Skip to content
Back to Blog
MEP

Is it GDPR-compliant to use AI for MEP design?

James Reed|June 25, 2026|2 min read

Key Takeaways

  • -Include data protection in the review of any AI workflow that uses personal information.
  • -Agree the project's processing purpose, access, retention and responsibilities with the relevant teams.
  • -Discuss WYRM's custom engineering model and your project security requirements directly with us.

An MEP project brings together drawings, models, correspondence and engineering records. Some of that material may include personal or commercially sensitive information. The first step is to understand the information involved and the requirements that apply to its use.

WYRM develops its own custom engineering model for the agentic MEP workflow. From everyday design work to projects involving sensitive information, discuss the access, handling and security requirements with our team before sharing project material.

Where personal data is involved, include the purpose of the processing, the people who need access, retention arrangements and the relevant contractual responsibilities in the assessment. Your engineering, IT and data protection teams can bring their requirements into that discussion.

Technical arrangements and security documentation are discussed directly through the appropriate review. Contact WYRM to explain the project's needs and agree the next steps.

The engineer remains responsible for the design. Review the inputs, assumptions and outputs in context before using them in an issued project deliverable. Data protection and engineering review address different responsibilities, and both belong in the workflow.

For further guidance on AI and personal data, consult the Information Commissioner's Office. WYRM's secure project workflow page provides the contact route for discussing your specific requirements.