The Blog
Notes · 30 Aug 2026 · 8 min read

UK Valuation Data Security Guide for Surveyors

A UK valuation data security guide for surveyors: assess encryption, retention, AI training and access controls before uploading valuation reports securely.

A valuation report can contain more than a market value and a schedule of comparable evidence. It may include borrower details, lease information, tenant covenant commentary, plans, photographs, lender instructions and commercially sensitive evidence. Once that report is uploaded to an external review tool, the question is not simply whether the tool is useful. It is whether your data remains under proper control. This UK valuation data security guide sets out the checks worth making before a draft report leaves your firm’s systems.

The point is not to avoid technology altogether. A well-designed review tool can help flag a £50,000 mismatch between the executive summary and valuation conclusion, a rent stated on the wrong basis, or an EWS1 disclosure omitted from a report where it is required. But the same professional care applied to the instruction, inspection and analysis should apply to the technology supporting the final review.

Start with the data in the report

Security discussions often begin with encryption. That matters, but it is only one part of the picture. First establish exactly what the provider receives and why.

A Red Book report for secured lending can contain personal data, confidential lender material and information that is commercially sensitive even where it is not personal data. A comparable schedule may reveal transaction terms not publicly available. A report on an investment property may include detailed tenant information, unexpired terms, break options and covenant observations. A residential report can include borrower names, addresses, photographs and information relevant to construction or cladding.

The sensible question is therefore: does the service need the whole report, or only extracted data? A document-wide audit will normally need access to the report as a whole. That is how it can identify a floor area of 1,240 sq m in the property description but 1,204 sq m in the valuation calculation, or spot that a 5.75% yield appears in one section while the adopted yield is 5.50% elsewhere. If full-document processing is necessary, the provider should be clear about the boundaries around that access.

Ask for a plain-English explanation of the data flow. You should be able to understand where the file is uploaded, how it is processed, who can access it, whether it is retained and when it is deleted. If the answer is vague, the risk has not been properly addressed.

UK valuation data security guide: the controls to test

A supplier does not need to disclose every internal security detail. Equally, broad assurances that data is “secure” are not enough for a report containing lender and client information. The following areas deserve a direct answer.

Encryption in transit and at rest

The report should be encrypted while moving from your browser to the provider and while held in any processing environment. Encryption in transit protects the upload. Encryption at rest protects data if storage or infrastructure is compromised.

This does not mean that encryption answers every question. A provider can encrypt files and still retain them for longer than necessary, use them for a purpose you did not expect, or give too many people access. Treat it as a baseline control, not the entire assessment.

Retention and deletion

For valuation work, retention is often the point that matters most. If a draft is uploaded for a two-minute review, there should be a clear reason for retaining it beyond that process.

Ask whether files are stored after the review is complete, whether the provider keeps extracted text or metadata, and whether deletion happens automatically. Also ask what is retained in backups and for how long. A service may remove the visible document from your account while copies remain in backup systems for a defined period. That can be acceptable if it is documented and proportionate, but it should not come as a surprise.

The strongest position for sensitive draft reports is usually minimal retention: process the document, return the findings and do not retain the report content unnecessarily. It reduces the volume of data that could be exposed later and makes internal approval easier.

Model training and secondary use

This point should be explicit, particularly where an AI service is involved. Some services use submitted documents to train or improve their models. That may not sit comfortably with confidential valuation reports, even if the data is said to be anonymised.

Ask a direct question: will our reports, extracted data or findings be used to train any model? A clear no is straightforward. If the answer depends on settings, contract terms or an opt-out, establish the default position and who in your firm can change it.

There is a practical distinction here. A provider may improve rules, workflows or software performance using aggregated operational information without using your report content for model training. The distinction is worth understanding rather than assuming. What matters is that the supplier explains it precisely and your firm knows what it has agreed to.

Access controls and support access

Not every person working for a technology provider should be able to open a valuation report. Access should be restricted to those with a defined operational reason, with permissions appropriate to their role.

Find out whether your own users can be given role-based access, whether multi-factor authentication is available, and whether account activity can be traced. For larger teams and panel managers, it is also worth considering whether a reviewer should be able to see every instruction or only the reports allocated to them.

Support access needs the same scrutiny. If a user has a technical issue, can provider staff view the document by default? Is access time-limited and logged? A support team may need limited access to resolve a genuine problem, but it should be controlled rather than assumed.

Processing location and third parties

A UK firm should understand where its report data is processed and whether subcontractors are involved. This is not a question of geography alone. It is about knowing which organisations touch the data, their role in the service and the safeguards that apply.

Ask whether the provider uses third-party hosting, document-processing or AI infrastructure, and whether those parties are named in the contractual documentation. If data is transferred outside the UK, your data protection lead may need to consider the relevant transfer arrangements. The answer may be workable, but it should be considered before the first report is uploaded, not after.

Do not overlook the human controls

A secure service can still be undermined by ordinary working practices. Shared logins, reports downloaded to unmanaged personal devices and former staff retaining access create risks that no encryption standard will fix.

For a small valuation practice, proportionate controls are usually enough: named user accounts, strong passwords, multi-factor authentication where available, prompt removal of leavers and a clear rule on who may upload reports. For a lender-side review team, the requirements may extend to delegated administration, audit logs and tighter separation between client portfolios.

It also helps to set a rule on timing. Upload the draft when it is ready for an independent read-through, not the working file containing unrelated notes, emails or background material that does not need to be reviewed. That keeps the review focused and limits unnecessary disclosure.

Security should support, not dilute, professional judgement

The purpose of a document audit is to take pressure off the repetitive cross-checking that is difficult to do perfectly at the end of a busy day. It can flag that the adopted market rent is £185 per sq m in the valuation table but £158 per sq m in the narrative, or that a comparable has an expiry date before the stated transaction date. The surveyor decides whether the finding is an error, a justified departure or a point requiring further investigation.

The same principle applies to security. The provider should process the report privately and with defined controls. The firm should decide what data is appropriate to submit, who may submit it and how the findings are used. Technology can provide a useful second pair of eyes, but it does not take responsibility for the valuation opinion away from the registered valuer.

WriteUp is built for this use case. It reviews draft valuation reports through private, encrypted processing, without storing report data or using it for model training. Its findings are presented to the surveyor for review, including report-wide contradictions, calculation issues and checks against relevant instructions. The final professional judgement remains where it belongs.

A proportionate supplier review before rollout

Before adopting any report-review service, involve the people who understand the operational and data risks in your firm. For a sole practitioner, that may mean checking the supplier’s terms and documenting your own decision. For a larger practice, it may involve directors, an IT lead, a data protection contact and the person responsible for valuation standards.

Keep the review practical. Read the data-processing terms, ask the questions that matter to your workflow and test the service with a suitable draft. Check whether the findings are useful, whether the report can be deleted as expected and whether user permissions work as intended. Security controls that cannot be explained or operated in day-to-day practice are less valuable than they appear on paper.

A careful review process should leave you with a simple, defensible position: you know what leaves your control, why it is processed, who can access it and what happens to it afterwards. That clarity lets you use a second pair of eyes before a report leaves your desk, without treating confidentiality as an afterthought.