What the conveyancer fine reveals
DPP Law was fined £60,000 following a ransomware attack. The ICO cited delayed breach notification and outdated, unpatched systems amongst the firm's failings. The penalty followed an incident that exposed client data, but the enforcement focused on what happened after the breach: how quickly the firm identified the problem, reported it, and whether basic security hygiene was in place.
Conveyancers handle transaction data across multiple parties, often via third-party case management platforms. The same structural risk applies to lettings agents processing tenant references, right-to-rent documents and guarantor details, and to estate agents uploading client contact lists to portals and email marketing tools.
The compliance gap is not whether a policy exists. It is whether the person handling a subject access request, or spotting unusual system activity, knows what to do next and can evidence that they acted correctly.
The DUAA complaints procedure is mandatory now
As of June 2026, all data protection provisions of the Data (Use and Access) Act 2025 are in force. The Act introduces a mandatory complaints-handling procedure for data protection issues. This means subject access requests, objections to processing, and complaints about marketing consent now require a documented, auditable process.
Most small-to-midsize agencies do not have in-house compliance resource. They rely on policies written in 2018 and staff trained once, often by a vendor whose product has since changed. The DUAA requirement shifts the burden from having a policy to demonstrating that the policy works when tested.
Firms should be able to answer the following:
- Can staff identify personal data and special category data in everyday transactions?
- Do employees understand the difference between data controllers and processors, and can they identify which role the agency occupies in a given transaction?
- Is there a documented escalation route for potential data breaches, and have staff been trained to use it?
- Are subject access requests logged, tracked and responded to within the statutory timeframe?
- Is the complaints-handling procedure documented, communicated and tested?
The ICO's focus is shifting from policy compliance to operational readiness. The DPP Law fine demonstrates that enforcement follows failures in execution, not gaps in documentation.
Where the operational risk sits in property
Lettings agents routinely handle special category data. Right-to-rent checks require processing of immigration status. Tenant referencing platforms process financial and employment data. Guarantor agreements involve third-party personal information. Each of these transactions involves lawful processing obligations under GDPR Articles 6 and 9, and most agencies rely on third-party platforms where controller and processor responsibilities may not be clearly understood by the person entering the data.
Estate agents face similar exposure. Uploading buyer contact details to portals, exporting mailing lists to marketing platforms, and sharing sale particulars with mortgage brokers all involve data flows where consent, legitimate interest or contractual necessity must be established. If a data subject objects to processing or requests deletion, the agency must be able to demonstrate compliance across every platform where the data sits.
The risk is compounded by legacy CRM systems, incomplete data processing agreements with vendors, and staff turnover. Induction training in 2018 does not cover the DUAA complaints procedure or the latest ICO guidance on lawful processing.
What agencies should do now
Audit whether the DUAA complaints-handling procedure is documented, communicated and embedded in day-to-day operations. If the procedure exists only in a policy folder, it will not withstand ICO scrutiny following a breach or complaint.
Test staff understanding with scenario-based questions. Ask a lettings negotiator what they would do if a tenant requested deletion of their data mid-tenancy. Ask a sales progressor how they would handle a buyer who objects to their details being shared with a mortgage broker. If the answer is uncertain or incorrect, the agency carries enforcement risk.
Review data processing agreements with third-party vendors. Identify which platforms process personal data on behalf of the agency, confirm controller and processor roles, and ensure agreements reflect current processing activities. Many agencies use portals, referencing platforms and CRM systems without up-to-date DPAs in place.
Document breach identification and escalation procedures. The DPP Law fine penalised delayed notification. Agencies should ensure that staff can recognise potential breaches, know who to notify internally, and understand the 72-hour reporting obligation to the ICO where required.
