All blog articles
July 26, 2026
Published onJuly 26, 2026

GDPR-Compliant Virtual Tours: What Agents and Property Managers Need to Know

Virtual tours capture far more personal data than most agents realize. Here is what you need to know about GDPR, consent, blurring, and vendor contracts before you commission your next 3D scan.

Virtual tours have become a standard tool in real estate marketing. A single 3D scan can replace dozens of static photos, let prospective tenants explore a property remotely at any hour, and dramatically cut down on unnecessary viewing appointments. But there is a side to this technology that many agents and property managers overlook: a matrix scan of an occupied apartment or office does not just capture rooms and furniture. It captures people, documents, vehicles, and personal details, often without anyone realizing it in the moment.

Unlike a curated photo shoot, where a photographer chooses each frame, a 360-degree scanner captures everything in its field of view continuously as it moves through a space. Family photos on a shelf, a name on a doorbell, mail lying on a kitchen counter, a car parked in the driveway with a visible license plate, a laptop screen left open — all of this can end up embedded in the raw scan data and, if unaddressed, in the finished virtual tour published online. Under the General Data Protection Regulation (GDPR) and Germany's Bundesdatenschutzgesetz (BDSG), this incidental capture of personal data is not a minor technicality. It is a genuine compliance question that agents, property managers, and their visual media providers need to think through before the tripod ever gets set up.

This article walks through where personal data typically arises in virtual tours, what legal basis applies, how blurring and anonymization work as safeguards, and what practical steps you should take when commissioning a tour of an occupied property. As with all of our Praxiswissen content, this is general guidance for orientation purposes only, not legal advice tailored to your specific situation — for binding assessments, especially in sensitive settings, consult a qualified data protection lawyer or your company's data protection officer.

When Personal Data Actually Arises

The GDPR defines personal data broadly: any information relating to an identified or identifiable natural person. In the context of a real estate scan, this is a wider net than most people expect. The most obvious case is a person's face, whether that's a tenant who happens to be home during the scan, a cleaner passing through a hallway, or a neighbor visible through a window. Even a partial view — a hand, a reflection in a mirror, a silhouette through frosted glass — can, depending on context, be enough to identify someone.

Beyond faces, nameplates and doorbells are a frequent and easily missed source of personal data. A scan of a multi-unit apartment building will typically capture the building's entire directory of nameplates in the entryway, associating names directly with a specific address. Vehicle license plates are another common example: cars parked in a driveway, garage, or visible through a window are captured with plates legible enough to be traced back to a registered owner. Visible documents present a similar risk — mail on a table, an open filing cabinet, a whiteboard with client names, a monitor displaying an email inbox, or medical paperwork left on a desk in a home office. None of these are hypothetical edge cases; they show up regularly in raw scan footage of lived-in homes and working offices.

It's worth being clear about what is not typically a problem: an empty, vacant, professionally staged property scanned before anyone moves in carries essentially no personal data risk, because there is no identifiable individual connected to the images. The concern scales directly with how "lived-in" a property is at the time of the scan — occupied rentals, active offices, and properties being sold while the current owner still lives there are the situations that warrant the most attention.

GDPR Article 6 requires that any processing of personal data rest on one of several recognized legal bases. For virtual tours, the two most relevant are consent (Article 6(1)(a)) and legitimate interest (Article 6(1)(f)), and understanding the difference matters because it changes what documentation you need and what you can safely publish.

Consent is the clearest basis when personal data is central to the tour rather than incidental — for example, if you deliberately want to show a resident's home office setup with them visible, or if an employee will appear in a commercial walkthrough used for marketing. Valid consent under GDPR must be freely given, specific, informed, and unambiguous, and it must be documented (a verbal "sure, go ahead" is not sufficient evidence if the matter is ever questioned). Crucially, consent must also be revocable, meaning a tenant who agreed to appear in a scan can later withdraw that consent and require the content to be taken down.

Legitimate interest is the more common basis for the incidental capture that happens during ordinary property marketing — the marketing interest of the property owner or agent in showcasing a space for sale or rent generally qualifies, provided this interest is balanced against the rights of the people who might appear in the footage. This is exactly why blurring and anonymization matter so much in practice: when identifiable personal data is removed from the published tour through technical safeguards, the balancing test tips clearly in favor of the legitimate marketing interest, because there is no meaningful residual risk to any individual. In effect, thorough anonymization is often what allows agents to rely on legitimate interest rather than having to chase down consent from every occupant, neighbor, or passerby who might have been in frame.

Blurring and Anonymization as the Key Technical Safeguard

If there is one measure that resolves the majority of GDPR concerns around virtual tours, it is systematic blurring of personal data before publication. Modern 3D scanning platforms (including the systems FotoEstate uses for matterport-style tours) offer built-in tools to blur faces, license plates, and even manually selected regions such as a nameplate, a computer screen, or a stack of mail. This is not a cosmetic nicety — it is the technical implementation of the data protection principle of data minimization, which requires that no more personal data be processed (including published) than is necessary for the purpose at hand.

Good practice is to treat blurring as a mandatory, non-optional step in the production workflow for any occupied property, rather than an afterthought applied only if someone raises a concern. Automated face and license-plate detection can catch the majority of cases, but it should always be followed by a manual review pass, since automated detection reliably misses reflections, partially obscured faces, and text on documents that require reading rather than just pattern recognition. For a residential building, this manual pass should specifically check entryway nameplates, mailboxes, and any personal photos or displayed correspondence within the scanned units.

It's also worth distinguishing between blurring for publication and true anonymization. Blurring applied only to the rendered output that visitors see, while the underlying raw scan data remains unblurred and stored on a server, still constitutes processing of personal data and still triggers GDPR obligations for that raw data (covered in more detail below). True anonymization — where the identifying information is irreversibly removed, not just visually obscured in one output layer — offers stronger protection but is technically demanding for panoramic image and point-cloud data. In practice, most reputable providers apply blurring at the point of processing and treat the raw, unblurred footage as sensitive material subject to strict access controls and limited retention, which is the pragmatic middle ground most real estate businesses adopt.

When a property is occupied — a tenant living in an apartment being marketed for sale, or employees working in an office space being scanned for a commercial listing — the question of consent becomes more concrete and more important to get right procedurally, not just technically. Even with excellent blurring, it is good practice (and in Germany, often a practical necessity given tenant rights) to inform occupants in advance that a scan will take place, what it will be used for, and what safeguards will be applied.

For residential tenancies in Germany, landlords generally do not have an unrestricted right to enter and photograph an occupied unit without advance notice and a legitimate reason (such as an upcoming sale), and tenants retain a right to object to being personally depicted. A simple written notice — sent by the landlord or agent ahead of the scan date — describing the purpose, the blurring measures to be applied, and offering the tenant the opportunity to tidy away personal items or request specific exclusions, resolves the great majority of friction points before they occur. Some agencies build this into their standard viewing-preparation checklist alongside routine housekeeping advice like removing clutter or personal photos, which conveniently serves both staging and privacy goals at once.

For commercial and office environments, the same logic applies to employees rather than tenants: if a scan will capture desks, screens, or common areas during working hours, informing staff in advance and, where an employee will be identifiably visible (for example, someone deliberately included in a lobby shot for a company profile tour), obtaining their explicit consent is the safer path. Works councils in Germany, where present, may also have co-determination rights over workplace monitoring-adjacent activities, so larger commercial scans are worth flagging to HR or facilities management before the day of the shoot.

Data Processing Agreements and Server Location

Whenever a virtual tour provider — whether an in-house team or an external agency like FotoEstate — processes scan data on behalf of an agency or property manager, GDPR Article 28 requires a Data Processing Agreement (Auftragsverarbeitungsvertrag, or AVV) between the two parties. This is a foundational and frequently overlooked requirement: if your agency instructs a photographer or scanning company to capture and host a 3D tour, and that provider stores the data on its own servers or a third-party cloud platform, a DPA needs to be in place defining the scope of processing, security measures, sub-processors used, and each party's responsibilities.

Server location is a related and equally important question. Many virtual tour platforms are built on cloud infrastructure operated by companies headquartered outside the EU. Since Schrems II, transfers of personal data to servers outside the EU/EEA require additional safeguards — standard contractual clauses, an adequacy decision, or equivalent mechanisms — and it is entirely reasonable for an agency to ask its virtual tour vendor directly where the hosting infrastructure is located and what transfer mechanism applies if it isn't within the EU. Providers who host on EU-based servers, or who can clearly document their transfer safeguards, make this part of due diligence considerably simpler for their clients.

When evaluating or commissioning a virtual tour vendor, it is worth asking directly: does a signed DPA exist covering this engagement, where is the data physically stored, which sub-processors (analytics tools, CDN providers, hosting partners) touch the data, and what happens to the data if the contract ends. These are reasonable, standard questions that any professional provider should be able to answer without hesitation.

Retention and Deletion of Raw Scan Data

One of the most practically important — and most frequently neglected — aspects of GDPR compliance for virtual tours is what happens to the data after the tour goes live. A completed matterport-style scan typically leaves behind not just the polished, published tour but a substantial amount of raw material: unprocessed panoramic images, point-cloud data, and sometimes video walkthrough footage captured during the scan.

GDPR's storage limitation principle requires that personal data not be kept longer than necessary for the purpose it was collected for. In practice, this means raw, unblurred scan data — which may still contain visible faces, documents, or nameplates that were subsequently blurred in the published version — should not sit indefinitely on a server "just in case." A sensible retention policy defines a clear window (for example, keeping raw data only until the published tour is finalized and quality-checked, or for a fixed period such as 90 days to allow for revisions) after which the raw files are permanently deleted, while the finished, blurred tour itself can be retained for as long as it serves its marketing purpose, since it no longer contains the same level of identifiable personal data.

Agencies and property managers should ask their virtual tour provider what the default retention period is for raw capture data, whether that period is documented in the DPA, and whether deletion is confirmed rather than merely assumed. When a listing is taken down — because a property sold, a tenant moved out, or a lease ended — the published tour itself should also be deprovisioned promptly rather than left accessible via an old, unlisted URL indefinitely, particularly if it depicts a residential interior.

Special Care for Hospitals, Schools, and Museums

While most virtual tour work in the real estate context involves residential and commercial properties, FotoEstate and similar providers are also frequently commissioned to scan institutional spaces — hospitals, clinics, schools, universities, and museums — for purposes ranging from wayfinding to marketing to accessibility documentation. These environments deserve meaningfully more caution than a typical apartment or office scan.

Healthcare facilities are an obvious high-risk category: patient rooms, waiting areas, and treatment spaces can incidentally capture patients, medical charts, prescription information, or monitoring equipment displaying health data, all of which falls under GDPR's special category of health data (Article 9), subject to stricter processing conditions than ordinary personal data. Scans of hospitals and clinics should generally be scheduled during closed hours or in unoccupied areas, with an explicit sign-off from the facility's data protection officer before any scan proceeds, and with particular attention to whiteboards or monitors that might display patient names or schedules.

Schools and universities raise similar concerns around minors — GDPR affords additional protection to children's data, and capturing identifiable images of students, even incidentally in a hallway or classroom scan, requires careful thought about parental consent and the institution's own safeguarding policies. Museums, meanwhile, often involve a different but related issue: rather than personal data of visitors, the sensitivity may lie in copyrighted artworks, loan agreements restricting how certain pieces may be photographed, or contractual limits imposed by lending institutions, which sit alongside (not instead of) any GDPR considerations if visitors or staff appear in the scan. For all of these institutional contexts, we recommend building in an extra planning conversation with the client's own compliance or legal contact well before the scan date, rather than treating it as a standard commercial or residential shoot.

Practical Checklist for Commissioning a Compliant Tour

Bringing the above together, here is a practical sequence to work through when commissioning a virtual tour of any property that is currently occupied or in active use:

  • Before the scan: Notify tenants, residents, or employees in writing of the scan date, purpose, and privacy safeguards; ask that personal documents, mail, and photographs be tidied away where practical; confirm with the vendor whether a DPA is in place and where data will be hosted.

  • Choose the right legal basis: Rely on legitimate interest paired with thorough blurring for routine marketing scans; obtain explicit, documented consent whenever an identifiable individual will remain visible in the published tour by design.

  • During production: Ensure the scanning team is briefed to flag obviously sensitive items (open documents, visible screens, nameplates) for the editing team.

  • During post-processing: Apply automated face and license-plate blurring as a default step, followed by a manual review pass focused on entryways, nameplates, mailboxes, and any visible personal or business documents.

  • Before publication: Do a final check of the published tour from a visitor's perspective, ideally by someone who wasn't involved in the scan and can spot what a stranger might notice.

  • After publication: Confirm the retention period for raw, unblurred scan data with your vendor and ensure deletion actually occurs on schedule; deprovision the published tour promptly once the listing is no longer active.

  • For sensitive institutions: Add an explicit compliance sign-off step with the client's own data protection contact before scheduling hospitals, schools, or similarly sensitive sites.


Treating this as a routine part of the production workflow, rather than a one-off compliance exercise, is what keeps it manageable — most of these steps take only a few extra minutes once they are built into a standard process.

Conclusion

Virtual tours are a genuinely valuable tool for real estate marketing, and the GDPR considerations around them are entirely manageable once they are understood and built into a standard workflow. The core principles are not complicated: minimize the personal data that ends up in a published tour through systematic blurring, choose the appropriate legal basis depending on whether identifiable individuals are meant to be shown, keep clear agreements and reasonable retention limits with whichever vendor processes the data, and apply extra caution in settings like healthcare and education where the stakes are higher.

For agents and property managers, the practical takeaway is simple: ask your virtual tour provider how they handle blurring, data processing agreements, server location, and data retention before you commission a scan of an occupied property. A provider who has clear, confident answers to these questions is one who has thought this through as part of their standard offering rather than treating it as an afterthought.

As noted at the outset, this article is intended as general orientation for real estate professionals and does not constitute legal advice. GDPR compliance can depend heavily on the specifics of a given property, tenancy situation, or institutional context, so for cases involving particular sensitivity — occupied residential tenancies in dispute, healthcare facilities, or scans involving minors — we recommend consulting a qualified data protection advisor or your organization's data protection officer to confirm the right approach for your specific situation.

Matching service

360°-Rundgang ab 199 €

Interaktive virtuelle Touren, die unqualifizierte Besichtigungen filtern und Kaufinteresse steigern.