Home services and trades
Who owns building automation system data?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Building automation data is usually controlled by the building owner, while the controls contractor keeps rights in its own tools, methods and service records, and the software vendor controls its platform and whatever its terms reserve. No single default rule settles it: the installation contract, service agreement and software license decide, so read those three first.
Key takeaways
- Trend logs, alarms and point histories a building generates are usually treated as the owner's data under turnover and service contracts.
- Controls contractors typically keep rights in their own programming libraries, tools and internal service records unless a contract transfers them.
- Cloud analytics and platform vendors may reserve rights to aggregated or de-identified data in their terms.
- Turnover clauses on programs, passwords and licenses often decide disputes more than ownership language does.
- A contractor's programming is protectable as a trade secret only if the contractor takes reasonable measures to keep it secret.
Who owns building automation data by default?#
Building automation data has no single default owner; the installation contract, the service agreement and the software license usually decide. In practice, data the building generates, such as trend logs and alarms, tends to be treated as the building owner's, while the controls contractor's methods and the vendor's software stay with them.
Many contracts were written before cloud analytics and remote access became routine, so they say a lot about drawings and warranties and little about trend data. Where contracts are silent, disputes turn on what was delivered at turnover, what the parties did in practice and which laws may apply, which is a question for counsel.
For a controls contractor, the useful question is narrower: which records can we keep, reuse or license, and which belong to customers?
Who controls what: owner, contractor and vendor#
The table shows the usual position for each type of record and who typically controls it. It reflects common contract patterns, not a legal rule, and any specific agreement can change the answer.
| Record or asset | Building owner | Controls contractor | Software or platform vendor |
|---|---|---|---|
| Trend logs and point histories | Usually controls as building data | Access under the service agreement | May host it; rights depend on terms |
| Alarm and event logs | Usually controls | Uses them to deliver service | May process them in a cloud platform |
| Site control programs and sequences | Often receives a copy at turnover | Often keeps rights in reusable code and libraries | Owns the programming tools |
| Graphics and point database | Usually receives at turnover | May keep templates and naming standards | Owns the software that renders them |
| Software and firmware licenses | Licensee if registered in its name | Licensee if registered in its name | Owns the software |
| Contractor service tickets and PM notes | Receives reports as deliverables | Usually owns its internal records | Not involved unless hosted |
| Aggregated or de-identified usage data | Depends on contract | Depends on contract | Often reserved in platform terms |
Contract clauses that decide ownership#
Ownership is settled, or left open, by a handful of clauses. Read these in every installation contract, service agreement and software license before deciding what you can do with the records.
Where clauses conflict, such as a broad confidentiality clause in the service agreement and a data-use clause in a platform's terms, counsel should decide which governs for the specific use you have in mind.
- Deliverables and work product: which programs, graphics and documents become the owner's property.
- License back: whether the contractor keeps the right to reuse code, libraries and standards on other jobs.
- Turnover and closeout: which programs, passwords, licenses and backups must be handed over.
- Data access and use: who may collect, store and analyze trend and alarm data during the service term.
- Confidentiality: whether building data counts as the owner's confidential information.
- Platform terms: whether the vendor may use aggregated or de-identified data, and for what purpose.
- Termination and transition: what each party keeps, returns or destroys when the agreement ends.
What a controls contractor can usually reuse#
A controls contractor can usually reuse its own internal records and know-how, subject to confidentiality terms, but needs permission to reuse a customer's building data. The distinction matters most when a contractor wants to analyze trend data across sites or license records to a third party.
Remote access adds a wrinkle. When a contractor connects to a site through a cloud gateway or a remote workstation, copies of trend data can end up on the contractor's own servers or in a vendor's analytics platform. Those copies usually remain the customer's building data under the contract, even though they sit on equipment the contractor controls. Map where copies live before assuming anything on your servers is yours to reuse.
| Record | Likely position | What to check before reuse |
|---|---|---|
| Service tickets, PM checklists and technician notes | Contractor's own records | Confidentiality clauses naming customer information |
| Commissioning workflows and test procedures | Contractor's own methods | Whether project specs made them deliverables |
| Programming libraries and templates | Contractor's own, if protected | License-back language and turnover copies |
| Site trend logs and alarm histories | Customer's building data | Express data-use rights or written permission |
| Data held in a vendor cloud | Shared by contract | Platform terms on export and reuse |
Protecting your programming and libraries#
Programming libraries and sequence templates are often a controls contractor's most valuable know-how, and their legal protection depends on how the contractor treats them. Under the federal Defend Trade Secrets Act, information is a trade secret only if its owner has taken reasonable measures to keep it secret and it derives independent economic value from not being generally known.
Department of Justice guidance says protective measures need not be absolute but must be reasonable under the circumstances, such as limiting access on a need-to-know basis and requiring confidentiality agreements. Reasonable measures in a controls business may include confidentiality terms in customer and employee agreements, access controls on code repositories, marking libraries as confidential, and leaving on site only what contracts require at turnover. Handing unrestricted source libraries to every customer weakens that position.
The same logic runs in reverse. If a customer's confidential building information sits in your systems, your agreements may require you to protect it with similar care, and a careless reuse could breach them even when no harm follows.
Illustrative: a controls contractor reviews its agreements#
Illustrative: a fictional mechanical and controls contractor services building automation systems for office landlords and a university campus. Its leaders want to know whether years of service tickets, commissioning reports and trend data could be licensed to AI developers studying building operations.
Counsel reviews the service agreement templates. Most give the contractor ownership of its internal service records and require confidentiality for customer information; none grants rights to reuse trend data. One landlord's agreement expressly allows de-identified analytics.
The contractor scopes a license to its own service tickets and commissioning workflows, with site names and addresses removed, and asks that one landlord for written permission to include its trend data. Every other customer's trend logs stay out.
How SourceX handles building automation records#
SourceX handles building automation records by separating what a contractor owns from what its customers own before anything else happens. The rights step of the SourceX five-step transaction reviews installation contracts, service agreements and platform terms, and customer building data is excluded unless written permission covers the specific use.
For records that proceed, the SourceX Evidence Packet documents provenance, licensing rights, permitted use, the privacy record and release authorization. The contractor approves every step and keeps ownership, and large trend archives can stay in the contractor's own storage.
Frequently asked questions
Does an open protocol like BACnet change who owns the data?
No. Open protocols such as BACnet affect how systems communicate and how easily another contractor can service them, not who owns the data. Ownership and use rights still come from contracts and software terms. Open systems can make turnover simpler, which tends to reduce disputes.
Can a building owner demand our source programs at the end of a contract?
It depends on the contract. Some agreements require full programs and backups at turnover; others require only what is needed to operate and service the system. Read the deliverables and turnover clauses, and raise questions with counsel before refusing or handing over code.
Are building automation logs personal data?
Usually they describe equipment, but some can relate to people, such as occupancy sensors, badge-linked access events or logs tied to named tenants. Privacy laws may apply to those records depending on the state and context. Identify them in any inventory and treat them separately.
Can we analyze trend data across our customers to improve service?
Only within the rights your contracts give you. Using a customer's data to serve that customer is usually covered; combining data across customers for analysis or products may need express permission. Review data-use language with counsel before building anything that depends on it.
What should we put in new service agreements?
Spell out who owns building data, what the contractor may do with it, whether de-identified or aggregated use is allowed, and what happens at termination. Clear terms now prevent disputes later and keep options open for analytics or licensing with the customer's knowledge.
Sources
- Under 18 U.S.C. 1839(3), as defined by the Defend Trade Secrets Act of 2016, information is a trade secret only if its owner has taken reasonable measures to keep it secret and it derives independent economic value from not being generally known. Source
- DOJ guidance states that trade secret protective measures need not be absolute but must be reasonable under the circumstances, citing examples such as limiting access on a need-to-know basis and requiring confidentiality agreements. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.