C-DRONE GUIDE · 20 AUGUST 2026
Drone data ownership and security: what the service contract must cover
A roof audit delivers fifty high-definition photos. A photogrammetry mission delivers a point cloud several gigabytes in size. Construction monitoring accumulates, month after month, orthophotos comparable over time. These files carry real value - as an asset, as evidence, sometimes strategically - that few drone quotes address explicitly. Who owns them? Where are they hosted? What happens to the archive if the provider closes down or switches tools? Here is what a serious drone service contract should cover, for companies and local authorities alike.
Published on 20 August 2026, reviewed on 20 August 2026 — regulations in force as of August 2026.
Who owns the files a drone captures?
The question sounds trivial - "I paid for the mission, so the files are mine" - but by default, the law says otherwise. An aerial photograph, an orthophoto or a 3D model produced by drone photogrammetry are works protected by copyright under article L112-2 of the French intellectual property code, exactly like the work of a photographer or a surveyor. The initial holder of that right is the author - the remote pilot or the company employing them - not the client who commissioned the mission. Without an explicit assignment clause in the quote, the client in practice gets an implied right of use limited to the contractual purpose (the inspection, the report, internal communication), not full ownership allowing resale, republication or reuse for other purposes.
This distinction matters a great deal for large, reusable deliverables: a point cloud, a database of mapped cracks, a history of thermal imaging campaigns compared year after year. This kind of data, not individually protected by copyright when it is raw, may fall under the database "sui generis" right (article L341-1 of the same code) once building it up represented a substantial investment - a common situation for a property portfolio tracked over several years. A contract that settles neither point leaves a damaging grey area: better to negotiate, from the quote stage, an explicit rights assignment covering the intended use, the duration and the geographic scope, rather than discovering the gap later in a disagreement - a scenario detailed in our guide to disputes with a drone provider.
GDPR: when the drone provider becomes a data processor
As soon as a drone mission captures identifiable people - employees on an industrial site, vehicles with readable number plates, residents near a construction site - it amounts to personal data processing under the GDPR. The company or local authority commissioning the mission is the "data controller"; the provider flying the drone and processing the images is the "data processor" under article 28 of the regulation. That article requires a detailed written contract: the subject, duration and purpose of the processing, the categories of data involved, security measures, the conditions for using a further sub-processor (a cloud host, for instance), and above all - point (h) of article 28.3 - what happens to the data once the mission ends: deletion or return, at the controller's choice. It is this precise clause, often missing from standard quotes, that protects the client when a contract ends or a provider changes. Our dedicated guide to GDPR and professional drones details the anonymisation obligations and the cases where an impact assessment (DPIA) becomes mandatory.
These obligations are not a mere formality: the fines set out in article 83 of the GDPR for a breach of article 28 reach €10 million or 2% of worldwide annual turnover, whichever is higher - an exposure that applies to the controller and the processor alike. The cost of compliance also weighs on companies' concrete trade-offs: a study by Mert Demirer, Diego Jiménez Hernández, Dean Li and Sida Peng, published in 2024 by the National Bureau of Economic Research, used seven years of data from a major cloud provider to show that European firms cut their data storage by 26% and their processing by 15% after the GDPR took effect, equivalent to roughly a 22% rise in the implicit cost of data (see the study on Google Scholar). In other words, negotiating these clauses at the quote stage costs less than restructuring data governance after the fact.
Hosting, encryption, backups: what a serious provider must guarantee
Beyond the legal framework, the operational security of drone data comes down to concrete, checkable points before signing. Hosting location first: storage within the European Union simplifies GDPR compliance and avoids the standard contractual clauses required for any transfer outside the EU. Encryption next - both for files at rest and for transfers to the client -, access control (authentication, logging of who viewed what) and a documented backup policy, so that an outage or a ransomware attack at the provider does not wipe out two years of roof monitoring or construction-monitoring history. These are not paperwork requirements: they directly determine the value of the service, since a lost or corrupted deliverable strips the client of the time comparison that makes periodic monitoring worthwhile.
The choice of hosting location also carries real economic weight, documented well beyond the drone sector alone: a study by Varadharajan Sridhar, Shrisha Rao and Sai Rakshith Potluri, published in 2020 in Telecommunications Policy, used agent-based simulation to model the effect of data localization rules on digital trade, showing that strict localization regimes reshape competition between local and international players, sometimes at the cost of reduced choice and service quality for the end client (see the study on Google Scholar). For a company, the practical takeaway is the same as with any cloud provider: ask explicitly where the data is hosted, not just whether it is "secure". The EU Data Act, in application since 12 September 2025, points the same way for cloud processing services: it strengthens clients' right to retrieve their data and, eventually, to switch providers without technical lock-in - a principle worth anticipating in a drone contract even before it applies explicitly to the sector.
The checklist of clauses to require before signing
In practice, a drone quote or contract that genuinely protects the client covers six points:
- Ownership of deliverables - explicit assignment of rights over photos, orthophotos, point clouds and reports, with the scope of use specified (internal, communications, resale to a third party).
- GDPR processing agreement - mandatory as soon as people are identifiable, with a clause on deletion or return at the end of the mission (article 28.3.h).
- Hosting location - preferably within the European Union, or explicit contractual guarantees for any transfer outside the EU.
- Retention period - defined contractually, with documented deletion procedures once it expires.
- Data portability clause - recovery of raw and processed data in an open format, independent of the provider's own software.
- Confidentiality and security - the provider's staff bound by confidentiality, encryption in place, and insurance covering, beyond aerial liability cover, the consequences of a data security incident.
This checklist should be negotiated at the same time as price and lead time, not afterwards: it is one of the criteria covered in our guide to choosing a professional drone pilot, alongside insurance and flight authorisations. For a recurring mission - construction monitoring, periodic thermal imaging, asset mapping - these clauses matter even more, since the accumulated history becomes, over time, the most valuable asset in the relationship. The simplest approach is to raise them explicitly from the very first quote request, rather than discovering - or regretting - their absence when a disagreement arises.
Frequently asked questions
Does the client of a drone mission automatically own the photos and files delivered?
Not necessarily. Images and 3D models are in principle protected by copyright in favour of their author - the remote pilot or their company - just as with a traditional photographer (article L112-2 of the French intellectual property code). Without an explicit assignment clause in the quote or contract, the client only holds a limited right of use tied to the mission's purpose, not full ownership that would, for instance, allow reselling or freely republishing the files.
Is a drone provider a data processor under GDPR?
Yes, as soon as the captured images allow people to be identified - workers on a site, vehicles with readable number plates, nearby residents. The client is then the "data controller" and the provider the "data processor" under article 28 of the GDPR, which requires a written contract specifying the purpose of the processing, the security measures, and what happens to the data once the mission ends.
What should the contract cover if the provider goes out of business?
A data portability (reversibility) clause: it guarantees the client the return of raw and processed data in an open, usable format, without depending on the provider's proprietary software. This is essential for recurring missions (construction monitoring, periodic thermal imaging) whose value lies precisely in comparing successive campaigns.
Put it into practice
- Drone security & surveillance: rates and cities covered from €600
- Security & surveillance in Châlons-en-Champagne Grand Est
- Security & surveillance in Thionville Grand Est
- Security & surveillance in Agen Nouvelle-Aquitaine