Do landlords need to register with the ICO and pay the data protection fee?
In the UK, landlords are under the same ICO fee and UK GDPR regime in England, Wales, Scotland and Northern Ireland; Scotland’s separate landlord registration scheme is a different system. The practical question is not whether someone is a landlord, but whether the landlord decides how tenant or applicant personal data is used.
In the UK, landlords are under the same ICO fee and UK GDPR regime in England, Wales, Scotland and Northern Ireland; Scotland’s separate landlord registration scheme is a different system. The practical question is not whether someone is a landlord, but whether the landlord decides how tenant or applicant personal data is used.
Automated property management for UK landlords & property managers
Free for our first 50 users — no agent fees
Do landlords need to register with the ICO and pay the data protection fee?
Most landlords who hold tenant or applicant data need to register with the ICO and pay the data protection fee; for an ordinary micro-landlord the fee is £52 a year, or £47 by direct debit, from 17 February 2025, and the tier-1 non-payment penalty is £400. The legal test is UK-wide: “A data controller must comply with the requirements of this regulation unless all of the processing of personal data they undertake is exempt processing.” The ICO’s landlord guidance says that if you produce tenancy agreements, obtain references or run credit checks, “This would require you to pay a data protection fee.” The £40 figure still repeated on some landlord sites is stale, because the 2025 amendment says “for ‘£40’ substitute ‘£52’”; the direct debit discount is still £5. The ICO also says registration is required by law, so a limited company that has received an ICO annual-fee letter should not ignore it merely because people call the duty registration rather than a fee.
Are you exempt from ICO registration?
You are exempt from paying the ICO fee only if all your processing falls within an exemption, and fee-exemption is not a GDPR-exemption: an exempt landlord can still owe privacy-notice, breach-reporting and subject-access duties. There is no landlord-only, one-property or portfolio-size exemption; the household exemption is a purpose test, and the ICO says it applies only if you are not running a business because “renting out a property is like running a small business”. A fully managed let can be different: the ICO says, “If you are using a letting agent who fully manages the letting of the property and you only receive a monthly statement and rent, this would fall under the accounts and records exemption.” But the exemption is narrow: credit-reference-agency data is carved out, and the ICO says that if a landlord creates a tenant database, chooses the tenant or receives electronic tenancy agreements, “payment of fee is required.” Most self-managing landlords are outside the exemption.
Does a sole trader landlord need to register with the ICO?
A sole trader landlord needs to register with the ICO and pay the fee if they use personal information for the letting business and no exemption covers all of that processing. The ICO’s self-assessment states: “Under the Data Protection (Charges and Information) Regulations 2018, organisations (including sole traders) that use personal information need to pay a data protection fee, unless they are exempt.” The first-time payment page is also explicit that it is for all data controllers, “including sole traders and companies”. A sole trader is therefore not outside ICO registration just because the rental property is owned personally rather than through a company; the same UK regulator and fee regime apply across all four nations. If a landlord owns some properties personally and some through a limited company, the safer practical distinction is that each legal person that decides how tenant data is processed is its own controller. A home-based sole trader can avoid publishing a home address by using a PO Box or alternative address where allowed.
Does GDPR apply to private landlords?
UK GDPR applies to private landlords who decide why and how tenant or applicant personal data is processed, even if they are small, self-managing or exempt from paying the ICO fee. UK GDPR defines a controller as the person or body that “determines the purposes and means of the processing of personal data”, and a landlord who collects references, bank details, rent records, repair messages or identification documents is normally doing exactly that. The personal or household carve-out is much narrower: UK GDPR excludes “the processing of personal data by an individual in the course of a purely personal or household activity”, and Recital 18 says that means activity with “no connection to a professional or commercial activity.” The ICO treats renting as business-like rather than domestic: “renting out a property is like running a small business”. Abodient can keep tenancy records, deposit details and documents scoped to the correct letting period, which matters because GDPR duties attach to how a landlord stores and retrieves tenant data, not just to the moment of signing the tenancy.
Do you have to give your tenant a privacy notice?
A landlord does not need a document with the exact title privacy notice, but must give the tenant the Article 13 privacy information when collecting their personal data unless the tenant already has it. UK GDPR says: “Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time when personal data are obtained, provide the data subject with all of the following information”. The ICO describes the same package as privacy information, saying “Articles 13 and 14 specify the types of information that you need to provide individuals with as a minimum.” A landlord privacy notice template is therefore only a format; the substance is the information about who the controller is, what data is collected, why it is used, lawful bases, retention, sharing, rights and ICO complaints. The duty does not duplicate information the tenant already has, because Article 13 says the obligation does not apply “to the extent that the data subject already has the information.”
Do you have to report a data breach to the ICO within 72 hours?
You must report a personal data breach to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, but only if it is likely to risk people’s rights and freedoms. Article 33 makes the 72-hour reporting duty conditional: the report goes to the Commissioner unless the breach is unlikely to result in that risk, so ransomware that locks a property-management system and exposes landlord bank details and tenant personal data is not assessed by the clock alone. The first question is whether the incident creates a risk to individuals. The ICO says, “You do not need to report every breach to the ICO.” Even where no ICO report is made, Article 33 still says the controller “shall document any personal data breaches” including facts, effects and remedial action.
What do you do if a tenant asks who you have shared their data with?
If a tenant asks who you have shared their personal data with, treat it as a subject access request and normally give the actual recipient names, not just categories, unless giving names is impossible, manifestly unfounded or excessive, or would wrongly identify another person. Article 15 itself refers to “the recipients or categories of recipient to whom the personal data have been or will be disclosed”, but the ICO’s current guidance says the person is entitled to “The identities of specific recipients you have or will be disclosing the personal information to … except where it would be impossible or manifestly unfounded or excessive to provide this information.” In England and Wales, Harrison v ACL applied the Austrian Post approach to UK GDPR, meaning the data subject can require specific identities; that ruling is not binding precedent in Scotland or Northern Ireland, though the UK-wide right of access still applies. If naming a contractor, agent or insurer would disclose another individual’s data, the Data Protection Act 2018 exemption may apply where it is not reasonable to disclose without that person’s consent.
How do you change your address on your ICO registration?
You change your address on ICO registration through the ICO change service, and if that cannot be used you email the ICO quoting your registration reference. The ICO page says, “Use this service to quickly update the details we hold about your registration,” and adds: “If you’re unable to use the service to change or update your details, email your request to us quoting your registration reference.” The 2018 Regulations require controllers to provide their name and address within the first 21 days of each 12-month charge period, including the address of a non-company business as its principal UK place of business, but they do not set a separate statutory mid-year change fee. Address choice matters because the ICO register is public: GOV.UK says, “If you run your business from home and do not want your home address to appear on the public register, provide a PO box or alternative address instead.” The annual ICO fee is separate from updating contact details.
Last reviewed September 2026.
Sources
- Data Protection (Charges and Information) Regulations 2018 reg.2 — “A data controller must comply with the requirements of this regulation unless all of the processing of personal data they undertake is exempt processing.” Source
- ICO real estate sector fee guidance — “This would require you to pay a data protection fee.” Source
- Data Protection (Charges and Information) (Amendment) Regulations 2025 reg.2 — “(a)in sub-paragraph (a), for “£40” substitute “£52”;” Source
- Data Protection (Charges and Information) Regulations 2018 reg.3 — “The applicable charge in paragraph (1) is reduced by £5.00 for a data controller that makes payment of the charge by direct debit.” Source
- ICO registration page — “We do not provide invoices as registration is required by law.” Source
- ICO fixed penalties for failure to pay the data protection charge — “(a) tier 1 (micro-organisations), is £400;” Source
- ICO real estate sector fee guidance — “This will only apply to you if you are not running a business (renting out a property is like running a small business).” Source
- ICO real estate sector fee guidance — “If you are using a letting agent who fully manages the letting of the property and you only receive a monthly statement and rent, this would fall under the accounts and records exemption.” Source
- Data Protection (Charges and Information) Regulations 2018 Sch. para.2 — “The processing of personal data by or obtained from a credit reference agency (within the meaning of section 145(8) of the Consumer Credit Act 1974) does not fall within the description of processing set out in sub-paragraph (2)(f).” Source
- ICO real estate sector fee guidance — “However, if as a landlord you create a database of potential tenants, make any decision to which tenant can rent your property and/or you receive electronic copies of tenancy agreements then payment of fee is required.” Source
- ICO exemptions guidance — “But even if you are exempt from paying a fee, you still need to comply with your other data protection obligations.” Source
- ICO fee self-assessment — “Under the Data Protection (Charges and Information) Regulations 2018, organisations (including sole traders) that use personal information need to pay a data protection fee, unless they are exempt.” Source
- ICO registration page — “It is for all organisations (we use this term to include all data controllers, including sole traders and companies) that need to pay a fee to the ICO.” Source
- ICO privacy notice for paying a data protection fee — “If this is the case, and you do not want the address to be made public on the register of controllers, please provide a PO Box or alternative address instead.” Source
- UK GDPR Article 4 — “(7)‘controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data (but see section 6 of the 2018 Act);” Source
- UK GDPR Article 2 — “(a)the processing of personal data by an individual in the course of a purely personal or household activity;” Source
- UK GDPR Recital 18 — “This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity and thus with no connection to a professional or commercial activity.” Source
- UK GDPR Article 13 — “Where personal data relating to a data subject are collected from the data subject, the controller shall, at the time when personal data are obtained, provide the data subject with all of the following information:” Source
- ICO right to be informed guidance — “Articles 13 and 14 specify the types of information that you need to provide individuals with as a minimum.” Source
- UK GDPR Article 13 — “Paragraphs 1, 2 and 3 do not apply to the extent that the data subject already has the information.” Source
- UK GDPR Article 33 — “In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the Commissioner, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.” Source
- ICO personal data breach assessment — “You do not need to report every breach to the ICO.” Source
- UK GDPR Article 33 — “The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken.” Source
- UK GDPR Article 15 — “(c)the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;” Source
- ICO right of access guidance — “The identities of specific recipients you have or will be disclosing the personal information to (including those in countries or territories outside the UK, or in international organisations), except where it would be impossible or manifestly unfounded or excessive to provide this information.” Source
- Harrison v ACL [2024] EWHC 1377 (KB) — “For the reasons I have given, in my judgment, the interpretation given by the CJEU in the Austrian Post case to article 15(1)(c) of the GDPR is correct and should be applied in determining the meaning of article 15(1)(c) of the UK GDPR.” Source
- Data Protection Act 2018 Sch.2 para.16 — “(b)it is reasonable to disclose the information to the data subject without the consent of the other individual.” Source
- ICO change registration details page — “Use this service to quickly update the details we hold about your registration.” Source
- ICO change registration details page — “If you’re unable to use the service to change or update your details, email your request to us quoting your registration reference.” Source
- Data Protection (Charges and Information) Regulations 2018 reg.2 — “Within the first 21 days of each charge period a data controller must provide to the Information Commissioner the following information, as of the first day of each charge period—” Source
- Data Protection (Charges and Information) Regulations 2018 reg.2 — “(b)the address of a person (other than a registered company) carrying on a business is that of the person's principal place of business in the UK.” Source
- GOV.UK data protection register guidance — “If you run your business from home and do not want your home address to appear on the public register, provide a PO box or alternative address instead.” Source
