LetCompliance
AES-256GDPREU-hostedGOV.UK
Data Protection9 min read

Tenant Privacy Notice UK: GDPR Landlord Guide

What to include in a UK tenant privacy notice, how it differs from your tenancy agreement, and how LetCompliance helps you generate a professional notice from the dashboard.

Tenant Privacy Notice UK: GDPR Landlord Guide — Quiet UK terraced street in early morning mist
Quiet UK terraced street in early morning mist
Free tool

Free compliance checker

Score any property 0–100 across the 6 statutory areas in under a minute. No signup.

Check a property
Free for 1 property

Keep one rental compliant for free in LetCompliance, no card. Rent, tax and unlimited doors on paid plans.

Start free

Ask an AI about this guide

Opens your assistant with this page as the cited source, so you get an answer grounded in the guide rather than a paraphrase of it.

Share this guide

𝕏

Prefer to watch?

See how it works

TL;DR — quick answer

What to include in a UK tenant privacy notice, how it differs from your tenancy agreement, and how LetCompliance helps you generate a professional notice from the dashboard.

What this guide covers

Private landlords process tenant names, contact details, bank data, references and sometimes ID. A clear privacy notice tells people what you do with that information and why. Here we cover what a tenant-facing notice should include, when to give it, and how LetCompliance subscribers can generate a document from the dashboard.

This is not legal advice. Rules differ in England, Scotland, Wales and Northern Ireland, and they change over time. Use the ICO guidance for organisations and speak to a solicitor if you are unsure.

What is a tenant privacy notice?

A tenant privacy notice (sometimes called a privacy information notice or fair processing notice) tells tenants who you are, what personal data you collect, why you use it, who you share it with, how long you keep it, and what rights they have. It is part of meeting transparency rules under UK GDPR and the Data Protection Act 2018.

It is not the same as your website privacy policy (which covers visitors to your site) or your contract with LetCompliance as software. It is the notice you give your tenants about your processing of their data, for example names, contact details, Right to Rent documents, bank details for rent, and correspondence about repairs.

Do UK landlords have to give tenants a privacy notice?

When you collect personal data directly from someone (such as a tenant or applicant), you generally need to provide privacy information at the time you collect the data, often described as Article 13 style information. Letting a property involves collecting and using personal data, so private landlords and agents are expected to take data protection seriously.

Failing to be transparent can damage trust, complicate disputes, and attract regulatory attention. The ICO publishes plain-English guidance for small organisations and landlords should follow a sensible, documented approach: keep the notice accurate, give tenants a copy (email or paper), and update it if your purposes or sharing change.

What should a UK landlord privacy notice include?

A practical notice for tenants usually covers:

  • Identity and contact details of the controller (you or your company) and, if relevant, your letting agent
  • Purposes of processing (referencing, tenancy setup, rent, repairs, compliance such as Right to Rent in England, deposit protection, disputes)
  • Lawful bases under UK GDPR Article 6 (contract, legal obligation, legitimate interests, etc.) explained in plain language
  • Recipients or categories of recipients (deposit scheme, contractors, insurers, accountants, referencing firms, authorities where required)
  • Retention, how long you keep different records (often several years after the tenancy for financial and dispute reasons; follow current Home Office rules for Right to Rent copies)
  • Rights, access, rectification, erasure in some cases, restriction, objection, portability where applicable, and the right to complain to the ICO
  • International transfers if you ever send data outside the UK
  • Whether providing some data is mandatory for the tenancy or by law
  • You can deliver the notice as a PDF, printed letter, or email attachment. Some landlords add optional signature lines so tenants can acknowledge receipt, signing is usually not required for the notice to be valid, but it can help show the tenant received a copy.

    Tenant privacy notice vs tenancy agreement

    The tenancy agreement sets out rent, deposit, obligations, and possession rules. The privacy notice deals only with personal data. They work together but serve different purposes. Do not assume a generic clause in the tenancy agreement replaces a clear, standalone privacy notice if you want to meet transparency expectations under data protection law.

    How to create a tenant privacy notice (template workflow)

    Many landlords start from a reputable template, then adapt it to their own contact details, whether they use an agent, and how they run their portfolio. Typical steps:

  • Draft using ICO themes (lawful bases, purposes, retention, rights)
  • Customise for your properties and processes
  • Review when you change how you use data or start using new tools
  • Give a copy to new tenants and, where appropriate, to existing tenants if you materially change processing
  • If you start from a downloaded template, avoid random PDFs from unverified sources. Check that the wording reflects UK law (not generic EU-only packs) and what you actually do with tenant data.

    Generating the notice, and keeping it current

    LetCompliance runs the whole let for UK private landlords and letting agents from one login — advertising and applications, referencing and Right to Rent, e-signed tenancies, rent collection with arrears chasing, maintenance, notices and the year-end tax pack. Data protection is one of the things it handles along the way rather than a separate chore. Paying subscribers (and those on an eligible trial) can use the Tenant privacy notice tool inside the app: go to Documents → Tenant privacy after you sign in.

    You enter your name, email, phone, address, and optional letting agent. The tool builds an Article 13-style notice in plain English, with sections on purposes, sharing, retention, rights, and optional signature blocks for tenant and landlord. You can:

  • Download HTML, open in a browser, print, or save as PDF with styled headings
  • Download plain text, paste into Word or email
  • Copy the full text
  • The template includes a clear “not legal advice” reminder. Your obligations depend on your situation; use ICO resources or professional advice for edge cases.

    Tenant data usually sits alongside Right to Rent checks, deposit protection and safety certificates. One place for dates and documents makes it less likely something slips through. If you want more context, see Right to Rent checks, deposit protection, and the 2026 landlord compliance checklist.


    Do landlords need to pay the ICO data protection fee?

    Most probably yes, and it is the single most commonly missed data-protection duty in letting — largely because nobody selling landlord services mentions it.

    Organisations that process personal data must pay an annual data protection fee to the Information Commissioner's Office unless they are exempt. Letting property is a business activity, and processing tenant data on a computer or phone for that business generally brings you within scope. The exemptions are narrower than landlords assume.

    The fee for a small operation is modest — a matter of tens of pounds a year, with a discount for paying by direct debit, but fees are reviewed periodically, so check the current figure rather than a number in a blog. The ICO publishes a short self-assessment that tells you whether you need to pay and at which tier; it takes a couple of minutes and it is the authoritative answer for your situation.

    Two practical notes. Non-payment is enforceable in its own right, separately from anything about how you actually handle data. And if you use a letting agent, both of you may have obligations — the agent is not automatically covering you, and who is controller for what should be set out in your terms of business.


    What about CCTV and video doorbells?

    This comes up constantly and the answer depends on who is recording and what the camera can see.

    A tenant's own doorbell camera. Cameras used by an individual for purely personal or household purposes fall outside data protection law. A tenant's Ring doorbell at their own front door is generally their business, though it can still cause neighbour disputes and your tenancy agreement can reasonably require permission before anything is fixed to the building.

    Your camera, in a property you let. This is where landlords get into difficulty. If you install cameras covering communal areas of an HMO, a shared hallway, or a driveway, you are recording other people for your own business purposes and the household exemption does not apply. You become a controller for that footage, with all that follows: a clear purpose, signage telling people they are being recorded, a retention period, security, and the ability to answer a subject access request from anyone captured.

    Inside a let property, never. Cameras in a dwelling you have let are effectively indefensible. The tenant has exclusive possession, and recording them in their home risks a data-protection breach, a harassment allegation and a claim for breach of quiet enjoyment all at once. If you are worried about what happens inside the property, the answer is inspections with proper notice, not a camera.

    If you do install cameras in communal areas, say so in the privacy notice, point them only where you need them, and set a short retention period — typically days rather than months, unless something has been reported.


    What if you get it wrong: breaches, retention and deletion

    Two duties that most landlord privacy notices describe and almost no landlord actually operates.

    Personal data breaches. A breach is not only a hack. Emailing one tenant's reference to another tenant, losing a phone with the tenancy files on it, or leaving a folder of Right to Rent copies in a car all qualify. Where a breach is likely to result in a risk to people, you must notify the ICO within 72 hours of becoming aware of it; where the risk is high, you must also tell the individuals affected. Seventy-two hours is short, so know in advance that this exists rather than discovering it during the week it happens.

    Deleting on schedule matters as much as keeping. Holding data longer than you need it is itself a breach, and one category is specific enough to diarise: Right to Rent copies should be kept for the tenancy plus one year, then destroyed. Immigration documents are sensitive, keeping them indefinitely serves no purpose you can justify, and a folder of expired passport scans is a liability with no upside.

    A workable retention position for a small landlord: tenancy agreements, inventories and correspondence for the tenancy plus six years, matching the contract limitation period; certificates and proof of service the same; Right to Rent the tenancy plus one year; unsuccessful applicants' data for a few months at most, then gone.

    Write those periods into the privacy notice, then actually run them. A notice that promises deletion you never perform is worse than one that promises nothing, because it is evidence of the standard you set yourself.

    Free PDF · instant by email

    2026 UK Landlord Compliance Cheat Sheet

    Every Gas Safety, EICR, EPC, deposit and Right to Rent deadline on one printable A4 page. Updated for the Renters’ Rights Act 2025.

    • Every UK statutory deadline by document type
    • Maximum penalty per breach (HSE, MEES, RtR, deposit)
    • What blocks a Section 8 / Form 6A possession claim
    • Print-friendly A4 with checkboxes

    We only add you to the tips list if you tick the box, and you can unsubscribe in one click.

    Frequently asked questions

    Is a tenant privacy notice the same as a tenancy agreement?

    No. The tenancy agreement covers rent, possession, and obligations. A privacy notice explains how you process personal data under UK GDPR, who you are, purposes, lawful bases, sharing, retention, and tenant rights.

    Where can I get a tenant privacy notice template for UK landlords?

    Use ICO themes and guidance, or a trusted template that matches UK law and your actual practices. LetCompliance subscribers can generate a notice from the dashboard (Documents → Tenant privacy) and download HTML or plain text.

    Do tenants have to sign a privacy notice?

    Usually no, transparency is the main requirement. An optional acknowledgment (signature and date) can show the tenant received a copy; it does not replace giving clear information at the right time.

    Run the whole tenancy in LetCompliance

    Advertise, collect rent, score compliance 0 to 100 and prepare your SA105 tax, the whole UK let in one login. Free forever for 1 property, plus 14 days of everything to start. Paid plans from £14.99/month, no card.

    compliance softwarefeaturespricingfree landlord softwareletting agent compliance softwareUK regulations

    Start free