Skip to main content
KasoriaKasoria
Back to blogGuide

GDPR for Estate Agent Websites: What You Actually Need (and What You Don't)

GDPR compliance for German estate agent websites: privacy policy, cookie consent, contact forms, CRM integration and listing photos — a practical overview without the legal jargon.

8 min readChristian Wenterodt
Independent estate agent sits smiling at her desk working on her laptop, a golden holographic shield icon with a checkmark floats beside her as a symbol for GDPR compliance// featured

Few businesses process as much personal data online as an estate agency: contact enquiries, financing details, viewing appointments, sometimes even proof-of-income documents submitted through a contact form. Yet many estate agent websites treat GDPR as a box-ticking exercise — a cookie banner slapped on top, a copy-pasted privacy policy, done. In practice that often isn't enough, and the actual gaps usually sit exactly where nobody looks for them: not on the website itself, but at the interfaces to the agency software and to Google.

This article focuses on Germany, since that's where GDPR compliance for estate agents has the most specific, well-documented requirements (the DDG/TMG obligations below are German law). If your agency operates elsewhere in the EU, the GDPR principles carry over, but check your local implementing law for the exact impressum-style requirements.

Why estate agent websites carry a particular GDPR risk

A typical business website rarely collects more than a name, email and a message. An estate agent website structurally collects more: enquiries tied to a specific property, often including budget, deposit amount or desired move-in date — information that edges close to financial and creditworthiness data. On top of that comes the connection to the agency software (onOffice, FlowFact, PROPSTACK and similar), through which this data usually flows onward automatically, and the listing photos themselves, which sometimes show identifiable people or private interiors. Each of these three points needs its own, properly handled answer.

The baseline: what every website needs regardless

Legal notice (Impressum) — mandatory for any commercial website under German law (§ 5 DDG, formerly TMG), independent of GDPR. Full legal name, a physical address that can receive service of process, a contact method, and for estate agents specifically, the § 34c GewO licence details and the responsible supervisory authority.

Privacy policy — must name concretely what data is processed for what purpose: the contact form, server logs, embedded third-party services (Google Maps, Google Fonts, Google Analytics), and in an estate agency context, explicitly the handover of enquiry data to whichever CRM is in use. A generic, off-the-shelf policy template almost never covers that last point.

Cookie consent — a banner that sets non-essential cookies (analytics, marketing pixels) before consent is given violates both § 25 TTDSG and GDPR. What matters isn't that a banner exists, but that it technically blocks those cookies until an active choice has been made.

The three places estate agent websites usually miss

1. Contact forms that ask for financing details

A form asking for deposit amount or desired loan range is potentially handling sensitive information. What's needed: explicit consent rather than an assumed one, encrypted transmission (TLS — standard today, but worth verifying), clear purpose limitation — the data may only be used for that specific enquiry, not silently added to a newsletter list — and a retention period stated in the privacy notice right next to the form, not buried somewhere in the general policy.

2. The CRM interface

The moment enquiry data flows automatically from the website into onOffice, FlowFact, PROPSTACK or any other system, that needs a legal basis and, in most cases, a data processing agreement (DPA/AVV) with the software vendor — the major providers offer one as standard, but it has to actually be signed, not just theoretically available. If you also sync listing data via an OpenImmo interface with real, indexable listing pages instead of an iframe (see our comparison of the three systems), pay particular attention here: every additional automated data transfer is an additional processing step that needs to be documented.

3. Listing photos and photos of people

Interior shots of an occupied property sometimes show private belongings, and occasionally people. Before publishing, you need consent from the residents or owners — ideally built into the agency agreement upfront, not asked as an afterthought. The same applies to team photos or client testimonials on your own site: written, documented consent, with a way to withdraw it.

Checklist: a 15-minute GDPR self-audit for your website

ItemCheck
Legal noticeComplete, including § 34c GewO licence detail and supervisory authority
Privacy policyNames the contact form, CRM handover, and embedded Google services specifically
Cookie bannerTechnically blocks non-essential cookies until consent is given
Contact formExplicit consent, TLS encryption, retention period stated
CRM integrationDPA actually signed with the software vendor, not just available
Listing photosResident/owner consent documented before publication
Google Maps/FontsLoaded only after cookie consent, not embedded by default

What GDPR compliance is not

A cookie banner alone doesn't make a website compliant, and neither does a 15-page privacy policy copied from the internet. Both are components, not a solution. Conversely, GDPR compliance doesn't mean giving up CRM integration, analytics or listing photos — it means each of those components needs a documented, properly implemented legal basis. In the end that's less work than a cease-and-desist letter or a complaint to the supervisory authority, and it builds exactly the trust that makes someone likely to submit a contact form with financing details in the first place.

This article is not legal advice. For the exact wording of your privacy policy and DPA, when in doubt, consult a lawyer specialising in data protection law or a data protection officer.

Blog

We build your website GDPR-compliant from day one

Privacy policy, cookie consent, secure forms and clean CRM integration are standard with us, not an add-on. In a discovery call we'll check exactly where your current website stands today.

Christian Wenterodt

About the author

Christian Wenterodt

Gründer, Kasoria

Christian Wenterodt ist Gründer von Kasoria. Er entwickelt Websites, SEO-Strategien und digitale Prozesse, die Unternehmen helfen, online sichtbarer zu werden und mehr qualifizierte Anfragen zu gewinnen.

Blog

Read all articles

More posts on web design, SEO and digital marketing for real estate professionals.