Is It Safe for French Real Estate Agents to Use AI?
AI helps draft listings and mandates. But pasting client data into a consumer AI creates a real GDPR risk for the agency.
The answer fits in one line. AI can help you draft a listing or a mandate. But never hand it your client data. An identity document. A buyer's income. An offer amount. Pasted into a consumer AI, these details leave your agency. That is exposure to a third party. Yet your agency stays the data controller under the GDPR. There is a clean method: anonymise before any prompt, then restore the values locally.
The problem: client data pasted into AI
The habit spreads fast in agencies. You ask an AI to draft a listing. You have it rewrite an email to a buyer. You submit a draft mandate. To save time, you paste the raw text. That text often holds the clients' real data. This is where the risk begins, not in the tool itself.
A property file concentrates sensitive data. Here is what a poorly prepared prompt can expose.
- The identity and contact details of sellers, buyers and third parties named.
- The buyers' financial situation: income, deposit, borrowing capacity.
- The offer amounts and the negotiation terms.
- The file documents: mandate, identity document, supporting papers.
The stake: the Hoguet law, the GDPR and confidentiality
An estate agent is not an ordinary provider. The activity is governed by the Hoguet law. That is Law No. 70-9 of 2 January 1970. Its implementing decree is Decree No. 72-678 of 20 July 1972. This framework requires a professional card. It is issued by the chamber of commerce and industry (CCI). It also requires a written mandate to act. The card carries a letter for the activity: T for transactions, G for management, S for building management.
Beware of one assumption. An estate agent is not bound by criminal professional secrecy, as a notary is. The duty is confidentiality and GDPR compliance. That does not make the data any less sensitive. It only changes the nature of the obligation.
The GDPR, for its part, applies fully. Your agency is the data controller for client data. So you carry three key obligations. A legal basis for each processing. Minimisation of the data collected. Security of that data. The minimisation principle is simple: collect and expose only what is strictly necessary.
The CNIL, France's data protection authority, already frames the sector. On 27 May 2021 it published a reference framework on rental management. It frames processing on the landlord and intermediary side. It is not binding. But any departure must be justifiable. The CNIL also published in 2025 its recommendations on AI and the GDPR. The message is clear. As soon as personal data is involved, the GDPR applies. The European regulation on AI (the AI Act) applies too.
A consumer AI provider is a third party. It sits outside the framework you control. Pasting client data into an AI means transferring it to that third party. The content can be retained, reviewed or reused to train the model. This exposure creates a real GDPR risk. It is enough to be a problem, even without a public leak.
Is AI banned in real estate?
No. No rule forbids an estate agent from using AI. The tool can structure a listing, rewrite an email or suggest a mandate outline. What causes trouble is exposing the data, not using AI itself. So the question is not “should we give up AI?”. The question is “how do we use it without exposing client data?”. The answer holds in one word: minimisation.
| Assumption | The reality |
|---|---|
| “Pasting a file into the AI stays between us” | It is a transfer to a third party outside your controlled framework, while you are the data controller |
| “The GDPR doesn't apply to AI” | The CNIL states there is no exemption: the regulation applies fully |
| “AI is banned in real estate” | No: it is exposing the client data that is the problem, not the tool |
| “An agent is bound by secrecy like a notary” | No: the duty is confidentiality and the GDPR, not criminal professional secrecy |
The fix: anonymise before the prompt
The fix matches what the CNIL says. When personal data is not needed for the processing, you strip it upstream. This is minimisation applied to AI. You keep the tool and save time. The AI never sees the file's real values. You stay in control of the client data, on your own machine.
In practice, you proceed step by step. You spot each identifying element. You replace it with a token before sending. The AI works on the shape of the file. It never reads the identities or the amounts. You then restore the real values, locally. Here is the order to follow.
- 1Spot the client data: identity, financial situation, offer amounts, references.
- 2Replace it with reversible tokens, in the browser.
- 3Send only the anonymized text to the AI.
- 4Restore the real values in the reply, locally, then re-read the result.
That's what ONYRI Sanitize is for. The engine detects sensitive data — identities, contact details, income, amounts — and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser. Only anonymized text reaches the model. The AI finds only tokens, never your client data. You get AI's help, while reducing the exposure the GDPR asks you to control.
Frequently asked questions
- Can an estate agent use AI without exposing client data?
- Yes, as long as identifying data is not pasted into the tool. The agency is the data controller under the GDPR. Pasting an identity document, income or an offer amount into a consumer AI exposes that data to a third party. AI stays useful on anonymized text: strip the client data before any prompt.
- Is AI banned in real estate?
- No. No rule forbids AI for estate agents. It is exposing the data that is the problem, not the tool. The CNIL notes that the GDPR applies fully to any AI processing personal data, and cites minimisation. So the good practice is to anonymise client data before submitting it.
- Is an estate agent bound by professional secrecy like a notary?
- No, not in the criminal sense. Unlike a notary, an estate agent is not bound by criminally sanctioned professional secrecy. The framework is the Hoguet law for practice and the GDPR for data: legal basis, minimisation, security. Client data stays sensitive, but the nature of the obligation differs.
Sources & references
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.
Anonymize my prompt