AI supplier checks for letting agencies before sharing tenant data
Applies to United Kingdom. This is general information, not legal advice — check the primary legislation or take advice before acting on a specific case.
Before sharing tenant data with an AI supplier, agree what the service will do, who controls the processing and which lawful basis applies. Review the processing contract, the full data route, access controls and deletion arrangements. Start demonstrations with fictional records. Keep live tenant data out until the responsible manager approves the arrangement.
An AI service may read a repair email, extract a certificate or draft a reply. Each task sends different information to different places. A demonstration shows whether the feature works; the supplier assessment establishes whether your agency can use it with the proposed records. These checks concern UK data protection across the United Kingdom, alongside the tenancy rules that differ by nation.
Map one proposed workflow
Choose the first task you intend to buy. Write down its input, output and permitted action before granting access to your whole portfolio. Include attachments, prompts, search results and any records the assistant can retrieve.
In a hypothetical London agency, the first pilot drafts acknowledgements from maintenance messages. It excludes applicant screening and requires a manager to approve every reply. A damp report may contain health information, so the assessment must cover unexpected sensitive content as well as the fields on the enquiry form.
Identify the minimum information needed. A drafting demonstration can often use a fictional message and a made-up property. If a live task needs a tenant identifier, restrict access to the relevant case. ICO’s AI data minimisation guidance supports reviewing information throughout the workflow, considering redaction and setting justified retention periods.
Agree who decides how the information is used
A controller determines the purposes and means of processing. A processor acts on the controller’s behalf and instructions. The practical decisions determine the role, regardless of the contract label. Review the agency, landlord, supplier and other providers separately for each activity, using ICO’s controller and processor guide.
Ask whether the supplier uses prompts, documents or outputs for its own model training or product development. Establish whether a setting disables that use, which account type it covers and how the agreement records it. If the supplier has its own processing purpose, have your data protection adviser assess the role and terms for that activity. Do not assume the entire supply chain is your processor.
ICO’s AI procurement guidance recommends mapping the relationships through the supply chain and agreeing them formally. Retain the map and the supplier’s dated answers with the purchasing decision.
Confirm the lawful basis and risk assessment
Identify and document the lawful basis before processing tenant information, and explain the purposes and basis in privacy information. ICO’s lawful basis guide, updated on 2 April 2026 after the Data (Use and Access) Act, says the basis depends on the purpose and relationship. Signing a software contract does not itself supply a lawful basis for every proposed use.
Health information requires an additional special-category condition as well as a lawful basis. Refer that assessment to someone qualified to decide it. Keep applicant scoring, eligibility decisions and other consequential uses outside a simple drafting pilot until they have their own assessment.
A data protection impact assessment (DPIA) is required for processing likely to result in high risk to individuals. ICO advises assessing AI case by case; if you conclude the particular use is not high risk, document why. Where a DPIA identifies high risk that cannot be sufficiently reduced, consult ICO before starting. Ask the supplier for information to support your assessment. Its own DPIA does not approve your agency’s proposed use.
Read the processing agreement before importing records
Where you use a processor, a written contract or other legal act must cover the processing.ICO’s contract checklist includes its subject matter, duration, nature, purpose, personal-data types, people concerned and the controller’s rights and obligations.
Check terms on documented instructions, confidentiality, security, authorised sub-processors, assistance with individual rights, breaches and DPIAs, audits, and return or deletion when the service ends, subject to legally required storage. Ask for a current sub-processor list and the process for authorising changes. Keep the signed version and the approved technical settings together.
Request answers you can verify
Ask for written answers and demonstrations of the controls. These are practical evidence requests, not a universal certification test.
| Question | Evidence to request |
|---|---|
| Does customer content train models? | Applicable contract clause, account settings and the scope of any exceptions. |
| Who receives tenant information? | A flow map naming legal entities, their purposes and sub-processors. |
| Who can view a case? | Demonstration of staff roles, branch boundaries and support access. |
| What remains after deletion? | Retention schedule for uploads, prompts, outputs, logs and backups; deletion procedure. |
| Can we retrieve records or respond to a tenant request? | Sample export and the process for finding information held by the supplier. |
| What happens during an incident? | Named contact, escalation process and contractual assistance obligations. |
Ask the supplier to demonstrate access restrictions with fictional records from two branches. Test what a user without permission can retrieve, as well as what an administrator sees. Request evidence of relevant security testing and ask how identified problems are handled.ICO’s AI security guidance supports assessing the system and its connected services before implementation.
Check overseas access as well as storage
A UK hosting region does not settle the international-transfer assessment.ICO’s guidance includes remote access by a separate organisation outside the UK, even when the information remains on UK servers.
Ask where each receiving legal entity is established, where support works and who initiates each transfer. The restricted-transfer test considers whether UK GDPR applies, whether a transfer is initiated to an organisation outside the UK and whether that organisation is a separate legal entity. ICO also distinguishes initiating a transfer from authorising a processor’s transfer.
Have the responsible adviser check the applicable transfer mechanism, which may be UK adequacy regulations, appropriate safeguards or a relevant exception. Ask for the assessment and agreements that support the route. Current ICO guidance calls the statutory test for safeguards a data protection test; it also uses transfer risk assessment terminology. A hosting address or a standard contract alone does not settle that assessment.
Run a bounded pilot and record the decision
Give the pilot an owner, a defined workflow and a review date. Use fictional records until the legal and security checks are resolved. Agree who reviews drafts, how staff report wrong outputs and how to stop access if the trial fails. Our guide to custom AI workflows explains the separate question of controlling the actions an assistant can take.
Record the approved purpose, data categories, contract version, settings, access permissions and unresolved issues. Review the next task before expanding: approval for maintenance drafts does not automatically cover analysing applicants or exposing finance records. Reassess changes to models, sub-processors or data use.
For wider buying decisions, use our property management software comparison. For integrations, map the systems your agency will keep before agreeing the data exchange. If your pilot supports an English tenancy-compliance workflow, the free Renters’ Rights readiness check can help identify that workflow’s gaps; it does not approve a supplier’s data protection arrangements.
ICO flags several AI and controller/processor guidance pages as under review following the Data (Use and Access) Act. Check the linked guidance at procurement and before expanding the service. This article is general operational information, not approval for a particular processing arrangement.
When evaluating Tekniti, start with the agency offering and current privacy notice. Ask for the terms and evidence applicable to the exact service, configuration and proposed data flow. Keep your agency’s decision and supporting records with the contract.
Tekniti runs this work for UK landlords and letting agencies — tracking it, preparing it, and holding what matters for a person to approve. See how it works for landlords or for letting agencies, or write to hello@tekniti.ai.