Data Protection for Estate Agents and Property Professionals UK

Estate agents, letting agents, and property managers routinely handle sensitive identity documents, bank details, and high-value transaction records. Protecting this information isn’t just about legal compliance—it’s critical to preventing identity theft and wire fraud. Discover how to balance UK GDPR, AML checks, and PECR marketing rules while keeping client data secure throughout the transaction process.
M
Maya Fletcher
Aug 10, 2026
11 min read
Estate agent discussing property documents with a client, highlighting secure buyer, seller and tenant data handling under UK GDPR.


Data protection for estate agents UK
businesses involves much more than keeping names and email addresses secure. Estate agents, letting agents and property managers routinely process identity documents, financial information, tenancy records, references, contact details and information connected with high-value property transactions.

That combination creates significant privacy and security responsibilities. Agencies must understand how the UK GDPR and Data Protection Act 2018 affect the way information is collected, used, shared, retained and protected throughout a sale or letting.

Property businesses also operate within a wider compliance environment. Anti-money laundering requirements can require identity verification, while electronic marketing is subject to both data protection law and the Privacy and Electronic Communications Regulations (PECR).

For a broader explanation of the core principles that apply across sectors, see our UK GDPR overview.

Why Estate and Letting Agents Handle High-Risk Personal Data

Estate and letting agencies sit at the centre of transactions involving buyers, sellers, tenants, landlords, solicitors, mortgage brokers, surveyors and referencing providers.

As a result, staff may have access to information that could cause significant harm if it is accidentally disclosed, deliberately stolen or sent to the wrong person.

A typical property file can contain:

  • names, addresses and contact details;
  • passport or driving licence copies;
  • dates of birth;
  • proof of address;
  • bank details;
  • salary and employment information;
  • affordability evidence;
  • mortgage information;
  • tenancy applications;
  • credit and referencing information;
  • landlord and tenant correspondence; and
  • information relating to property ownership and transactions.

Some property records may also reveal information that falls within special category data rules. For example, a tenant may disclose health or disability information when requesting adjustments or explaining particular housing requirements.

The UK GDPR requires organisations to use appropriate technical and organisational measures to protect personal information. What is appropriate depends on the nature of the information, the way it is processed and the risks to the people concerned.

This makes GDPR for property professionals an operational issue rather than something that should sit solely with a compliance manager. Negotiators, administrators, property managers and branch staff all play a part.

Data Collected From Buyers, Sellers and Tenants

The amount of personal information collected during a property transaction can grow quickly.

For sellers, an agency may need ownership information, identification documents, contact information and information necessary to market and progress the property.

For buyers, records may include:

  • identity documents;
  • proof of address;
  • contact information;
  • evidence of funding;
  • mortgage position;
  • source-of-funds information where required; and
  • correspondence concerning an offer.

Letting agent data protection can involve an even broader range of ongoing information. Tenant records may contain income evidence, employment details, previous addresses, references, guarantor information, identification documents and payment records.

The fact that information is useful does not automatically justify collecting it. The UK GDPR's data-minimisation principle requires personal information to be adequate, relevant and limited to what is necessary for the purpose for which it is processed.

Agencies should therefore be able to explain why particular documents or data fields are required.

They should also give buyers, sellers, landlords and tenants appropriate privacy information explaining matters such as:

  • what information is collected;
  • why it is needed;
  • the lawful basis for using it;
  • who it may be shared with;
  • how long it may be retained; and
  • the individual's relevant data protection rights.

Tenant data GDPR practices should be built into application and management processes from the beginning rather than added after information has already been collected.

Anti-Money Laundering Checks and Data Protection

Property businesses have responsibilities beyond the UK GDPR. Estate agency businesses within the scope of the Money Laundering Regulations must conduct customer due diligence and comply with relevant HMRC supervision requirements.

Current HMRC guidance states that estate agency businesses must identify relevant parties and verify that customers involved in property transactions are who they say they are. Customer due diligence is risk-based, and additional checks may be appropriate in higher-risk situations.

This can involve examining documents such as passports, driving licences and proof of address. Depending on the risk, agencies may also need information about matters such as source of funds or beneficial ownership.

These records deserve particularly careful protection because they can be extremely useful to criminals committing identity or financial fraud.

However, an important distinction should be made: a passport copy, bank statement or proof-of-address document is not automatically special category data under Article 9 of the UK GDPR simply because it is sensitive. Special category data covers specific categories such as health information, racial or ethnic origin, religious beliefs, biometric identification data and sexual orientation.

AML checks instead involve an additional legal processing context. Agencies need an appropriate lawful basis for processing personal data while also complying with their separate statutory AML responsibilities.

HMRC's 2026 guidance also confirms that estate agency businesses must retain documents and information obtained to meet relevant customer due diligence requirements for five years after the applicable business relationship ends, after which the data must generally be deleted in accordance with the regulations.

Agencies looking to strengthen frontline understanding of these obligations can use GDPR Essentials for UK Businesses. Wider teams that regularly process identity, financial and customer records may also benefit from Data Protection & GDPR Compliance training.

Sharing Data With Mortgage Brokers and Solicitors

Property transactions depend on information moving between several organisations.

An estate agent may communicate with:

  • conveyancing solicitors;
  • licensed conveyancers;
  • mortgage brokers;
  • lenders;
  • surveyors;
  • referencing services;
  • landlords;
  • managing agents; and
  • other estate agencies.

Sharing information is not automatically prohibited by GDPR. However, an agency should know why the information is being shared, identify an appropriate lawful basis, disclose only what is necessary and make the sharing transparent to the individual.

The ICO's data-sharing guidance applies where personal data is disclosed between separate controllers and recommends clear governance around the purpose and handling of shared information. Data-sharing agreements can also help organisations document responsibilities for routine sharing arrangements.

For example, telling a solicitor that an offer has been accepted may be necessary for progressing a sale. Sending an entire file containing unrelated identification or financial information is unlikely to be justified merely because the solicitor is involved in the transaction.

The same principle applies to mortgage brokers.

An agency should not simply assume that a buyer wants their information passed to a particular broker. Where an agency makes referrals, it should be clear about what information will be passed on, why, and which organisation will use it.

Buyer and seller data protection therefore depends partly on purpose limitation: share what the recipient genuinely requires, rather than forwarding everything available in the CRM.

Marketing Property to Past Clients

A completed transaction does not turn a former client's contact information into an unrestricted marketing list.

If an estate agency wants to email or text individuals about valuations, new properties, landlord services or other promotions, PECR must be considered alongside the UK GDPR.

The ICO explains that electronic marketing to individuals generally requires consent unless the conditions for the existing-customer soft opt-in are met.

The soft opt-in can apply where the organisation:

  • obtained the contact details directly from the person;
  • obtained them during a sale or negotiations for a sale;
  • markets its own similar products or services;
  • offered a clear opportunity to opt out when collecting the details; and
  • provides an opt-out in every subsequent marketing communication.

Simply having someone's email address because they rented a flat or viewed a property several years ago does not, by itself, make future marketing compliant.

Agencies should maintain accurate suppression records so people who unsubscribe are not accidentally added back into campaigns.

Marketing databases should also be reviewed periodically. Keeping large volumes of former customer data indefinitely because it might be useful one day conflicts with good data protection practice.

Cybersecurity Risks in Property Transactions

Property transactions are attractive targets for cybercriminals because they involve valuable payments, time pressure and frequent email communication between multiple parties.

Illustration showing cybersecurity controls protecting property transactions from phishing, email compromise and fraudulent payment redirection.

One recognised threat is business email compromise, where a criminal impersonates or compromises a legitimate account and sends convincing instructions designed to redirect a payment. The NCSC describes this type of fraud as involving messages that appear to come from a trusted business contact but direct the recipient to a different bank account.

The risk is particularly relevant to property transactions.

The Solicitors Regulation Authority has documented email-modification fraud in conveyancing and advises organisations to verify unusual payment instructions and changes to bank details through reliable methods. Recent SRA scam alerts in 2026 have also involved fraudulent emails impersonating genuine legal professionals in property transactions and supplying false payment details.

Estate agency compliance UK procedures should therefore include basic cyber controls such as:

  • multi-factor authentication where available;
  • strong access controls;
  • secure handling of ID and financial documents;
  • careful checking of email addresses and domains;
  • independent verification of unexpected payment or banking instructions;
  • limiting staff access according to their role;
  • promptly removing access when staff leave;
  • phishing awareness training; and
  • clear procedures for reporting suspected incidents.

The UK GDPR requires security measures proportionate to the risks involved, and ICO guidance specifically identifies access management, secure devices, vulnerability management and protection against cyberattack as relevant controls.

For agencies wanting to strengthen these controls, cybersecurity training for small businesses can help staff recognise phishing, account compromise and unsafe information-handling practices.

Retention of Sales and Tenancy Records

The UK GDPR does not prescribe one universal retention period for all property or tenancy records.

Instead, the storage-limitation principle requires organisations to keep identifiable personal data only for as long as it is needed for the purposes for which it is held. Organisations should establish justified retention periods and review or securely delete information when it is no longer required.

This means an agency's retention schedule may distinguish between:

  • AML customer due diligence documents;
  • unsuccessful tenancy applications;
  • current tenancy records;
  • completed tenancy files;
  • property sales records;
  • financial and accounting records;
  • complaint records;
  • marketing information; and
  • information retained in connection with potential legal claims.

Relevant legislation, tax requirements, regulatory obligations and legitimate requirements to establish or defend legal claims may justify different retention periods.

AML documentation is a particularly important example because specific rules apply. As noted above, current HMRC guidance requires relevant estate agency customer due diligence records to be kept for five years after the business relationship ends before deletion is generally required under those rules.

For ordinary tenancy records, there is no single GDPR rule saying that every document must be kept for a fixed number of years. Agencies should determine and document appropriate periods based on the reason each record is retained rather than adopting an indefinite "keep everything" policy.

Training Agency Staff on Data Protection

Even a well-written privacy policy provides limited protection if frontline employees do not understand how to apply it.

Property staff often receive sensitive documents directly from customers. A negotiator might receive a passport by email, an administrator may download a bank statement, or a property manager may have access to years of tenant correspondence.

Effective GDPR training for small businesses UK agencies should therefore focus on practical situations rather than legal terminology alone.

Training should cover:

  • recognising personal and special category data;
  • UK GDPR principles;
  • lawful use of buyer, seller and tenant information;
  • secure processing of passports and identity evidence;
  • AML information-handling procedures;
  • sharing information with brokers and solicitors;
  • secure CRM use;
  • email and phishing risks;
  • verifying unusual financial requests;
  • responding to data subject requests;
  • marketing rules and opt-outs;
  • retention and secure deletion; and
  • recognising and reporting personal data breaches.

The ICO's current accountability framework expects organisations to consider role-appropriate data protection and information-governance training, including induction and refresher training. It specifically identifies information security, data sharing, breach management and records management as important training topics.

For smaller property firms, SME data protection training does not need to be unnecessarily complicated. Staff should understand what they may do, what they should avoid and who to contact when they are unsure.

The aim is to make secure information handling part of normal estate agency operations.

FAQs

Does UK GDPR apply to estate and letting agents?

Yes. Estate and letting agencies that process identifiable information about buyers, sellers, tenants, landlords or other individuals must comply with applicable UK data protection law. Their responsibilities include lawful and transparent processing, data minimisation, appropriate security and justified retention.

What ID checks can agents legally carry out on buyers?

Estate agency businesses covered by the Money Laundering Regulations must conduct appropriate customer due diligence, including identifying and verifying relevant customers. HMRC guidance confirms that buyers and sellers can fall within these requirements, with the extent of checks depending partly on risk.

Can agents share client data with mortgage brokers?

Yes, but not automatically. The agency should have a clear purpose and appropriate lawful basis, tell the individual how their information will be used and share only information that is necessary for the referral or service.

How long should tenancy records be kept?

UK GDPR does not specify one fixed retention period for all tenancy records. Agencies should maintain a retention schedule based on legal, contractual, regulatory and legitimate business requirements and securely delete or anonymise information once it is no longer needed.

What is email fraud risk in property transactions?

Criminals may compromise or imitate genuine email accounts and send fraudulent payment instructions, sometimes changing bank details during a property transaction. Agencies should treat unexpected financial instructions as high risk and verify them using trusted contact details or another established communication channel.

Protect your agency and your clients. Give staff the practical knowledge to handle buyer, seller and tenant information responsibly, recognise privacy risks and apply GDPR principles during everyday property transactions. Explore our GDPR Essentials for UK Businesses course and strengthen data protection across your property business.

Article by:

Professional portrait of a cybersecurity awareness and organisational risk writer.

Maya Fletcher

Maya Fletcher is a cybersecurity awareness and organisational risk writer who helps businesses understand digital threats, strengthen staff awareness and adopt practical measures to protect information, systems and day-to-day operations.

Start Building Your Data Protection Skills Today

Explore flexible online courses designed to help you learn, apply, and strengthen data protection knowledge at your own pace.

Browse Courses