ComplianceApril 16, 20264 min read

GDPR for Real Estate Agencies: A Plain Guide for 2026

What UK and EU data protection law means for an agency handling applicant data: lawful basis, access requests, retention, breaches and the Data (Use and Access) Act 2025. Not legal advice.

L

Loftfolio's founder

Builds Loftfolio. Writes about what small agencies and landlords actually deal with.

GDPR for Real Estate Agencies: A Plain Guide for 2026

Read this first

This is a plain-language overview, checked in September 2026. It isn't legal advice. Data protection law changes, and how it applies depends on what you do and where. For anything that matters, check the regulator's guidance (the ICO in the UK, your national authority in the EU) or ask a lawyer.

Does it apply to you?

  • UK agencies: yes. The UK has its own version, the UK GDPR, alongside the Data Protection Act 2018. The Data (Use and Access) Act 2025 amended both, and its changes are being brought into force in stages.
  • EU agencies: yes, the EU GDPR.
  • Agencies elsewhere: the GDPR can apply if you offer services to people in the EU or UK, but usually your own country's law is what matters: PIPEDA and provincial laws in Canada, the Privacy Act 2020 in New Zealand, and a growing number of state privacy laws in the US, many of which only apply above certain size thresholds. The habits below are good practice anywhere.

What you collect

A letting or leasing agency typically holds names and contact details, ID documents, proof of income, employment details, references, and notes about what someone is looking for. ID and financial documents are the sensitive part. They're what you most need to protect, and to delete when you're done.

The main obligations

A lawful basis for each use

For applicant data this is usually one of:

  • Contract: processing needed to take steps at the applicant's request before a lease, such as considering their application
  • Legal obligation: for example, Right to Rent checks in England
  • Legitimate interests: where you have a genuine need and it doesn't override the person's interests
  • Consent: typically for marketing, such as emailing someone about other properties

Marketing email also falls under separate rules (PECR in the UK, the ePrivacy rules in the EU). Get consent before sending it, and make unsubscribing easy.

Tell people what you do

A privacy notice that matches what you actually collect, why, who you share it with, how long you keep it, and what rights people have. Link it from your application form.

Cookies

Non-essential cookies generally need consent. The 2025 Act relaxes this in the UK for some low-risk cookies, such as certain analytics, provided people can object. Check the ICO's current guidance before relying on it.

Access requests

People can ask for a copy of the data you hold about them. You generally have one month to respond, which can be extended by up to two further months for complex or numerous requests. In the UK, the 2025 Act confirms that you need to make reasonable and proportionate searches, and lets the clock pause while you ask for information you genuinely need to deal with the request.

Deletion and retention

Decide how long you keep applicant data, write it down and stick to it. Unsuccessful applicants' ID and payslips are the obvious candidates for early deletion. People can ask for erasure; you must comply unless you have a legal reason to keep the data.

Breaches

If personal data is lost or exposed, you must report it to the regulator within 72 hours of becoming aware of it, unless it's unlikely to put anyone at risk. If it's likely to put people at high risk, tell them too, without undue delay.

Complaints

The 2025 Act requires UK controllers to have a way for people to make data protection complaints to them directly. Check the ICO's guidance for when this applies.

Fines

Regulators can fine seriously: the higher tier reaches €20 million or 4% of annual turnover (whichever is higher) in the EU, and £17.5 million or 4% under the UK GDPR. For a small agency, a regulator's attention is the more likely cost than the maximum fine.

Your software suppliers

Anything that holds applicant data on your behalf is a processor, and you're the controller. You should have a data processing agreement with each one and know where they store data.

How Loftfolio handles its part

For applicant data on your site, you're the controller and Loftfolio is the processor. We offer a data processing agreement on request. The database is hosted in the United Kingdom (AWS London region, through Supabase); our GDPR page lists the sub-processors and how transfers are covered.

In the product: photos are stripped of location metadata on upload; you can export listings, applications and messages as CSV, JSON or ZIP on every plan; the owner portal shows applicants by stage, never by name; AI inquiry triage reads messages on our own servers rather than sending them to an AI provider; and applicant matching emails go out only with recorded consent, with a one-click unsubscribe.

What stays with you: your privacy notice, your retention policy, which documents you ask for, and answering requests from applicants.

→ Read Loftfolio's GDPR page

#GDPR#UK GDPR#data protection#privacy#letting agents
Share this article
XLinkedIn
L

Written by Loftfolio's founder

Builds Loftfolio. Writes about what small agencies and landlords actually deal with.

Ready to build your agency website?

A branded website, the application pipeline and your team — live this afternoon, from $39 a month for the whole agency.

→ See the three plans

No contract · Cancel anytime