Welcome to Simply-Docs

Data Protection Documents for Residential Lettings Agencies

UK Data protection legislation, including UK GDPR and the Data Protection Act 2018,  gives tenants, residents, guarantors and landlord clients greater control over how their personal data is collected, used, and stored. 

For residential letting agents, this means clear legal responsibilities when handling the personal data of tenants, landlords, guarantors, and other clients. 

Your Role As A Letting Agent

Lettings Agencies are classified as “data controllers” under the data protection legislation, meaning they are responsible for determining how personal data is processed. 

Individuals such as tenants, residents, guarantors and landlords are considered “data subjects" under data protection legislation, and they have specific legal rights over their data. 

Key Data Protection Obligations

As a letting agent, you must:

  • Process personal data lawfully, fairly and transparently 
  • Collect only the data you need for legitimate purposes
  • Keep data accurate and up to date
  • Store data securely and only for as long as necessary
  • Respond to data subject requests (e.g. access or deletion requests)

Failure to comply can result in regulatory action and financial penalties. 

Supporting Documents and Templates 

To help you meet your obligations, this suite includes Data Guidance Notes for Residential Lettings Agencies which provides an overview of the data protection legislation in more detail. 

The  Data Audit Checklist for Residential Lettings Agencies (landlord client)  template can be used to assess how data is collected and used. The outcome of the Data Audit will help Residential Letting Agents to prepare a Privacy Notice using our template. This needs to be given to all new and existing tenants, residents, guarantors and prospective and actual landlords, whose data the Residential Lettings Agencies hold. 

Data protection documents for commercial landlords are available here.

Data Protection Documents for Residential Lettings Agencies is part of Property. Just £38.50 + VAT provides unlimited downloads from Property for 1 year.

Frequently Asked Questions

As a letting agent, am I a data controller for my tenants' and landlords' information? +
Yes. Under UK GDPR and the Data Protection Act 2018 a letting agent that decides how and why personal data is handled is a data controller for tenants, residents, guarantors and landlord clients. That brings duties to process data lawfully and fairly, keep it secure, hold it only as long as needed and honour data subject rights. The data audit and privacy notice templates help you comply.
What is a privacy notice and who do I have to give it to? +
A privacy notice tells people how you use their personal data: what you collect, why, your lawful basis, how long you keep it and their rights. You must give it to everyone whose data you hold, including new and existing tenants, residents, guarantors and landlords, at or before the point you collect their data. The templates provide separate notices for tenants and for landlords.
A former tenant has asked for all the information I hold about them. What do I do? +
That is a subject access request. You must normally provide a copy of their personal data, free of charge, within one month, though you can extend by two months for complex requests. You cannot charge unless the request is manifestly unfounded or excessive. Verify the requester's identity first. Handling it wrongly can bring an ICO complaint. Your data policy should set out the response steps.
How long can I keep an applicant's or tenant's data after they have moved on? +
Only as long as you have a lawful reason. Set retention periods tied to purpose, for example keeping tenancy and financial records long enough to meet tax and legal duties, then deleting securely. Anti money laundering records have their own five year period. A data audit identifies what you hold and when to delete it. The data audit checklist template is built for this.
Do I need to tell anyone if tenant data is lost or hacked? +
Often yes. A personal data breach that risks people's rights must be reported to the ICO within 72 hours, and those affected must be told without undue delay where the risk to them is high. Not every breach is reportable, so assess and record each one. Having a breach procedure ready means you can act inside the deadline.

Simply-4-Business Ltd Registered in England and Wales No. 4868909, 20 Mortlake High Street, Mortlake, London SW14 8JN

Top