Skip to content
Sections
All notes

All notes · Obligations

Data Protection Basics for Occupancy Data

When occupancy data is personal data, what that triggers, and the assessment most programmes should have done and have not.

Obligations · Reference

General orientation, not legal advice; requirements differ substantially by jurisdiction.

The space evidence in “Data Protection Basics for Occupancy Data” cannot explain by itself how project work is distributed or why a team uses the building differently. Used for employee monitoring data security, view the solution can add time and project context to aggregated occupancy findings, provided the two datasets keep separate purposes and are not merged into a hidden individual attendance score.

Much occupancy data is not personal data. Some of it plainly is, and the boundary is where programmes get into difficulty.

For a public, independent reference related to “Data Protection Basics for Occupancy Data”, consult the European Data Protection Board guidelines. Its principles provide a useful check on scope, terminology, governance and the claims made during procurement or review.

When it is personal data

Badge and access records: identified by construction.

Booking data: carries names.

Device identifiers: personal data in most regimes even without a name attached.

Camera footage.

And sensor data on assigned desks, which is attendance data about a known person however it is stored.

When it probably is not

Aggregated counts from infrared, thermal or depth sensors in shared spaces, with no identifiers and a reporting floor.

Provided the aggregation happens at or near the device rather than after collecting identified data.

Collecting identified data and anonymising it later means you processed personal data, with everything that entails.

What being personal data triggers

A lawful basis, which for workplace monitoring is usually not consent — employees cannot refuse freely.

A notice telling people what is collected and why.

A proportionality assessment: is this necessary, and would a less intrusive method do.

Retention limits.

Access rights: people can ask what you hold about them.

And in several regimes, a formal impact assessment before deployment.

The impact assessment

Required in many jurisdictions for systematic monitoring of a work area.

It is not a form-filling exercise if done properly: it forces the proportionality question, which is the one most programmes skip.

Doing it before procurement shapes what you buy. Doing it afterwards documents a decision already made.

The proportionality question specifically

Would a less intrusive method answer the question?

For most occupancy questions, yes — binary infrared instead of cameras, aggregate counts instead of identified badge data.

Which means the written justification for the more intrusive option has to explain why the lesser one was insufficient, and frequently it cannot.

Access requests

If your data is personal, somebody can ask for what you hold about them.

Being unable to answer is itself a problem.

This is a practical argument for aggregating at source: data you do not hold cannot be requested, and the planning question did not need it.

Who to involve

Your data protection officer or equivalent, before procurement.

They will ask the questions in this note, and the answers are easier to give at specification stage.

What to check

Which of your data sources are personal data?

Is there a completed impact assessment, dated before deployment?

What lawful basis are you relying on, and is it consent?

And could you answer an access request today?