Sharing Tenant Data with Your Solicitor, the GDPR Way
The moment a rent ledger leaves your hands for a solicitor, you have disclosed personal data to a third party. How you did it becomes a question the day the case reaches court.
Somewhere in most landlords’ sent folders sits an email that would make a data protection officer wince: a full rent ledger, an address history, sometimes a note about a benefits claim, sent to a solicitor with no agreement attached and no record of what went out. It is rarely careless. It is just how the handover has always been done, right up until someone asks how the data was actually shared.
When a tenant’s ledger, notices, or personal details leave your hands for an external solicitor, personal data has been disclosed to a third party. Under UK GDPR that solicitor becomes a Data Processor acting on your instructions as Data Controller, and the Information Commissioner’s Office is clear that the relationship is expected to be governed by a written contract, not an informal email, before any data is accessed.
What Article 28 calls for
Article 28 sets out what a Data Processing Agreement between landlord and solicitor should cover: the subject matter, duration, and purpose of the processing, the categories of personal data, the processor’s confidentiality and security obligations, and what happens to the data when the engagement ends. A case-sharing process with no equivalent in place before data changes hands is unlikely to meet that standard, however secure the email itself was in transit.
Data minimisation, in practice
Article 5(1)(c) is read as limiting what you share to what is necessary for the purpose. For a possession case that means the single tenant’s case pack, not your whole database, leaving out other tenants’ details even where they share the property, and no financial data beyond the arrears or possession matter. A solicitor instructed on one case has no need to see your other tenancies.
Why accountability matters more than it sounds
Article 5(2) puts the burden on you to demonstrate compliance, not merely to achieve it. If your data-sharing is ever questioned, by the tenant, the ICO, or in litigation, being able to show when a solicitor was granted access, what they could see, what they opened, and when access ended is the difference between a defensible process and a difficult conversation. An email from a personal inbox provides none of that; a folder of PDFs, barely more.
A checklist before you share
- Confirm the solicitor is SRA-registered, using their number
- Put a Data Processing Agreement in place, or use a platform that gates access behind one
- Scope what is shared to the single case, not the wider portfolio
- Keep a record of what was shared, with whom, and when
- Revoke access once proceedings conclude or the solicitor changes
The record Articles 28 and 5 call for
Compliance tracked, evidence ready
STEMHQ keeps certificates, arrears, and the court paper trail in one place, so the next rule change is a checklist, not a scramble.
