GDPR is not new any more, but it has not stood still either. Since the regulation came into force in May 2018, the UK has left the EU, built its own version of the law (UK GDPR), and in 2025 passed the biggest reform to that framework since Brexit: the Data (Use and Access) Act. For estate and letting agents, who handle a constant flow of personal data from buyers, sellers, landlords and tenants, staying current with these changes matters just as much now as compliance did back in 2018.
Most estate agents’ data is still more disorganised than they’d like
If your agency has been trading for a while, the chances are you are still holding data from prospective buyers, tenants, vendors and landlords across several systems. Old enquiries sit in one spreadsheet, CRM exports in another, and archived email threads somewhere else entirely. Sorting through it properly takes time, and day-to-day work tends to take priority.
Sound familiar?
You are not alone. Most agencies that have operated for more than a year or two hold data captured through multiple channels and stored in multiple places, some of it long past the point where it should have been reviewed or deleted.
Why this still matters
The rules have not softened. Under UK GDPR, the Information Commissioner’s Office (ICO) can fine businesses up to £17.5 million or 4% of global annual turnover, whichever is greater. As an estate or letting agent, you are a data controller: you decide why and how personal data connected to sales and lettings is processed, which means you are directly responsible for getting this right, not just your software provider.
That responsibility covers everything from email marketing and SMS campaigns to more complex use of data such as targeted advertising audiences. It also extends to the anti-money laundering checks agents are legally required to carry out on buyers, sellers, landlords and tenants, which involve collecting and verifying identity documents and, increasingly, using Digital Verification Services as these become more widely adopted across the property sector.
What changed with the Data (Use and Access) Act 2025
The Data (Use and Access) Act (DUAA) received Royal Assent on 19 June 2025 and is being introduced in stages through to June 2026. It amends UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR) rather than replacing them, and it is worth understanding what it actually changes for a business like yours:
A new lawful basis: “recognised legitimate interests.” Certain processing, such as safeguarding or crime prevention, no longer requires a formal balancing assessment. Direct marketing can still rely on legitimate interest, but a Legitimate Interests Assessment is still expected for that.
Clearer subject access request timelines. The one-month response window remains, but there is now a “stop the clock” mechanism if you reasonably need more information from the requester before you can respond.
Some cookie consent requirements have eased. Low-risk cookies used for things like statistics or remembering site preferences no longer always require explicit consent, though marketing and tracking cookies still do.
A new mandatory complaints process. From 19 June 2026, organisations must have a formal internal process for handling data protection complaints, acknowledging them within 30 days before a complainant escalates to the ICO.
PECR fines now match UK GDPR fines. Breaches involving unsolicited marketing communications can now carry the same £17.5 million or 4% turnover penalty.
None of this reduces your obligations. If anything, it raises the bar on demonstrating that you handle data properly, particularly around marketing consent and complaint handling.
Four steps to stay on top of it
Know what applies to you now, not just what applied in 2018. The ICO’s UK GDPR guidance and resources hub is kept current and is the right starting point, along with the ICO’s dedicated DUAA guidance for what has changed. Make sure whoever handles data protection in your agency, even informally, is aware of the DUAA timeline.
Audit your data properly. Know what personal data you hold, where it lives, who can access it and where it originally came from.
Aim to keep marketing and sales data in one system, ideally your CRM. If your CRM provider is not UK GDPR compliant, that is a conversation worth having now.
Consolidate any Excel spreadsheets holding personal data into your CRM, then delete the spreadsheets.
Only collect what you genuinely need. If you do not need a buyer’s date of birth for the transaction, do not ask for it.
Restrict access appropriately. Full database export rights should sit with owners or senior managers only; negotiators generally only need the ability to add or edit records relevant to their work.
Check how data is actually being used. A vendor requesting a valuation has not automatically consented to their details being passed to a third-party mortgage adviser.
Review how you capture consent and rely on lawful basis. Content marketing and email marketing both depend on this being right.
Check how many people on your newsletter list have genuinely opted in, and whether your current sign-up wording still meets UK GDPR standards.
Consider whether the new recognised legitimate interests basis applies anywhere in your processing, and document it if so.
Use this as a prompt to review your wider marketing strategy: are you attracting the right prospects, with the right data, in the first place?
Put a proper complaints process in place before June 2026. This is the most concrete new obligation from the DUAA. You need a way for people to raise a data protection complaint directly with your agency, acknowledge it within 30 days, and resolve or escalate it appropriately, before it reaches the ICO. This is also a good moment to review your privacy policy and cookie policy with a solicitor, particularly if you rely on any third-party data sharing arrangements.
A note for letting agents
If you operate in lettings, the Renters’ Rights Act 2025, in force since May 2026, adds another layer worth factoring into your data practices. Its anti-discrimination provisions mean agents need clear, defensible records of how applications are assessed, which makes tidy, well-governed data even more important than a compliance exercise on its own.
Getting this right protects more than your compliance record
Knowing how you use personal data is only half the job. You also need to be able to explain it clearly to prospects and clients, including how they can object or opt out, and now, how they can complain directly to you if something goes wrong. A data protection specialist or solicitor can take a holistic view of your setup, from marketing consent through to employee and CCTV data, and help you align it with how your agency actually operates.
Art Division is a boutique digital marketing & web design agency specialising in the UK property market. We help estate & letting agents grow with profit by attracting and converting more clients (vendors, landlords, buyers, tenants or investors) through effective digital marketing and cutting edge, marketing-ready websites.
Art Division is a boutique digital marketing & web design agency specialising in the UK property market. We help estate & letting agents grow with profit by attracting and converting more clients (vendors, landlords, buyers, tenants or investors) through effective digital marketing and cutting edge, marketing-ready websites.