A single misdirected tenancy email can expose passports, bank details or safeguarding information. When that happens, the first hours matter. Contain access, keep proof, and avoid rushed promises before you know what was disclosed.
For Property managers & letting agents: data breaches can be as simple as a tenancy file sent wrongly. Your response still needs a clear order. Contain the incident, assess risks, record decisions, and check the ICO’s 72-hour rule. Notify tenants where needed. Tell your cyber insurer promptly.
Summary of the process
Follow this order when tenant data has been seen, lost, changed, or accessed without permission. A personal data breach is not only a hack. It can include a wrong email, lost paper file, or portal showing another tenant’s records.
- Contain the exposure: Stop further access without deleting logs or messages.
- Record the facts: Write what happened, when you learned of it, and which records may be involved.
- Assess the harm: Decide if there is no likely risk, likely risk, or high risk.
- Assign responsibilities: Check who is the controller, processor, or joint controller for this data use.
- Report and communicate: Notify the ICO within 72 hours where likely risk exists. Tell affected people where a likely high risk exists.
- Notify insurers and close properly: Follow policy terms before accepting fault or paying compensation.
The ICO says every breach should be documented. This applies even when you do not need to report it. The 72-hour clock starts when the relevant data controller knows about a reportable incident. It does not wait until every technical fact is known. Read the ICO’s personal data breach guidance alongside this guide.
You can report to the ICO in stages. If facts remain incomplete at hour 60, report what you know. Explain what you are checking. Send missing details later.
Contain the incident and keep proof
Stop unauthorised access now and keep evidence for your assessment.
Lock down the affected route
For a misdirected email, use your mail system’s recall or message restriction tool. Do not rely on it. Call the recipient using a number you already hold. Ask them not to open attachments. Ask them to delete the email permanently. Record their answer word for word.
This usually takes 10 to 20 minutes when the recipient answers. The typical error is trusting an email recall notice. Recall often fails when the recipient uses another mail system.
Keep the original message intact.
Create an incident record
Open a new document or restricted case folder. Write the discovery time, the reporter’s name, and the affected system. Add the tenant names, data types, recipient details, and all containment actions.
Save screenshots, email headers, audit logs, and call notes. Do not alter the source files. These records show what happened and support your ICO decision.
A common case involves a negotiator sending one applicant’s references to another applicant. The recipient deletes the file after a call. The agency still logs the breach and records why harm was unlikely.
⚠️ Do not delete the wrong email, portal logs, or staff messages before saving evidence. Deleted evidence can make your risk assessment harder to defend.
Assess risk and decide who must act
Classify the data and likely harm before deciding on ICO reporting.
Score the likely harm
Ask four written questions:
- Who received the data, and do you know them?
- What could they do with the data?
- How many tenants are affected?
- What has reduced the chance of misuse?
Special category data includes health, race, religion, and similar sensitive details. It needs extra care. Disclosure can cause discrimination or distress.
Risk depends on people, data, and access. A wrong viewing appointment email is not equal to exposed passports and bank details.
| Incident | Immediate action | Likely reporting position |
|---|
| Email with one rent statement to known recipient | Restrict, call, obtain deletion confirmation | Assess and log; often lower risk, facts decide |
| Portal shows tenant passports and bank details | Remove access, save audit logs, reset accounts | ICO report likely; tenant contact may be needed |
| Ransomware affecting tenancy system | Isolate device, call insurer and IT response line | Assess promptly; theft or exfiltration raises risk |
Map the real responsibilities
Tenant breach route: discovery to closure
1. Contain
0 to 40 mins
→
2. Log
same hour
→
3. Assess
day 1
→
4. ICO / tenants
within 72 hrs
→
5. Insurer / close
after evidence
Set the lawful basis and privacy expectations
Beyond incident roles, identify a lawful basis for each routine personal data handling purpose. Do not rely on one blanket consent tick-box. Managing tenancies, collecting rent, arranging repairs, and right-to-rent checks often need different lawful bases.
These bases may include contract, legal duty, or legitimate interests. The right basis depends on the activity. Consent must be freely given and easy to withdraw.
Consent rarely works where a tenant has no real choice. Your privacy notice should explain collected data, recipients, retention periods, and tenant rights. Those rights include access, correction, deletion, restriction, and objection. This makes property manager data protection decisions more consistent before complaints or breaches.
Clear privacy notices reduce confusion during incidents.
Decide roles, contracts and escalation routes
Role labels must match how data is handled. Do not rely only on supplier contract wording. A landlord and letting agent may be separate data controller organisations. They may also be joint controllers when both decide why and how data is used.
A property platform or referencing provider is often a data processor. This applies when it acts only on written instructions. It may be its own controller for verification or fraud prevention.
Processor contracts should require quick breach alerts and suitable security. They should also cover help with tenant requests. They should require data return or deletion when the service ends. Most controllers that are not exempt should check if they must pay the ICO data protection fee. An ICO breach reporting decision remains the controller’s job. A processor must alert its controller without undue delay.
⚠️ Do not assume your software supplier will report to the ICO for you. Its contract may require an alert, but the controller decides whether to report.
Report, notify and protect your cover
Make a timely, factual report without guessing or accepting legal blame.
Write to tenants where risk is high
Tell affected tenants without undue delay when the breach is likely to create high risk. Use plain words. State what happened, what data was involved, what you did, and what they should do.
Do not promise compensation or say the breach caused identity theft. You may not know that yet. The most frequent mistake is sending a vague message that leaves tenants unsure what to do.
Subject: Important information about your tenancy data
We are writing to tell you that on [date], [brief factual event] may have exposed [data types]. We stopped the access on [date] and are investigating. This may create [specific risk]. Please [specific protective action]. Contact [named person, phone and email] if you have questions. We have also [reported to the ICO / assessed whether a report is required].
Notify the insurer before commitments
Call the cyber insurance incident number when the event may lead to a claim. Many policies require prompt notice of a suspected incident. The insurer may give you a breach coach, technical investigators, and legal support.
Cover may include notification help, data recovery, and business interruption support. Check your policy before paying compensation or hiring outside experts. This takes five to 15 minutes if the policy contact is ready.
Early insurer contact can protect cover and preserve choices.
⚠️ Do not admit fault, promise payment, or appoint a lawyer before checking policy terms. These actions can affect insurance cover.
Avoid costly mistakes and close the file
Close the incident only after recording the decision, fixing the cause, and checking the fix.
Fix the weakness that caused it
Find the exact route that let data escape. Check the email address entry, shared mailbox rule, portal permission, device setting, or staff action. Then make one specific change and test it.
A quick fix may stop today’s issue. The correct fix also checks whether the same weakness exists elsewhere. For example, remove portal access, then review every former staff account.
This works well in theory, but access reviews take longer than expected. They often reveal old contractors, transferred portfolios, and shared accounts.
Keep a useful breach register
Keep one restricted breach register for every incident. Include dates, data types, people affected, containment steps, risk findings, ICO decisions, and tenant contact. Add the final cause and your tested fix.
The register should explain why you did not report an incident. It should also show why you did report one. The ICO expects records even where no report was needed.
Review the register every six to 12 months. Look for repeat issues, such as wrong email addresses or excess portal access.
Build controls around common tenancy-data failures
Prevention should focus on how tenancy records leave your business. Require MFA for email, cloud storage, and property systems. MFA means a second proof of identity, like a code on your phone.
Use role-based access. This means staff see only properties they manage. Review portal security after staff departures, portfolio transfers, or software changes.
Encrypt stored files and secure file transfers. Set retention periods for applications and references. Use checked secure deletion for old paper and digital records. A two-person or address check can stop a misdirected tenancy email. Phishing training should include fake repair invoices and landlord payment requests.
Treat tenant passport details and any bank details exposure as higher-risk data sets. Your plan should include the policy-specific cyber insurance notification contact and deadline.
⚠️ This process does not replace expert legal, data protection, or insurance advice. Seek specialist help for serious harm, fraud, safeguarding risks, litigation, or complex controller disputes.
Frequently asked questions
Does GDPR apply to landlords in England?
Yes. Landlords and letting agents often hold contact details, tenancy files, identity records, and payment data. UK GDPR and the Data Protection Act 2018 can apply. Duties depend on whether they act as controller, joint controller, or processor.
When do I have to tell the tenant?
Tell the tenant without undue delay when the breach is likely to create high risk. Passport copies, bank details, login details, and safeguarding data are more likely to meet this test. A single routine appointment email may not.
Can a tenant claim compensation after a breach?
A tenant may seek compensation for financial loss or distress. There is no fixed tariff. Do not agree payment or accept fault before checking evidence, contracts, legal advice, and cyber insurance terms.
Is cyber insurance worth it for a small letting business?
It can be worth considering when you hold large amounts of identity, bank, reference, or right-to-rent data. Cover differs between policies. Check for breach response, legal costs, forensic work, tenant notification, and business interruption.
⚠️ A policy does not remove your need to keep a breach register. You must still assess ICO reporting and protect tenant records with sensible access controls.
Make the next response easier
Set a 30-minute incident routine now, so a future breach begins with action rather than panic. Keep contacts in one restricted folder. Test the process every six to 12 months. Test it after changing property software or staff roles.
Must I report every wrong email to the ICO?
No. Assess and log every wrong email containing personal data. Report to the ICO only when it is likely to risk people’s rights and freedoms. The recipient’s identity, data type, and deletion evidence affect that decision.