Data Sharing Terms

Passref LTD — Controller-to-Controller Data Sharing Terms

Last updated: 15 June 2026 · Version: 0.1

Drafting note (delete before publishing): Working draft. Fill in every [BRACKETED] item, resolve the drafting notes, and have it reviewed by a data protection specialist before use. These terms govern the sharing of Applicant personal data between you (the Customer) and us as two independent controllers. They form part of, and should be read with, our Terms of Service and our Applicant Privacy Notice. This is not a processor agreement — neither party processes the other's data on its instructions, so the Article 28 processor obligations do not apply.


1. Status of the parties

1.1 In relation to Applicant personal data, Passref LTD ("we", "us") and the Customer ("you") each act as an independent controller, each determining its own purposes and means for the data it processes.

1.2 We are not your processor, and you are not ours. We are not joint controllers.

Drafting note: if any specific, narrow activity is genuinely jointly determined, that part may need an Article 26 joint-controller arrangement instead — but the default and cleaner position for referencing is independent controllers, as set out here.

2. Definitions

Terms defined in the Terms of Service have the same meaning here. In addition:

  • Data Protection Law — the UK GDPR, the Data Protection Act 2018, and other applicable data protection and privacy laws, as amended (including by the Data (Use and Access) Act 2025).
  • Personal Data, Controller, Processor, Personal Data Breach, Data Subject — as defined in Data Protection Law.
  • Shared Data — Applicant personal data shared between the parties under these terms (see the Schedule).

3. Purpose and scope of sharing

3.1 The sharing covers:

(a) the Applicant's contact details that you disclose to us so that we can invite the Applicant to complete their reference (the Applicant provides all other data to us directly); and

(b) the Reference and Recommendation that we disclose to you for your letting decision.

3.2 Each party will use the Shared Data only for the purposes set out in the Schedule, and not in any way incompatible with those purposes.

3.3 You will share with us only the personal data that is necessary for the referencing requested.

4. Compliance with Data Protection Law

Each party will comply with its own obligations under Data Protection Law in respect of its processing of the Shared Data.

5. Lawful basis and transparency

5.1 Each party is responsible for ensuring it has a valid lawful basis for its own processing of the Shared Data.

5.2 You confirm that you have a lawful basis to share the Applicant's contact details with us, and that you have made the Applicant aware — including through your own privacy information — that you use a referencing provider and will pass their contact details to us.

5.3 Because Applicants submit their information to us directly, we will provide our Applicant Privacy Notice to the Applicant at the point we collect their data, and we are responsible for the transparency information relating to our own processing.

Drafting note: 5.2 mirrors clauses 7.2 and 7.3 of the Terms of Service — keep them aligned if either changes.

6. Data quality

Each party will take reasonable steps to ensure the Shared Data it provides is accurate, and will inform the other without undue delay if it becomes aware that Shared Data it has provided is inaccurate or out of date.

7. Security

Each party will implement appropriate technical and organisational measures to protect the Shared Data against unauthorised or unlawful processing and accidental loss, destruction, or damage, taking into account the state of the art, the costs of implementation, and the risks involved. Our measures include encryption of Shared Data in transit and at rest, and role-based access controls that limit access to authorised personnel.

8. Personal data breaches

8.1 If a party becomes aware of a Personal Data Breach affecting the Shared Data, it will notify the other party without undue delay and provide enough information to allow the other party to meet its own obligations.

8.2 Each party is responsible for making its own notifications to the Information Commissioner's Office (ICO) and to affected Data Subjects where required by Data Protection Law, and the parties will cooperate reasonably in relation to any such breach.

9. Data subjects' rights

9.1 Each party is responsible for handling requests from Data Subjects that relate to its own processing.

9.2 If a party receives a request that relates to the other party's processing, it will promptly inform the requester and/or pass the request on as appropriate, and the parties will give each other reasonable assistance in responding.

Drafting note: this is the mechanism for the scenario where an Applicant asks the agent for information you hold (or vice versa). Make sure your internal process can route these.

10. Retention and deletion

10.1 Each party will retain the Shared Data only as long as necessary for its own purposes and in line with its own retention policy and Data Protection Law.

10.2 Because each party is an independent controller, neither is required to delete data merely on the other's instruction; each will deal with retained data in accordance with its own legal obligations.

11. Onward sharing and processors

11.1 Each party may engage its own processors to handle the Shared Data, provided it does so under a written contract that meets the requirements of Data Protection Law.

11.2 Neither party will disclose the Shared Data to any other third party except as permitted by these terms, as described in the relevant privacy information, or as required by law.

12. International transfers

Each party is responsible for ensuring that any transfer of the Shared Data outside the UK is subject to an appropriate safeguard or other lawful transfer mechanism under Data Protection Law.

13. Records and cooperation

Each party will keep records of its processing of the Shared Data as required by Data Protection Law, and will provide the other with reasonable information and cooperation needed to demonstrate compliance with these terms.

Drafting note: this is intentionally proportionate cooperation between controllers, not the intrusive audit right you'd impose on a processor.

14. Liability and indemnity

14.1 Each party is responsible for its own compliance with Data Protection Law and for any regulatory fines imposed on it for its own breaches.

14.2 You will indemnify us against losses, claims, and costs arising from your breach of these terms or of Data Protection Law in respect of the Shared Data, including any failure to provide the Applicant Privacy Notice or to have a lawful basis under clause 5.

14.3 The liability provisions in the Terms of Service otherwise apply.

Drafting note: check this dovetails with clauses 16 and 17 of the Terms of Service so liability isn't double-counted or contradicted.

15. Term and termination

15.1 These terms take effect alongside the Terms of Service and continue while you use the Services.

15.2 On termination, each party will continue to comply with these terms and Data Protection Law in respect of any Shared Data it retains.

15.3 Clauses intended to survive (including 8, 9, 10, 12, 13, and 14) continue after termination.

16. Review

The parties will review these terms periodically and update them as needed to reflect changes in the Services or Data Protection Law.

17. Relationship to the Terms of Service

These Data Sharing Terms form part of the Terms of Service. If there is a conflict on a data protection matter, these terms prevail.


Schedule — details of the data sharing

Drafting note: complete this to give the arrangement concrete detail — the ICO's Data Sharing Code expects this kind of record.

  • Categories of Data Subjects: prospective tenants, guarantors, and other named applicants.
  • Personal data shared to us by you: the Applicant's email address / contact details, used to invite the Applicant to complete their reference. The Applicant provides all other personal data to us directly.
  • Categories of data shared to you by us: the Applicant's full name, the identity-verification result, the Right to Rent confirmation result, the income and affordability assessment, the financial history the Applicant declares (CCJs, IVAs, bankruptcies), CCJ / public-record findings, and our overall reference outcome and recommendation.
  • Purpose of sharing: tenant referencing, identity verification, Right to Rent confirmation, and your letting decision.
  • Lawful basis (you): legitimate interests (you are responsible for confirming and documenting your own basis).
  • Lawful basis (us): legitimate interests (confirmed via our signed-off Legitimate Interests Assessment).
  • Retention: we retain Shared Data for up to 6 years after the reference, in line with our Privacy Notice; you retain Shared Data in line with your own retention policy and legal obligations.
  • Special category data: none intended.