Skip to content
wohnsignal

GDPR basics for property managers communicating with tenants

Tenant data is personal data. An overview of what property managers should keep in mind under the GDPR when communicating with tenants digitally.

Nabil ChouaibPublished on 2 min read

Note: This post is a general overview and not legal advice. For your specific situation, please consult your data protection officer or a lawyer.

Property managers process personal data every day: names, addresses, phone numbers, flat assignments, sometimes bank details. As soon as that data moves into tenant communication software, the question is: what does the General Data Protection Regulation (GDPR) require?

Who is responsible?

As a rule, the property manager is the controller under the GDPR (Art. 4(7)). They decide which data is processed and why. The provider of communication software is usually a processor – it processes data on behalf of and on the instructions of the property manager.

The data processing agreement (DPA)

When a service provider processes personal data on your behalf, Art. 28 GDPR requires a data processing agreement. Among other things, it covers:

  • subject matter, duration, nature and purpose of processing
  • types of data and categories of data subjects
  • technical and organisational measures (TOMs)
  • use of sub-processors
  • deletion or return of data at the end of the contract

Tip: ask every software provider for their DPA and list of sub-processors before signing.

Communicating with tenants about tenancy matters – maintenance visits, house rules, repair requests – can often rely on performance of a contract (Art. 6(1)(b) GDPR). Other purposes may need a different legal basis or consent. Check the details with your data protection officer.

Data minimisation

The GDPR requires processing only as much data as the purpose needs (Art. 5(1)(c)). For a communication platform, that means for example:

  • Not every field from your property management system needs to be in the tenant app.
  • Tenants should only see data that concerns them.
  • Data of former tenants should be deleted after defined periods.

Hosting and international transfers

Where is the data stored? Are providers outside the EU involved? Transfers to third countries such as the US require additional safeguards, such as certification under the EU-US Data Privacy Framework or standard contractual clauses. A trustworthy provider answers these questions openly.

Common mistakes

  • WhatsApp groups with tenants: convenient, but problematic for data protection, as phone numbers are visible to every member.
  • Open email distribution lists: putting all recipients in the “To” field is a common data protection breach.
  • Notices with names: personal information doesn’t belong on the notice board.

Conclusion

Digital tenant communication and data protection are not at odds – quite the opposite: a well-designed solution can be more privacy-friendly than WhatsApp groups and open email lists. What matters is a proper DPA, transparency about hosting and the principle of data minimisation.

How we handle these topics at Wohnsignal is described on our security & privacy page.

Be part of it from day one

We are looking for property managers who want to use Wohnsignal early and help shape it. Sign up with no obligation.

Request early access