Tenant Personal Data Protection — GDPR in Landlord Practice
The General Data Protection Regulation (GDPR) applies to every landlord who collects and processes personal data from tenants — and that means virtually every landlord. From the moment a prospective tenant sends you their first inquiry, you are handling personal data that falls under GDPR protection. Despite this, many landlords remain unaware of their obligations, risking significant fines and legal consequences. This guide breaks down what GDPR means for landlords in practical, actionable terms.
What Counts as Personal Data in Rental Management?
Personal data is any information that can be used to identify a natural person, directly or indirectly. In the context of rental management, this includes a surprisingly wide range of data:
- Identification data: full name, PESEL number, ID card or passport number, date of birth
- Contact data: email address, phone number, postal address
- Financial data: bank account numbers, salary information, employment history, credit references
- Tenancy data: lease agreements, payment history, maintenance requests, correspondence
- Documentation: photographs of identification documents, income certificates, employment contracts
- Visual data: photographs taken during check-in/check-out inspections that include tenants
Every piece of this information is subject to GDPR rules, regardless of whether you store it digitally or on paper.
Legal Basis for Processing Tenant Data
Under GDPR, you need a valid legal basis for processing every category of personal data. For landlords, the most relevant legal bases are:
- Contract performance (Art. 6(1)(b)): You can process data that is necessary to perform the lease agreement. This covers collecting names, contact details, and bank information for rent payment. This is your primary legal basis for most tenant data processing.
- Legal obligation (Art. 6(1)(c)): Some data processing is required by law — for example, tax reporting obligations require you to retain certain financial records, and tenant registration (zameldowanie) requires identity data.
- Legitimate interest (Art. 6(1)(f)): You can process data where you have a legitimate interest that is not overridden by the tenant's rights. This can justify credit checks, reference verification, and security camera footage in common areas.
- Consent (Art. 6(1)(a)): For any data processing that does not fall under the above categories, you need the tenant's explicit consent. This must be freely given, specific, informed, and revocable at any time.
What Data Can You Collect During Tenant Screening?
Tenant screening is where many landlords inadvertently cross GDPR boundaries. Here is what you can and cannot request:
Permissible during initial screening:
- Full name and contact information
- Current employment status and employer name
- Income level (to verify ability to pay rent) — but you should request a range or minimum threshold rather than exact figures
- References from previous landlords (with the applicant's consent)
Permissible only after deciding to proceed with a specific candidate:
- PESEL number or ID document details — only when preparing the lease agreement
- Bank account details — only for rent payment setup
- Copies of income documentation — only to the extent necessary to verify ability to pay
Not permissible (unless specifically justified):
- Information about marital status, family planning, or number of children
- Religious affiliation, political views, or sexual orientation
- Medical conditions or disability status
- Criminal background (unless you have a specific, documented security concern)
Data Minimization Principle
GDPR requires that you collect only data that is adequate, relevant, and limited to what is necessary for the purposes for which it is processed. In practice, this means:
- Do not request copies of entire ID documents if you only need the ID number — note the number instead
- Do not keep applications from rejected candidates longer than necessary (typically 3 months maximum)
- Do not collect data "just in case" — every data point you hold must have a clear purpose
- Regularly review what data you hold and delete anything that is no longer needed
Secure Storage Requirements
GDPR requires appropriate technical and organizational measures to protect personal data. For landlords, this translates into practical obligations:
- Digital data: Use password-protected systems, encrypted storage, and secure cloud services. Avoid storing tenant data in unprotected spreadsheets, unsecured email attachments, or on unencrypted USB drives.
- Physical documents: Store paper documents containing personal data in locked cabinets or rooms with restricted access. Do not leave tenant files visible to unauthorized persons.
- Communication security: When sending personal data by email (e.g., lease agreements), use encrypted channels or password-protected attachments.
- Access control: Limit who can access tenant data. If you use property management employees or agents, ensure they are bound by data protection obligations.
Using a professional property management platform like Brokik significantly simplifies GDPR compliance by providing secure, encrypted storage for all tenant data, controlled access permissions, and audit trails that document who accessed what data and when. This is considerably more secure than managing tenant information in spreadsheets, paper files, or email inboxes.
Tenant Rights Under GDPR
Your tenants have specific rights under GDPR that you must be prepared to fulfill:
- Right to information (Art. 13-14): You must inform tenants about what data you collect, why, how long you will keep it, and who you share it with. This is typically done through a privacy notice provided at the start of the tenancy.
- Right of access (Art. 15): Tenants can request a copy of all personal data you hold about them. You must respond within one month.
- Right to rectification (Art. 16): Tenants can request correction of inaccurate data.
- Right to erasure (Art. 17): After the tenancy ends and all legal retention periods have expired, former tenants can request deletion of their data. However, you can retain data necessary for legal claims (typically 3-6 years after the lease ends).
- Right to data portability (Art. 20): Tenants can request their data in a structured, commonly used format.
- Right to object (Art. 21): Tenants can object to data processing based on legitimate interest.
Data Retention Periods
One of the most common GDPR compliance failures among landlords is keeping data longer than necessary. Here are recommended retention periods:
- Rejected applicant data: Delete within 3 months of rejection (unless the applicant consents to longer retention)
- Lease agreements and payment records: Retain for the duration of the tenancy plus 6 years (for tax and legal claim purposes)
- Correspondence: Retain for the duration of the tenancy plus 3 years (statute of limitations for most civil claims)
- Check-in/check-out documentation: Retain for the duration of the tenancy plus 3 years
- Tax-related records: Retain for 5-6 years as required by tax law
Sharing Tenant Data with Third Parties
Landlords frequently need to share tenant data with third parties. Each instance requires careful consideration:
- Property management companies: Must have a data processing agreement (DPA) in place before sharing any tenant data
- Maintenance contractors: Share only the minimum data necessary (e.g., address and phone number for access coordination, not financial details)
- Tax authorities: Sharing data for tax compliance is a legal obligation and does not require consent
- Insurance companies: Share only data relevant to the claim, and only when necessary
- Utility companies: Meter readings and basic tenant identification for account transfers
- New property owners: If you sell the property, tenant data can be transferred to the new owner as part of the lease transfer, but tenants must be informed
Privacy Notice Template for Landlords
Every landlord should provide a privacy notice to tenants. At minimum, it should cover:
- Your identity and contact details as the data controller
- Categories of personal data you process and the purposes for each
- Legal basis for each processing activity
- Recipients or categories of recipients of the data
- Data retention periods
- The tenant's rights (access, rectification, erasure, portability, objection)
- The right to lodge a complaint with the supervisory authority (UODO in Poland)
Common GDPR Violations by Landlords
Awareness of common mistakes can help you avoid them:
- Keeping copies of rejected applicants' ID documents indefinitely
- Sharing a tenant's personal information with other tenants in the building (e.g., in response to noise complaints)
- Posting personal information about tenants on building notice boards
- Accessing tenant data without a legitimate reason
- Failing to provide a privacy notice at the start of the tenancy
- Not deleting data after the retention period expires
- Sending bulk emails with tenant email addresses visible to all recipients (use BCC)
Consequences of Non-Compliance
GDPR violations carry serious penalties. Administrative fines can reach up to 20 million EUR or 4% of annual turnover, whichever is higher. While individual landlords are unlikely to face maximum fines, even modest penalties can be significant. Beyond fines, non-compliance can result in compensation claims from affected tenants, reputational damage, and legal costs.
Practical Steps for GDPR Compliance
Here is a practical checklist to help you achieve and maintain compliance:
- Prepare and distribute a privacy notice to all current and new tenants
- Audit all tenant data you currently hold — delete anything you do not need
- Implement secure storage solutions — migrate from spreadsheets to a secure platform like Brokik
- Create a data processing agreement template for any third parties who handle tenant data
- Establish a process for responding to tenant data access requests within 30 days
- Set up calendar reminders for data deletion dates
- Document your data protection practices in writing
Summary
GDPR compliance is not an optional extra for landlords — it is a legal obligation that applies from the first moment you receive a tenant inquiry. While the requirements may seem daunting, the practical steps are manageable, especially when you use professional tools designed to handle personal data securely. Platforms like Brokik are built with data protection in mind, providing encrypted storage, access controls, and systematic data management that makes GDPR compliance part of your daily workflow rather than a separate burden. By taking data protection seriously, you protect both your tenants and yourself from the legal and financial consequences of non-compliance.