The law changed on 1 May 2026. Section 21 is abolished and new tenancies are now assured periodic tenancies. See what every landlord must do →
Landlord Laws & Legislation

UK GDPR and the Data Protection Act 2018: A Landlord's Guide

← Part of Landlord Laws & Legislation

Reviewed by Bradley Askew, Solicitor (non-practising), England & Wales. Reviewed 18 July 2026.

The UK General Data Protection Regulation (UK GDPR) — the retained, UK-specific version of the EU regulation, applied and supplemented by the Data Protection Act 2018 (DPA 2018) — governs how landlords collect, use, store, and dispose of tenant personal data. It applies from the first enquiry through to years after a tenancy ends. Landlords are "data controllers." The maximum civil penalty is £17.5 million or 4% of worldwide turnover, whichever is higher. Subject access requests must be answered within one month. Notifiable data breaches must be reported to the Information Commissioner's Office (ICO) within 72 hours. Many landlords also need to register with the ICO and pay an annual data protection fee — a step the framework requires but that is frequently overlooked. The Data (Use and Access) Act 2025 (DUAA), now largely in force, has added new duties on top of this framework, including a requirement from 19 June 2026 to handle tenant complaints about data protection directly, before the ICO gets involved.

This guide covers who counts as a controller, whether you need to register with the ICO, the legal bases for processing tenant data, the data protection principles, privacy notices, subject access requests and other data subject rights, retention periods, security obligations, the 72-hour breach reporting rule, the new DUAA complaints duty, and the current penalty regime.

Key takeaways

  • Almost every landlord who processes tenant applications, references, credit checks, or tenancy agreements is a UK GDPR "data controller" — portfolio size is irrelevant.
  • If you carry out credit checks or hold a database of prospective tenants (rather than fully delegating to a managing agent), you likely need to pay the ICO's data protection fee — £52 a year for most individual landlords, or £47 by direct debit.
  • Subject access requests must be answered within one calendar month (extendable to three months for complex requests), and the DUAA 2025 now lets you pause that clock while waiting for reasonable clarification.
  • Notifiable breaches must be reported to the ICO within 72 hours of you becoming aware of them; the maximum civil penalty is £17.5 million or 4% of turnover.
  • From 19 June 2026, you must have a process for handling data protection complaints made directly to you by tenants, acknowledged within 30 days — a new duty introduced by the DUAA 2025.
  • None of this is displaced by the Renters' Rights Act 2025. The tenancy structure changed; the data protection framework did not.

Who this applies to: are you a "data controller"?

A "data controller" is anyone who decides why and how personal data is processed. A landlord who collects a prospective tenant's name, date of birth, address history, employer details, bank details, and emergency contacts — and decides what to do with that information — is a data controller, whether they own one property or a hundred. There is no small-landlord exemption from the substance of the framework itself, though (as covered below) there are exemptions from the separate duty to pay the ICO's data protection fee.

Some landlords assume that delegating day-to-day management to a letting agent removes them from the picture entirely. It doesn't, unless the agent has genuinely full management responsibility and the landlord's own involvement is limited to receiving a monthly statement and the rent. Where a landlord makes tenant-selection decisions, holds a database of applicants, or receives copies of tenancy paperwork directly, the landlord remains a controller in their own right, alongside the agent.

Do you need to register with the ICO and pay the data protection fee?

This is the step most individual landlords miss. Under the Data Protection (Charges and Information) Regulations 2018, organisations and sole traders that process personal data must pay the ICO's data protection fee unless an exemption applies. Failing to pay when required is a criminal offence, enforced separately from ordinary UK GDPR compliance.

According to the ICO's own guidance for the real estate sector, a landlord needs to pay the fee if they process personal data to produce tenancy agreements, run credit checks through a reference agency, or obtain references on prospective tenants. A landlord who uses a letting agent for full management and only ever receives a monthly statement and the rent can usually rely on the "accounts and records" exemption — but that exemption falls away the moment the landlord creates their own database of applicants, makes tenant-selection decisions directly, or receives electronic copies of tenancy agreements.

The current fee is £52 a year for most individual landlords and small portfolios (Tier 1), or £47 if paid by direct debit. The ICO publishes a free self-assessment tool to confirm whether a fee is payable and, if so, which tier applies.

What counts as personal data in landlord operations

Personal data is any information relating to an identified or identifiable individual. In landlord operations this typically includes:

  • Tenant identification — names, dates of birth, photographs, ID document copies.
  • Contact information — addresses, phone numbers, email addresses.
  • Employment information — employer names, payslip details, employer references.
  • Financial information — bank details for rent payments, credit check results, deposit references.
  • Right-to-rent documentation — passport copies, visa documents, online share codes.
  • Communication records — emails, texts, and letters relating to the tenancy.
  • Property and tenancy records — inspection reports, repair history, complaints.
  • Emergency contacts — names and contact details of family or others.

Some of this is "special category" data under Article 9, attracting heightened protection — information revealing health conditions, religious belief, ethnic origin, political opinions, trade union membership, sex life or sexual orientation, or biometric data used for identification. Landlords occasionally encounter this (for example, medical information supporting a disability-related reasonable adjustment request, or health information disclosed in an arrears or possession dispute) and must identify a specific Article 9 condition — commonly that the processing is necessary for the establishment, exercise, or defence of legal claims — in addition to an ordinary Article 6 legal basis.

The legal bases for processing (Article 6)

Every processing operation needs a legal basis under Article 6 of the UK GDPR. Six bases are available:

  • Consent — clear, freely given, informed, specific agreement from the data subject.
  • Contract — processing necessary to perform a contract, or to take pre-contractual steps at the data subject's request.
  • Legal obligation — processing necessary to comply with a legal duty, such as right-to-rent checks under the Immigration Act 2014.
  • Vital interests — processing necessary to protect someone's life.
  • Public task — processing necessary for tasks carried out in the public interest (rare for private landlords).
  • Legitimate interests — processing necessary for the controller's legitimate interests, provided these aren't overridden by the data subject's rights and freedoms.

In practice, landlords rely most heavily on:

Contract — collecting rent, sending statutory notices, arranging repairs, and general tenancy administration all fall within "necessary to perform the contract."

Legal obligation — right-to-rent checks under the Immigration Act 2014, deposit-protection prescribed information under the Housing Act 2004, and gas safety record provision under the Gas Safety (Installation and Use) Regulations 1998 are all separate statutory duties that also justify the associated data processing.

Legitimate interests — tenant referencing, credit checks, and retaining records after a tenancy ends for limitation-period purposes typically rely on this basis, supported by a documented legitimate interests assessment weighing the landlord's interest against the tenant's rights.

Consent is generally a weak basis for core tenancy processing because it can be withdrawn at any time, potentially leaving the landlord without a lawful basis to continue essential processing. Reserve it for genuinely optional processing (for example, opting in to receive property-related marketing after the tenancy ends) rather than anything necessary to run the tenancy itself.

The DUAA 2025 also introduced a narrow, defined list of "recognised legitimate interests" — specific categories such as safeguarding vulnerable individuals, crime prevention, and national security — where a controller can rely on legitimate interests without carrying out the balancing exercise. These categories are prescribed and narrow; they rarely apply to routine landlord administration, but a landlord dealing with a genuine safeguarding concern about a vulnerable tenant may find this route relevant.

The data protection principles (Article 5)

Article 5 sets out the principles that govern all processing:

  • Lawfulness, fairness, and transparency — process with a legal basis, without misleading the data subject, and with clear information about what you're doing.
  • Purpose limitation — collect data for specified purposes and don't repurpose it incompatibly.
  • Data minimisation — collect and retain only what's necessary.
  • Accuracy — keep data accurate and up to date; correct errors promptly.
  • Storage limitation — don't keep data longer than necessary.
  • Integrity and confidentiality — process data securely.
  • Accountability — be able to demonstrate compliance with all of the above.

The ICO assesses landlord conduct against these principles when investigating complaints, and breach of the principles can support a civil claim by an affected tenant.

Privacy notices: what tenants must be told

Article 13 requires controllers to give data subjects specified information at the point of collection. For landlords, this means a privacy notice covering:

  • The landlord's identity and contact details.
  • The purposes of processing.
  • The legal basis relied on for each purpose.
  • The legitimate interests pursued, where that's the basis.
  • Recipients or categories of recipients of the data.
  • How long data will be retained.
  • The tenant's rights and how to exercise them.
  • The right to complain to the ICO.

Most landlords meet this requirement with a privacy notice given at the start of the application process, often included as a schedule to the tenancy agreement. The ICO's SME web hub sets out what a compliant privacy notice needs to cover in plain terms.

Data subject rights and subject access requests

Tenants have substantial rights under UK GDPR, including:

  • The right of access — a subject access request (SAR) entitles a tenant to a copy of the personal data held about them.
  • The right to rectification — inaccurate data must be corrected on request.
  • The right to erasure — data must be deleted in defined circumstances.
  • The right to restrict processing — processing must be paused in defined circumstances.
  • The right to data portability — data must be provided in a portable format on request.
  • The right to object — processing based on legitimate interests must stop on request unless the landlord can demonstrate overriding legitimate grounds.

Subject access requests are the most common right exercised against landlords. A current or former tenant requesting "all the data you hold about me" is entitled to a copy within one calendar month of a valid request, extendable by up to two further months for complex or numerous requests (the landlord must notify the tenant of any extension within the first month). Following the DUAA 2025 changes, a landlord can also pause the one-month clock while waiting for reasonable clarification of a broad or ambiguous request. Requests are normally free; manifestly unfounded or excessive requests can be refused or charged a reasonable fee, though the burden is on the landlord to show a request meets that bar.

Automated decision-making and tenant-screening tools

An increasing number of landlords and letting agents use automated referencing or credit-scoring platforms to assess prospective tenants. Article 22 of the UK GDPR restricts decisions based solely on automated processing that have a legal or similarly significant effect on someone — for example, automatically rejecting an application on the basis of a credit score alone, with no human review. The DUAA 2025 changed this framework: the strict prohibition is now narrowed to decisions involving special category data, while wider use of automated decision-making is permitted for ordinary data, subject to safeguards such as the right to request human intervention, to express a view, and to contest the decision.

A landlord who relies on an automated tenant-screening tool should confirm that a human being reviews any automated rejection before it's communicated, or that the tenant is told how to request human review — both to comply with Article 22 and because purely automated rejections are a common source of tenant complaints and discrimination risk.

Retention periods for landlord records

Storage limitation requires data to be kept only as long as necessary. Typical periods in landlord operations:

  • Right-to-rent records — Home Office guidance expects copies to be kept for the duration of the tenancy plus 12 months after it ends.
  • Tenancy agreements and amendments — typically 6 years from the end of the tenancy, matching the standard contract limitation period.
  • Deposit records — for the duration the deposit is held, plus a reasonable period after return (commonly 6 years).
  • Gas safety records — a minimum of 2 years under the Gas Safety (Installation and Use) Regulations 1998; many landlords keep them longer as best practice.
  • Tenant referencing data not leading to a tenancy — typically a matter of months unless retained for a specific, documented purpose.
  • Email correspondence — follow contract retention (6 years) for substantive correspondence about the tenancy; shorter for routine queries.

Records connected to an ongoing or reasonably foreseeable dispute may need to be kept longer — the landlord's legitimate interest in defending a claim usually justifies extension until the relevant limitation period has expired.

Data security obligations (Article 32)

Article 32 requires "appropriate technical and organisational measures" to secure personal data. In practice this typically means:

  • Encrypted storage for digital records, including backups, mobile devices, and cloud storage.
  • Strong access controls — passwords, two-factor authentication, no shared or generic logins.
  • Secure transmission — encrypted email or secure file transfer for sensitive documents such as ID scans.
  • Physical security for paper records — locked storage, restricted access.
  • Secure disposal — shredding for paper, secure deletion for digital files once the retention period ends.

Inadequate security that leads to a breach can result in ICO investigation and enforcement, civil claims from affected tenants for distress or financial loss, and reputational harm affecting future lettings and any HMO licensing applications.

Breach reporting: the 72-hour rule

Where a personal data breach is likely to result in a risk to the rights and freedoms of the individuals affected, it must be reported to the ICO without undue delay and, in any event, within 72 hours of the landlord becoming aware of it. Where the risk is high, the affected individuals must also be told directly. The ICO's own guidance recognises that a full investigation won't always be possible within 72 hours — an initial report can be made with the information available, followed by supplementary detail as the investigation progresses.

"Breach" is broadly defined: accidental disclosure (sending tenant data to the wrong recipient), unauthorised access (a stolen laptop or phone containing tenant records), unauthorised alteration, and accidental loss all count. Every landlord should have a written breach-response procedure, even a short one, so the 72-hour clock doesn't start with a decision about what to do.

New duty: handling data protection complaints directly

From 19 June 2026, the DUAA 2025 introduced a statutory requirement for controllers — including landlords — to have a process for handling data protection complaints made directly to them by data subjects. Where a tenant complains that a landlord has mishandled their data, the landlord must acknowledge the complaint within 30 days and take appropriate steps to respond, before the tenant escalates to the ICO. This is a genuinely new operational duty, distinct from responding to a subject access request, and sits alongside (not instead of) the tenant's separate right to complain to the ICO at any time.

A short written procedure — how a complaint is logged, who reviews it, and the 30-day acknowledgement point — is enough for most individual landlords and small portfolios to meet this duty.

Civil penalties and enforcement

Two tiers of monetary penalty apply under the UK GDPR and DPA 2018 framework:

  • The higher maximum — £17.5 million or 4% of total worldwide annual turnover, whichever is greater — for breaches of the core data protection principles, individual rights, or international data transfer rules.
  • The standard maximum — £8.7 million or 2% of turnover, whichever is greater — for breaches of other, more administrative requirements.

In practice, penalties for typical landlord-scale breaches have historically been far below these statutory ceilings; the ICO's stated approach is that penalties should be effective, proportionate, and dissuasive, decided case by case. The bigger practical risk for most landlords is not a large fine but reputational damage, ICO investigation, and civil claims from affected tenants for compensation, distress, or the cost of protective measures such as credit monitoring.

One structural point worth noting: the DUAA 2025 replaces the Information Commissioner's Office's current legal structure (a single office-holder, the Information Commissioner) with a new body corporate, the Information Commission, led by a chair (who retains the title "Information Commissioner"), a chief executive, and other members. This is a governance change, not a change to the regulator's functions or the penalty framework — "ICO" remains the practical name landlords will deal with.

How UK GDPR sits alongside the Renters' Rights Act 2025

The Renters' Rights Act 2025 restructured tenancies from 1 May 2026 — Section 21 abolished, fixed-term assured shorthold tenancies gone, and possession now running through an expanded Section 8 grounds framework. None of this displaces the data protection framework described on this page. Every application form, right-to-rent check, Information Sheet, rent-increase notice, and possession-ground record a landlord now handles under the post-1-May-2026 regime is still personal data, still processed under a UK GDPR legal basis, and still subject to the same retention, security, and subject-access obligations as before.

Practical compliance checklist

A landlord managing this well typically:

  1. Confirms whether they need to pay the ICO's data protection fee and pays it if they do — this is a separate legal duty from the substantive UK GDPR framework.
  2. Provides a privacy notice to every prospective and actual tenant, tailored to their own operations.
  3. Maintains a documented retention schedule — what's held, why, and for how long.
  4. Stores data securely — encrypted digital records, secure paper files, proper disposal.
  5. Responds to subject access requests within the statutory deadline, using the DUAA clarification pause where a request is genuinely unclear.
  6. Has a written breach-response procedure, ready to use within the 72-hour reporting window.
  7. Has a short complaints procedure so a tenant's data protection complaint is acknowledged within 30 days, per the DUAA 2025 duty.
  8. Reviews annually — processing activities, retention practice, security measures, and any further Data (Use and Access) Act 2025 provisions coming into force.

When to get proper advice

This guide sets out the general framework for landlords in England and Wales. It is not a substitute for advice on your specific situation. If you're facing an active ICO investigation, a significant data breach involving sensitive or special category data, a subject access request connected to a live dispute, or uncertainty about whether an exemption from the ICO fee applies to your circumstances, speak to a practising solicitor or a qualified data protection adviser. The ICO's advice for small organisations is a good first stop for self-serve guidance before instructing an adviser.

Sources

This guide reflects UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act 2025 as at 18 July 2026. The DUAA 2025 is commencing in stages; some provisions may still be subject to further commencement regulations. Check gov.uk and ico.org.uk for updates.

Common questions

Do landlords need to register with the ICO and pay the data protection fee?

Usually yes. If you produce tenancy agreements, run credit checks through a reference agency, or obtain references on prospective tenants, the ICO's own guidance says you need to pay the data protection fee — currently £52 a year (£47 by direct debit) for most individual landlords and small portfolios. The main exemption is where a letting agent fully manages the property and you only ever receive a monthly statement and the rent. Failing to pay when required is a criminal offence, separate from and in addition to any UK GDPR compliance failure.

What is a subject access request and how quickly must I respond?

A subject access request (SAR) is a request from a current or former tenant for a copy of the personal data you hold about them. You must respond within one calendar month of receiving a valid request, extendable by up to two further months for complex or numerous requests (you must tell the requester within the first month if you're extending). Since the Data (Use and Access) Act 2025 changes, you can also pause the clock while you wait for reasonable clarification of a broad or unclear request.

What is the maximum fine for a UK GDPR breach?

The higher maximum is £17.5 million or 4% of total worldwide annual turnover, whichever is greater, for breaches of the core data protection principles, individual rights, or international transfer rules. A lower standard maximum of £8.7 million or 2% of turnover applies to breaches of administrative requirements. In practice, the ICO's actual fines for small landlord-scale breaches have historically been far below these statutory ceilings, but the ceilings themselves are real.

Do I have to report every data breach to the ICO within 72 hours?

No — only breaches likely to result in a risk to the rights and freedoms of the individuals affected. If a breach is unlikely to cause harm (for example, a password-protected file sent to the wrong internal folder with no third party ever seeing it), it may not be reportable. When in doubt, the ICO's guidance is to err on the side of reporting, and you must always keep an internal record of every breach, reportable or not.

Has the Data (Use and Access) Act 2025 changed my duties as a landlord?

Yes, in several practical ways. From 19 June 2026, you must have a process for handling data protection complaints made directly to you by tenants, acknowledging them within 30 days. Subject access request handling gained a 'stop the clock' clarification pause. Automated decision-making rules changed, which matters if you use an automated tenant-screening or credit-scoring tool. The core framework — legal bases, principles, breach reporting, fine levels — is unchanged.

Does UK GDPR still apply now the Renters' Rights Act 2025 has abolished Section 21?

Yes, entirely. The Renters' Rights Act 2025 changed the tenancy structure — periodic tenancies only, Section 21 gone, new statutory grounds — but it did not touch data protection law. Every notice, application form, referencing check, and record you handle under the post-1-May-2026 framework is still personal data subject to the full UK GDPR and Data Protection Act 2018 framework described on this page.