Data Protection and Customer Confidentiality
Mortgage advisers handle a lot of personal information.
For example, a customer may provide details about:
- income
- debts
- savings
- employment
- family circumstances
- bank accounts
- credit history
In addition, they may provide documents such as payslips and bank statements.
Therefore, this information needs to be handled carefully.
The basic principle is simple:
Use customer information properly, keep it secure and do not share it without a valid reason.
Why Does Data Protection Matter?
Customers need to provide detailed information when applying for a mortgage.
However, that information could cause harm if it falls into the wrong hands.
For example, stolen information could be used for:
- identity theft
- fraud
- scams
Therefore, financial firms need strong controls.
At the same time, customers have legal rights over their personal information.
The Main Data Protection Laws
Two important parts of the UK framework are:
UK GDPR
and:
Data Protection Act 2018
Together, they provide rules for handling personal information.
Therefore, mortgage firms need to understand how these rules affect their work.
What Is UK GDPR?
GDPR originally came from European Union law.
However, the UK now has its own version.
This is known as the:
UK General Data Protection Regulation
or:
UK GDPR
It sets important rules for how organisations use personal data.
What Is the Data Protection Act 2018?
The Data Protection Act 2018 works alongside UK GDPR.
It provides additional UK data protection rules.
Therefore, the two are closely connected.
For CeMAP, remember:
UK GDPR + Data Protection Act 2018 = Main UK data protection framework
What Is Personal Data?
Personal data is information relating to an identified or identifiable living person.
For example:
- name
- home address
- email address
- phone number
- date of birth
- account details
However, personal data is wider than basic contact details.
For example, financial information can also be personal data.
Mortgage Applications Contain Large Amounts of Personal Data
A mortgage application may contain:
- income
- spending
- debts
- dependants
- employment details
- credit history
- property information
- bank details
Therefore, mortgage advisers regularly handle sensitive and private information.
As a result, data protection is part of everyday mortgage work.
What Is Processing?
Under data protection law, processing has a wide meaning.
It includes activities such as:
- collecting data
- recording it
- storing it
- changing it
- using it
- sharing it
- deleting it
Therefore, almost anything a mortgage firm does with customer data can count as processing.
A Simple Processing Example
Imagine a customer emails three months of bank statements to their adviser.
The adviser:
Receives them
↓
Saves them
↓
Reviews them
↓
Sends relevant information to the lender
Each of these steps involves processing personal data.
Therefore, data protection applies throughout the process.
The Data Protection Principles
UK GDPR contains important principles for handling personal data.
These can be simplified into seven areas:
- Lawfulness, fairness and transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
These principles sit at the heart of data protection.
Let’s look at each one.
1. Lawfulness, Fairness and Transparency
Personal data should be used:
- lawfully
- fairly
- openly
Therefore, customers should not be misled about how their information will be used.
For example, a firm should explain relevant data use through suitable privacy information.
As a result:
Customers should understand what is happening to their data.
2. Purpose Limitation
Data should be collected for clear and proper purposes.
Then, it should not normally be used for an unrelated purpose without a valid basis.
For example, a customer may provide information for a mortgage application.
That does not automatically mean the firm can use the information for any other purpose it chooses.
Therefore:
Collect data for a reason and use it properly.
3. Data Minimisation
Firms should collect information that is:
- relevant
- necessary
- appropriate
Therefore, they should not collect personal information simply because it might be interesting.
For example, if information has no real purpose in the mortgage process, the adviser should consider why it is being requested.
In simple terms:
Only collect what you need.
4. Accuracy
Personal data should be accurate.
Where needed, it should also be kept up to date.
For example, a customer may:
- change address
- change employer
- receive a salary increase
- repay a debt
Therefore, incorrect information should be corrected when appropriate.
This is particularly important in mortgage applications.
5. Storage Limitation
Personal information should not be kept for longer than necessary.
However, this does not mean firms should delete mortgage records immediately after completion.
Financial firms may need to keep records for:
- regulatory reasons
- legal reasons
- complaint handling
- business needs
Therefore, firms should have proper retention policies.
6. Integrity and Confidentiality
Personal information should be kept secure.
Therefore, firms need to protect it against:
- unauthorised access
- accidental loss
- theft
- damage
- improper disclosure
This includes both digital and paper records.
As a result:
Security is a key part of data protection.
7. Accountability
Firms should be able to show that they comply with data protection requirements.
Therefore, it is not enough simply to say:
We take privacy seriously.
Instead, firms may need suitable:
- policies
- records
- training
- security controls
In simple terms:
Follow the rules and be able to show that you followed them.
A Simple Memory Aid
Remember:
Lawful
↓
Purpose
↓
Minimum
↓
Accurate
↓
Not Forever
↓
Secure
↓
Accountable
This gives you the basic idea behind the seven principles.
A Lawful Basis Is Needed
A firm needs a lawful basis for processing personal data.
There are several possible lawful bases under UK GDPR.
These include:
- consent
- contract
- legal obligation
- vital interests
- public task
- legitimate interests
However, not every basis will apply to every situation.
Therefore, firms should identify the correct basis for the processing they carry out.
Consent Is Not Always Required
A common misunderstanding is:
A company always needs consent to use personal data.
That is not correct.
Consent is only one possible lawful basis.
For example, some information may need to be processed because it is necessary for a contract or legal requirement.
Therefore:
Lawful processing does not always mean consent.
If Consent Is Used
Where consent is the lawful basis, it needs to meet proper standards.
Broadly, it should be:
- freely given
- specific
- informed
- clear
In addition, the person should be able to withdraw consent.
Therefore, hiding consent inside confusing wording would not be a good approach.
Special Category Data
Some personal information receives extra protection.
This is known as special category data.
It can include information about:
- health
- racial or ethnic origin
- religious beliefs
- political opinions
- trade union membership
- genetic data
- biometric data used for identification
- sex life
- sexual orientation
Therefore, firms need additional care when handling this information.
A Mortgage Example
Imagine a customer explains that a serious health condition affects their income.
That health information may be relevant to the advice process.
However, it is also special category data.
Therefore, the firm needs to handle it appropriately and securely.
Customer Confidentiality
Data protection and confidentiality are closely linked.
However, they are not exactly the same thing.
Data protection is based on legal rules about personal data.
Meanwhile, confidentiality is the wider duty to protect private customer information.
Therefore:
Customer information should not be discussed or shared casually.
A Confidentiality Example
Imagine an adviser sees a customer in a café.
A friend asks:
Isn’t that one of your mortgage clients? How much are they borrowing?
The adviser should not discuss the customer’s financial affairs.
Therefore, confidentiality continues outside the office.
Sharing Information Within a Firm
Customer information may sometimes need to be shared with colleagues.
For example:
- compliance staff
- case managers
- administrators
However, access should have a proper business reason.
Therefore:
Working for the same company does not mean everyone needs access to everything.
Information should be shared appropriately.
Sharing Information With Lenders
Mortgage advisers often need to send customer information to lenders.
For example:
- income details
- employment information
- credit commitments
- property information
This may be necessary to arrange the mortgage.
However, the information still needs to be handled properly.
Therefore, secure processes should be used.
Sharing Information With Third Parties
Other third parties may also become involved.
For example:
- solicitors
- valuers
- insurers
- mortgage networks
- service providers
Therefore, firms need to consider what information is being shared and why.
The customer should also receive suitable privacy information.
Do Not Send Information to the Wrong Person
A simple mistake can become a serious data problem.
For example, an adviser may accidentally email:
Customer A’s bank statements
to:
Customer B
That could expose:
- name
- address
- account details
- spending
- income
Therefore, advisers should check recipients carefully before sending information.
What Is a Personal Data Breach?
A personal data breach is a security problem involving personal data.
For example:
- information is lost
- information is stolen
- the wrong person receives it
- someone gains access without permission
- information is changed improperly
Therefore, a breach does not always involve hackers.
Human error can also cause one.
A Simple Data Breach Example
Imagine an adviser leaves a customer file on a train.
The file contains:
- payslips
- bank statements
- address details
- mortgage information
That is a serious security problem.
Therefore, the firm should follow its data-breach procedure.
Reporting Data Breaches
Some personal data breaches need to be reported to the Information Commissioner’s Office, or ICO.
Where the reporting requirement applies, the firm should normally report the breach without undue delay and, where feasible, within:
72 hours of becoming aware of it
Therefore, firms need processes that allow problems to be raised quickly.
Not Every Breach Must Be Reported to the ICO
The reporting requirement depends on the level of risk to people’s rights and freedoms.
Therefore, firms need to assess what happened.
However, advisers should not make that decision alone unless it is part of their role.
Instead:
Report the incident internally straight away and follow the firm’s procedure.
This allows the correct people to assess it.
Customers May Also Need to Be Told
In more serious cases, affected customers may also need to be informed.
For example, this may happen where the breach creates a high risk to their rights and freedoms.
Therefore, data-breach handling can involve both:
- the ICO
- affected customers
The exact response depends on the situation.
What Is the ICO?
The Information Commissioner’s Office is the UK’s independent regulator for information rights.
It oversees areas including data protection.
Therefore:
FCA → Financial regulation
while:
ICO → Data protection and information rights
This is a useful distinction.
Customer Data Rights
UK GDPR gives people important rights over their personal information.
Depending on the circumstances, these include:
- right to be informed
- right of access
- right to rectification
- right to erasure
- right to restrict processing
- right to data portability
- right to object
- rights relating to automated decisions
Therefore, personal data does not simply become the firm’s property once it is collected.
The Right of Access
Customers can ask for access to personal information held about them.
This is often known as a:
Subject Access Request
or:
SAR
Therefore, a customer may ask:
What information do you hold about me?
The firm then needs to respond according to data protection rules.
Subject Access Requests
A SAR does not usually require special legal wording.
For example, a customer might simply say:
Please send me the personal information you hold about me.
That may be enough.
Therefore, staff should recognise possible subject access requests and follow the firm’s process.
How Long Does a Firm Have to Respond?
In many cases, a firm should respond to a subject access request within:
One month
However, some situations allow extra time.
Therefore, requests should be passed to the correct person promptly.
The Right to Rectification
If personal information is wrong, the customer may have the right to have it corrected.
For example:
Incorrect address
↓
Customer tells firm
↓
Firm corrects the information where appropriate
Therefore, accuracy is both a data protection principle and a customer right.
The Right to Erasure
You may hear this called the:
Right to be Forgotten
However, it is not an absolute right.
For example, a mortgage customer cannot always demand that every record is deleted immediately.
The firm may need to retain information because of:
- legal requirements
- regulatory requirements
- possible legal claims
Therefore:
The right to erasure has limits.
Data Security
Firms need suitable security for customer information.
This may include:
- passwords
- access controls
- secure email
- encryption
- locked storage
- staff training
Therefore, security is both a technology issue and a people issue.
Passwords and Access
Employees should not casually share passwords.
Likewise, systems should limit access to people who need the information.
Therefore:
Access should be controlled.
This helps reduce both accidental and deliberate misuse.
Working From Home
Remote working can create extra risks.
For example:
- family members may see documents
- screens may be visible
- paperwork may be left unsecured
- devices may be lost
Therefore, customer confidentiality still applies outside the office.
A Home-Working Example
Imagine an adviser works from the kitchen table.
A customer file is left open.
Later, visitors arrive.
Even if nobody deliberately reads it, the information has not been protected properly.
Therefore, paper and digital records should be secured.
Public Places
Advisers should also be careful when working in:
- cafés
- trains
- airports
- shared workspaces
For example, discussing a customer’s income loudly on a train could reveal private information.
Therefore:
Confidentiality applies to conversations as well as documents.
Identity Checks
Before sharing information, the firm may need to confirm who it is dealing with.
For example, someone may phone and claim to be the customer.
Therefore, appropriate security questions or identification checks may be needed.
This helps prevent unauthorised disclosure.
Data Protection and Financial Crime
Sometimes a firm may need to use or share information because of legal duties linked to financial crime.
For example:
- money laundering checks
- fraud prevention
- legal reporting requirements
Therefore, customer confidentiality does not mean information can never be shared.
Instead, information should be shared only where there is a proper reason.
Marketing and Personal Data
Data protection rules can also affect marketing.
For example, a firm should not assume that receiving someone’s details for a mortgage application automatically allows every form of future marketing.
Therefore, firms need to consider the rules that apply to marketing communications.
As a result:
Mortgage application data should not simply become unrestricted marketing data.
Keep Data Only as Long as Needed
Firms should have rules for how long different records are kept.
Therefore:
Collect
↓
Use
↓
Store securely
↓
Retain where required
↓
Delete or dispose of securely when appropriate
This is the basic data life cycle.
Secure Disposal
Deleting information also needs care.
For example, paper records containing customer data should not simply be placed in an ordinary bin.
Likewise, old electronic devices may contain stored information.
Therefore, secure disposal is part of data protection.
A Full Mortgage Example
Imagine Emma applies for a mortgage.
She provides:
- passport
- payslips
- bank statements
- address details
- employment information
The adviser needs this information for the mortgage process.
Therefore:
Collect only what is needed
↓
Explain relevant data use
↓
Store it securely
↓
Share it only where appropriate
↓
Keep it only as long as required
↓
Dispose of it securely
This is data protection in practice.
What Should an Adviser Do?
A mortgage adviser should:
Collect Carefully
Only request relevant information.
↓
Check Accuracy
Make sure important information is correct.
↓
Protect It
Keep documents and systems secure.
↓
Share Carefully
Use customer information only for proper reasons.
↓
Report Problems
Raise possible data breaches immediately.
↓
Respect Customer Rights
Follow the firm’s process when customers exercise their data rights.
This provides a simple working framework.
What Should an Adviser Avoid?
Avoid:
- discussing customers in public
- sending information to the wrong person
- leaving documents unsecured
- sharing passwords
- collecting unnecessary information
- using customer data for unrelated reasons without a proper basis
Therefore:
Treat customer information as something valuable that has been entrusted to you.
A Simple Memory Aid
For the data protection principles, remember:
Use it lawfully
↓
Use it for the right purpose
↓
Collect only what you need
↓
Keep it accurate
↓
Do not keep it forever
↓
Keep it secure
↓
Be able to show compliance
This captures the main ideas.
Key Terms to Remember
UK GDPR
The UK General Data Protection Regulation.
Data Protection Act 2018
UK legislation that works alongside UK GDPR.
Personal Data
Information relating to an identified or identifiable living person.
Processing
Almost any action involving personal data.
Special Category Data
Certain sensitive personal information receiving additional protection.
ICO
Information Commissioner’s Office.
Personal Data Breach
A security incident affecting personal data.
Subject Access Request
A request by a person for access to their personal information.
Data Minimisation
Collecting only the personal information that is needed.
Confidentiality
Keeping private customer information protected from improper disclosure.
Quick Knowledge Check
1. What are the two main parts of the UK data protection framework covered here?
UK GDPR and the Data Protection Act 2018.
2. What is personal data?
Information relating to an identified or identifiable living person.
3. What does processing mean?
Almost any action involving personal data, including collecting, storing, using, sharing or deleting it.
4. What does data minimisation mean?
Collect only the information that is needed.
5. Does a firm always need consent to process personal data?
No. Consent is only one possible lawful basis.
6. What does ICO stand for?
Information Commissioner’s Office.
7. How quickly must certain reportable data breaches normally be reported to the ICO?
Without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
8. What is a Subject Access Request?
A request by a person for access to personal information held about them.
9. Is the right to erasure absolute?
No. Firms may have valid reasons or duties to retain some information.
10. Does confidentiality still apply when working from home?
Yes. Customer information should remain protected wherever the adviser works.
Quick Summary
Mortgage advisers handle large amounts of personal information.
Therefore, data protection is an important part of the job.
The main framework includes:
UK GDPR
and:
Data Protection Act 2018
The key principles are simple:
Use data lawfully
↓
Use it for the right purpose
↓
Collect only what is needed
↓
Keep it accurate
↓
Do not keep it longer than necessary
↓
Keep it secure
↓
Show that you comply
Meanwhile, customers have important rights over their personal information.
Therefore, advisers should understand requests involving:
- access
- correction
- deletion
- restriction
- objection
Most importantly:
Customer information should never be treated casually.
For a mortgage adviser, the basic rule is:
Collect carefully. Use properly. Share carefully. Store securely.
Next Page
Money Laundering Regulations
