Property sector
Data protection for
estate agencies
Estate agencies handle identity documentation, financial solvency data and financial information relating to buyers and tenants. Property portals, anti-money-laundering regulations and the retention of data following unsuccessful transactions are the main regulatory challenges.
Act 10/2010
AML — mandatory identification
10 years
retention of AML data
Art. 28
GDPR — portals as data processors
24 h
personalised proposal
Sector challenges
General obligations for estate agencies
Identity documentation
The collection of national identity documents, NIE numbers or passports from buyers and tenants is mandatory under anti-money-laundering regulations. This processing must be documented and retained in accordance with the periods set out in Act 10/2010.
Financial solvency data
Payslips, bank statements and tax returns collected to verify the solvency of a buyer or tenant are particularly sensitive financial data.
Property portals
Idealista, Fotocasa and other portals may act as data processors or as independent data controllers depending on how they use the data transferred to them. The relationship must be documented.
Retention after unsuccessful transactions
Data relating to contacts and candidates who do not proceed to purchase or rent cannot be retained indefinitely. A reasonable retention period and a deletion procedure must be established.
Data of owners in listings
Information about the owner who instructs the sale (contact data, property data, mortgage situation) must be processed with the same safeguards as buyers' data.
Marketing and client acquisition
Email marketing campaigns, targeted advertising and the management of property leads require documented consent or legitimate interests and a straightforward opt-out mechanism.
The service
What is included in the data protection service for your estate agency
Record of Processing Activities
Tailored RoPA (Record of Processing Activities): buyers, tenants, owners, employees and portals as data processors.
Information clauses
Texts for the owner instruction form, buyer and tenant forms, and web forms.
Privacy policy and legal notice
Legal documentation for the agency's website and its contact forms.
Data Processing Agreements (DPA)
DPAs for property portals, CRM software, digital signature platforms and marketing tools.
Data breach protocol
Incident response procedure with notification within 72 hours.
Data subject rights management
Documented procedure for handling requests from buyers, tenants and owners.
Document management platform
Access to a private platform with documents, templates and electronic signature.
Ongoing support
Unlimited queries. Updates in response to regulatory changes.
External DPO (where applicable)
As a general rule, estate agencies are not listed in the exhaustive provisions of art. 34 LOPDGDD or art. 37 GDPR. The final requirement will depend on the scale, volume and exact nature of each entity's processing activities. Each case requires individual analysis. Separate contract.
Do you need a proposal for your agency?
Tell us the size and scope of your business. Proposal in under 24 hours.
FAQ
Frequently asked questions about data protection in estate agencies
How long may an estate agency retain client data after an unsuccessful transaction?
The retention period must be limited to the time necessary to evidence compliance with contractual obligations and to address potential claims. In practice, a maximum of 1 to 3 years after the end of the mandate is recommended, unless another legal basis applies. Once that period has elapsed, data must be blocked or deleted.
Can estate agencies request payslips and bank statements from buyers and tenants?
Yes, but the collection must be proportionate and rely on the performance of the intermediation contract or the legitimate interests of verifying solvency. The agency must inform the data subject of this purpose in the information clause and may not retain these documents longer than is necessary to verify solvency.
Are property portals such as Idealista or Fotocasa data processors for the estate agency?
It depends on the use. If the agency transfers client contact data to a portal so that the portal manages it on the agency's behalf, the portal acts as a data processor. If the portal uses the data for its own commercial purposes, it acts as an independent data controller. In both cases, the relationship must be governed contractually.
Who is the data controller: the agency or the owner who instructs the sale?
The estate agency is the data controller for the processing of buyers' and tenants' data that it collects during the transaction. The property owner may access certain data within the scope of the intermediation, but the processing in the agency's systems is the agency's responsibility.
May personal information about the owner be included in sale listings?
No. Sale or rental listings must not include personal data of the owner (name, telephone number, full address) without their explicit consent for that publication. Common practice is for all contact to be channelled through the estate agency.
Is identity verification of the seller or buyer required in a sale transaction?
Yes. Act 10/2010 on the prevention of money laundering requires estate agencies to identify parties by means of an identity document. This identification must be documented and retained in accordance with the retention periods established by anti-money-laundering regulations (10 years).
Free tool
Data protection self-check
Check in 5 minutes your overall adaptation level in personal data protection.
No email · Anonymous · No commitment
Property sector
GDPR compliance
for your estate agency.
An expert analyses your practice and proposes the appropriate solution. No intermediaries.
Proposal within 24 h · info@certix.es
Legal notice: This content is for informational and educational purposes only; it does not constitute specialist legal advice. The application of the regulations to each specific case requires individual analysis.