All insights Construction

Who owns the data your PropTech platform generates on a UAE construction site?

UAE · construction technology
Photo: Nico Knaack / Unsplash

As developers and contractors bolt AI monitoring, BIM and IoT sensors onto UAE projects, the unresolved question is not whether the technology works, it is who owns the data it produces, and whether that data becomes the evidence that decides a decennial liability claim a decade later.

Why this matters now

The Innovo/Dubai PropTech tie-up is one of several signals that construction technology, BIM modelling, drone inspection, IoT structural sensors, AI-driven defect detection, is moving from pilot projects to standard practice across UAE developments. Contractors and developers are adopting these platforms under vendor terms drafted for a software sale, not for a construction dispute that might surface eight years after handover. That mismatch is the real exposure.

The decennial liability backdrop

Under the UAE Civil Code (Federal Law No. 5 of 1985), the contractor and the supervising engineer carry joint decennial liability for total or partial collapse of a building, or defects that threaten its stability, for ten years from handover (Article 880). This liability is mandatory: it cannot be contracted out of, and it survives even where the employer accepted the works without objection. Any evidence bearing on the cause and timing of a structural defect is potentially relevant for the full decade, and often beyond it once a claim is filed and litigated.

PropTech platforms now generate exactly that kind of evidence continuously: sensor logs showing load stress at the time of pour, BIM model revisions showing design changes mid-build, drone survey imagery showing curing conditions, AI flags on anomalies that were or were not escalated. None of this existed in the paper-file era. It now sits on a vendor's servers, often outside the contractor's control, and often subject to a retention policy set by the vendor's commercial terms rather than the ten-year exposure window the Civil Code imposes.

The ownership gap

Most PropTech vendor agreements are procured quickly, frequently by a project manager rather than legal, and rarely address:

  • Who owns the raw data versus the vendor's processed analytics and dashboards
  • Whether the contractor or developer has an unrestricted, perpetual licence to retrieve raw records after the contract ends
  • Data retention periods, and whether they match the ten-year decennial window rather than a standard three or five-year SaaS default
  • Chain-of-custody and metadata integrity, so that records remain admissible as evidence years later
  • Who bears liability if the vendor's platform itself misreports a defect signal that a contractor relied on

Left unaddressed, a contractor can find itself unable to retrieve exculpatory sensor data because the vendor purged it after contract expiry, while the developer's own possession of the same data (obtained through its separate PropTech licence) becomes the sole evidentiary record in a dispute, on terms the contractor never agreed to.

The sensor log a vendor deletes after two years may be the only record that would have defeated a decennial liability claim filed in year nine.

Data protection adds a second layer

Where the platform captures personal data, site worker access logs, biometric turnstile records, driver telematics for plant and machinery, the UAE's federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) applies onshore, and the DIFC Data Protection Law (DIFC Law No. 5 of 2020) applies where a DIFC-registered vendor or group entity processes the data. Contractors need to know which regime governs before agreeing to a platform, because retention obligations, cross-border transfer restrictions and breach notification duties differ, and a developer's group data protection officer may impose retention limits that conflict with the ten-year litigation horizon.

Practical steps before rollout

  • Insist on a data ownership and licence clause in the vendor agreement that gives the contractor and the engineer of record a perpetual, exportable copy of all raw project data, independent of the vendor's own retention schedule
  • Align data retention terms with the ten-year decennial exposure window, not the vendor's standard commercial default
  • Require the vendor to preserve metadata (timestamps, device IDs, unedited version history) sufficient to support admissibility before the UAE courts or in DIFC/ADGM-seated arbitration
  • Check professional indemnity cover extends to claims where PropTech-generated data, rather than physical inspection, forms the primary evidence
  • Map which data protection law applies before data leaves the site, especially where the vendor stores records outside the UAE

Key instruments: UAE Civil Code (Federal Law No. 5 of 1985), Article 880 (decennial liability); UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021); DIFC Data Protection Law (DIFC Law No. 5 of 2020). This is general information, not legal advice.

Have a matter to discuss?

If a regulatory change or a dispute is on your desk, let's talk it through, confidentially and without obligation.

Get in touch