Privacy

Is your business premises lease agreement GDPR-compliant?

A lease agreement for commercial premises is GDPR-compliant as soon as you transparently record therein which personal data you process, on what legal basis, and how long you retain it. As a landlord, you almost always process personal data: for drafting and executing...

Published on June 13, 2019 by MKBjuristen.nl
Request a free quote Call 085 25000 44

MKB Juristen drafts custom legal documents

It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.

  • Custom contracts, terms and conditions, and legal documents
  • Budget-friendly and clear about the costs upfront
  • Request a free consultation or a no-obligation quote
Free consultation Request a free quote

A lease agreement for commercial premises is GDPR-compliant as soon as you transparently record which personal data you process, on what legal basis, and how long you retain it. As a landlord, you almost always process personal data: for drafting and executing the contract, for screening prospective tenants, and sometimes for granting access via a personal badge. Many standard model contracts fail to take this sufficiently into account, putting you at risk of complaints, reputational damage, and enforcement by the Dutch Data Protection Authority.

What does “GDPR-compliant” mean for a lease agreement?

Being GDPR-compliant means that the way you process personal data in and around the rental agreement complies with the core principles of the General Data Protection Regulation (GDPR). It is not about a stamp or certificate, but about demonstrable choices: for each processing activity, you must be able to explain why you need the data, what you base this on, and how you secure and store it.

Personal data is any data relating to an identifiable person: name, email address, telephone number, a photograph, and in many cases, financial data as well. As soon as you record, organize, or store this data, processing takes place and the GDPR rules apply. Please note: in practice, you also process personal data when renting to a company, for example, of the authorized director, the contact person, or employees with an access pass.

Why does a landlord process personal data?

When renting out commercial premises, the use of personal data is unavoidable. You need names, contact details, and often financial information to draft and execute the lease agreement. In addition, you sometimes process data for:

  • Screening of prospective tenants, for example, a check on creditworthiness or payment history.
  • Access control, such as a personal badge with name and photo to enter the premises.
  • Management and communication during the term of the lease, such as maintenance notifications and invoicing.

Every processing activity falls under the GDPR. This means that for each processing activity, you must be able to explain why you need the data and on what legal basis you rely.

The three core principles for landlords

1. A valid basis

You may only process personal data if you have a legal basis for doing so. For entering into and executing the lease agreement, you generally rely on the legal basis of “necessary for the performance of a contract”. For security and access control, a legitimate interest serve as a legal basis, provided that interest outweighs the privacy of the data subject. Consent is by no means always required and is, moreover, cumbersome: the tenant can withdraw consent at any time.

2. Data minimization

Only request what you truly need. For a badge, a name and photo are justifiable, but sensitive data such as religion, health, or sexual orientation do not belong there. In fact, requesting someone's religion, for example, can easily create the appearance of discrimination. Limit yourself to the necessary data.

3. Transparency

The tenant must know in advance and free of charge what you do with their data. Are you conducting a screening? Then clearly explain which data you are requesting, why, how long you retain it, and what happens to it afterwards. In practice, you include a privacy clause in the rental agreement for this purpose and refer to a privacy statement.

Practical example: screening and access badges

Suppose you rent out a multi-tenant office building and want to screen new tenants for their payment history and provide them with a photo access badge. For the screening, you rely on your legitimate interest to prevent non-payment, but you only request what is necessary for this purpose and inform the candidate in advance that you are performing this check. You do not retain the badge photo for longer than the tenant has access. If, in addition, you request health data or a copy of the passport containing the BSN, you are almost certainly going too far: that data is not necessary, and as a landlord, you are generally not allowed to simply process the BSN.

Do you always need permission from the tenant?

No. A common misconception is that you must ask for consent for every processing activity. For most processing activities related to a lease agreement, you actually rely on the legal bases of “performance of the contract” or “legitimate interest.” This is more practical, because consent is subject to strict requirements and can always be withdrawn.

However, a number of obligations apply, regardless of the legal basis. For example, as a data controller, you must maintain a processing register stating which data you process, for what purpose, which retention periods you apply, and which security measures you have taken.

Where do standard model contracts go wrong?

In practice, we observe that lease agreements for commercial premises are rarely properly aligned with the GDPR. Many landlords still use older standard contracts for retail or office space that were drafted before the GDPR came into force. These templates typically contain no privacy clause or an outdated one and are effectively unusable in this respect.

Are you using an older model? Then have the privacy provisions checked and supplemented. This is often a minor adjustment that prevents major problems. Our legal experts would be happy to review the commercial lease agreement for you.

What other GDPR obligations do you have as a landlord?

In addition to legal basis, data minimization, and transparency, you have further obligations:

  • Security. Take appropriate technical and organizational measures. Consider good system access security, not leaving files containing personal data lying around, and periodically assessing whether your security is still adequate.
  • Data Breach Notification Obligation. In the event of a data breach posing a risk to data subjects, you must report this to the Dutch Data Protection Authority, in principle without undue delay and no later than 72 hours after you discover the breach. A misaddressed email or a lost laptop can already constitute a data breach.
  • Data Processing Agreement. Are you engaging an external party to process data on your behalf (for example, a property manager or software supplier)? Then record the agreements in a data processing agreement.
  • Rights of data subjects. Tenants can view, correct, or delete their data. Ensure that you can handle such a request in a timely manner.

What are the risks if you don't have it in order?

The GDPR grants the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) strong enforcement powers. In addition to a warning or an order subject to a penalty payment, the supervisory authority can impose a fine . However, for an SME landlord, the greatest risk rarely lies in a direct mega-fine, but rather in the combination of consequences: a complaint from a (prospective) tenant to the AP, a request for access or deletion that cannot be handled, reputational damage, and the time and costs involved in recovery. Those who properly arrange privacy provisions in advance usually prevent these problems with limited effort.

Step-by-step plan: make your rental agreement GDPR-compliant

  1. Map out which personal data you process and for what purpose.
  2. Determine the correct legal basis for each processing activity and delete data that you do not need.
  3. Include a clear privacy clause in the lease agreement and refer to a privacy statement.
  4. Establish retention periods and set up a processing register.
  5. Arrange a data processing agreement with parties that process data on your behalf.
  6. Check your security measures and your process for reporting data breaches.

Frequently asked questions about a GDPR-compliant lease agreement

Do I need a privacy statement as a landlord?

Yes. Because you process personal data of (prospective) tenants, you must inform them transparently about what you do with that data. A privacy statement is the standard means for this, in addition to a privacy clause in the rental agreement itself.

Is the tenant's permission always required?

No. For the drafting and execution of the lease agreement and for security, you can generally rely on the grounds of “performance of the contract” or “legitimate interest”. Consent is then not required and often not desirable either, because it can be withdrawn.

Am I allowed to screen a prospective tenant for creditworthiness?

That is possible, provided you limit yourself to what is necessary to prevent non-payment and inform the candidate in advance about the screening. Do not request more than necessary and do not retain the outcome longer than necessary. Sensitive data or a BSN do not fall under this.

What information am I allowed to put on an access badge?

Limit yourself to what is necessary for security, such as name and photo. You may not include sensitive data, such as religion or health, on a badge.

What should I do in the event of a data breach?

Assess whether the breach poses a risk to data subjects. If so, you must in principle report it to the Dutch Data Protection Authority within 72 hours of discovery and, if necessary, also inform the data subjects. Document the breach and your assessment internally.

How long am I allowed to retain tenant data?

No longer than necessary for the purpose for which you collected them. Statutory retention periods apply to some data, for example based on tax obligations. Establish a substantiated retention period for each category in your processing register.

Does the GDPR also apply if I rent to a company?

Yes. Even when renting to a legal entity, you almost always process personal data of natural persons, such as the director, a contact person, or employees with access to the premises. These processing activities fall under the GDPR, regardless of whether the tenant is a business itself.

Have your lease agreement reviewed by MKB Juristen

Are you unsure whether your commercial lease agreement complies with the GDPR, or are you still using an older standard contract? Our legal experts help you bring your privacy provisions into order and prevent bigger problems. View our expertise in privacy legislation or arrange immediate legal assistance.

Schedule a no-obligation intake and let us review your contract.

Please note: an article provides general information, but your legal situation may turn out differently.

A contract, conflict, or legal risk must always be assessed based on the facts, documents, evidentiary position, and interests. Are you in doubt? Have your situation assessed before you act.

Legal question regarding this article?

A blog provides explanation, but your situation often requires a concrete legal choice. MKB Juristen helps entrepreneurs with contracts, terms and conditions, GDPR documents, employment documents, disputes, and customized legal solutions.

Drafting, reviewing, and amending contracts
Legal Assistance Help with conflicts and disputes.
Expertise Specialist legal experts and lawyers.
Fixed rates. Clarity on costs in advance.

Latest articles

July 24, 2026

Having general terms and conditions drafted for the website: costs and process

Having general terms and conditions for the website drafted by a lawyer: what does it cost, how does the process work, and when should you choose custom-made...

July 24, 2026

Having a non-compete clause drafted: costs and process

Having a non-compete clause drafted by a lawyer: what does it cost, how does the process work, and when to choose a custom draft over a template.

July 24, 2026

Checking contracts: step-by-step plan for SME entrepreneurs

Checking or reviewing a contract before signing: step-by-step plan, red flags, checklist, and when you need a lawyer.

July 24, 2026

Having general terms and conditions drafted for contractors: costs and process

Having general terms and conditions for contractors drafted by a lawyer: what does it cost, how does the process work, and when do you choose custom work over...

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation