Prop-Pocket

How to secure tenant data: a landlord's compliance checklist

Published 20 August 2026 by Prop-Pocket Team

Discover essential steps to secure tenant data and ensure compliance as a landlord. Protect personal information and avoid legal issues today!

How to secure tenant data: a landlord's compliance checklist

Decorative title card illustration

Secure tenant data means holding only the personal and tenancy information you genuinely need, storing it with encryption and clear access rules, and being able to prove you did so if the Information Commissioner's Office (ICO) or a tenant ever asks. As a landlord, you're a data controller under UK GDPR, which means you decide why and how tenant data gets processed, and you carry the legal responsibility if it's mishandled.

Three actions get you moving today:

Key Takeaways

Secure tenant data requires collecting only what's necessary, encrypting and access-controlling what you keep, and maintaining evidence such as retention logs and DPAs to prove compliance.

| Point | Details |
| --- | --- |
| Confirm your controller status | Register with the ICO where required and document your lawful basis for processing tenant data. |
| Cut collection to the essentials | Map what you gather from applicants and stop retaining anything beyond genuine need. |
| Set a retention schedule | Keep contract records up to 6 years and right-to-rent documents for 2 years after tenancy end. |
| Log every breach and SAR | Record discovery, actions taken, and respond to SARs within one calendar month. |
| Centralise records with evidence built in | Prop-Pocket combines encrypted storage, role-based access, and audit logs to support ICO compliance. |

Table of Contents

What are a landlord's legal duties for secure tenant data?

Being a data controller isn't a formality. It means you're personally accountable for how tenant applications, right-to-rent checks, guarantor forms, and rent records are stored and shared, and UK GDPR and the Data Protection Act 2018 set the rules you must follow. Non-compliance can lead to serious penalties, so registration status and paperwork matter more than most landlords assume.

Landlord securing server cabinet lock

Many landlords who process personal data for business purposes need to register with the ICO and pay the data protection fee. Even where registration isn't required, keeping evidence of your lawful basis for processing (usually contract or legitimate interest for tenancy management) protects you if questioned.

Subject Access Requests deserve particular attention. A tenant can ask what personal data you hold on them at any time, and you must usually respond within one calendar month, extended by up to two months for genuinely complex requests. Practical prep matters here:

Pro Tip: Build a simple SAR log now, even before you receive one. A blank template with columns for date received, identity check, and response date turns a stressful scramble into a five-minute task.

How do you collect, store and share tenant data securely?

Start with the principle of least data: map every piece of information you currently collect from applicants and tenants, then ask whether you actually need it. Landlords routinely hoard old bank statements, spare copies of passports, and guarantor details for tenancies that ended years ago. None of that should still exist.

  1. Control your intake channel. Replace email attachments with a secure upload portal that logs who submitted what and when. If a portal isn't available, at least password-protect documents and confirm receipt in writing.
  2. Encrypt data at rest and in transit. Files sitting on a laptop or shared drive should be encrypted, and any transfer, whether to your accountant or a new letting agent, should go through an encrypted channel rather than plain email.
  3. Enforce multi-factor authentication. Every device and account touching tenant records, from your phone to your cloud storage, should require more than a password.
  4. Apply role-based access control. A contractor fixing a boiler doesn't need to see rent arrears history; they need an address and a job description. Grant the minimum, and revoke access the day the work finishes.
  5. Vet your vendors properly. Before handing tenant data to a letting agent, accountant, or software provider, check they'll sign a Data Processing Agreement, confirm where data is stored, and ask how they support deletion and access logging. This aligns with wider cyber-security guidance for property management, which flags shared inboxes and unmonitored payment workflows as common weak points.

If you manage multiple tenancies or share admin duties with a family member or co-landlord, permission creep becomes a real risk fast. Someone gets added "temporarily" to a shared inbox and stays there for years after they stop helping. Review who has access at least twice a year, and remove anyone whose role has changed. Understanding the full scope of a landlord's role in a tenancy helps clarify exactly what data each stage of the relationship actually justifies collecting.

How long should landlords keep tenant data, and how do you delete it?

Retention should follow a written schedule, not guesswork or "just in case." Official guidance from Rent Smart Wales recommends keeping right-to-rent documents for two years after a tenancy ends, while a separate GDPR retention guide suggests six years for many tenancy contract records, covering the standard limitation period for contract claims.

Redaction should sit alongside retention. Keep unredacted originals, such as full bank statements or passport scans, in a restricted archive with a documented access list, and use redacted copies (income figures only, no account numbers) for day-to-day reference. Document redaction guidance for property managers also recommends deleting rejected applicants' records within a short, defined window rather than letting them linger indefinitely.

| Record type | Suggested retention |
| --- | --- |
| Tenancy agreements and contract records | Up to several years after tenancy ends |
| Right-to-rent documents | 2 years after tenancy ends |
| Rejected applicant records | Deleted promptly, within a short defined window |

Digital deletion isn't as final as it looks. A file dragged to the recycle bin often leaves recoverable traces on the drive, so use a proper overwrite tool for anything sensitive, and don't forget backups, which quietly retain copies long after the "original" is gone. For paper, certified shredding is the baseline. Either way, keep a deletion log recording what was destroyed, when, and by whom. It's the single piece of evidence that turns "we deleted it" into something you can actually prove.

What should landlords do when a breach or data request happens?

A suspected breach demands speed. Contain it first: disconnect the affected account or device, change passwords, and work out what data was exposed before you do anything else.

  1. Assess the risk to tenants. If the breach could cause real harm (identity theft, financial loss, distress), you're generally expected to notify the ICO within 72 hours of becoming aware.
  2. Log everything as you go. Record who discovered the breach, when, what data was involved, and what you did to contain and mitigate it. The ICO expects this evidence trail even if you conclude notification isn't required.
  3. Treat DSARs with the same discipline. Log the request date, confirm the requester's identity, search all storage locations, and respond within one calendar month wherever possible.

Retaining your privacy notice, DPAs with vendors, and deletion logs gives you the documentary evidence that separates a landlord who acted properly from one who simply got lucky.

What most landlords get wrong about data security

Landlords tend to treat data protection as a compliance box to tick once, rather than a process that needs revisiting every time a tenancy starts or ends. That's backwards. The biggest exposure isn't usually a hacker; it's an old spreadsheet with three years of ex-tenants' bank details still sitting in someone's downloads folder.

My starting plan for any landlord serious about this: first, map what you collect and cut anything you don't need. Second, centralise what's left behind one access-controlled system instead of scattering it across email, phone photos, and paper files. Third, automate retention and deletion so nothing depends on someone remembering to act. This is precisely where Prop-Pocket's approach to centralised, structured records earns its place. Rapid onboarding means you're not stuck migrating data for weeks while your exposure sits unmanaged, and having every document behind one system with a clear audit trail reduces the everyday human error that causes most breaches, not sophisticated attacks.

A more secure way to manage tenant data day to day

Prop-Pocket gives you a genuine practical route to everything covered above, without turning compliance into a second job. Rather than juggling email attachments, a locked cabinet, and a mental note about retention dates, you get encrypted document storage, role-based permissions so contractors only see what they need, and audit logs that record exactly who accessed what and when.

Prop-Pocket

That combination matters when a tenant sends a Subject Access Request or the ICO comes asking questions, because you're not scrambling to reconstruct a history; you already have it. Retention scheduling flags records due for deletion, the AI communication drafter helps you respond to tenant queries without slow, error-prone manual replies, and the property overview dashboard keeps every tenant's records organised property by property rather than scattered across folders. If you're managing your first property, you can set this up at no cost. Explore the full feature set and get your account running in minutes.

Where to read more on landlord data protection

For deeper detail beyond this checklist, the ICO's own guidance and the sources referenced throughout remain the most reliable starting points.

Frequently asked questions

What counts as tenant data landlords need to secure?
Personal and tenancy records, including applications, ID documents, right-to-rent checks, guarantor details, rent payment history, and correspondence containing personal information.

Do landlords need to register with the ICO?
Many landlords processing personal data for business purposes must register and pay the data protection fee; check your specific circumstances against official guidance.

How quickly must a landlord respond to a Subject Access Request?
Generally within one calendar month, with a possible two-month extension for complex requests.

How long should landlords keep rejected applicants' data?
Delete it promptly, within a short, documented window, since there's no ongoing tenancy relationship to justify retention.

What should a landlord do first after a suspected data breach?
Contain it immediately: secure the affected account or device, assess what was exposed, and log the incident before deciding whether ICO notification is required.

Frequently asked questions — overview diagram

How does joint or shared tenancy affect data handling?
Each named tenant has independent data rights, so a SAR from one joint tenant should be handled individually, and access to shared records should still follow role-based permissions rather than blanket sharing.

Sources

Recommended

Never miss a compliance deadline

Joinlandlords using Prop-Pocket to track certificates, manage repairs and stay compliant — for free.

Try Prop-Pocket Free

← Back to all articles