Data protection

Data handling and protection policy

Effective date30 July 2026
Policy ownerASJ Estates Preston Ltd
ICO certificateDownload PDF

Postal address: 3 Stanley Street, Preston, PR1 4AT.

1. Purpose

ASJ Estates Preston Ltd is committed to handling personal information lawfully, fairly, transparently and securely.

This policy explains how personal information must be collected, accessed, used, stored, shared, retained and deleted by ASJ Estates Preston Ltd and its employees, contractors and authorised representatives.

It applies to personal information relating to:

  • Tenants and prospective tenants
  • Landlords and prospective landlords
  • Guarantors and occupiers
  • Property applicants and viewers

Employees, applicants and contractors.

  • Suppliers and professional advisers
  • Complainants and other people who communicate with us
  • Any other identifiable individual whose information we handle

This is an internal data handling policy. It should be read alongside the company’s privacy notice, cookie information, retention schedule, information security procedures and any relevant contractual requirements.

2. Legal framework

ASJ Estates Preston Ltd will process personal information in accordance with applicable UK data protection legislation, including:

The UK General Data Protection Regulation.

The Data Protection Act 2018.

The Data (Use and Access) Act 2025.

The Privacy and Electronic Communications Regulations 2003, where electronic marketing or cookies are involved.

  • Other legislation requiring the collection, retention or disclosure of information in connection with property management and letting activities

The company is registered with the Information Commissioner’s Office and will maintain its registration and pay any applicable data protection fee.

The UK GDPR requires personal information to be processed lawfully, fairly and transparently; collected for specified purposes; limited to what is necessary; kept accurate; retained only as long as required; and protected using appropriate security measures. The company must also be able to demonstrate its compliance.

3. Data protection principles

ASJ Estates Preston Ltd will ensure that personal information is:

3.1 Processed lawfully, fairly and transparently

Individuals will be told, through an appropriate privacy notice or other communication, why their information is being collected, how it will be used, who it may be shared with and how long it is likely to be retained.

3.2 Collected for specified purposes

Personal information will only be collected for clear, specific and legitimate purposes. It will not be used for an unrelated purpose unless that further use is lawful and the individual has been appropriately informed.

3.3 Adequate, relevant and limited

Only the minimum amount of information reasonably required for the intended purpose will be collected or retained.

Employees must not request information merely because it may be useful at some unspecified point in the future.

3.4 Accurate and up to date

  • Reasonable steps will be taken to ensure that personal information is accurate and, where necessary, kept up to date

Information found to be inaccurate will be corrected or clearly marked as disputed while the matter is investigated.

3.5 Retained only for as long as necessary

Personal information will not be kept indefinitely. It will be reviewed, securely deleted or anonymised when it is no longer required for the purpose for which it was collected or for a legal, regulatory, accounting, insurance or dispute-resolution requirement.

The UK GDPR does not prescribe one retention period for every category of information. Retention periods must therefore be determined according to the purpose, relevant legal obligations and the company’s documented retention schedule.

3.6 Kept secure

Appropriate technical and organisational measures will be used to protect information against:

  • Unauthorised access
  • Accidental disclosure
  • Loss or theft
  • Unlawful alteration
  • Destruction or damage
  • Cyberattack, malware or ransomware
  • Inappropriate use by employees or contractors

3.7 Handled accountably

ASJ Estates Preston Ltd will maintain appropriate policies, records, contracts, training and procedures to demonstrate compliance.

4. Personal information we may handle

Depending on the service provided, the company may handle:

4.1 Identity and contact information

  • Names and previous names
  • Dates of birth
  • Residential and correspondence addresses
  • Email addresses and telephone numbers
  • Photographs and identification documents
  • Signatures
  • Tenant, landlord, property or customer reference numbers

4.2 Property and tenancy information

  • Property addresses
  • Tenancy applications and agreements
  • Occupancy details
  • Deposit information
  • Rent, arrears and payment records
  • Inspection reports and photographs
  • Maintenance and repair reports
  • Communications between tenants, landlords, contractors and the company
  • Notices, complaints and dispute records

4.3 Financial information

  • Bank account and payment details
  • Income and affordability information
  • Employment details
  • Credit and referencing results
  • Rent payment history
  • Invoices, statements and accounting information

Payment card information must not be recorded or retained unless this is necessary and processed through an appropriately secured payment system.

4.4 Compliance and vetting information

  • Identity verification results
  • Right to Rent documentation or results where applicable
  • Tenant and guarantor referencing information
  • Fraud prevention results
  • Sanctions or compliance screening results where legally required or appropriate

Information required by insurers, deposit protection providers, local authorities or regulators.

4.5 Communications and technical information

  • Emails, letters, forms and messages
  • Telephone call notes and recordings, where applicable
  • Website enquiry information
  • Login, access and audit records
  • Device, browser and IP address information where collected through company systems

4.6 Special category and criminal offence information

The company may occasionally receive information relating to health, disability, vulnerability or other special category information, particularly where reasonable adjustments, safeguarding or emergency assistance are required.

Special category information will only be processed where both a lawful basis and an additional condition under data protection legislation have been identified. Criminal offence information will only be processed where there is a lawful basis and the additional legal requirements for handling such information have been met.

Employees must not record excessive or speculative information about a person’s health, personal circumstances or alleged criminal conduct.

5. Purposes for which information may be used

Personal information may be processed to:

  • Respond to enquiries and arrange property viewings
  • Process tenancy or landlord applications
  • Carry out identity, affordability, referencing and vetting checks
  • Prepare and administer tenancy, management and other agreements
  • Collect rent, fees and other payments
  • Protect and administer tenancy deposits
  • Manage properties, inspections, repairs and maintenance
  • Communicate with tenants, landlords, guarantors, contractors and occupiers
  • Meet health and safety, housing, immigration, taxation and regulatory obligations
  • Investigate complaints, disputes, fraud or alleged breaches of an agreement
  • Establish, exercise or defend legal claims
  • Maintain accounting, insurance and audit records
  • Protect the company’s systems, properties, employees and customers
  • Recruit, employ and manage staff
  • Provide marketing information where this is lawful
  • Improve company services and staff training

Information must not be used for personal purposes or for any purpose unrelated to the employee’s duties.

6. Lawful bases

Before processing personal information, the company must identify and document an appropriate lawful basis.

Depending on the circumstances, the company may rely upon:

6.1 Contract

  • Processing may be necessary to enter into or perform a tenancy, property management, employment, contractor or other agreement

6.2 Legal obligation

  • Processing may be necessary to comply with legislation, a court order, regulatory requirement or another binding legal obligation

6.3 Legitimate interests

Processing may be necessary for a legitimate business interest, such as managing properties, preventing fraud, maintaining security, recovering debts or defending legal claims, provided that the interests and rights of the individual have been properly considered.

A legitimate interests assessment should be completed where the processing could have a significant effect on individuals.

6.4 Consent

  • Consent may be used where the individual has been given a genuine and informed choice and can withdraw consent without unfair consequences
  • Consent should not be relied upon where another lawful basis is more appropriate or where the individual has no realistic choice

6.5 Vital interests

Information may be processed where necessary to protect someone’s life, for example during a genuine emergency.

The company must identify its lawful basis before beginning the processing and record that basis in its privacy information and internal records.

7. Electronic storage and employee access

7.1 Secure server

Personal information is primarily stored electronically on a secure company server or within authorised business systems.

The company will use appropriate protections, which may include:

  • Individual employee accounts
  • Strong passwords
  • Multi-factor authentication where available
  • Encryption in transit and, where appropriate, at rest
  • Firewalls, antivirus and security monitoring
  • Regular software and security updates
  • Secure backups
  • Access and activity logs
  • Controlled remote access
  • Procedures for disabling access when employment ends

7.2 Access by employees

Authorised employees may be technically able to access information held on the secure server. This does not give employees unrestricted permission to inspect or use all available information.

Employees may only access personal information:

  • When reasonably necessary for their assigned duties
  • For an authorised company purpose
  • To the minimum extent needed to complete the task
  • In accordance with confidentiality requirements

Using approved devices, systems and login details.

Employees must not access records relating to friends, relatives, colleagues, tenants, landlords or other individuals out of curiosity or for a personal reason.

Where reasonably practicable, the company will use role-based permissions, restricted folders, case allocation or other access controls to limit information according to employees’ responsibilities.

  • Access logs may be reviewed to investigate suspected inappropriate access or disclosure
  • Unauthorised access may be treated as a disciplinary matter and may also constitute a personal data breach or criminal offence

7.3 User accounts and passwords

Employees must:

  • Use only their own login account
  • Keep passwords confidential
  • Use strong and unique passwords
  • Enable multi-factor authentication where required
  • Lock their screen when leaving a device unattended
  • Report suspected account compromise immediately
  • Never share authentication codes or passwords with another person

7.4 Remote working

Personal information may only be accessed remotely through approved systems and devices.

Employees must take reasonable steps to prevent information being seen or overheard by family members, visitors or members of the public.

Company information must not be downloaded to personal computers, personal cloud storage, personal email accounts or unauthorised removable media.

8. Sharing information with third parties

Personal information may be shared with third parties where sharing is necessary, proportionate and lawful.

Recipients may include:

  • Tenant referencing and vetting providers
  • Identity verification and fraud prevention providers
  • Credit reference agencies
  • Landlords, tenants and authorised representatives
  • Guarantors
  • Deposit protection providers
  • Maintenance contractors and property inspectors
  • Inventory and check-in providers
  • Utility companies and local authorities
  • Insurers and insurance brokers
  • Accountants, auditors and professional advisers
  • Solicitors, courts and debt recovery providers
  • Regulatory and redress organisations
  • Government departments and law enforcement agencies
  • IT, hosting, communications and software providers

Payment and banking providers.

Only the minimum information necessary for the relevant purpose will be shared.

Before routinely sharing information, the company must consider:

The purpose and lawful basis for sharing.

  • Whether the recipient is acting as a controller or processor
  • What information is necessary
  • How the information will be transferred securely
  • How long the recipient needs the information
  • Whether a contract or data sharing agreement is required
  • Whether the individual has been properly informed

Where a supplier processes information on behalf of ASJ Estates Preston Ltd, an appropriate written processor contract must be in place. Such contracts must address confidentiality, security, permitted processing and the processor’s obligations.

Routine controller-to-controller sharing should be documented and, where appropriate, governed by a data sharing agreement setting out the parties’ roles, purposes and responsibilities.

Information will not be sold to third parties.

9. Compliance and vetting checks

  • Applicants, tenants, landlords, guarantors, employees or contractors may be asked to provide information for lawful compliance and vetting purposes

Checks may include:

  • Identity verification
  • Address verification
  • Affordability and employment checks
  • Landlord or letting references
  • Credit-related checks
  • Right to Rent checks where required
  • Fraud prevention checks
  • Checks required by insurers or other authorised organisations

Individuals must be given appropriate privacy information explaining the nature and purpose of the checks.

Only information reasonably necessary for the check will be provided to the third-party provider. Results will only be used for the stated purpose or another compatible and lawful purpose.

  • Decisions must not be based on inaccurate, irrelevant or discriminatory information

Where a decision is made solely by automated means and has a legal or similarly significant effect, the company will provide the safeguards and rights required by applicable law, including human review where required.

10. Email, messaging and document handling

Employees must:

  • Check email recipients carefully before sending
  • Use blind carbon copy where appropriate when emailing unrelated recipients
  • Avoid including unnecessary personal information in subject lines
  • Password-protect or securely transfer sensitive documents where appropriate
  • Verify a recipient’s identity before disclosing confidential information
  • Avoid discussing confidential matters over unapproved messaging services
  • Store important communications in the approved company system
  • Report any email or document sent to the wrong person immediately

Personal information must not be copied into personal notes, private messaging accounts or unapproved software.

11. Paper records

Where paper records are used, they must:

  • Be stored in locked cabinets or secure rooms when unattended
  • Not be left visible to visitors or unauthorised people
  • Be removed from printers promptly
  • Be transported in a secure folder or container
  • Not be left in an unattended vehicle unless secured and unavoidable
  • Be destroyed using confidential waste disposal or cross-cut shredding when no longer required

12. Data retention and deletion

The company will maintain a retention schedule covering its main categories of information.

Retention periods will take account of:

The purpose for which the information was collected.

  • Contractual and tenancy requirements
  • Taxation and accounting obligations
  • Property, deposit and regulatory obligations
  • Limitation periods for legal claims
  • Complaints and dispute-resolution requirements
  • Insurance requirements

The sensitivity and volume of the information.

The risks associated with continued retention.

At the end of the applicable retention period, information will be:

  • Securely deleted
  • Confidentially destroyed

Permanently anonymised; or

  • Retained for a longer period only where a documented lawful reason exists

Deletion must include reasonably accessible copies, subject to appropriate backup deletion cycles and any legal preservation requirement.

Information relevant to an anticipated complaint, investigation or legal claim must not be destroyed while the matter remains active.

13. Individual rights

Depending on the circumstances and lawful basis, individuals may have the right to:

  • Be informed about how their information is used
  • Access their personal information
  • Have inaccurate information corrected
  • Have incomplete information completed
  • Request deletion of information
  • Request restriction of processing
  • Object to certain processing
  • Receive eligible information in a portable format
  • Withdraw consent where processing is based on consent
  • Object to direct marketing at any time
  • Request safeguards in relation to solely automated decisions
  • Complain to the Information Commissioner’s Office

These rights are not absolute and may be restricted where an exemption or other lawful reason applies. Individuals must be informed of the rights relevant to the company’s processing activities.

14. Subject access requests

An individual may request confirmation of whether ASJ Estates Preston Ltd holds or uses their personal information, a copy of that information and the supplementary information required by law.

A request does not have to use the words “subject access request” and may be made verbally or in writing. Employees who receive a request for a person’s information must immediately forward it to the person responsible for data protection.

Requests may be submitted by:

Email: support@asj.estates

Post:

Data Protection Request

ASJ Estates Preston Ltd

3 Stanley Street

Preston

PR1 4AT

The requester should provide sufficient information to identify themselves and help locate the relevant records. The company may request proportionate proof of identity where reasonably necessary.

The company will:

  • Record the date the request was received
  • Confirm the requester’s identity where necessary
  • Ask for clarification only where reasonably required
  • Conduct a reasonable and proportionate search
  • Review information for third-party data and applicable exemptions
  • Provide the response securely and in a clear, accessible form
  • Maintain a record of the response and decision-making

A subject access request will normally be answered without undue delay and within one month after the company has received the request and any reasonably required identity or authority information.

The response period may be extended by up to two further months where the request is complex or the individual has made a number of requests. The individual must be told about an extension and the reason for it within the initial one-month period.

Where clarification is reasonably required, the statutory response period may be paused while the company awaits the clarification. The company is required to make a reasonable and proportionate search rather than an unlimited search.

Subject access requests will normally be dealt with free of charge. A reasonable fee may only be charged, or a request refused, where permitted by law, such as where a request is manifestly unfounded or excessive.

Information relating to other people must not be disclosed unless it is reasonable and lawful to do so. Redaction may be used to protect third-party information.

15. Requests to correct, delete, restrict or object

Requests concerning correction, deletion, restriction, objection or another data protection right must be sent immediately to the person responsible for data protection.

The company will:

  • Verify the identity of the requester where appropriate
  • Consider whether the right applies
  • Inform relevant recipients of corrections, deletion or restrictions where required
  • Provide a response within the applicable statutory period
  • Explain any refusal and the right to complain to the ICO

An objection to direct marketing must be acted upon promptly. The right to object to processing for direct marketing is absolute.

16. Personal data breaches

A personal data breach includes accidental or unlawful loss, destruction, alteration, unauthorised disclosure of, or access to personal information.

Examples include:

  • Sending an email to the wrong recipient
  • Losing a laptop, telephone or paper file

An employee accessing records without authority.

  • Disclosing information to an unauthorised landlord, tenant or contractor
  • Malware or ransomware affecting company systems
  • Publishing personal information online accidentally
  • Losing access to information because of system failure
  • Sharing the wrong tenant’s or landlord’s documents

Theft of passwords or login details.

  • All suspected breaches must be reported internally immediately. Employees must not attempt to conceal a mistake

The company will:

  • Contain the incident where possible
  • Record when and how it was discovered
  • Identify the information and people affected
  • Assess the likely risks to individuals
  • Preserve relevant evidence and system logs
  • Take steps to reduce harm
  • Decide whether the ICO must be notified
  • Decide whether affected individuals must be informed
  • Document the incident, decision and remedial action
  • Review whether procedures, training or security controls require improvement

A notifiable personal data breach must be reported to the ICO without undue delay and, where feasible, within 72 hours of the company becoming aware of it. All breaches must be documented, whether or not they meet the threshold for reporting.

Where a breach is likely to create a high risk to individuals, affected individuals will also be informed without undue delay unless a lawful exception applies.

17. International transfers

Personal information will not be transferred outside the United Kingdom unless:

The transfer is necessary and lawful.

The destination is covered by an applicable adequacy regulation; or

Appropriate safeguards, contractual provisions and risk assessments are in place; or

  • Another lawful transfer mechanism applies

The use of cloud, email, referencing or software providers must be reviewed to establish where information is stored and accessed.

18. Staff responsibilities and confidentiality

  • All employees, contractors and authorised users are responsible for protecting personal information

They must:

  • Complete required data protection and security training
  • Follow this policy and related procedures
  • Maintain confidentiality during and after their engagement
  • Access information only for legitimate duties
  • Keep information accurate where they are responsible for entering it
  • Use only approved systems and equipment
  • Report security weaknesses, suspicious activity and breaches
  • Cooperate with subject access requests and investigations
  • Return or securely delete company information when instructed

Employees must not:

  • Disclose personal information without authority
  • Use information for personal gain
  • Search records out of curiosity
  • Photograph company records using a personal device
  • Store documents in personal cloud services
  • Forward work information to a personal email account
  • Share passwords or leave accounts logged in
  • Remove records from company systems without permission
  • Discuss confidential matters in public or with unauthorised people

A breach of this policy may result in disciplinary action, termination of access, dismissal, contractual action or referral to an appropriate authority.

19. Training and monitoring

Data protection training will be provided:

  • During induction
  • At appropriate intervals
  • When relevant laws or procedures change
  • Following an incident or identified weakness

Before an employee is given access to particularly sensitive information.

The company may monitor system access, audit logs and use of company equipment where this is lawful, necessary and proportionate.

20. Data protection by design

Data protection must be considered when:

  • Introducing new software or systems
  • Appointing a new supplier
  • Beginning a new type of vetting or monitoring
  • Collecting a new category of information
  • Installing surveillance equipment
  • Sharing information with a new organisation

Using automated decision-making.

  • Significantly changing how information is used

A data protection impact assessment will be completed before processing likely to result in a high risk to individuals.

21. Complaints

Anyone with concerns about how ASJ Estates Preston Ltd has handled their personal information should contact:

Email: support@asj.estates

Post:

Data Protection Complaint

ASJ Estates Preston Ltd

3 Stanley Street

Preston

PR1 4AT

The company will investigate concerns in accordance with its complaints procedure.

Individuals also have the right to raise a concern with the Information Commissioner’s Office. The company will cooperate with any lawful ICO enquiry or investigation.

22. Policy review

This policy will be reviewed:

  • At least annually
  • Following a significant data breach
  • When relevant legislation or ICO guidance changes
  • When the company introduces significant new systems or processing activities
  • When an audit identifies a weakness