Schroders real estate privacy policy
This Privacy Policy is designed to help you understand what information we gather and process about you in connection with managing properties and providing our real estate services, why and how we use it, and with whom we share it. It also sets out the rights you may have in relation to your information and how you may contact us with questions.
Definitions used in this Privacy Policy are as follows
“Schroders”, “we” or “us” means Schroders plc with its registered office at 1 London Wall Place, London EC2Y 5AU, or any of its subsidiaries or affiliates, and each entity advised or managed by them, as applicable. Together these are also referred to as the Schroders Group. Schroders is also now part of the Nuveen group of companies (“Nuveen”). This notice also describes personal data sharing with Nuveen in section 5.
“Schroders Websites” means the websites operated by Schroders or on behalf of Schroders.
“Personal Data” means any data which relates to a living individual who can be identified from that data or from that data and other information which is in the possession of, or is likely to come into the possession of, Schroders (or its representatives or service providers). In addition to factual information such as a name or address, it could include an expression of opinion about or an indication of intention in respect of an individual.
“Tenant” means a tenant or occupier of a property which is owned or managed by Schroders, who may be an individual tenant or a corporate tenant.
“Supplier” means a supplier of services to a property which is owned or managed by Schroders who may be an individual or a corporate supplier.
“You” means each individual to whom this notice is addressed, who may be:
(a) a Tenant or prospective Tenant;
(b) a Supplier or prospective Supplier;
(c) an employee, director, officer or representative of a Tenant or Supplier; or
(d) a visitor to a Schroders Website.
1. Background information
(1.1) Schroders collects and uses certain Personal Data. Schroders is responsible for ensuring that it uses that Personal Data in compliance with data protection laws.
(1.2) At Schroders, we respect your privacy and we are committed to keeping your Personal Data secure.
(1.3) This Privacy Policy is directed to Tenants and Suppliers whose Personal Data we handle in the course of carrying on our real estate services and related activities. For details of our processing of personal data of website users, please see Schroders Group cookie policy
2. Overview of when we handle your Personal Data
(2.1) This Privacy Policy explains how we handle Personal Data that we collect in the following ways:
(a) Information we receive during the course of our Tenants’ or prospective Tenants’ relationship with us;
(b) Information we receive during the course of our Suppliers’ or prospective Suppliers’ relationship with us;
(c) Information we receive during the course of the use of the properties which are owned or managed by Schroders; and
(d) Information we receive through Schroders Websites. Details of how we handle the information we receive through Schroders Websites are set out in paragraph 10 of this Privacy Policy.
3. The types of Personal Data we collect
(3.1) We will collect and process the following Personal Data during the course of your relationship with us:
Information that you provide to Schroders. This includes information about you that you provide to us. The nature of our relationship with you will determine the kind of Personal Data we might ask for, though such information may include:
- basic Personal Data such as first name, family name, national insurance number, email address, phone number, address (including city postcode and country), occupation and job title, bank details, credit and debit card details, ID documentation, tax classifications, gender, and date of birth, and
Information that we collect or generate about you. This may include:
- files that we may produce as a record of our relationship with our Tenants and Suppliers, including contact history, property management matters for the administration of our property management system, know your client and anti-money laundering checks and procedures on our Tenants, energy consumption, water usage and usage of other utilities (including meter readings), payment history, authorised signatories of Tenants, health and safety information where insurance claims are made in connection with the use of properties, details of disabilities if requests are made for modifications to buildings to accommodate disabilities, CCTV and other security provisions, car registration plate number for the purpose of car park management; and
Information we obtain from other sources. This may include:
- information from publicly available sources, including third party agencies such as credit reference agencies; fraud prevention agencies; law enforcement agencies; public databases, registers and records such as Companies House; the FCA Register; the Land Registry; the DVLA, and other publicly accessible sources.
4. How we use your information
(4.1) Your Personal Data may be processed by us in the following ways and for the following purposes:
Legal basis under which we use your Personal Data | How we use your Personal Data | Types of Personal Data we use |
Performance of a contract | To enter into, administer and perform leases, licences, supply arrangements and other property-related contracts; onboard Tenants and Suppliers; manage payments; and manage access to, occupation and use of properties and associated facilities where these form part of our contractual relationship. | Names and contact details; occupation, job title and organisation; authorised signatory details; addresses; bank, credit and debit card details; payment history; tax classifications; identification documents; correspondence; property, lease and supplier records; occupancy and access details; vehicle registration number; utility consumption, water usage and meter readings; and service requests. |
Compliance with legal and regulatory obligations | To carry out know-your-client, anti-money laundering, sanctions and fraud-prevention checks; respond to regulators, law-enforcement bodies and public authorities; and meet tax, accounting, audit, health and safety, insurance, building management, record-keeping and litigation-hold requirements. | Names and contact details; date of birth; nationality where relevant; identification documents; national insurance or other government identifiers; occupation; ownership and control information; tax classifications; bank and payment information; results of checks against public registers, fraud-prevention sources and other lawful databases; transaction, incident, accident, insurance, correspondence, CCTV and access records where relevant. |
Legitimate interests | To manage and administer properties, property management systems and relationships with current or prospective Tenants and Suppliers; communicate and maintain accurate records; protect people, premises, assets and systems; manage physical access, parking and security; prevent and investigate misuse, fraud, cyber threats and other incidents; administer and improve our IT systems, databases, websites and property services; respond to enquiries and complaints; establish, exercise or defend legal rights; and manage corporate transactions involving relevant properties or business assets. | Names; business and personal contact details; organisation, occupation and job title; authorised signatory information; correspondence and contact history; property, tenancy, supplier, service and payment records; CCTV images; visitor and access records; vehicle registration numbers; device, network, cookie, website and security information; incident records; information from fraud-prevention agencies, law-enforcement bodies and public sources; service requests and complaints; utility and property-service usage data; and relevant contractual, claim and due-diligence information. |
Consent | To process your Personal Data for a specific optional purpose where we have asked for your agreement, including use of information that is not otherwise necessary for the purposes described above. You may withdraw your consent at any time. | The Personal Data identified when consent is requested and which you choose to provide. |
Substantial public interest, vital interests and legal claims | To prevent or detect unlawful acts, fraud and financial crime where sensitive information is involved; manage accessibility requests, health and safety matters, emergencies, accidents and insurance claims; protect vital interests; and establish, exercise or defend legal claims. | Relevant identity, due-diligence, sanctions, fraud-prevention, criminal allegation or offence information; health, disability and accessibility information; incident, accident, insurance and claim information; contact details; CCTV and access records; and information obtained from public authorities or lawful databases. |
(4.2) Within Schroders, your Personal Data is accessed only by employees of Schroders that have a need to access it for the purposes described in this Privacy Policy.
5. Disclosure of your information
(5.1) We may share your Personal Data within Schroders for the purposes described above.
(5.2) As Schroders is part of the wider Nuveen group, we may share personal data with Nuveen for the purposes described above, as well as for group governance and business operations and integration activities. In some circumstances Nuveen group companies will process personal data as separate controllers for their own legitimate business purposes. Information about such processing can be found in the relevant Nuveen privacy notice, available at Privacy notice | Nuveen.
(5.3) We may also share your Personal Data outside of Schroders as further described below:
- with business partners of ours where they are contractually obliged to comply with appropriate data protection obligations;
- with third-party agents, contractors and service providers that support our real estate activities, including property and facilities managers, professional advisers, IT and systems providers, payment and banking providers, security and CCTV providers, utilities providers, insurers, auditors, and compliance service providers;
Where appropriate, these third parties are subject to contractual, confidentiality and data protection obligations.
- to the extent required by law or regulation, for example if we are under a duty to disclose your Personal Data in order to comply with any legal obligation (including, without limitation, in order to comply with tax reporting requirements and disclosures to regulators, auditors or public authorities), or to establish, exercise or defend our legal rights; and
- if we sell any part of our business or our assets, in which case we may need to disclose your Personal Data to the prospective buyer for due diligence purposes.
6. International transfers of Personal Data
(6.1) Schroders is a global business with operations around the world. As a result we collect and transfer Personal Data on a global basis. That means that we may transfer your Personal Data to locations outside of your country.
(6.2) Where we transfer your Personal Data to another country it will be protected and transferred in a manner consistent with legal requirements. In relation to data being transferred outside of the UK or the European Economic Area (the “EEA”), for example, this may be done in one of the following ways:
- the country to which we send your Personal Data might be approved by the European Commission or the UK as offering an adequate level of protection for Personal Data;
- the recipient might have signed up to a contract based on “model contractual clauses” approved by the European Commission or the UK, obliging it to protect your Personal Data, and we have assessed that the legislation of the third country of destination enables the recipient to comply with those clauses;
- in other circumstances the law may permit us to otherwise transfer your Personal Data outside the EEA/UK.
(6.3) Transfers that we make within the Schroders Group or between the Schroders Group and Nuveen are governed by an intra group data sharing agreement which incorporates appropriate export safeguards required by local laws.
(6.4) You can obtain more details of the protection given to your Personal Data when it is transferred outside the EEA and elsewhere by contacting us as described in paragraph 11 below.
7. How we safeguard your Personal Data
(7.1) Data is a critical business asset and must be protected appropriate to its risk as well as its importance or value. We operate layers of safeguards and defences designed to ensure that Schroders is able to operate safely. We have extensive controls and mechanisms in place designed to detect, respond and recover in case of any adverse events that may arise.
8. How long we keep your Personal Data
(8.1) The length of time for which we hold your Personal Data will vary as determined by the following criteria:
- the purpose for which we are using it (as further described in this Privacy Policy) – we will need to keep the data for as long as is necessary for that purpose; and
- our legal obligations – laws or regulation may set a minimum period for which we have to keep your Personal Data.
9. Your rights
(9.1) In all the above cases in which we collect, use or store your Personal Data, you may have the following rights and, in most cases, you can exercise them free of charge. These rights include:
- the right to obtain information regarding the processing of your Personal Data and access to the Personal Data which we hold about you;
- the right to withdraw your consent to the processing of your Personal Data at any time. Please note, however, that we may still be entitled to process your Personal Data if we have another legitimate reason for doing so. For example, we may need to retain your Personal Data to comply with a legal or regulatory obligation or to satisfy our internal audit requirements;
- in some circumstances, the right to receive some Personal Data in a structured, commonly used and machine-readable format and/or request that we transmit such data to a third party where this is technically feasible. Please note that this right only applies to Personal Data that you have provided directly to Schroders;
- the right to request that we rectify your Personal Data if it is inaccurate or incomplete;
- the right to request that we erase your Personal Data in certain circumstances. Please note that there may be circumstances where you ask us to erase your Personal Data but we are required or entitled to retain it;
- the right to object to, or request that we restrict, our processing of your Personal Data in certain circumstances. Again, there may be circumstances where you object to, or ask us to restrict, our processing of your Personal Data but we are required or entitled to refuse that request; and
- the right to lodge a complaint with the relevant data protection regulator if you think that any of your rights have been infringed by us.
(9.2) You can exercise your rights by contacting us using the details provided at paragraph 11 below.
10. Changes to this Privacy Policy
(10.1) Any changes we make to our Privacy Policy in the future will be posted on this website and where appropriate, notified to you by email. Please check back frequently to see any updates or changes to our Privacy Policy.
11. Questions and concerns
(11.1) If you have any questions or concerns about Schroders’ handling of your Personal Data, or about this Privacy Policy, please contact us using the following contact information:
Privacy@schroders.com
We are usually able to resolve privacy questions or concerns promptly and effectively. If you are not satisfied with the response you receive, you may escalate concerns to the applicable privacy regulator in your jurisdiction. Upon request, we will provide you with the contact information for that regulator.
Last updated: September 2026