Back to Blog

GDPR and Real Estate: What Agents in the UK and Europe Need to Know About Contact Data

GDPR for real estate agents explained plainly — what lawful basis means, the three riskiest data practices, and what a compliant contact database actually looks like.

By Voqo Team9/6/202610 min read
GDPR and Real Estate: What Agents in the UK and Europe Need to Know About Contact Data

GDPR is now seven years old, but many real estate agencies in the UK and Europe are still running contact databases and outreach campaigns that would not survive a regulatory audit. The risk is not theoretical. The Information Commissioner's Office has steadily increased enforcement actions against estate agents since 2020, and the profile of businesses being investigated has shifted from large enterprises to mid-sized and independent agencies operating with inadequate data governance. The legal landscape has been settled for years. The implementation gap remains wide.

The agencies that have made the adjustment are not operating under unusual constraint — they are running more effective prospecting programmes because their databases are cleaner, their consent records are current, and their contacts have a reasonable expectation of being contacted. Compliance and commercial performance are not in opposition. The agencies discovering this tend to be the ones who actually read the regulation rather than relying on second-hand summaries of what it probably means.

What GDPR Means for a Real Estate Agency in Plain Terms

The General Data Protection Regulation establishes three core obligations for any business that holds personal data about individuals. First, you need a lawful basis to store that data and to use it for any given purpose. Second, you must be transparent about how the data is used — through a privacy notice that the contact can reasonably access. Third, individuals have enforceable rights over their own data, including the right to request correction, the right to restrict processing, and the right to have their data deleted.

For a real estate agency, personal data includes every name, phone number, email address, and property interest recorded in the CRM. The lawful basis question is not a formality. Every individual contact record needs to have a basis — and if that basis is challenged in an investigation or complaint, the agency needs to be able to point to evidence. The two lawful bases most commonly relied upon by estate agents are legitimate interests and consent, and they operate quite differently.

Legitimate Interests vs Consent: The Distinction That Matters

Legitimate interests allows an agency to process personal data without explicit consent, where the agency has a genuine business interest in doing so and that interest is not overridden by the individual's rights and expectations. For a real estate agency, this might apply to contacting a recent enquirer about comparable properties, or following up with a past vendor about current market conditions in their suburb. The test is whether a reasonable person in that position would expect to receive contact of that nature from an agency they have previously engaged with.

Consent, by contrast, is a freely given, specific, and informed agreement by the individual to have their data used for a defined purpose. Consent must be as easy to withdraw as to give, and once withdrawn it cannot be relied upon as a basis for further contact. The critical operational implication is that relying on consent means tracking it — when it was given, through what mechanism, and whether it has since been withdrawn.

Many agencies make the mistake of assuming that because a contact gave their details at an open home or on a portal enquiry form, they have consented to receive future marketing communications. That assumption is incorrect. Providing details to register for an inspection creates a business interaction — it does not constitute consent to an ongoing marketing relationship. Whether legitimate interests applies to subsequent contact depends on the nature of that contact and the recency of the original engagement.

The Three Highest-Risk Practices in Estate Agency

The first is purchasing contact lists. Third-party contact lists sold to agencies almost never come with verifiable consent records or legitimate interests assessments. Sending marketing communications to contacts acquired this way exposes the agency to enforcement risk on every message sent, and the reputational cost if a recipient complains to the ICO is compounded by the fact that the agency cannot point to any relationship with the contact.

The second is indefinite data retention. GDPR requires that personal data be kept only for as long as necessary for the purpose for which it was collected. An enquiry contact who never proceeded with a transaction and has had no further interaction in three years is likely no longer appropriate to hold in a live marketing database. Agencies without a defined retention policy — and the systems to enforce it — are holding data they have no legitimate basis to retain.

The third is treating transactional data as marketing permission. A contact who provided their details to complete a rental application, a sale, or a property management agreement gave that data for a specific purpose. Using it to send ongoing prospecting messages about unrelated services requires a separate lawful basis. Many agencies do not make this distinction in their CRM setup, which means their entire database may be operating on a legally uncertain foundation.

What a Compliant Estate Agency Contact Database Looks Like

A compliant database has, for each contact, a documented basis for holding and processing their data. That documentation does not need to be elaborate — it needs to be consistent and retrievable. Consent records should capture the date and mechanism of consent. Legitimate interests assessments should be documented for the categories of contact the agency makes under that basis. Retention periods should be defined for each contact type: active vendor, past vendor, open home registrant, portal enquiry, and so on.

Opt-out processing is the other operational requirement that most agencies underinvest in. When a contact asks to be removed from marketing communications, that request needs to be processed promptly across every system — not just the email platform, but the SMS tool, the CRM, and any third-party services the agency uses for outreach. A contact who opted out via SMS and then received an email campaign two weeks later has grounds for a complaint, and the agency will have difficulty demonstrating that its systems were operating as required.

The Soft Opt-In Question

The Privacy and Electronic Communications Regulations, which sit alongside GDPR for direct marketing purposes, include a provision known as the soft opt-in. It allows marketing communications to be sent to individuals who provided their contact details in the course of a transaction or enquiry, without express consent to marketing, provided they were given a clear opportunity to opt out at the time and have not done so.

For estate agents, this provision potentially covers contacts who registered interest in a specific property, submitted an online appraisal request, or made a rental enquiry. The soft opt-in is not blanket permission to market indefinitely — it is limited to communications about similar products or services, and it lapses when the underlying relationship has become too distant. Using it correctly requires understanding both its scope and its limits, and it should not be treated as a substitute for a properly maintained consent and legitimate interests framework. Agencies operating across jurisdictions will find the equivalent rules for Australia, the US, and Canada set out in the SMS marketing laws guide for real estate.

What ICO Enforcement Actually Looks Like

Investigations by the Information Commissioner's Office are typically triggered by individual complaints, which can be filed by anyone who believes their data has been used without proper basis. A single complaint from a contact who received an unsolicited marketing SMS can initiate an investigation into the agency's entire data processing operation — not just the specific message. What the ICO finds in that investigation determines the outcome.

Fines under GDPR can reach four percent of annual global turnover or £17.5 million, whichever is higher — but the more common consequence for estate agents is a formal reprimand, a mandatory remediation programme, and publication of the enforcement action. For agencies also sending marketing SMS in Australia, the guide to SMS marketing legality in Australia explains how the Spam Act 2003 interacts with similar consent principles. The reputational damage of appearing in ICO enforcement records typically exceeds the financial penalty, particularly for agencies whose business depends on the trust of local vendors and landlords.

Voqo stores consent records, respects opt-out instructions across every channel, and provides a compliant operating foundation for estate agencies in the UK and European markets. See how Voqo works.

See it in action

15 minutes with our founders. We'll show you how it works and tell you straight if it's a fit.