What this guide covers
Private landlords process tenant names, contact details, bank data, references and sometimes ID. A clear privacy notice tells people what you do with that information and why. Here we cover what a tenant-facing notice should include, when to give it, and how LetCompliance subscribers can generate a document from the dashboard.
This is not legal advice. Rules differ in England, Scotland, Wales and Northern Ireland, and they change over time. Use the ICO guidance for organisations and speak to a solicitor if you are unsure.
What is a tenant privacy notice?
A tenant privacy notice (sometimes called a privacy information notice or fair processing notice) tells tenants who you are, what personal data you collect, why you use it, who you share it with, how long you keep it, and what rights they have. It is part of meeting transparency rules under UK GDPR and the Data Protection Act 2018.
It is not the same as your website privacy policy (which covers visitors to your site) or your contract with LetCompliance as software. It is the notice you give your tenants about your processing of their data, for example names, contact details, Right to Rent documents, bank details for rent, and correspondence about repairs.
Do UK landlords have to give tenants a privacy notice?
When you collect personal data directly from someone (such as a tenant or applicant), you generally need to provide privacy information at the time you collect the data, often described as Article 13 style information. Letting a property involves collecting and using personal data, so private landlords and agents are expected to take data protection seriously.
Failing to be transparent can damage trust, complicate disputes, and attract regulatory attention. The ICO publishes plain-English guidance for small organisations and landlords should follow a sensible, documented approach: keep the notice accurate, give tenants a copy (email or paper), and update it if your purposes or sharing change.
What should a UK landlord privacy notice include?
A practical notice for tenants usually covers:
You can deliver the notice as a PDF, printed letter, or email attachment. Some landlords add optional signature lines so tenants can acknowledge receipt, signing is usually not required for the notice to be valid, but it can help show the tenant received a copy.
Tenant privacy notice vs tenancy agreement
The tenancy agreement sets out rent, deposit, obligations, and possession rules. The privacy notice deals only with personal data. They work together but serve different purposes. Do not assume a generic clause in the tenancy agreement replaces a clear, standalone privacy notice if you want to meet transparency expectations under data protection law.
How to create a tenant privacy notice (template workflow)
Many landlords start from a reputable template, then adapt it to their own contact details, whether they use an agent, and how they run their portfolio. Typical steps:
If you start from a downloaded template, avoid random PDFs from unverified sources. Check that the wording reflects UK law (not generic EU-only packs) and what you actually do with tenant data.
Generating the notice, and keeping it current
LetCompliance runs the whole let for UK private landlords and letting agents from one login — advertising and applications, referencing and Right to Rent, e-signed tenancies, rent collection with arrears chasing, maintenance, notices and the year-end tax pack. Data protection is one of the things it handles along the way rather than a separate chore. Paying subscribers (and those on an eligible trial) can use the Tenant privacy notice tool inside the app: go to Documents → Tenant privacy after you sign in.
You enter your name, email, phone, address, and optional letting agent. The tool builds an Article 13-style notice in plain English, with sections on purposes, sharing, retention, rights, and optional signature blocks for tenant and landlord. You can:
The template includes a clear “not legal advice” reminder. Your obligations depend on your situation; use ICO resources or professional advice for edge cases.
Related compliance topics
Tenant data usually sits alongside Right to Rent checks, deposit protection and safety certificates. One place for dates and documents makes it less likely something slips through. If you want more context, see Right to Rent checks, deposit protection, and the 2026 landlord compliance checklist.
Do landlords need to pay the ICO data protection fee?
Most probably yes, and it is the single most commonly missed data-protection duty in letting — largely because nobody selling landlord services mentions it.
Organisations that process personal data must pay an annual data protection fee to the Information Commissioner's Office unless they are exempt. Letting property is a business activity, and processing tenant data on a computer or phone for that business generally brings you within scope. The exemptions are narrower than landlords assume.
The fee for a small operation is modest — a matter of tens of pounds a year, with a discount for paying by direct debit, but fees are reviewed periodically, so check the current figure rather than a number in a blog. The ICO publishes a short self-assessment that tells you whether you need to pay and at which tier; it takes a couple of minutes and it is the authoritative answer for your situation.
Two practical notes. Non-payment is enforceable in its own right, separately from anything about how you actually handle data. And if you use a letting agent, both of you may have obligations — the agent is not automatically covering you, and who is controller for what should be set out in your terms of business.
What about CCTV and video doorbells?
This comes up constantly and the answer depends on who is recording and what the camera can see.
A tenant's own doorbell camera. Cameras used by an individual for purely personal or household purposes fall outside data protection law. A tenant's Ring doorbell at their own front door is generally their business, though it can still cause neighbour disputes and your tenancy agreement can reasonably require permission before anything is fixed to the building.
Your camera, in a property you let. This is where landlords get into difficulty. If you install cameras covering communal areas of an HMO, a shared hallway, or a driveway, you are recording other people for your own business purposes and the household exemption does not apply. You become a controller for that footage, with all that follows: a clear purpose, signage telling people they are being recorded, a retention period, security, and the ability to answer a subject access request from anyone captured.
Inside a let property, never. Cameras in a dwelling you have let are effectively indefensible. The tenant has exclusive possession, and recording them in their home risks a data-protection breach, a harassment allegation and a claim for breach of quiet enjoyment all at once. If you are worried about what happens inside the property, the answer is inspections with proper notice, not a camera.
If you do install cameras in communal areas, say so in the privacy notice, point them only where you need them, and set a short retention period — typically days rather than months, unless something has been reported.
What if you get it wrong: breaches, retention and deletion
Two duties that most landlord privacy notices describe and almost no landlord actually operates.
Personal data breaches. A breach is not only a hack. Emailing one tenant's reference to another tenant, losing a phone with the tenancy files on it, or leaving a folder of Right to Rent copies in a car all qualify. Where a breach is likely to result in a risk to people, you must notify the ICO within 72 hours of becoming aware of it; where the risk is high, you must also tell the individuals affected. Seventy-two hours is short, so know in advance that this exists rather than discovering it during the week it happens.
Deleting on schedule matters as much as keeping. Holding data longer than you need it is itself a breach, and one category is specific enough to diarise: Right to Rent copies should be kept for the tenancy plus one year, then destroyed. Immigration documents are sensitive, keeping them indefinitely serves no purpose you can justify, and a folder of expired passport scans is a liability with no upside.
A workable retention position for a small landlord: tenancy agreements, inventories and correspondence for the tenancy plus six years, matching the contract limitation period; certificates and proof of service the same; Right to Rent the tenancy plus one year; unsuccessful applicants' data for a few months at most, then gone.
Write those periods into the privacy notice, then actually run them. A notice that promises deletion you never perform is worse than one that promises nothing, because it is evidence of the standard you set yourself.
2026 UK Landlord Compliance Cheat Sheet
Every Gas Safety, EICR, EPC, deposit and Right to Rent deadline on one printable A4 page. Updated for the Renters’ Rights Act 2025.
- Every UK statutory deadline by document type
- Maximum penalty per breach (HSE, MEES, RtR, deposit)
- What blocks a Section 8 / Form 6A possession claim
- Print-friendly A4 with checkboxes
Frequently asked questions
Is a tenant privacy notice the same as a tenancy agreement?
No. The tenancy agreement covers rent, possession, and obligations. A privacy notice explains how you process personal data under UK GDPR, who you are, purposes, lawful bases, sharing, retention, and tenant rights.
Where can I get a tenant privacy notice template for UK landlords?
Use ICO themes and guidance, or a trusted template that matches UK law and your actual practices. LetCompliance subscribers can generate a notice from the dashboard (Documents → Tenant privacy) and download HTML or plain text.
Do tenants have to sign a privacy notice?
Usually no, transparency is the main requirement. An optional acknowledgment (signature and date) can show the tenant received a copy; it does not replace giving clear information at the right time.
