CeMAP 25

Data Protection and Customer Confidentiality

Mortgage advisers handle a lot of personal information.

For example, a customer may provide details about:

  • income
  • debts
  • savings
  • employment
  • family circumstances
  • bank accounts
  • credit history

In addition, they may provide documents such as payslips and bank statements.

Therefore, this information needs to be handled carefully.

The basic principle is simple:

Use customer information properly, keep it secure and do not share it without a valid reason.


Why Does Data Protection Matter?

Customers need to provide detailed information when applying for a mortgage.

However, that information could cause harm if it falls into the wrong hands.

For example, stolen information could be used for:

  • identity theft
  • fraud
  • scams

Therefore, financial firms need strong controls.

At the same time, customers have legal rights over their personal information.


The Main Data Protection Laws

Two important parts of the UK framework are:

UK GDPR

and:

Data Protection Act 2018

Together, they provide rules for handling personal information.

Therefore, mortgage firms need to understand how these rules affect their work.


What Is UK GDPR?

GDPR originally came from European Union law.

However, the UK now has its own version.

This is known as the:

UK General Data Protection Regulation

or:

UK GDPR

It sets important rules for how organisations use personal data.


What Is the Data Protection Act 2018?

The Data Protection Act 2018 works alongside UK GDPR.

It provides additional UK data protection rules.

Therefore, the two are closely connected.

For CeMAP, remember:

UK GDPR + Data Protection Act 2018 = Main UK data protection framework


What Is Personal Data?

Personal data is information relating to an identified or identifiable living person.

For example:

  • name
  • home address
  • email address
  • phone number
  • date of birth
  • account details

However, personal data is wider than basic contact details.

For example, financial information can also be personal data.


Mortgage Applications Contain Large Amounts of Personal Data

A mortgage application may contain:

  • income
  • spending
  • debts
  • dependants
  • employment details
  • credit history
  • property information
  • bank details

Therefore, mortgage advisers regularly handle sensitive and private information.

As a result, data protection is part of everyday mortgage work.


What Is Processing?

Under data protection law, processing has a wide meaning.

It includes activities such as:

  • collecting data
  • recording it
  • storing it
  • changing it
  • using it
  • sharing it
  • deleting it

Therefore, almost anything a mortgage firm does with customer data can count as processing.


A Simple Processing Example

Imagine a customer emails three months of bank statements to their adviser.

The adviser:

Receives them

Saves them

Reviews them

Sends relevant information to the lender

Each of these steps involves processing personal data.

Therefore, data protection applies throughout the process.


The Data Protection Principles

UK GDPR contains important principles for handling personal data.

These can be simplified into seven areas:

  1. Lawfulness, fairness and transparency
  2. Purpose limitation
  3. Data minimisation
  4. Accuracy
  5. Storage limitation
  6. Integrity and confidentiality
  7. Accountability

These principles sit at the heart of data protection.

Let’s look at each one.


1. Lawfulness, Fairness and Transparency

Personal data should be used:

  • lawfully
  • fairly
  • openly

Therefore, customers should not be misled about how their information will be used.

For example, a firm should explain relevant data use through suitable privacy information.

As a result:

Customers should understand what is happening to their data.


2. Purpose Limitation

Data should be collected for clear and proper purposes.

Then, it should not normally be used for an unrelated purpose without a valid basis.

For example, a customer may provide information for a mortgage application.

That does not automatically mean the firm can use the information for any other purpose it chooses.

Therefore:

Collect data for a reason and use it properly.


3. Data Minimisation

Firms should collect information that is:

  • relevant
  • necessary
  • appropriate

Therefore, they should not collect personal information simply because it might be interesting.

For example, if information has no real purpose in the mortgage process, the adviser should consider why it is being requested.

In simple terms:

Only collect what you need.


4. Accuracy

Personal data should be accurate.

Where needed, it should also be kept up to date.

For example, a customer may:

  • change address
  • change employer
  • receive a salary increase
  • repay a debt

Therefore, incorrect information should be corrected when appropriate.

This is particularly important in mortgage applications.


5. Storage Limitation

Personal information should not be kept for longer than necessary.

However, this does not mean firms should delete mortgage records immediately after completion.

Financial firms may need to keep records for:

  • regulatory reasons
  • legal reasons
  • complaint handling
  • business needs

Therefore, firms should have proper retention policies.


6. Integrity and Confidentiality

Personal information should be kept secure.

Therefore, firms need to protect it against:

  • unauthorised access
  • accidental loss
  • theft
  • damage
  • improper disclosure

This includes both digital and paper records.

As a result:

Security is a key part of data protection.


7. Accountability

Firms should be able to show that they comply with data protection requirements.

Therefore, it is not enough simply to say:

We take privacy seriously.

Instead, firms may need suitable:

  • policies
  • records
  • training
  • security controls

In simple terms:

Follow the rules and be able to show that you followed them.


A Simple Memory Aid

Remember:

Lawful

Purpose

Minimum

Accurate

Not Forever

Secure

Accountable

This gives you the basic idea behind the seven principles.


A Lawful Basis Is Needed

A firm needs a lawful basis for processing personal data.

There are several possible lawful bases under UK GDPR.

These include:

  • consent
  • contract
  • legal obligation
  • vital interests
  • public task
  • legitimate interests

However, not every basis will apply to every situation.

Therefore, firms should identify the correct basis for the processing they carry out.


Consent Is Not Always Required

A common misunderstanding is:

A company always needs consent to use personal data.

That is not correct.

Consent is only one possible lawful basis.

For example, some information may need to be processed because it is necessary for a contract or legal requirement.

Therefore:

Lawful processing does not always mean consent.


If Consent Is Used

Where consent is the lawful basis, it needs to meet proper standards.

Broadly, it should be:

  • freely given
  • specific
  • informed
  • clear

In addition, the person should be able to withdraw consent.

Therefore, hiding consent inside confusing wording would not be a good approach.


Special Category Data

Some personal information receives extra protection.

This is known as special category data.

It can include information about:

  • health
  • racial or ethnic origin
  • religious beliefs
  • political opinions
  • trade union membership
  • genetic data
  • biometric data used for identification
  • sex life
  • sexual orientation

Therefore, firms need additional care when handling this information.


A Mortgage Example

Imagine a customer explains that a serious health condition affects their income.

That health information may be relevant to the advice process.

However, it is also special category data.

Therefore, the firm needs to handle it appropriately and securely.


Customer Confidentiality

Data protection and confidentiality are closely linked.

However, they are not exactly the same thing.

Data protection is based on legal rules about personal data.

Meanwhile, confidentiality is the wider duty to protect private customer information.

Therefore:

Customer information should not be discussed or shared casually.


A Confidentiality Example

Imagine an adviser sees a customer in a café.

A friend asks:

Isn’t that one of your mortgage clients? How much are they borrowing?

The adviser should not discuss the customer’s financial affairs.

Therefore, confidentiality continues outside the office.


Sharing Information Within a Firm

Customer information may sometimes need to be shared with colleagues.

For example:

  • compliance staff
  • case managers
  • administrators

However, access should have a proper business reason.

Therefore:

Working for the same company does not mean everyone needs access to everything.

Information should be shared appropriately.


Sharing Information With Lenders

Mortgage advisers often need to send customer information to lenders.

For example:

  • income details
  • employment information
  • credit commitments
  • property information

This may be necessary to arrange the mortgage.

However, the information still needs to be handled properly.

Therefore, secure processes should be used.


Sharing Information With Third Parties

Other third parties may also become involved.

For example:

  • solicitors
  • valuers
  • insurers
  • mortgage networks
  • service providers

Therefore, firms need to consider what information is being shared and why.

The customer should also receive suitable privacy information.


Do Not Send Information to the Wrong Person

A simple mistake can become a serious data problem.

For example, an adviser may accidentally email:

Customer A’s bank statements

to:

Customer B

That could expose:

  • name
  • address
  • account details
  • spending
  • income

Therefore, advisers should check recipients carefully before sending information.


What Is a Personal Data Breach?

A personal data breach is a security problem involving personal data.

For example:

  • information is lost
  • information is stolen
  • the wrong person receives it
  • someone gains access without permission
  • information is changed improperly

Therefore, a breach does not always involve hackers.

Human error can also cause one.


A Simple Data Breach Example

Imagine an adviser leaves a customer file on a train.

The file contains:

  • payslips
  • bank statements
  • address details
  • mortgage information

That is a serious security problem.

Therefore, the firm should follow its data-breach procedure.


Reporting Data Breaches

Some personal data breaches need to be reported to the Information Commissioner’s Office, or ICO.

Where the reporting requirement applies, the firm should normally report the breach without undue delay and, where feasible, within:

72 hours of becoming aware of it

Therefore, firms need processes that allow problems to be raised quickly.


Not Every Breach Must Be Reported to the ICO

The reporting requirement depends on the level of risk to people’s rights and freedoms.

Therefore, firms need to assess what happened.

However, advisers should not make that decision alone unless it is part of their role.

Instead:

Report the incident internally straight away and follow the firm’s procedure.

This allows the correct people to assess it.


Customers May Also Need to Be Told

In more serious cases, affected customers may also need to be informed.

For example, this may happen where the breach creates a high risk to their rights and freedoms.

Therefore, data-breach handling can involve both:

  • the ICO
  • affected customers

The exact response depends on the situation.


What Is the ICO?

The Information Commissioner’s Office is the UK’s independent regulator for information rights.

It oversees areas including data protection.

Therefore:

FCA → Financial regulation

while:

ICO → Data protection and information rights

This is a useful distinction.


Customer Data Rights

UK GDPR gives people important rights over their personal information.

Depending on the circumstances, these include:

  • right to be informed
  • right of access
  • right to rectification
  • right to erasure
  • right to restrict processing
  • right to data portability
  • right to object
  • rights relating to automated decisions

Therefore, personal data does not simply become the firm’s property once it is collected.


The Right of Access

Customers can ask for access to personal information held about them.

This is often known as a:

Subject Access Request

or:

SAR

Therefore, a customer may ask:

What information do you hold about me?

The firm then needs to respond according to data protection rules.


Subject Access Requests

A SAR does not usually require special legal wording.

For example, a customer might simply say:

Please send me the personal information you hold about me.

That may be enough.

Therefore, staff should recognise possible subject access requests and follow the firm’s process.


How Long Does a Firm Have to Respond?

In many cases, a firm should respond to a subject access request within:

One month

However, some situations allow extra time.

Therefore, requests should be passed to the correct person promptly.


The Right to Rectification

If personal information is wrong, the customer may have the right to have it corrected.

For example:

Incorrect address

Customer tells firm

Firm corrects the information where appropriate

Therefore, accuracy is both a data protection principle and a customer right.


The Right to Erasure

You may hear this called the:

Right to be Forgotten

However, it is not an absolute right.

For example, a mortgage customer cannot always demand that every record is deleted immediately.

The firm may need to retain information because of:

  • legal requirements
  • regulatory requirements
  • possible legal claims

Therefore:

The right to erasure has limits.


Data Security

Firms need suitable security for customer information.

This may include:

  • passwords
  • access controls
  • secure email
  • encryption
  • locked storage
  • staff training

Therefore, security is both a technology issue and a people issue.


Passwords and Access

Employees should not casually share passwords.

Likewise, systems should limit access to people who need the information.

Therefore:

Access should be controlled.

This helps reduce both accidental and deliberate misuse.


Working From Home

Remote working can create extra risks.

For example:

  • family members may see documents
  • screens may be visible
  • paperwork may be left unsecured
  • devices may be lost

Therefore, customer confidentiality still applies outside the office.


A Home-Working Example

Imagine an adviser works from the kitchen table.

A customer file is left open.

Later, visitors arrive.

Even if nobody deliberately reads it, the information has not been protected properly.

Therefore, paper and digital records should be secured.


Public Places

Advisers should also be careful when working in:

  • cafés
  • trains
  • airports
  • shared workspaces

For example, discussing a customer’s income loudly on a train could reveal private information.

Therefore:

Confidentiality applies to conversations as well as documents.


Identity Checks

Before sharing information, the firm may need to confirm who it is dealing with.

For example, someone may phone and claim to be the customer.

Therefore, appropriate security questions or identification checks may be needed.

This helps prevent unauthorised disclosure.


Data Protection and Financial Crime

Sometimes a firm may need to use or share information because of legal duties linked to financial crime.

For example:

  • money laundering checks
  • fraud prevention
  • legal reporting requirements

Therefore, customer confidentiality does not mean information can never be shared.

Instead, information should be shared only where there is a proper reason.


Marketing and Personal Data

Data protection rules can also affect marketing.

For example, a firm should not assume that receiving someone’s details for a mortgage application automatically allows every form of future marketing.

Therefore, firms need to consider the rules that apply to marketing communications.

As a result:

Mortgage application data should not simply become unrestricted marketing data.


Keep Data Only as Long as Needed

Firms should have rules for how long different records are kept.

Therefore:

Collect

Use

Store securely

Retain where required

Delete or dispose of securely when appropriate

This is the basic data life cycle.


Secure Disposal

Deleting information also needs care.

For example, paper records containing customer data should not simply be placed in an ordinary bin.

Likewise, old electronic devices may contain stored information.

Therefore, secure disposal is part of data protection.


A Full Mortgage Example

Imagine Emma applies for a mortgage.

She provides:

  • passport
  • payslips
  • bank statements
  • address details
  • employment information

The adviser needs this information for the mortgage process.

Therefore:

Collect only what is needed

Explain relevant data use

Store it securely

Share it only where appropriate

Keep it only as long as required

Dispose of it securely

This is data protection in practice.


What Should an Adviser Do?

A mortgage adviser should:

Collect Carefully

Only request relevant information.

Check Accuracy

Make sure important information is correct.

Protect It

Keep documents and systems secure.

Share Carefully

Use customer information only for proper reasons.

Report Problems

Raise possible data breaches immediately.

Respect Customer Rights

Follow the firm’s process when customers exercise their data rights.

This provides a simple working framework.


What Should an Adviser Avoid?

Avoid:

  • discussing customers in public
  • sending information to the wrong person
  • leaving documents unsecured
  • sharing passwords
  • collecting unnecessary information
  • using customer data for unrelated reasons without a proper basis

Therefore:

Treat customer information as something valuable that has been entrusted to you.


A Simple Memory Aid

For the data protection principles, remember:

Use it lawfully

Use it for the right purpose

Collect only what you need

Keep it accurate

Do not keep it forever

Keep it secure

Be able to show compliance

This captures the main ideas.


Key Terms to Remember

UK GDPR

The UK General Data Protection Regulation.

Data Protection Act 2018

UK legislation that works alongside UK GDPR.

Personal Data

Information relating to an identified or identifiable living person.

Processing

Almost any action involving personal data.

Special Category Data

Certain sensitive personal information receiving additional protection.

ICO

Information Commissioner’s Office.

Personal Data Breach

A security incident affecting personal data.

Subject Access Request

A request by a person for access to their personal information.

Data Minimisation

Collecting only the personal information that is needed.

Confidentiality

Keeping private customer information protected from improper disclosure.


Quick Knowledge Check

1. What are the two main parts of the UK data protection framework covered here?

UK GDPR and the Data Protection Act 2018.

2. What is personal data?

Information relating to an identified or identifiable living person.

3. What does processing mean?

Almost any action involving personal data, including collecting, storing, using, sharing or deleting it.

4. What does data minimisation mean?

Collect only the information that is needed.

5. Does a firm always need consent to process personal data?

No. Consent is only one possible lawful basis.

6. What does ICO stand for?

Information Commissioner’s Office.

7. How quickly must certain reportable data breaches normally be reported to the ICO?

Without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

8. What is a Subject Access Request?

A request by a person for access to personal information held about them.

9. Is the right to erasure absolute?

No. Firms may have valid reasons or duties to retain some information.

10. Does confidentiality still apply when working from home?

Yes. Customer information should remain protected wherever the adviser works.


Quick Summary

Mortgage advisers handle large amounts of personal information.

Therefore, data protection is an important part of the job.

The main framework includes:

UK GDPR

and:

Data Protection Act 2018

The key principles are simple:

Use data lawfully

Use it for the right purpose

Collect only what is needed

Keep it accurate

Do not keep it longer than necessary

Keep it secure

Show that you comply

Meanwhile, customers have important rights over their personal information.

Therefore, advisers should understand requests involving:

  • access
  • correction
  • deletion
  • restriction
  • objection

Most importantly:

Customer information should never be treated casually.

For a mortgage adviser, the basic rule is:

Collect carefully. Use properly. Share carefully. Store securely.

Next Page

Money Laundering Regulations