What Is The Data Paradox For Smart Buildings?
Smart buildings are built on a simple proposition: the more closely a property can be measured, the better it can be managed. In September 2026, that proposition acquired new regulatory force.
On 1 September 2026, the UK government confirmed that, from 1 September 2027, new fixed-term energy contracts for smaller businesses and public-sector sites will require consumers to have, or agree to install, a smart or advanced meter. Eleven days later, a new obligation under the EU Data Act began applying to connected products and related services placed on the European market, requiring the data they generate to be accessible to users by default.
The measures address different parts of the same problem but point in the same direction: more building data, made available in more usable form. The earlier property-data debate centred on information held around the asset - listings, transactions and valuations. Smart-building data is generated inside the asset itself, continuously, by its systems and by the people using it.
A half-hourly meter reading can help an owner identify waste or plan a retrofit. It can also show when a business opens, closes or stops using a space. An access log can secure a building while creating a record of who entered, when and how often. The same dataset can describe both the asset and its occupants.
This is the smart building’s data paradox. The detailed information needed to manage a building, cut emissions and comply with new rules can also become a record of behaviour. The question is no longer only who owns building data, but how much an owner needs to know about the people inside the asset - and who else should be allowed to see it.
The building becomes a connected product
The EU Data Act offers one of the clearest attempts to address the first part of that question.
The regulation has applied generally since 12 September 2025. It gives a person or business that owns, rents or leases a connected product the right to access data generated through its use and, in many circumstances, have that information transferred to a third party.
From 12 September 2026, connected products and related services placed on the EU market must be designed so that the data they generate is, by default, easily and securely available to users, free of charge and in a machine-readable format. Where technically feasible, it must be directly accessible.
Many of the components used to make a building smart - from environmental sensors and connected controls to heating and lighting systems - may fall within this framework. The European Commission says the rules cover raw and pre-processed sensor data, including information on temperature, pressure, flow and position. More highly inferred or derived information generally sits outside it.
That distinction matters because a smart-building system does not produce only one kind of information. An owner might be entitled to access the temperature readings produced by a connected heating system without automatically acquiring the vendor’s analysis of how the building should be operated. The raw data, the interpretation and the service built around it may be controlled by different parties.
The Act therefore allocates rights to access, use and transfer data rather than attempting to establish a single owner. That reflects the reality of a smart building. The property owner may own the equipment, the tenant may use it, a facilities manager may operate it and the technology provider may hold the resulting information. Where the data relate to identifiable occupants, those individuals may have separate rights of their own.
The legislation opens more of the system, but it does not make its competing interests disappear.
When a meter measures the tenant
Britain’s new policy for non-domestic smart meters brings this tension into practical focus.
The government’s final response, published on 1 September 2026 , covers approximately three million meters across smaller businesses and public-sector sites. At the end of the first quarter of 2026, 67% of smaller non-domestic sites already had a smart or advanced meter.
From 1 January 2027, suppliers must begin informing consumers about the next stage of the rollout. From 1 September 2027, any new fixed-term energy contract within the initial scope of the policy must include a condition that the consumer already has, or agrees to install, a smart or advanced meter. Suppliers must also comply with a legally binding consumer-protection code from that date.
A consumer can still decline the installation and choose another form of energy contract. However, the government describes fixed-term contracts as significantly cheaper than the alternatives commonly available in the non-domestic market. The choice therefore remains, but not necessarily on equivalent commercial terms.
In qualitative research published alongside the policy , participants wanted suppliers to state that alternative clearly and explain what would happen if they agreed to an installation but could not complete it. The study involved 43 energy decision-makers, including 14 tenants, and no landlords, so it provides useful evidence about communication rather than the scale of landlord-tenant disputes.
The government estimates that smart metering could reduce electricity use among smaller businesses and public-sector sites by 2.8% and gas consumption by 4.5%. Its impact assessment projects that the policy will help take non-domestic smart-meter uptake to 88% by the end of 2030.
Those figures explain why owners want the resulting data. It is difficult to identify waste, assess an intervention or plan investment without knowing how a property is actually using energy. Yet in a rented commercial building, the tenant may hold the energy contract and control access to the readings, while the landlord remains responsible for the performance and long-term value of the asset.
Commercial-property representatives asked the government to require tenants to give landlords access to half-hourly consumption data. The government declined. It concluded that readings at that level of detail could reveal information about a tenant’s commercial operations and, where only a small number of people occupy the premises, might also constitute personal data. Respondents had provided no quantitative evidence that tenant refusal was widespread enough to justify mandatory access.
The result is a three-way split. The tenant’s activity produces the consumption pattern, the supplier holds the readings, and the landlord may need the information to improve the building. The government is making the meter increasingly difficult to avoid while leaving access to its most detailed data dependent on consent, third-party services or the terms of a green lease.
Smart metering does not resolve real estate’s familiar split incentive. It turns it into a data problem: the party expected to improve the building may not control the information needed to understand it.
When operational data becomes behavioural
The sensitivity of building data depends not only on what is measured, but on how frequently it is recorded and what it is combined with.
A monthly energy total says how much electricity a property consumed. Half-hourly readings begin to show when that consumption occurred. Add access, temperature, lighting or air-quality data, and the same system can start to explain the activity behind it.
A 2023 study using hourly smart-meter readings developed a model that identified whether a home was occupied with nearly 92% accuracy. The result comes from a particular model and dataset, rather than representing the performance of every meter. It nevertheless demonstrates what can be inferred from information that appears, at first glance, to describe only energy consumption.
The capabilities of these systems also appear to be developing faster than occupants’ understanding of them. A 2022 study of commercial smart buildings found that only 19.75% of occupants in the building studied recognised that the information being collected could be related to them. Once the implications were explained, more than half expressed concern about how occupancy data might be used.
Part of the difficulty is that most building sensors do not appear to collect personal information. A carbon-dioxide sensor measures air quality, a thermostat records temperature and an access system secures a door. Analysis can turn those readings into estimates of occupancy, working patterns and movement through a building.
Some regulators have started drawing boundaries around particular systems. New York City’s Tenant Data Privacy Law , adopted in 2021, requires express consent for certain data used by smart-access systems in multiple dwellings. It limits collection to what is needed to provide access, generally requires authentication data to be destroyed within 90 days and prohibits using access information to harass or evict tenants.
The law is relatively narrow. It governs smart access rather than the full range of information collected by a connected building. But it establishes an important principle: data gathered for one operational purpose should not quietly become available for another.
The privacy risk therefore lies not only in the individual sensor. It lies in what can be inferred when apparently routine measurements are analysed together.
Performance rules meet the data gap
Limits on access are emerging just as regulators are asking owners to provide better evidence of how their buildings perform.
The revised EU Energy Performance of Buildings Directive entered into force on 28 May 2024. Its general deadline for national transposition was 29 May 2026, and member states must submit their final national building-renovation plans by 31 December 2026.
Approximately 75% of European buildings have poor energy performance, while the annual renovation rate remains around 1%. The directive is intended to accelerate that process by triggering the renovation of the worst-performing 16% of non-residential buildings by 2030 and 26% by 2033.
It also provides for digital energy-performance certificates, national databases of building information and greater use of automation and control systems in non-residential property. The precise obligations will differ between member states, but the direction is consistent: building performance is becoming more measurable, comparable and difficult to treat as an estimate.
That exposes a particular weakness in multi-let property. An owner may have detailed information about the energy used in common areas but limited visibility of consumption within individual units. The resulting data may show that a building is performing poorly without explaining where the problem sits or which investment would address it.
The gap affects more than regulatory reporting. It can limit an owner’s ability to plan capital expenditure, verify whether improvements have worked and explain changes in performance across a portfolio. At the same time, the most detailed tenant data may disclose more about the occupier’s business than the landlord needs to know.
Performance and privacy rules are not necessarily in conflict. They are asking the same data to perform different functions. The challenge is to make the building visible enough to manage without making its occupants equally visible.
Access matters more than ownership
A smart building does not produce one dataset. It produces layers of information with different users, purposes and levels of sensitivity. Equipment-performance data may reasonably need to follow the asset. Consumption data may belong within the commercial relationship between landlord and tenant. Access records may require tighter limits because they describe identifiable people rather than simply the building.
The EU Data Act reflects that distinction by allocating rights rather than awarding ownership. Users can access and transfer much of the data generated through connected products, while personal information remains subject to data-protection law and commercially sensitive material can retain additional safeguards.
It is also beginning to address the systems in which building data becomes trapped. From 12 January 2027, the Act will prohibit switching and data-egress charges for cloud and edge services. For owners relying on cloud-based building platforms, easier switching could matter as much as access to the underlying sensor data. Information is of limited practical value if moving it to another system is prohibitively expensive or technically difficult.
The more useful model is therefore not one in which every party receives every reading. It is one in which access follows purpose. Owners need sufficient information to manage performance and investment. Tenants need to understand what their occupation reveals. Technology providers need clearly defined rights to process the information required to provide their service, without treating all data passing through their systems as an indefinitely reusable asset.
That division will need to be reflected in leases, technology contracts and transactions. Agreements will have to address not simply who can view the information, but at what level of detail, for what purpose, for how long and what happens to it when a tenancy ends, a platform changes or the building is sold.
Making buildings more measurable is becoming both a regulatory and commercial necessity. The harder task is deciding who is entitled to read them and ensuring that better visibility of the asset does not become unrestricted visibility of its occupants.