Certix

Data protection in a real estate agency: where to start

Certix
Certix®
· 1 Jun 2026 · 8 min read

Informative article. It does not replace individualised professional advice.

A real estate agency manages personal data on three simultaneous fronts: those of the owner who sells or rents, those of the buyer or tenant who shows interest and those of its own network of suppliers (portals, notary, gestoría, mortgage broker, building manager). Through that chain flow names, ID numbers, proof of income, property photos, floor plans, cadastral references and, frequently, sensitive financial data. Data protection in this sector is not a formality: it is what separates a professional agency from an informal intermediary.

This guide summarises the minimum documentation and the operational decisions that a real estate agency should have settled before taking on its first listing, under the framework of the GDPR (Regulation (EU) 2016/679), the LOPDGDD (Spain's Organic Law 3/2018 on Data Protection), the LSSICE (Spain's Law 34/2002 on Information Society Services) and the Spanish anti-money laundering rules that affect the sector.

Three data flows, three distinct legal bases

The defining feature of the sector is that a real estate agency works with three parallel contractual relationships, each with its own legal basis and its own retention periods. It is worth being clear about this from day one:

  • Seller or landlord owner: the legal basis is the performance of the agency contract or engagement letter (Art. 6(1)(b) GDPR). The data processed are identification data, contact details, property ownership data (cadastral reference, deed, registry status) and, in rentals, banking data for rent settlement. Retention is governed by the duration of the engagement plus accounting and tax periods.
  • Buyer or tenant: the legal basis is the performance of the contract or pre-contractual measures requested by the data subject (Art. 6(1)(b) GDPR): viewing of the property, signed viewing sheet, offer, deposit, earnest money contract, tenancy agreement. Retention is linked to the transaction: if it closes, until accounting and anti-money laundering obligations are met; if it falls through, until any associated civil actions lapse or any claim can be ruled out.
  • Suppliers (real estate portals, mortgage broker, gestoría, notary, building manager, removals company, professional photographer): the legal basis is the performance of the commercial contract with the supplier (Art. 6(1)(b) GDPR). When the supplier processes personal data on behalf of the agency — for example, a portal showing the listing or a broker handling financing — a data processor contract is required (Art. 28 GDPR) governing the relationship.

This triple basis requires structuring internal documentation in differentiated blocks and, above all, not mixing purposes: data collected to manage a viewing of a flat is not automatically reusable to send the client future commercial opportunities.

Minimum documentation for the agency

These are the documents any real estate agency should have available before the first transaction. Some are mandatory by law; others are good practices that prevent problems if a client complaint arrives, an inspection from AEPD (the Spanish Data Protection Authority) takes place or a real estate group audit comes along.

Document Purpose Mandatory
Record of Processing Activities (RoPA) Inventory of processing operations: owner acquisition, buyer viewings, tenancy management, marketing, portal management. Yes (Art. 30 GDPR)
Privacy notices One for sellers/landlords, another for buyers/tenants, another for web visitors. Deliver before collecting data. Yes (Arts. 13–14 GDPR)
Compliant viewing sheet Document signed by the visitor: identifies the client, records the viewing and delivers the privacy notice. Good practice
Engagement letter / mandate Written contract with the owner that delimits the engagement, exclusivity and disclosures to portals and other parties. Yes (commercial)
Art. 28 GDPR contracts With real estate portals, CRM software, mortgage broker, professional photographer or videographer where applicable. Yes (Art. 28 GDPR)
Security policy Individual CRM passwords, role-based access, backups, screen locking, off-boarding of departing staff. Yes (Art. 32 GDPR)
Web notices and cookies LSSICE legal notice, privacy policy, cookie policy with valid prior consent for all cookies that are not strictly necessary. Yes (LSSICE + GDPR)
Breach protocol Procedure for detecting, recording and notifying the AEPD of a data breach within 72 hours (Arts. 33–34 GDPR). Yes (Art. 33 GDPR)
AML documentation For the real estate operations covered by Law 10/2010: enhanced identification, special examination, internal manual and ten-year retention. Yes (Law 10/2010)

Viewing sheet: what it should contain

The viewing sheet is one of the most underused documents in the sector and, however, one of the most useful from a data protection standpoint. It serves three functions: it identifies the visitor, records that the viewing took place and is used to deliver the privacy notice before collecting data.

Reasonable content for a viewing sheet includes:

  • Basic identification of the visitor: name, ID document or equivalent, telephone and email. There is no need to photocopy the ID document: noting the number and checking it visually is enough to evidence the viewing.
  • Identification of the property visited, date, time and agent accompanying the viewing.
  • Compact privacy notice on the back or on a second sheet: identity of the agency, purpose of processing (managing the viewing and any subsequent transaction), legal basis (pre-contractual measures requested by the visitor), foreseen recipients (notary, bank, gestoría, owner), retention period, rights of the data subject and means of exercising them.
  • Separate, unticked-by-default checkboxes for additional and optional purposes: "I consent to my data being kept for future real estate opportunities", "I agree to receive commercial communications by email". These checkboxes cannot be bundled with the main signature nor presumed accepted.
  • Signature of the visitor and the agent, with an indication that a copy of the information has been delivered.

The paper viewing sheet is digitised on return to the office, incorporated into the client's file in the CRM and, if the transaction does not come to fruition, kept for the reasonable time needed to rule out claims of intrusion, double commission or disputes with another agency.

Identity documents: no routine photocopies, no mass archives

The real estate sector has a recurring temptation: asking for and filing a photocopy of the ID document from the viewing sheet "just in case". It is a disproportionate practice and, in most cases, contrary to the principle of minimisation of Art. 5(1)(c) GDPR.

The practical rule is straightforward:

  • At acquisition and viewing: it is enough to note the name and the number of the ID document. No copy or scan is needed.
  • At the deposit and the contract: it becomes necessary to have a copy of the document for the earnest money contract, the tenancy agreement or the signing before the notary. That copy is requested at that moment and kept in the specific file, not in a shared folder of "client IDs".
  • In AML operations (Law 10/2010): obliged parties must apply enhanced identification measures and keep a copy for ten years. Here, document storage is justified, but only for the operations falling within the law's scope.

Commercial marketing: where the contract ends and consent begins

Once a transaction is closed, the agency usually wants to keep the client in its commercial database to send new opportunities, market valuations or notices of similar properties. That processing is no longer covered by the legal basis of the closed contract: the purpose changes and, therefore, the legal basis changes.

The two reasonable options are:

  • Express consent collected at the time with a specific, unticked-by-default checkbox. It is the cleanest option and the one that best withstands a potential complaint.
  • Legitimate interest under Art. 6(1)(f) GDPR to send communications about products or services similar to those already contracted, provided that this possibility has been disclosed and that a clear and free objection mechanism is offered in each message (the well-known "unsubscribe" option). This route requires a prior legitimate interest balancing test and is limited to the existing client, not to someone who merely viewed a property years ago without closing anything.

Under either route, commercial messages by email or SMS must also comply with Art. 21 LSSICE: prior consent or a prior contractual relationship involving similar products, clear identification of the sender and an accessible unsubscribe mechanism in every communication.

"A real estate agency that doesn't get anything signed by the client coming in to view a flat is leaving two doors open: first, a data protection complaint for failing to inform; second, an argument with another agency about who really brought in the buyer. The viewing sheet solves both."

Mario P. Talamillo · Managing Partner, Certix®

Before taking the first engagement: minimum checklist

  • RoPA drafted with the sector's processing operations: acquisition, viewings, tenancies, marketing, portal management, HR.
  • Separate privacy notices for owner, buyer or tenant and web visitor, ready to deliver before the first contact.
  • Viewing sheet with a privacy notice block on the back and independent checkboxes for future commercial uses.
  • Art. 28 GDPR contracts signed with the real estate portals being used, with the CRM provider and with any regular mortgage broker.
  • Internal security policy: individual CRM passwords, role-based access, backups, automatic screen lock, log of staff joining and leaving with access to files.
  • Cookie policy on the live website with valid prior consent and blocking of non-essential cookies until the visitor accepts.
  • Breach protocol and internal log, with identification of the person responsible for notifying the AEPD if necessary.
  • Specific analysis of AML obligations for transactions falling within Law 10/2010 and implementation of the associated processes.

Frequently asked questions

Does a real estate agency need the buyer's or tenant's consent to process their data?

For the ordinary handling of a sale or rental, consent is not required: the legal basis is the performance of the contract or pre-contractual measures requested by the data subject (Art. 6(1)(b) GDPR). What is mandatory is to deliver the privacy notice of Art. 13 GDPR at the first contact. Express consent only comes into play for additional processing such as commercial marketing or disclosures to mortgage brokers.

Is it lawful for the agency to keep the client's data after the transaction closes or falls through?

It is lawful as long as there are live legal obligations or legal risks. As a reference, commercial documentation must be kept for six years (Art. 30 of the Spanish Commercial Code), tax obligations lapse after four years and civil actions after five. In addition, operations subject to the Spanish Anti-Money Laundering Law (Law 10/2010) require identification documentation to be kept for ten years.

May the agency hand over the buyer's ID document to the notary or the bank without explicit permission?

Yes. Communication to a notary, financial institution, gestoría or building manager does not require additional consent: it is a disclosure necessary for the performance of the contract (Art. 6(1)(b) GDPR). The agency must inform of these foreseen disclosures in the privacy notice (Art. 13(1)(e) GDPR) and limit the information to what is strictly necessary for each recipient.

Is it mandatory to appoint a Data Protection Officer (DPO) in a real estate agency?

As a general rule, no. A standard real estate agency does not fall within the cases of Art. 37 GDPR or Art. 34 LOPDGDD that impose a mandatory DPO. The exception are large real estate groups whose activity can be equated with regular and systematic large-scale monitoring. Although this is the sector's general rule, the final requirement will depend on the scale, volume and exact type of processing of each entity. Each case requires individual analysis.

This content is for informational and educational purposes only and does not constitute legal advice. Applying the regulation to each specific case requires individual analysis. Regional sectoral regulations may extend or modify time limits and requirements.

Need to put your real estate agency's data protection in order?

At Certix we assign you an expert in real estate sector compliance. No sales intermediaries, no generic templates.

Speak to a specialist

Initial assessment

Need data protection advice?

At Certix you will deal directly with an expert, with no sales teams involved.

BASIC DATA PROTECTION INFORMATION: In accordance with Data Protection regulations, we provide the following processing information: Controller: Certificación y Gestión Normativa S.L.U. Purpose: to handle your request and contact you to provide the requested information. Rights: access, rectification, portability, erasure, restriction and objection, and other rights detailed in the additional information. More info: You can find more detailed information in our Privacy Policy.

Or tell us your full case →