Fix Tenant Profile Privacy in 5 Steps for Landlords — Templates & LIA
3 September 2026
18 min read
Practical, operations-first checklist for landlords: five immediate actions to secure tenant profile privacy, copy-ready privacy-notice lines, an LIA...
As the data controller for your properties, you must only collect what you need, give a privacy notice, secure tenant data properly, and keep clear deletion schedules. Do these five things now: limit collection to what tenancy actually requires, issue a privacy notice before or when you collect data, secure storage with encryption and access controls, set retention windows in advance, and prepare a simple process for subject access requests and breaches. The templates and checklists below make each step quick to put into practice.
TL;DR:
Landlords should only collect tenant data necessary for each stage of the rental process, avoiding unnecessary sensitive information such as health or ethnicity details unless strictly needed.
A privacy notice must be given before or at the point of data collection, clearly outlining purposes, lawful bases, sharing, and retention periods in a simple, accessible format.
Tenant data should be stored securely using encryption, strong passwords, and role-based access controls, with regular reviews of who has access every six months.
Records must be retained only as long as necessary—typically the duration of the tenancy plus six years for core records—and securely deleted afterward by shredding physical copies or digitally overwriting files.
Sharing tenant data with agents or third-party software requires explicit agreements covering scope, security, and data deletion, with the landlord remaining ultimately responsible for compliance and data handling practices.
#gdpr tenant data ireland#tenant data privacy#secure document sharing rentals#landlord gdpr ireland#tenant confidentiality measures#landlord tenant data protection#share documents securely#tenant data security#privacy rights for tenants#how to protect tenant information#tenant profile privacy#rental application privacy#gdpr for landlords
What tenant data do landlords collect, and what needs extra care?
A tenant's rental journey generates far more personal data than most landlords realise, and it arrives in stages. At viewing stage, you might collect a name, phone number, and email. By application, you're usually holding a full photo ID, proof of income, references, and often a credit check. Once the tenancy starts, you add bank details for rent payments, emergency contact information, and sometimes CCTV or smart-lock access logs. After the tenancy ends, you're still sitting on all of it unless you've actively deleted it.
Some of what lands in your inbox counts as "special category" data under data protection law: health conditions, disability details, religious observance, or racial or ethnic origin. This kind of information deserves far tighter handling than a standard ID scan, and in most cases you shouldn't be asking for it at all. A tenant volunteering a health condition to explain a reasonable adjustment request is different from you proactively asking about medical history on an application form. If you don't strictly need it to run the tenancy, don't collect it.
Here's what typically gets gathered, stage by stage:
Enquiry/viewing: name, contact details, general preferences
Application: passport or driving licence, proof of address, employment and income evidence, referee contact details, credit check consent
Tenancy: bank account details for rent, guarantor information, emergency contacts, maintenance request logs
Post-tenancy: deposit return correspondence, references given to future landlords, dispute records
The riskiest habits tend to be the most convenient ones. Sending a photo of someone's passport over WhatsApp feels harmless in the moment, but that message sits on a server you don't control, often forever, with no audit trail. Storing scanned IDs in a shared drive with no password protection is just as exposed. If a device gets lost or a phone gets sold on without a proper wipe, that data goes with it. As a data controller, you must have a lawful basis for holding tenant information and keep it secure throughout its life with you, not just when it's collected.
Which lawful basis applies to each type of tenant data?
Every piece of tenant data you hold needs a lawful basis attached to it, and you need to be able to name that basis if asked. Most landlord activity falls under one of three: contract, legal obligation, or legitimate interests. Consent is rarely the right fit for anything a tenancy actually requires, because consent has to be freely given and easily withdrawn, which doesn't work when the data is essential to running the letting.
Here's how the common bases map onto everyday landlord tasks:
Contract covers anything needed to perform the tenancy agreement: rent collection details, maintenance requests, move-in inventories.
Legal obligation covers right-to-rent checks, tax reporting, and anything a statute requires you to record or retain.
Legitimate interests covers things like credit checks during screening, or using CCTV footage to investigate an incident, where you have a genuine business reason that doesn't override the tenant's rights.
Consent covers the rare cases outside the tenancy itself, such as opting into a newsletter about future properties.
When you rely on legitimate interests, a Legitimate Interests Assessment (LIA) is your paper trail if a tenant or the regulator ever asks why you held their data. It doesn't need to be long. A workable skeleton looks like this:
Purpose: why are you processing this data? (e.g. "verifying affordability before offering a tenancy")
Necessity: is there a less intrusive way to achieve the same result?
Balancing test: does your interest outweigh the tenant's right to privacy in this specific case?
Mitigation: what safeguards reduce the risk (limited access, short retention, anonymising where possible)?
Pro Tip:Write your LIA before you start the activity, not after a complaint lands. A one-paragraph LIA saved in your property file takes ten minutes and answers most regulator questions on its own.
If you're managing several properties or run a letting business, check whether your activity triggers a registration or fee obligation with your data protection regulator. Rules vary by scale and structure, so it's worth confirming your position directly with your regulator's guidance rather than assuming a small portfolio is automatically exempt.
What must a tenant privacy notice include, and when do you give it?
A privacy notice tells tenants what you're doing with their data, and it has to arrive at or before the point you collect it. Bolting it onto a tenancy agreement three weeks after you've already taken a passport scan is too late.
At minimum, your notice needs to cover:
Who you are (landlord or managing agent name and contact details)
The purposes you're processing data for (screening, tenancy management, legal compliance)
The lawful basis for each purpose
Who you might share the data with (referencing agencies, letting platforms, contractors)
How long you'll keep each category of data
The tenant's rights (access, correction, deletion, complaint)
Contact details for complaints, including your relevant regulator
You don't need a legal document. A single page or an email works fine, provided it's clear. Adaptable fields for your own notice might read:
"We collect [data type] to [purpose]."
"We rely on [lawful basis] to process this."
"We keep this data for [retention period] because [reason]."
"We may share this with [named third parties] for [purpose]."
"You can request access, correction or deletion by contacting [email/name]."
"If you're unhappy with how we've handled your data, you can complain to [regulator]."
How should you store tenant data and control access to it?
Storage security comes down to a handful of habits, most of which cost nothing beyond a few minutes of setup. Turn on device encryption for the laptop or phone where tenant files live. Use a password manager and unique passwords rather than reusing the one you've had since 2015. Enable two-factor authentication on your email and any cloud storage account holding tenant documents. Keep software updated, because most breaches exploit vulnerabilities that were already patched months earlier.
If you work with a letting agent, a co-landlord, or contractors, apply the principle of least privilege: give people access only to what their role actually requires. A contractor fixing a boiler doesn't need to see a tenant's bank details. An agent handling viewings doesn't need access to signed guarantor forms unless they're managing the full tenancy.
Practical dos and don'ts that matter more than any policy document:
Never send passports, proof of income, or bank details over WhatsApp, SMS, or social media messaging.
Use a secure upload flow or encrypted email attachment instead of a shared, unlocked folder.
Lock down cloud folders with restricted sharing settings, not "anyone with the link."
Keep an audit trail of who accessed or downloaded sensitive files and when.
Delete drafts, duplicate scans, and old versions once a final copy is confirmed correct.
Pro Tip:Set a calendar reminder every six months to review who has access to your tenant files. People change roles, contractors finish jobs, but access permissions rarely get revoked automatically.
If you're managing several properties across different agents or family members helping with the letting, tools built for managing multiple rental properties securely can reduce the number of loose spreadsheets and shared folders you're relying on.
How long should you keep tenant records before deleting them?
Retention should follow the life of the tenancy, not your own convenience. A sensible default is to keep core tenancy records, such as the signed agreement, rent statements, and deposit correspondence, for the length of the tenancy plus about six years, matching the general civil limitation period for contract disputes. Right-to-rent copies should be kept for the tenancy plus twelve months, then deleted. Unsuccessful applicants are a different case entirely: if someone didn't get the tenancy, there's rarely a reason to hold their documents beyond a short window, typically a matter of weeks, unless you've told them otherwise and have a genuine reason.
These retention defaults, tenancy plus six years for core records and tenancy plus twelve months for right-to-rent evidence, give you a defensible starting point rather than an indefinite "just in case" archive.
If you think you need to keep something longer, for an ongoing dispute or a pending legal claim, write down why. A one-line note in your file ("retained beyond standard period due to active deposit dispute, review March 2027") is enough to show you've thought about it rather than defaulted to keeping everything forever.
When it's time to delete:
Shred physical documents rather than binning them whole.
Use your cloud provider's secure deletion function, not just moving files to a folder marked "old."
Overwrite rather than simply unlink files on local drives where sensitive scans were stored.
Keep a short deletion log noting what was removed and when, so you have proof if ever asked.
How do you handle a subject access request or a data breach?
A subject access request (SAR) is a tenant asking what data you hold on them, and you have one calendar month to respond, extendable by up to two further months for genuinely complex requests. The clock starts the day you receive the request, not the day you get round to reading it.
A workable SAR process:
Acknowledge the request within a few days, confirming what you understood them to be asking for.
Locate all the data you hold across email, cloud storage, and any property management software.
Redact any third-party personal data mixed in (a guarantor's details, a reference from a previous landlord) before disclosing.
Send the response within the one-month window, in a clear and readable format.
A breach is different, and speed matters more than perfection. If a laptop with tenant files is stolen, or you send a passport scan to the wrong email address, you must report it to your regulator within 72 hours if it's likely to risk tenants' rights and freedoms, and tell affected tenants directly if the risk is high.
A short checklist for the moment you discover a breach:
Contain it immediately (revoke access, change passwords, recall the email if possible).
Assess who's affected and how serious the exposure is.
Report to your regulator within 72 hours if the risk threshold is met.
Notify affected tenants directly if the risk to them is high.
Record what happened and what you changed to stop it recurring.
Pro Tip:Draft your breach notification template before you ever need it. A calm, factual email written in advance beats a panicked one written at 11pm the night you discover the leak.
A short acknowledgement line for a SAR might read: "We've received your request for the personal data we hold about you and will respond within one calendar month." A breach notification opener might read: "We're writing to let you know about a data security incident that may have affected your personal information, and what we're doing about it."
What should you check before sharing tenant data with agents or software providers?
Any time a letting agent, referencing agency, or property software handles tenant data on your behalf, they're a processor and you're still the controller. That means the responsibility for their mistakes ultimately traces back to you, so the contract you sign with them matters more than most landlords assume.
Check that any processor agreement covers:
The exact scope of what data they can access and for what purpose
The security measures they commit to (encryption, access controls, staff training)
Rules around using sub-processors, and whether you're told if they change
What happens to the data on contract termination, ideally guaranteed deletion, not just "we'll get round to it"
Your right to audit or ask questions about their practices
Operationally, ask where the data is actually hosted, and whether it ever leaves your jurisdiction. If a referencing agency stores files on servers outside the country, that's an international transfer, and it needs its own safeguard, not just a shrug. Ask how quickly they'd tell you about a breach on their end, because your 72-hour clock starts when you become aware, and a slow processor puts you at risk of missing it. If a provider can't answer these questions clearly, that's a reasonable moment to look elsewhere.
Quick checklist and copy-ready templates for landlords
Here's a one-page version of everything above, condensed into something you can actually run through before your next viewing or application.
Collect only what the tenancy genuinely requires; skip anything special-category unless it's essential.
Notify tenants with a privacy notice at or before collection.
Secure storage with encryption, 2FA, and restricted access.
Retain according to your set windows, and log what you delete.
Respond to SARs within one month, and have a breach process ready before you need it.
Copy-ready snippets to adapt:
Privacy notice line: "We process your data to [purpose] under [lawful basis], and keep it for [retention period]."
LIA skeleton: purpose, necessity, balancing test, mitigation, one line each.
Breach email opener: "We're writing to inform you of a data security incident affecting your personal information."
If you work with an agent or use a rental platform, some of this can be delegated, secure upload flows and consent screens, for instance, are often handled at platform level. But the underlying responsibility, knowing what's collected, why, and for how long, stays with you as the data controller regardless of who's doing the day-to-day handling.
What happens to tenant data when someone moves in or moves out?
Move-in is when most landlords collect the bulk of a tenant's personal data in one go: signed agreement, deposit registration, right-to-rent evidence, standing order details. It's worth pausing here to confirm you actually need everything you're about to file away, rather than defaulting to "better safe than sorry." An inventory with photos is standard and sensible; a full copy of a tenant's bank statement going back six months usually isn't necessary once affordability has already been checked at application stage.
Move-out triggers the opposite discipline: deciding what to delete and what to retain, as detailed in guidance on the role of maintenance records in property management. Deposit deduction evidence, final meter readings, and any dispute correspondence belong in your retention schedule. But contact details used purely for day-to-day tenancy communication, emergency numbers, guarantor details for a guarantee that's now expired, can usually be deleted once the deposit is returned and any dispute window has closed.
A structured tenant screening checklist applied consistently at application stage also reduces the temptation to over-collect at move-in, because you've already gathered what you need earlier in the process rather than duplicating it. The tenancy transition points, in and out, are where privacy habits either tighten up or quietly slip, so it's worth treating both as a deliberate checkpoint rather than paperwork to get through quickly.
What changes when tenant data is shared across a landlord group or agency?
Sharing tenant data between properties within the same landlord group, or between branches of a larger agency, isn't automatically fine just because it stays "in the family." Each transfer still needs its own lawful basis and its own line in your privacy notice, particularly if tenant data collected for one property is later used to assess that same person's application for a different property in the portfolio.
If you run a multi-property portfolio or work through a managing agency, be explicit about who's the controller for each purpose. Sometimes a managing agency acts as a processor, following your instructions; other times it's making its own decisions about tenant data and becomes a joint controller alongside you. That distinction affects who's accountable if something goes wrong, so it's worth clarifying in writing rather than assuming.
Practical steps for group or agency setups:
Maintain a single access log across the portfolio rather than separate, untracked spreadsheets per property.
Tell tenants explicitly if their data might be used to assess them for other properties within the same group.
Agree internally who signs off on SARs and breach notifications when more than one branch or manager might be involved.
The bigger the operation, the easier it is for a tenant's file to end up duplicated across three different folders with three different access lists, none of which anyone remembers to update.
Hauzed's perspective: design choices that protect tenant profile privacy
Most privacy failures in renting aren't malicious. They're the result of documents scattered across WhatsApp threads, personal email accounts, and shared drives nobody's audited in years. Hauzed's approach starts from the opposite instinct: build the secure path first, so the insecure one never becomes the default. Tenant documents move through consent-based upload flows rather than chat attachments. Verification happens once, in a structured profile, instead of being re-requested and re-sent every time a new landlord asks. Role-based access means an agent managing viewings doesn't automatically see the same data a landlord reviewing a signed application does.
None of this replaces your own responsibilities as a data controller. But it does remove several of the riskiest habits, unlocked folders, chat-based ID transfers, duplicate files, before they become a problem. Worth reviewing your own current process against that standard: how many places does a single tenant's passport scan currently live?
— Hauzed
How Hauzed helps landlords protect tenant profile privacy and simplify compliant workflows
Hauzed is the alternative to scattered email threads and messaging apps for handling rental documents: tenant identity checks, references, and supporting files move through one secure, consent-based flow instead of a dozen inboxes and phones.
Every applicant on Hauzed builds a structured tenant profile once, with identity verification and consent screens built into the process rather than bolted on afterwards. As a landlord, you review that profile directly instead of asking someone to resend a passport photo over text. Role-based access means agents and team members only see what their part of the job requires, and activity around a tenant's request or invitation leaves an audit trail you can point to if a question ever comes up. That's fewer insecure channels, clearer records for every candidate, and less time spent chasing documents that should have arrived properly the first time.
If you're managing lettings in Dublin or elsewhere in Ireland and want a workflow built around verified, privacy-aware tenant profiles rather than anonymous messages, visit Hauzed to see how the platform handles matching, chat, and document flow from one place.
Is a landlord classed as a data controller under GDPR?
Yes. If you decide what tenant data to collect and why, you're the controller and carry the legal responsibility for how it's handled, even if an agent does the day-to-day work.
Do I need a privacy notice for every applicant, not just accepted tenants?
Yes. Anyone whose data you collect, including unsuccessful applicants, should receive privacy information at or before you collect it, not just tenants who go on to sign a lease.
How long can I keep an unsuccessful applicant's documents?
Delete them promptly once the decision is made, typically within a matter of weeks, unless you have a specific, recorded reason to keep them longer.
What is the required timeframe for reporting a data breach to your regulator?
You must report a breach to your regulator promptly if it is likely to risk tenants' rights and freedoms, and directly notify affected tenants if the risk to them is high.
Can I send a tenant's ID document over WhatsApp if they send it first?
You should avoid it. Insecure messaging channels are one of the most common sources of accidental exposure, and a secure upload flow or encrypted email attachment is a safer default for both sides.
Does using a letting agent remove my data protection responsibilities?
No. Your agent typically acts as a processor working to your instructions, and you remain the controller responsible for the lawful basis, retention, and security of tenant data throughout.