GDPR for estate agents: the five things that actually catch people
Data protection in an estate agency tends to get handled in one of two ways: a policy document that somebody bought in 2018 and nobody has opened since, or a low-level anxiety that produces nothing in particular. Neither is much use, largely because they are both aimed at the wrong thing.
The ICO does not audit estate agents at random. It responds to complaints. So the practical question is not whether your documentation is perfect, it is which behaviours generate complaints. They are boringly consistent, and there are about five.
One: marketing to people who registered for something else. Somebody books a viewing, or submits a valuation request, and six months later they are receiving your monthly newsletter. They did not ask for that. This is the single most common source of complaints in our industry, and the fix is a genuine separation between the record of somebody who transacted with you and the list of people who agreed to hear from you. If your mailing list is everybody in your database, you have this problem.
Two: keeping applicant records forever. An applicant who registered in 2019, viewed two houses and bought elsewhere is not a live record, and holding their details indefinitely with no stated retention period is hard to justify if anybody asks. The fix is a retention period you have actually decided on, written down, and can point to. Any defensible period is better than none.
Three: the WhatsApp problem. Negotiators conduct large parts of the working day in personal messaging apps: photographs of properties, tenant details, offers, copies of passports for identity checks. When that person leaves the business, the data leaves with them, on their own phone, and the agency has no copy and no control. This is a genuine breach waiting to happen and it is nearly universal. You do not solve it with a policy telling people not to. You solve it by making the sanctioned route faster than the unsanctioned one.
Four: identity documents left where they landed. AML requires you to collect and keep identity evidence, which means every agency is holding a pile of passport and driving licence scans. Very often those live in an email inbox, or in a shared drive folder that the whole office can read, sometimes with the sale completed three years ago. Photographs of identity documents are the highest-risk data an agency holds and they are routinely the least deliberately stored.
Five: subject access requests answered badly or not at all. These are rare, and they usually arrive attached to a dispute: a tenant in a deposit argument, a vendor who feels misled. Somebody who is already unhappy asks what you hold about them, gets ignored, and complains. A request has a deadline and an ignored one is an escalation. Know who in the office would handle it, today, before one arrives.
Notice that four of those five are workflow rather than paperwork. That is the point. The documentation matters, and you should have it, but the documentation is not what generates the complaint. What generates the complaint is a negotiator doing a reasonable thing in an unreasonable place because the reasonable place was slower.
This is a description of where the risk actually sits, not legal advice. If you are unsure about your specific position, ask somebody qualified, and ask before you need to.