:
- who can view footage
- how requests are handled
- how long footage is kept
- when footage can be shared
- how access is logged
Common mistake: keeping footage indefinitely because storage is cheap or because nobody set a deletion rule.
5. Secure phones, tablets and onsite records
A lot of FM data risk sits in day to day operations. Engineers and site teams may take photos, capture names at reception, use messaging apps or carry incident notes between locations.
Practical controls often include:
- device passwords and mobile management tools
- rules on personal device use
- secure upload procedures for photos and reports
- restricted access to cloud folders and portals
- clean desk and paper disposal rules for reception areas
- staff training on phishing and misdirected emails
Common mistake: writing a policy that does not match how field teams actually work.
6. Set realistic retention periods
Personal data should not be kept for longer than necessary. In FM businesses, that usually means different retention periods for different records.
For example, CCTV footage, visitor records, maintenance call recordings, complaint files and accident reports may each justify different retention decisions. The right period depends on purpose, legal obligations, claims risk and client arrangements.
Common mistake: a blanket rule that says everything is retained for the same number of years.
7. Prepare for data subject requests and breaches
You do not need a large legal team, but you do need a clear process. Someone in the business should know how to recognise a subject access request, how to escalate a possible breach, and when to involve the client if data is handled on their behalf.
Write down:
- who owns the response
- how deadlines are tracked
- how data is searched across systems
- when identity checks are used
- how exemptions are considered
- when clients and regulators may need to be notified
Common mistake: treating requests informally and missing the one month response window.
8. Check whether a DPIA is needed
A data protection impact assessment, often called a DPIA, may be needed where processing is likely to result in high risk to individuals. This can be relevant for large scale monitoring, biometric access systems, extensive CCTV use or tracking tools in sensitive environments.
A DPIA is not just a form to file away. It should test necessity, proportionality, risks and safeguards before you spend money on setup.
9. Train managers and site leads
Privacy compliance often fails at handover points. Site managers, reception teams, security supervisors and operations leads need simple guidance that fits the work they actually do.
Common mistake: limiting training to office staff while onsite teams make most of the real world collection decisions.
10. Align privacy with wider business documents
Your privacy position should fit with your broader legal setup. That can include your business structure, client terms, subcontractor agreements, employment contracts, acceptable use policies and any registration or licence style requirements relevant to the site or service.
If you are scaling, selling online, using a new business name or expanding into new verticals, check whether your trade mark, customer terms and internal policies still match the way data is actually collected and used.
FAQs
Do facilities management companies need a privacy policy?
Usually yes, but one policy is rarely enough on its own. Most FM businesses need a public facing privacy notice and may also need staff, visitor, CCTV or contractor specific notices depending on how data is collected.
Can we rely on consent for CCTV and visitor data?
Usually not as the main basis. In many site security situations, legitimate interests or legal obligation is more suitable, provided the collection is necessary, proportionate and properly explained.
Who owns the data when we manage a client site?
There is no single rule. It depends on who decides the purpose and means of processing for each activity. In some cases the client will be the controller and the FM company will be the processor, but some activities may make the FM company a controller in its own right.
Do we need contracts with subcontractors who might access personal data?
Yes, in most cases you should have written terms dealing with data handling, confidentiality, security, breach reporting and deletion or return of data. This matters even where the subcontractor only has occasional access.
How long can we keep CCTV footage and visitor logs?
There is no universal retention period. You should keep data only for as long as necessary for the stated purpose, taking into account security needs, complaints, claims risk, client obligations and any legal requirements.
Key Takeaways
- Facilities management businesses often collect personal data through security, maintenance, reception, building technology and incident handling, even where that is not the main service being sold.
- UK privacy compliance depends on identifying what data you collect, why you collect it, your lawful basis, and whether you act as controller, processor or both.
- Generic privacy wording is rarely enough for FM operations. Your notices, contracts and site procedures should reflect real collection points such as CCTV, visitor systems and helpdesk tools.
- Client contracts and subcontractor agreements should clearly deal with data protection responsibilities, security, breach handling and end of contract data return or deletion.
- Common mistakes include overcollecting data, retaining it too long, using intrusive monitoring without proper assessment, and ignoring everyday risks in mobile and onsite working.
- Practical preparation matters most before you sign a contract, introduce new building technology or respond to a complaint, request or breach.
If your business is dealing with privacy data collection rules for facilities management company and wants help with privacy notices, data processing agreements, CCTV compliance, supplier contracts, you can reach us on 08081347754 or team@sprintlaw.co.uk for a free, no-obligations chat.
Get your customer-facing terms right
When should you formalise this?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.






