Data Security for Landlords: Protecting Tenant Data
A plain English UK GDPR guide for landlords: ICO fees, lawful basis, how long to keep tenant data, practical security steps and handling a data access request.
Data security for landlords: protecting tenant data
If you decide what tenant information to collect and why, you are a data controller under UK GDPR, and the law expects you to keep that information safe, accurate and no longer than you need it. For most self managing landlords that means registering with the ICO, paying a small annual fee, and following a handful of sensible habits.
This is not as scary as it sounds. You almost certainly hold sensitive details already: passport scans, bank details, references. The job is to handle them deliberately rather than leaving them scattered across your inbox. This guide walks the rules in plain terms, with every legal point verified against the ICO and GOV.UK. It is general guidance, not legal advice, so check the ICO for your exact situation.
Are landlords really data controllers?
Yes. A data controller is the organisation, business or person that decides why and how people's personal information is handled, and that can be a sole trader, a limited company or anything in between, according to the ICO. When you choose what to ask a tenant for and how to store it, you are making those decisions, so you are the controller.
Being a controller means you are responsible for protecting that data and keeping records that show how you meet your obligations. The ICO frames this as taking responsibility, having appropriate measures in place, and being able to demonstrate compliance. In practice it is less about paperwork and more about good habits applied consistently. If you use a letting agent who fully manages the property and you only receive a monthly statement and rent, you may fall under the accounts and records exemption, per the ICO real estate guidance. Most self managing landlords do not, because they hold and decide things directly.
Do landlords need to register with the ICO and pay the fee?
Most self managing landlords do. If you build a database of prospective tenants, decide who gets the tenancy, run credit checks, obtain references or hold tenancy agreements electronically, you need to pay the data protection fee, according to the ICO real estate sector guidance. The fee is annual and you must renew it or tell the ICO when it no longer applies.
The fee comes in three tiers based on turnover and staff numbers, per the ICO guide to the data protection fee. Almost every independent landlord sits in tier 1.
| Tier | Who it covers | Annual fee |
|---|---|---|
| Tier 1 (micro) | Up to £632,000 turnover or up to 10 staff | £52 |
| Tier 2 (small/medium) | Up to £36 million turnover or up to 250 staff | £78 |
| Tier 3 (large) | Anyone above the tier 1 and tier 2 limits | £3,763 |
You get a £5 discount for paying by direct debit, so a typical landlord pays £47. Not paying when you should can land you a fixed penalty of up to £4,000 on top of the fee owed, according to the ICO. If you are unsure, the ICO has a short self assessment that tells you whether you need to pay.
What personal data do landlords actually hold?
More than most realise. A single tenancy generates a stack of personal and often sensitive data: proof of identity, Right to Rent documents, financial details and references. Treating it as one pile to protect, rather than odd files here and there, is the first step. Here is the usual inventory.
- Identity documents: passport or driving licence scans, photos, dates of birth.
- Right to Rent evidence: copies of immigration or ID documents plus the date you checked.
- Financial data: bank details for standing orders, payslips, proof of income, credit checks.
- References: from previous landlords, employers or guarantors, including guarantor details.
- Contact and tenancy data: phone numbers, emails, next of kin, the signed agreement.
Some of this is special category data or close to it, so the bar for protecting it is higher. If you also run developments, your trades contact book and site photos can contain personal data too. Keeping it organised matters as much for compliance as for sanity, which is part of keeping tenancy records compliant.
Lawful basis and data minimisation in plain terms
You need a valid reason (a lawful basis) to hold each piece of data, and you should only collect what you genuinely need. UK GDPR sets out lawful bases such as contract, legal obligation and consent. Most landlord data is justified by performing the tenancy contract or meeting a legal duty like the Right to Rent check, not by consent.
Data minimisation means limiting what you collect to what you actually need, and holding more than necessary is likely to be a breach of that principle, according to the ICO. In practice: do not photograph a whole passport when a Right to Rent check needs specific pages, and do not keep failed applicants' full files once the property is let.
The principles are not optional extras. Infringing the basic principles for processing sits in the highest fine tier, up to £17.5 million or 4% of worldwide annual turnover, whichever is higher, per the ICO. Those headline figures target serious failures by large firms, but the duty to minimise applies to everyone.
How long should you keep tenant data, and how to delete it
Keep data only for as long as you need it, then destroy it securely. This is the storage limitation principle: when you no longer need personal data it should be securely deleted, and UK GDPR sets no single retention period, leaving it to you to justify, according to the ICO. So you set sensible periods tied to a real purpose.
Some retention is fixed for you. For Right to Rent, you must keep a copy of each document checked plus the date of the check, securely, for the duration of the tenancy and for at least one year after it ends, after which the file must be securely destroyed, per the Landlord's guide to Right to Rent checks. Tax records have their own timeframes, so do not delete everything the day a tenant leaves.
Secure deletion is part of the job. Empty the recycle bin, do not just file an email in a folder, and shred any paper. For unsuccessful applicants, set a short window (for example, a few months in case of dispute) then delete. A simple written retention note, even one page, shows you have thought it through.
Practical security steps that actually work
You do not need an IT department. A few solid habits cover most of the risk for a small landlord. The ICO's data storage advice for small organisations stresses controlling access and protecting what you store, which boils down to the steps below.
- Use strong, unique passwords and turn on two factor authentication on email and any storage you use. Email is where most tenant data leaks from.
- Control who can see what. If a partner, family member or assistant helps, give them only the access they need, not the keys to everything.
- Store sensitive files in encrypted, reputable cloud storage rather than as loose attachments or on an unencrypted laptop or USB stick.
- Be careful with email and WhatsApp. Avoid sending passport scans over WhatsApp, and double check the recipient before attaching anything sensitive.
- Know what a breach is. Losing a phone with tenant data, or emailing details to the wrong person, can be a personal data breach you may have to report.
If you manage with spreadsheets and shared folders, access control is hard to enforce, which is one reason landlords move to dedicated software. A tool like Build & Let keeps tenant records, agreements and files in one place with per property access, so the right people see the right data and nothing more. Sorting out roles and permissions for your property team is far easier when access is built in rather than bolted on.
Breaches: what counts and the 72 hour rule
A personal data breach is any security incident affecting the confidentiality, integrity or availability of personal data, and that includes accidental loss as well as hacking. If a breach is likely to result in a risk to people's rights and freedoms, you must report it to the ICO within 72 hours of becoming aware, where feasible, according to the ICO.
If the risk to individuals is high, you must also tell the affected people directly and without undue delay. Not every slip needs reporting, but you must assess each one, so when in doubt, document what happened and use the ICO's self assessment. Failing to report a notifiable breach can attract a significant fine, so do not bury it.
Handling a tenant's data access request
A tenant can ask for a copy of the personal data you hold about them. This is a subject access request (SAR), and it can be made verbally or in writing, even casually. You must respond without undue delay and within one calendar month of receiving it, according to the ICO. The month runs from the day you receive the request.
You can extend by a further two months if the request is genuinely complex, but you must tell the tenant and explain why within the first month, per the same ICO guidance. You generally cannot charge a fee. Gather everything you hold (emails, the agreement, references, notes), redact other people's personal data where needed, and send it securely. Handling a SAR is far quicker when your records are organised, which is one more reason a tidy self managing landlord workflow pays off.
Your landlord data protection checklist
Run through this once a year and after every new tenancy. It covers the points above in order, so you can work top to bottom.
| Task | What good looks like | Status |
|---|---|---|
| ICO registration | Fee paid (tier 1, £52, or £47 by direct debit) and renewed annually | |
| Data inventory | You know what tenant data you hold and where it lives | |
| Lawful basis | Each type of data tied to a real reason, not just collected by habit | |
| Data minimisation | You collect only what you need; failed applicants' files cleared | |
| Retention rule | Right to Rent kept 1 year past tenancy end, then securely destroyed | |
| Strong access | Unique passwords, 2FA on email and storage, limited access for helpers | |
| Encrypted storage | Sensitive files in reputable encrypted storage, not loose attachments | |
| Safe sharing | No passport scans over WhatsApp; recipients double checked | |
| Breach plan | You know the 72 hour rule and where to self assess | |
| SAR readiness | Records tidy enough to answer a request within one month |
Frequently asked questions
Do I need to register with the ICO as a private landlord?
Most self managing landlords do. If you build a tenant database, decide who rents, run credit checks, take references or hold agreements electronically, you must pay the data protection fee, per the ICO. The tier 1 fee is £52, or £47 by direct debit.
How long can I keep an ex tenant's data?
Only as long as you have a genuine reason. The ICO's storage limitation principle says delete data when you no longer need it. Right to Rent copies must be kept for at least one year after the tenancy ends, then securely destroyed, according to GOV.UK. Tax records follow separate timeframes.
Can a tenant ask to see the data I hold on them?
Yes. That is a subject access request. You must respond without undue delay and within one calendar month, according to the ICO. You can usually only extend by two months for genuinely complex requests, and you must explain any delay within the first month.
What should I do if I lose tenant data or email it to the wrong person?
That may be a personal data breach. Assess the risk to the tenant. If it is likely to risk their rights and freedoms, report it to the ICO within 72 hours of becoming aware, where feasible, per the ICO. If the risk is high, tell the tenant directly too.
Is storing tenant data in a spreadsheet against the rules?
Not automatically, but it makes the rules harder to follow. Spreadsheets and shared folders are tough to lock down, so access control and minimisation slip. UK GDPR cares about how you protect data, not the format, so if you use a spreadsheet, encrypt it, control access and keep it tidy.
Keep tenant data tidy and compliant
Good data protection is mostly good organisation: hold what you need, keep it secure, delete it on time, and know what to do when a tenant asks. If your records currently live across email, folders and a spreadsheet, that is where the risk hides. Build & Let keeps tenancies, agreements and documents in one secure workspace with per property access built in, so compliance is the default rather than a chore. Start your 14 day free trial and bring your tenant data under one roof.
Written by Build & Let · Last updated 17 August 2026
Back to all articles