Case Study: What we can learn from the October 2025 Special Investigation into Lewisham Council and the failings around customer data management
Getting Data Right for Purpose and Trust
Source: Extracted from a recent Housing Ombudsman investigation into Lewisham Council (2025) examining how the landlord’s fragmented data systems and unclear processes undermined its ability to support residents effectively, especially those with additional needs.
Background
The landlord had planned to expand its understanding of who lived in its homes by conducting a large-scale survey. However, its existing data systems were already struggling:
• Resident information was held in multiple unconnected systems
• “Vulnerability flags” were inconsistently recorded and appeared to have disappeared when systems were merged
• Staff were unsure where to look for key information, or whether it was accurate
• Sensitive data was being held outside core systems (for example, in separate spreadsheets)
• Different teams held different versions of the truth
The Ombudsman found that staff genuinely cared about residents’ needs, but their tools and processes failed them. The Ombudsman noted some cultural issues (lack of accountability) and systemic ones (poor data design, inadequate training, no clear ownership).
Key Findings
- Data silos and duplication: Staff across departments used different systems to record repairs, resident information and vulnerability notes, leading to confusion, inconsistency and data loss.
- Loss of critical information: During a system migration, vulnerability flags were lost or changed in format or location. Staff in some teams could not see information recorded by others, depending on which screen or module they used.
- Unverified and unshared information: Vulnerability details told to one officer were not always recorded centrally. In some cases, they were left in emails, not systems.
- Manual workarounds: Housing officers kept separate spreadsheets of “known vulnerabilities” outside the core system, unprotected and invisible to colleagues.
- Impact on residents: Repairs were delayed, and residents repeatedly had to re-explain their circumstances. Some felt unsafe or ignored because their needs were not recognised or prioritised.
- Good intentions, poor infrastructure: Staff showed commitment and compassion, but lacked reliable tools and governance to act on what they knew.
Positive Steps Identified
The Ombudsman recognised that the landlord was trying to improve. Measures included:
• Commissioning an independent review to understand the causes
• Launching a home-check programme (310 visits, 45 referrals for support, 91 repairs identified)
• Introducing a “3 Questions” approach at first contact to update resident details and check for vulnerabilities
• Planning a major data-gathering exercise, with a focus on data that’s actually used for directly improving the service each customer receives, adapted to their particular needs.
The Real Lesson: From data about people to data that helps people
The Ombudsman’s findings underline a vital principle of data protection and information management in housing:
Collect data for a clear purpose that helps residents, not because it might be “nice to know”.
Collecting broad demographic data (ethnicity, religion, sexuality, socio-economic background) without a defined purpose can harm trust and create risk.
By contrast, collecting needs-based information e.g. “does this resident require reasonable adjustments for communication or mobility?” directly supports service delivery and aligns with the Purpose Limitation principle in data protection law.
Lessons Learned
Start with Purpose
Before collecting or refreshing data, ask: What decision or action will this information enable? Who will use it, and how? What outcome for residents will it improve? If you can’t answer those, you probably don’t need the data.
Map and Integrate
Audit where resident information is held. How many systems contain resident data? Do they “talk” to each other? Can staff see what they need at the right point in the process? Create a simple data flow map to visualise where information enters, where it’s stored, and who can access it.
Define Ownership
Avoid the “everyone and no one” problem. Each type of information (repairs, contact details, support needs, tenancy history, etc.) should have a clear owner responsible for quality, consistency and updates.
Record Needs, Not Labels
Design data fields and forms that focus on practical needs rather than personal characteristics.
Keep it in One System
Discourage the use of spreadsheets and “shadow databases.” Ideally, if your current system can’t record what you need, document the gap and escalate it through governance channels rather than creating unmanaged data.
Train and Empower Staff
Customer-facing staff are often the first to hear when residents’ circumstances change. Train them to capture information in the right place, explain why it’s collected, and understand their responsibilities.
Close the Loop
Information should not die in someone’s inbox. Build processes where any new information is verified, logged and visible to others who need to act on it.
Key Takeaway
Purposeful data protects both people and organisations. When we collect only what we need, and use it well, we earn the trust we need to serve effectively.
If you have any further questions or or comments, give me a shout! Clare@cpdataprotection.com

