Data Protection in Real Estate Management

8 min readLast updated By Marc Grob

Introduction

Real estate managers process personal data of high sensitivity in every mandate: credit reports and debt-collection register extracts of prospective tenants, salary statements, family constellations, possibly residency permits, then later rent-payment histories, defect lists, correspondence with authorities and images from building surveillance. With the revised Federal Act on Data Protection (DSG), in force since 1 September 2023, the requirements for property managers, janitor companies and cooperative administrations have become significantly more concrete. At the same time, Swiss tenancy law (Art. 253 ff. OR), civil-law personality protection (Art. 28 ZGB) and data protection continuously intersect.

This article provides a practice-oriented overview. It covers:

  • permissible data collection in the application and tenancy phases (Art. 6 DSG, proportionality);
  • credit and debt-collection enquiries, ZEK/CRIF data and the discrimination risk;
  • video surveillance in stairwells, lifts, underground parking and entrances (Art. 28 ZGB, FDPIC guidance);
  • processing on behalf with external service providers (concierge, cleaning, property-management software);
  • information duties towards tenants (Art. 19 DSG);
  • retention and deletion after the end of tenancy.

The target audience comprises managing directors of property-management firms, portfolio managers at institutional owners and boards of housing cooperatives that want to set up compliant processes without slowing down day-to-day operations.

Legal framework for property managers

Private real estate managers are controllers within the meaning of Art. 5 lit. j DSG. They determine the purpose and means of processing, usually on behalf of the owner, who in turn remains a controller. This results either in a processing-on-behalf relationship under Art. 9 DSG (where the owner narrowly prescribes how data is to be processed) or in joint controllership. Both constellations require contractual arrangements; the standard contracts of SVIT or HEV often fall short and should be supplemented with data-protection clauses.

Public-sector property administrations (cantonal real-estate offices, municipal housing providers) are additionally subject to the relevant cantonal information and data-protection act (IDG ZH, KDSG BE, IDG BS, etc.). Housing cooperatives are private-law controllers and fall under the DSG.

Cross-references exist to the Code of Obligations (Art. 253-274g OR on tenancy, in particular the duty of proper record-keeping over the tenancy), to the cantonal conciliation authorities (Art. 200 ZPO in conjunction with cantonal law), to the Anti-Money-Laundering Act for certain brokerage activities and to the Unfair Competition Act (UWG) where, for example, address data is shared for marketing purposes.

Cross-border ownership structures (foreign pension funds, German real-estate funds) may additionally trigger the EU GDPR as soon as data flows to entities in the EU. An EU representative under Art. 27 GDPR then has to be considered.

Data collection from prospective tenants

The most delicate phase is candidate screening. Prospective tenants fill in application forms that frequently go far beyond what is proportionate. The yardstick is Art. 6(2) DSG (proportionality) and the purpose of "contract conclusion and performance" under Art. 31(2)(a) DSG. The consequence: in the first step, before the selection decision is taken, only data strictly necessary to assess ability to pay and need for a rental deposit may be collected.

A two-tier approach works well in practice. Stage 1 (all candidates): name, address, e-mail, phone number, number of moving-in persons, desired move-in date, broad professional category. Stage 2 (only short-listed candidates, against consent): salary statements or tax documents, recent debt-collection extract (no older than three months) and a reference from the current property manager.

Generally not permissible are: religion, marital status with relationship details, political views, photograph, nationality in a differentiated form, family planning, prior pregnancies, criminal records without specific relevance. Such data is partly sensitive within the meaning of Art. 5 lit. c DSG, and its processing requires a special justification that almost never exists in a tenancy context. Inadmissible fields on application forms quickly trigger complaints to the FDPIC and reputational damage in local media.

Equally important is the retention of application files of non-selected candidates: at the latest three months after conclusion of the tenancy these must be destroyed unless concrete legal disputes are looming.

Credit and debt-collection enquiries

Obtaining a debt-collection extract under Art. 8a SchKG is common practice and permissible under the DSG provided that the person submits it themselves or expressly consents. Credit services such as CRIF, Intrum, Deltavista or Creditreform additionally deliver aggregated scores. Such a credit enquiry is based on the landlord's legitimate interest (Art. 31(1) DSG), but it is proportionate only where (1) the prospective tenant has been transparently informed in advance, (2) the score is not the sole basis for the decision, and (3) the source of the information is documented at the conclusion of the tenancy.

Automated individual decisions without human assessment fall under Art. 21 DSG: if an application is rejected solely on the basis of an algorithmic score, the person must be informed and given an opportunity to state their position. In practice we recommend using score values only as one element alongside income, history and personal impression, and to enshrine a four-eyes principle in the internal process.

Discrimination risks are real. If selection criteria indirectly latch on to nationality, religion or family status, not only data protection but also personality rights (Art. 28 ZGB) and, in publicly owned property, the prohibition of discrimination (Art. 8 of the Federal Constitution) may be triggered. A documented selection matrix with objective criteria (solvency, household size matching apartment size, contractual reliability) protects both applicants and the property manager.

Video surveillance on the premises

Cameras in entrances, underground garages, lifts, refuse rooms and outdoor areas are standard in many buildings. From a data-protection viewpoint this is the processing of particularly intrusive personal data, because tenants, visitors and suppliers can hardly avoid being captured. The yardstick is again Art. 6 DSG (proportionality, purpose limitation) and the FDPIC "Guidance on video surveillance by private parties" in its current version.

The following review steps must be documented before any installation:

  1. Purpose (e.g. protection against vandalism following several concrete incidents, safety in the underground garage), a vague "feeling of safety" is not enough;
  2. Less intrusive means (better lighting, badge access control, organisational measures) have been considered and found insufficient;
  3. A camera plan with viewing angles that omits apartment doors, interior rooms, individual mailboxes and adjacent public walkways;
  4. Information signs stating purpose, controller and contact details at the start of each monitored area (Art. 19 DSG);
  5. Retention period of no more than 72 hours as a rule, with an auditable deletion routine;
  6. Access permissions strictly for defined persons (manager, police on the basis of an order);
  7. Information of the condominium owners' meeting or the tenant community.

For particularly intrusive surveillance, such as audio recording, facial recognition or permanent recording in semi-public interior spaces, a data-protection impact assessment under Art. 22 DSG must be carried out, and where high residual risk remains, submitted to the FDPIC for consultation.

Processors and the service-provider chain

A modern property manager works with an entire chain of external service providers: property-management software (typically cloud-based), debt-collection partners, external janitors, cleaning firms, concierge services, locking-system vendors, heating-cost statement providers and increasingly AI-supported applicant tools. Each such service provider that processes personal data on instructions is a processor within the meaning of Art. 9 DSG.

A data-processing agreement (DPA) is required, containing at least: a description of the processing, the data categories, security measures under Art. 8 DSG, sub-processor rules, support duties for data-subject rights and breach handling, deletion and return obligations at the end of the contract, and audit rights. For providers established or processing data outside Switzerland and the EU, a transfer assessment under Art. 16 et seq. DSG is additionally needed, in practice with standard contractual clauses plus a transfer-impact assessment.

Often underestimated: janitor firms that perform apartment hand-overs see very private spheres of life. Cleaning firms have access to rooms containing correspondence and documents. These individuals must be bound in writing to confidentiality (Art. 4 DSV), and the property manager must be able to demonstrate in an audit who accessed which premises when. With electronic locking systems the logging of access events is itself relevant under data-protection law and must be backed by clear retention periods (typically 30 to 90 days).

Information duties, access and deletion

Art. 19 DSG requires appropriate information to all persons whose data is processed. In real-estate management this means concretely: an understandable privacy notice on the property manager's website, an additional notice in the application form for prospective tenants, and a third notice in the tenancy agreement or as an attachment to it describing the ongoing processing during the tenancy (heating- and ancillary-cost statements, repairs, insurance cases, dunning, conciliation and court proceedings).

Access requests under Art. 25 DSG must be answered within 30 days free of charge. In disputes, such as those about defect notifications or termination grounds, tenants are increasingly using this right strategically. The property manager must be able to retrieve all data stored about a person across the property-management system, e-mail archive, paper file and video recordings, and to provide it in a readable form. Grounds for refusal or restriction (Art. 26 DSG, e.g. overriding third-party interests) must be explicitly justified.

After the end of the tenancy, retention obligations kick in: accounting documents must be retained for ten years under Art. 958f OR; security deposit documents until release; correspondence typically as long as claims from the tenancy can be enforced (generally ten years under Art. 127 OR). Thereafter, the data must be deleted or reliably anonymised. A documented deletion routine including deletion logs is mandatory, both to comply with Art. 6(4) DSG and to defend against later claims.

How SIDD supports you

SIDD accompanies real estate managers, institutional owners and housing cooperatives throughout their data-protection practice: from initial review of existing application forms, tenancy agreements and house rules, through the design of a record of processing activities under Art. 12 DSG, to handling concrete access requests or data breaches. We provide external data-protection advisers under Art. 10 DSG, audit your video surveillance against FDPIC guidance and support you in negotiating DPAs with your property-management software vendors.

Concretely we combine three service packages: an external data-protection adviser for Switzerland as a single point of contact internally and externally, a data-protection workshop for your management teams in which application processes, video surveillance and access-request handling are trained in a hands-on way, and where needed a penetration test of your property-management software. Write to us via the contact form or request a specific quote for your real-estate portfolio.

Need help putting this into practice? SIDD operates the matching service.
See service →

Data Protection in Real Estate Management

INSIGHT

Data Protection
24 May 2026
Marc Grob
Data protection in property management: data of rental applicants, credit and debt enforcement checks, video surveillance and service providers.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.