Loading Guild Resources
Loading Guild Resources
Loading Guild Resources
We have already produced some reasonably detailed guidance about GDPR, and that should be consulted in the first instance to get you up to speed with the new phrases and principles of GDPR.
This article is aimed at landlords, but agents may find its contents useful.
Specifically for agents, Training for Professionals (with whom we work closely) has new GDPR privacy notices aimed explicitly at agents.
The rules for landlord registration have not changed. You should register if you store, use, or delete tenant personal information (such as name, email, telephone number, etc.) using an electronic device (mobile phone, computer, etc.). That is, regardless of GDPR.
Registration costs £35.00 per year (including the direct debit discount) and is quick and easy. You can quickly check if you need to register by using this tool on the ICO website.
One of the first steps to complying with GDPR is to document processing activities so you can establish what personal information you hold, who it is shared with, and how long it is retained. The document should list the categories of people for whom you process data.
We have conducted an audit of processing activities for our tenancy portfolio (if you didn’t know, we are a landlord as well as running the Guild).
We have found four main categories of tenants:
The audit should detail how personal information is used, who it is shared with, and how long it is retained. It should also refer to any privacy policy that informs them of how their data is used and shared.
Our GDPR audit is available here in Excel spreadsheet format. You will need to amend it to match the data you use. Our audit is in its early stages and may be amended as we consider what further information should be contained in the audit.
However, it should provide a good start for you, if nothing else.
To process personal information, landlords must have a “lawful basis” to process the data.
Processing includes storing, using, sharing, and deleting the information. We have detailed these processes in detail in our earlier article, but to summarise, for landlords, the main bases for processing will be:
Following the audit and understanding the lawful bases, you are allowed to process the information; you then need to inform the tenants how you will use the information.
We have updated all our relevant forms with new GDPR privacy policies, which are listed below.
If you use our forms, you should only need the privacy policy for the enquiring tenant (which we will discuss in a moment).
The following landlord forms and templates include GDPR privacy notices (links require an active subscription):
The GDPR guidance says that anything that requires consent should not form part of the main contract but instead be a separate consent form that can be withdrawn as quickly as permission was given.
You do not need to issue a new tenancy agreement simply because data protection law has changed. There is also no blanket requirement to send an updated privacy notice to every existing tenant.
However, privacy information that you provide from 19 June 2026 must explain how the person can complain to you and how they can complain to the Information Commissioner. Check the notices and response templates you currently use and update them where necessary. Our tenancy privacy notice can help with this.
Crucially, as long as you’re processing the data under one of the lawful bases (legitimate interest, contract fulfilment, legally required, etc.), you should be just fine.
From 19 June 2026, landlords and agents who are data controllers must make it easy for people to raise data protection complaints. A complaint must be acknowledged within the period of 30 days beginning when it is received. The controller must then make appropriate enquiries, respond without undue delay, keep the complainant informed about progress, and tell them the outcome.
This does not mean every repair or tenancy complaint becomes a GDPR matter. The new duty applies where a person complains about the handling of their personal data, for example, an alleged unauthorised disclosure, inaccurate data, insecure storage, or a refusal to correct it. We explain the new duty in our article on data protection complaint duties for landlords.
A tenant, applicant, guarantor, or other person can ask for a copy of their personal data by making a subject access request. Record when the request arrives, check the person’s identity where necessary, and respond without undue delay, normally within one month. If you reasonably need clarification to identify the information covered by an access request, ask promptly. If the request is complex, or the person has made several requests, you may extend the deadline by up to two further months, but you must tell them within the first month and explain why.
Search the places where the information is likely to be held, including relevant email accounts, property-management systems, and suppliers. The search must be reasonable and proportionate. The first copy is normally free, although a reasonable administrative fee may be charged for further copies.
People can also ask for inaccurate information to be corrected or for information to be erased. Erasure is not automatic. You may keep information where the law requires it or where you have another lawful reason, such as dealing with a legal claim. If you refuse a rights request or decide not to act, explain why and give the person details of how to complain to you and to the Information Commissioner.
If you use cloud software, a referencing service, or another supplier, check where personal data can be accessed as well as where it is stored. Access by a separate organisation outside the UK may count as an international transfer, even if the data remains on a UK server. Before using the service, check that the supplier has suitable UK data-transfer arrangements and whether overseas staff or subcontractors can access the information. The ICO has guidance on international transfers.