Data Protection in Property: How Landlords and Agents Can Avoid Breaching UK GDPR
Estate agents, letting agents, landlords and block managers routinely handle passports, bank statements, tenancy applications, employment details, access codes, forwarding addresses and financial records.
This information is necessary for managing property, but it cannot be collected, shared or retained carelessly. A data breach does not have to involve hackers. Sending an email to the wrong person, copying tenants into a group email, releasing documents without checking someone’s authority or leaving an application form unsecured can all create serious problems.
The seven principles of data protection
The UK GDPR is built around seven principles:
-
Lawfulness, fairness and transparency
-
Purpose limitation
-
Data minimisation
-
Accuracy
-
Storage limitation
-
Security and confidentiality
-
Accountability
In practical terms, this means knowing what information you hold, why you need it, how it is protected, who may receive it and when it should be deleted.
1. Establish a lawful reason for using personal information
An agent or landlord must identify a lawful basis before collecting or using personal information. Depending on the circumstances, this may include:
-
Taking steps before entering a contract
-
Performing a tenancy or management contract
-
Complying with legal obligations
-
Protecting someone’s vital interests
-
Pursuing a legitimate business interest
-
Obtaining valid consent where consent is genuinely appropriate
Consent is not automatically required for every activity. However, you must still tell people how their information will be used through a clear privacy notice.
Information collected for referencing should not quietly be reused for unrelated marketing or passed to another business simply because it might be useful. The proposed use must be lawful, fair and reasonably expected.
2. Collect only what is genuinely required
A common mistake is requesting every available document rather than considering what is actually necessary.
For example, an applicant may need to provide identification, right-to-rent evidence, proof of income and address history. That does not justify collecting unrelated medical information, complete financial histories or personal information about people who will not occupy the property.
The ICO’s data-minimisation principle requires information to be adequate, relevant and limited to what is necessary for the stated purpose.
Before requesting a document, ask:
-
Why do we require it?
-
What lawful basis allows us to use it?
-
Do we require the entire document?
-
Could unnecessary information be redacted?
-
Who needs access to it?
-
How long will it be retained?
3. Verify authority before releasing information
Someone knowing the property address does not prove that they are entitled to receive information.
Before releasing tenancy records, leaseholder accounts, service-charge information, keys, access details or correspondence, verify:
-
The person’s identity
-
Their relationship to the property
-
Whether they are the landlord, tenant or registered leaseholder
-
Whether an agent, solicitor or relative has written authority
-
Exactly what information the authority permits you to disclose
A solicitor stating that they act for somebody does not automatically mean that every document can be released. Where necessary, obtain written authority from the person concerned and confirm the scope of that authority.
4. Share the minimum information required
Contractors normally need the property address, the nature of the repair and suitable access arrangements. They rarely need a tenant’s complete application, passport, bank details or tenancy file.
Similarly, a freeholder, managing agent or residents’ management company should not circulate complaints containing unnecessary personal accusations or identifying information.
Only disclose what the recipient genuinely needs to complete the authorised task.
5. Take care with emails and messaging services
Before sending an email:
-
Check every recipient carefully
-
Review attachments before pressing send
-
Remove documents from historic email chains where they are no longer required
-
Use password protection or a secure portal for sensitive files
-
Send the password separately
-
Use BCC or an appropriate mailing system for genuine group communications
-
Avoid exposing tenants’ or leaseholders’ email addresses to one another
The ICO warns that incorrectly using CC instead of BCC has caused hundreds of reported data breaches. BCC may still be unsuitable where the communication itself reveals sensitive information about the recipients.
WhatsApp may be convenient, but convenience does not remove data-protection duties. Avoid sending passports, bank statements or complete tenant files through informal group chats. Business devices should be protected by strong passwords, multi-factor authentication and controlled access.
6. Do not retain information indefinitely
“Keep everything just in case” is not a lawful retention policy.
Businesses should establish retention periods for different categories of information, considering contractual requirements, legal obligations, limitation periods and regulatory requirements.
When information is no longer required, it should be securely deleted, destroyed or properly anonymised. The ICO confirms that organisations must be able to justify how long information is retained and should review their records periodically.
7. Recognise subject access requests
A person does not have to use the words “subject access request” for their request to be valid. A request may be made by email, letter, telephone, social media or during a conversation.
Most valid subject access requests must be answered without undue delay and within one month. The response must be secure, and information concerning unrelated third parties may need to be redacted.
Staff should know how to identify a request and immediately pass it to the person responsible for data protection.
8. Act immediately when something goes wrong
If information is lost, disclosed incorrectly or accessed without authority:
-
Contain the incident.
-
Recover or restrict the information where possible.
-
Record what happened.
-
Identify the people and information affected.
-
Assess the likely risk.
-
Consider whether the individuals must be informed.
-
Decide whether the ICO must be notified.
A reportable personal-data breach must be notified to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Not every incident must be reported, but every incident should be properly assessed and documented.
Practical compliance is more important than paperwork
A privacy policy sitting on a website is not enough. Proper compliance requires daily discipline:
-
Verify identities and authority
-
Limit access to sensitive records
-
Train staff
-
Review suppliers and data-processing agreements
-
Keep software and devices secure
-
Maintain retention and deletion procedures
-
Record decisions
-
Respond quickly when mistakes occur
Data protection should not prevent responsible property management. It should ensure that necessary information is handled properly, shared only with authorised people and protected from misuse.
At My Estate Luton, we believe professional property management includes protecting the information entrusted to us by landlords, tenants, buyers, sellers and leaseholders.
Richard Gedall MNAEA | AARLA
Director
My Estate Luton Limited
An ARLA Propertymark Protected Agency. Client Money Protection (CMP) is provided by Propertymark.
This article provides general information and does not constitute legal advice.
Comments