Skip to content

Engineering and architecture

How engineering firms can explain data use to clients

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Engineering firms explain data use to clients best by settling each client's scenario before the conversation: excluded, included in de-identified form, or included only with written consent. Then say plainly which record types are involved, what is removed, what never leaves the firm and who approves. Contract terms decide the scenario, not the relationship.

Key takeaways

  • Sort every client into one of three scenarios before anyone calls: excluded, de-identified inclusion or consent-based inclusion.
  • Clients worry most about drawings, site details, their staff's names and pricing, so prepare answers on those four points first.
  • De-identified inclusion still deserves a clear explanation of what is removed and how a person checks the removal.
  • A consent request should name record types, projects, form, purpose and how the client can withdraw before release.
  • Record every client decision against the client and project so the rights review can rely on it later.

What should an engineering firm tell clients about data use?#

An engineering firm should tell clients four things about data use: which record types are involved, whether that client's projects are included, in what form, and who approved the release. Clients rarely object to the idea in the abstract. They object to surprises, vague answers and the sense that their drawings left the building without anyone asking.

The records that interest AI developers are mostly the firm's own working history: RFI responses, submittal review comments, internal QA checks, design review notes, scope changes and the reasoning behind them. Stamped drawings, client-furnished surveys and site security details are a different category, and saying so early takes most of the heat out of the conversation.

Data is licensed, not sold outright. The firm keeps ownership, and the license limits how the buyer may use the records. That distinction is worth stating in plain words, because many clients hear 'selling data' and picture their project files posted somewhere.

Decide the client's scenario before the conversation#

The client's scenario should be settled internally before a principal calls anyone. Three scenarios cover almost every client relationship, and each leads to a different conversation, a different entry in the project file and a different amount of effort.

Contract terms decide the scenario first and the relationship second. An agreement with a broad confidentiality clause, a no-AI-use clause or client ownership of all project documents points toward exclusion or consent. An agreement that is silent on the firm's internal work product may allow de-identified inclusion, subject to the rights review and counsel's reading.

Decide the client's scenario before the conversation
ScenarioTypical fitWhat you tell the clientWhat you record
Excluded clientRestrictive confidentiality terms, security-sensitive sites, or a client who has already said noTheir projects are not part of any license, and nothing changes for themAn exclusion flag at client level
De-identified inclusionThe agreement allows internal use of work product and records can be stripped of identifying detailWhich internal record types may be used, what is removed and how removal is checkedThe clause relied on, any notice date and the preparation log
Consent-based inclusionThe agreement is unclear or gives the client control, and the records justify the effortA specific written request covering record types, form, purpose and approval rightsThe signed consent and any conditions the client added

Which client questions come first, and how to answer them#

Client questions about data use cluster around a few worries, and a prepared answer for each keeps the conversation short. Project managers should hear these answers too, because clients often ask the person they meet every week rather than the principal.

Which client questions come first, and how to answer them
Client questionPlain answer to prepare
Are our drawings and models going to an AI company?State whether issued drawings, models and client-furnished files are excluded, and if not, exactly what form they would take.
Could anyone tell the project was ours?Explain that names, addresses, parcel and permit numbers, title blocks and seals are removed, and that a person reviews the result.
Will our staff's names or emails appear?Explain that personal details of client staff are removed or replaced, and that correspondence is reduced to its technical content.
Does this expose our budgets or bids?Say whether fee and cost records are excluded, generalized or delayed, and why.
What do we get to approve?Name the decision points the client controls in its scenario, and the point after which the package is fixed.

Scenario one: the excluded client#

An excluded-client conversation is the shortest of the three and often the most useful for trust. The message is that the firm has reviewed its agreements, that this client's projects will not be part of any data license, and that the firm is telling them so they hear it first.

Exclusion makes sense for utilities and critical infrastructure owners, clients with security-sensitive facilities, projects under claims or litigation, and any client whose agreement gives it ownership or control of all project documents. Excluding a client often costs less than it first appears, because the firm's QA procedures, templates and general methods can still be reviewed separately.

Tag exclusions at the client level, not the project level, so a new project for the same client inherits the flag automatically in Deltek, BQE Core or whichever system holds the project list.

Scenario two: de-identified inclusion#

De-identified inclusion means the client's projects contribute internal working records after identifying details are removed, so the conversation centers on what removal covers. Some firms notify these clients even when the contract does not require it, because a short letter now is easier than a difficult call later.

For engineering records, identifying details go well beyond names. Title blocks, seals, sheet borders, project numbers, permit and parcel numbers, coordinates, street names in drawing notes and photographs of recognizable sites all carry identity. RFI and submittal logs often name the contractor, the owner's representative and the building official.

Explain that automated tools do part of the work and people check the rest. Presidio, an open-source de-identification toolkit, states in its own documentation that automated detection cannot guarantee finding all sensitive information and that additional protections should be used. That is an honest point to share with a client who asks how removal is verified.

Consent-based inclusion applies when the firm wants records the client has a say over, and it starts with a written request rather than a phone call alone. A specific request is easier for the client's counsel to approve than an open-ended one.

Keep the request free of hype and free of any figure about what the records might be worth. Value is known only once a buyer engages, and a client who sees a number tends to ask for a share of it before reading the rest.

  • Record types requested, named concretely: RFI log with responses, submittal review comments, design review notes, change documentation.
  • Projects covered, by name or date range.
  • Form of release: de-identified, with the categories of detail removed.
  • Purpose and permitted use in the license's terms, and confirmation that the firm keeps ownership.
  • What stays out entirely, such as drawings, models, site security information and client-furnished documents.
  • The client's approval point and how to withdraw consent before release.
  • A named contact at the firm for questions.

Illustrative: a civil and structural firm sorts its client list#

Illustrative: a fictional civil and structural engineering firm with three offices keeps projects in Deltek Vantagepoint, RFIs and submittals in Procore, and review markups in Bluebeam. Before anyone is contacted, the managing principal asks the contracts manager to sort active and recent clients into the three scenarios.

A regional water utility lands in the excluded group because its agreement treats all project information as confidential and its sites are security-sensitive. Most private developers fall into de-identified inclusion, and each receives a short notice letter listing the internal record types. One manufacturing client's agreement gives it control of all project documents, so the firm sends a consent request covering RFI responses and design review notes only. The client approves on condition that process equipment layouts stay out, and the firm records that condition against every affected project.

How SourceX approaches client communication#

SourceX treats client communication as part of the Rights step in the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. Each client's scenario is settled during the rights review, before preparation starts, and the firm approves every step.

The decisions are documented in the SourceX Evidence Packet, which records provenance, licensing rights, permitted use, the privacy record and release authorization. A consent letter or exclusion flag becomes part of that record, so the firm can show any client exactly what was decided and why.

Frequently asked questions

Should we tell clients even when the contract allows de-identified use?

Often yes, though it is a judgment call. A short notice letter costs little, and a long-standing client hears the news from a principal rather than from a rumor. Some firms notify only clients with active work; others notify everyone in scope. Counsel can say whether any agreement requires notice.

What if a client says no after its records were prepared?

Remove them. Until release is approved, any project can be pulled from the package, and the preparation log should show the removal. Pulling a client late means some rework, which is one reason to settle every scenario before preparation begins rather than during it.

Do former clients need to hear from us?

Former clients are covered by the same agreements as current ones, so their scenario still depends on the contract. Many firms contact former clients only where consent is needed and rely on the contract elsewhere. Keep the decision and its reason in the project file either way.

Who should lead the conversation, the project manager or a principal?

A principal should lead, with the project manager briefed beforehand. Clients take the message more seriously from someone who can make commitments, and project managers need to give the same answers if the subject comes up later in a site meeting or a weekly call.

What should employees say if a client raises it informally?

Employees should give the short, accurate version and route details to a named principal. A one-page internal FAQ helps: which record types are involved, what is excluded and who to contact. Guessing in a site meeting creates more concern than saying who has the answer.

Sources

  • Presidio's own documentation warns that because it uses automated detection mechanisms, there is no guarantee that Presidio will find all sensitive information, and additional systems and protections should be employed. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify