Skip to content
Cuan
Compliance

Can an OMC name owners in arrears?

Directors want transparency about who has not paid. Data-protection law says be careful. Here is where the line sits, what you can share, and how to keep the board informed without breaching GDPR.

7 minUpdated July 2026

The short version

  • 1Naming individual owners who are in arrears to the wider membership is generally not permitted under GDPR.
  • 2The Data Protection Commission has indicated it is unlikely there is a lawful basis for disclosing members' service-charge payment details to other members without consent.
  • 3An OMC is a data controller; if it uses a managing agent, the agent is usually a data processor.
  • 4You can be fully transparent by reporting arrears in aggregate: the total and the ageing, without names.
  • 5Where a director genuinely needs named detail, access should be limited, justified and logged.

The short answer

In almost all cases, no. An OMC should not name the owners who are in arrears to the rest of the members. An owner's service-charge payment record is their personal data, and disclosing it to neighbours needs a lawful basis under the General Data Protection Regulation (GDPR). The Data Protection Commission (DPC) has indicated it is unlikely that a valid lawful basis exists for disclosing the payment details of members to all or some other members without their consent.

This is general information

Data-protection questions turn on the specific facts. This guide explains the general position; for a decision on your own development, take advice from a solicitor or a data-protection professional.

Why directors want to name arrears

The instinct is understandable. Arrears are unfair on the owners who do pay, they starve the development of cash, and naming feels like the honest, transparent thing to do. Boards often believe a bit of social pressure will bring people to the table. The problem is that the law treats an owner's payment history as private financial data, and the desire for transparency does not, on its own, create a lawful basis to publish it.

What GDPR and the DPC actually say

An OMC processes personal data about its members, including who owns what and who has paid, so it is a data controller under GDPR and the Data Protection Act 2018. Where a managing agent handles that data on the OMC's behalf, the agent is usually a data processor acting on the OMC's instructions.

As a controller, the OMC can only disclose personal data where it has a lawful basis. The DPC has addressed this directly for management companies and indicated that it is unlikely there is a valid lawful basis for disclosing the service-charge payment details of members to all or some other members without consent. In plain terms: circulating an arrears list that identifies individuals is very hard to justify.

What you can share

Transparency and data protection are not in conflict; you just report at the right level. An OMC can and should keep members and directors informed by sharing arrears in aggregate:

  • The total amount of service charge outstanding across the development.
  • How that total is ageing (for example, 30, 60 and 90-plus days).
  • The number of units in arrears, without identifying which ones.
  • What recovery action is under way in general terms.

This gives the meeting and the board a true picture of the development's financial health without disclosing any individual owner's payment history.

When might naming be lawful?

There are narrow situations where processing named arrears data is legitimate, for example where it is necessary to actually recover a debt, to take legal proceedings, or to comply with a specific legal obligation. Even then, the data should only go to those who genuinely need it for that purpose, such as the OMC's solicitor, and not to the wider membership. The safe default is: aggregate for everyone, named detail only where there is a specific lawful reason, limited to who needs it, and logged.

How to run transparent, GDPR-safe arrears

The practical answer is a system that separates the two views by default. Directors see the totals and the ageing so they can govern; the named, unit-level detail stays with the people running collection, and any exception is recorded. That is exactly how Cuan's director portal works: arrears are shown to the board in aggregate, named detail is a deliberate, logged exception, and the arrears ladder recovers the money without anyone being named to their neighbours.

A simple policy for boards

Put a short arrears-disclosure policy in place: report arrears in aggregate to members and the board; do not circulate lists that identify individuals; route named detail only to those who need it to recover the debt; and log any disclosure. It protects owners' rights, keeps directors on the right side of the law, and still gives everyone a clear view of the development's finances.

Common questions

Generally no. The Data Protection Commission has indicated it is unlikely there is a valid lawful basis for disclosing the service-charge payment details of members to all or some other members without consent. Naming individuals in arrears to the wider membership is therefore usually not permitted.

Next: For the fair, effective way to actually recover what is owed, read Recovering service-charge arrears, humanely.

Note: This guide is general information for managing agents and OMC directors, not legal or financial advice. Cuan encodes these obligations as workflows, but always confirm specifics with the OMC's solicitor, accountant or company secretary.
See it in the product

Transparent with the board. Safe with the data.

Cuan shows directors arrears in aggregate by default and keeps named detail a logged exception, so the board governs without starting a neighbour war.