Industry GDPR documentation

Written and maintained by Chris Haycock, GDPRQuick.com/CliqTo Ltd
Last reviewed Not yet reviewed


GDPR for estate agents & letting agents

Estate agents and letting agents handle a wide range of personal data: buyer and seller details, landlord records, tenant applications, viewing notes, offer records, referencing information, Right to Rent checks, AML identity documents, contractor details, photos, keys, and access instructions. This page explains the GDPR decisions an agency needs to document, and how GDPRQuick turns those answers into practical records.

Let's begin.

Free PDF checklist

Download and use this checklist in your business.

Use it as a practical hand-off for owners, managers, and staff who need to understand the GDPR points covered on this page.

What personal data property agents handle

Property agencies collect personal data from vendors, landlords, buyers, tenants, guarantors, contractors, referees, and sometimes neighbours or occupants. The same agency may handle sales, lettings, property management, maintenance, marketing, and compliance checks.

Typical personal data includes:

  • Names, addresses, phone numbers, email addresses, and contact preferences
  • Viewing records, offer notes, negotiation history, and chain information
  • Tenant applications, income details, employer information, references, and guarantor details
  • Right to Rent documents, identity checks, and immigration-related evidence
  • AML checks, proof of funds, source-of-funds notes, and identity documents
  • Landlord records, bank details, property management notes, and contractor instructions
  • Property photographs, video tours, CCTV, alarm codes, keys, and access arrangements

Your GDPR documentation should explain what data is collected for each activity, where it comes from, which systems hold it, who it is shared with, and how long it is retained.

Sales data, offers and buyer records

Sales work can create detailed records about buyers, sellers, offers, financing, chains, and negotiations. A viewing enquiry may start as a simple contact record, but it can quickly become a file containing affordability, proof of funds, mortgage status, family circumstances, and moving plans.

The agency should document why this information is needed and how it is shared with sellers, conveyancers, mortgage brokers, surveyors, and other parties involved in a transaction.

Avoid over-sharing during negotiations

A seller may need enough information to consider an offer, but that does not mean every buyer detail should be shared automatically. Your process should distinguish between useful transaction information and excessive personal detail.

Tenant referencing and guarantor checks

Letting agents often collect more intrusive data than sales agents. Tenant applications can include employment details, salary information, bank or affordability checks, previous addresses, landlord references, credit checks, and guarantor information.

Because referencing data is sensitive in context, agencies should be clear about what is collected directly, what is collected through a referencing provider, what is shared with landlords, and what happens if an application is unsuccessful.

  • Tell applicants what checks will be carried out before collecting documents
  • Keep referencing data separate from general marketing lists
  • Avoid retaining unsuccessful application evidence longer than necessary
  • Explain what information is shared with landlords and why

Not sure what applies to your estate agents & letting agents?

Take the quick risk check before you get too deep into the detail.

Take the 2-minute check

Right to Rent checks and identity documents

Right to Rent checks mean letting agents may handle passports, share codes, visas, biometric residence permits, and other immigration-related evidence. These documents are personal data and may reveal nationality or immigration status.

Your records should explain why checks are carried out, who performs them, where evidence is stored, who can access it, and how long it is retained after the tenancy ends.

Keep compliance evidence controlled

Identity and immigration evidence should not sit indefinitely in email inboxes or general property folders. It should be stored deliberately and deleted when the retention reason has expired.

AML checks and proof of funds

Estate agents may need to complete anti-money laundering checks on sellers, buyers, beneficial owners, and sometimes landlords. This can include identity documents, proof of address, sanctions checks, politically exposed person checks, source-of-funds notes, and evidence of financing.

These checks have a legal compliance purpose, but they still need GDPR documentation. The privacy notice should explain what checks are carried out, which verification providers may be used, and why evidence may be retained.

  • Document the lawful basis for AML processing
  • Restrict access to identity and source-of-funds evidence
  • Record retention periods separately from ordinary enquiry data
  • Make sure third-party verification providers are covered in your processor list

Property portals, CRMs and software suppliers

Most agencies use property portals, CRM systems, viewing booking tools, email marketing platforms, referencing providers, inventory software, e-signature tools, cloud storage, payment systems, and property management platforms.

Your GDPR records should list the categories of suppliers you use, what personal data each one handles, where data is stored, and whether appropriate processor terms are in place.

Portals do not replace your own privacy notice

A portal privacy policy explains the portal's own data use. It does not fully explain how your agency handles enquiries, viewings, offers, tenancy applications, property management records, or marketing preferences.

Photos, video tours and occupied properties

Property photographs can include personal data where people, family photos, valuables, documents, children's items, vehicles, or distinctive possessions are visible. Video tours and virtual viewings can increase that risk.

Agencies should have a practical process for preparing occupied properties before photography and for responding if an occupier asks for an image to be removed or changed.

  • Check rooms for visible documents, photos, calendars, medication, and valuables
  • Avoid capturing children, tenants, neighbours, or vehicle registration plates where possible
  • Explain where property images will be used, including portals and social media
  • Keep a process for correcting or removing images that reveal personal information

Marketing, mailing lists and property alerts

Agents often send property alerts, valuation emails, landlord newsletters, market updates, and promotional messages. Some contact is expected as part of an active enquiry, while broader promotional marketing needs clearer controls.

Your documentation should explain how buyers, tenants, landlords, and vendors are added to lists, how preferences are recorded, how opt-outs work, and how old leads are removed.

Separate active enquiries from marketing databases

Someone asking about one property is not the same as agreeing to receive indefinite marketing. A clean CRM process helps avoid stale lead lists and unwanted follow-up messages.

Access notes, keys and property management records

Letting and management files can include alarm codes, key logs, access instructions, occupier details, maintenance issues, vulnerability notes, neighbour disputes, complaint records, and contractor appointments.

This information can affect security and privacy, so it should be accurate, limited, and only visible to people who need it.

  • Limit access to key codes, alarm details, and access arrangements
  • Share only necessary information with contractors
  • Keep maintenance notes professional and factual
  • Review old property management records when tenancies end

What GDPR documents does a property agency need

A practical GDPR pack for estate agents and letting agents should reflect how property data moves through enquiries, instructions, viewings, offers, applications, tenancies, management, and compliance checks.

  • A privacy notice covering buyers, sellers, landlords, tenants, guarantors, contractors, applicants, and staff
  • A Record of Processing Activities covering sales, lettings, property management, AML, Right to Rent, marketing, and staff records
  • A processor list covering CRMs, portals, referencing providers, AML tools, e-signature, email, cloud storage, and IT support
  • A retention policy for enquiries, offers, tenancy applications, AML evidence, Right to Rent checks, property files, and marketing leads
  • A breach response process for misdirected emails, portal access issues, lost documents, CRM exposure, and supplier incidents
  • A subject access request process for mixed property files and negotiation notes
  • A marketing preference process for buyers, tenants, landlords, valuation leads, and property alerts

The documents should match your actual agency model. A sales-only agency will need different records from a lettings and management agency handling tenant applications, inspections, rent records, deposits, contractors, and maintenance.

Build your agency GDPR documents from your own answers

GDPRQuick guides you through questions about how your agency works: what services you provide, which portals and CRMs you use, what compliance checks you perform, how you handle viewings, what data is shared with landlords and sellers, and how long records are kept.

Your answers become the wording for your GDPR statement, processing records, action plan, and supporting forms. You can return later and update the documents when your agency changes software, services, suppliers, or retention rules.

GDPRQuick.com UI Platform Screenshot

Check your GDPR risk first.

Use the GDPRQuick risk calculator to get an indicative view of where your estate agents & letting agents data protection work may need attention.

Start the risk calculator

Questions about GDPR for estate agents & letting agents

Do estate agents need GDPR documentation?

Most estate agents and letting agents should keep GDPR documentation because they handle buyer, seller, tenant, landlord, contractor, compliance, marketing, and staff data regularly.

Are property viewing records personal data?

Yes. Viewing records can identify buyers, tenants, applicants, occupiers, and sometimes their preferences or circumstances, so they should be handled as personal data.

Can letting agents keep tenant referencing documents?

Yes, where there is a clear reason and retention period. The agency should explain what is kept, why it is kept, who can access it, and when it is deleted.

Do Right to Rent checks need GDPR controls?

Yes. Right to Rent evidence can include identity and immigration-related information, so access and retention should be controlled carefully.

Can an agency share offer details with a seller?

Yes, where it is necessary for the transaction, but the agency should avoid sharing excessive buyer information that the seller does not need.

Do property photos count as personal data?

They can. Photos and videos may reveal people, personal possessions, family images, documents, vehicle plates, or other information linked to occupants.

Do property portals make GDPR the portal's responsibility?

No. Portals may have their own privacy responsibilities, but your agency still needs to explain how it handles enquiries, viewings, offers, applications, records, and marketing.

What if a tenancy application is emailed to the wrong landlord?

That is a personal data breach in principle. The agency should contain it, assess the risk, record the incident, and decide whether it must be reported to the ICO or affected people.

Is GDPRQuick a replacement for legal advice?

No. GDPRQuick helps you create and maintain practical documentation. It does not certify compliance, and your organisation remains responsible for its own policies, processes, security measures, and legal decisions.