Do we have to keep tenant and owner records accurate and up to date?
You must take such steps (if any) as are reasonable in the circumstances. APP 10.1 applies to information you collect, requiring reasonable steps to ensure it is accurate, up to date and complete. APP 10.2 applies to information you use or disclose, adding that it must also be relevant, and judged having regard to the purpose of that use or disclosure. Neither limb is a guarantee of accuracy, and APP 10.2 is not a higher standard of care, it is the same reasonable-steps duty with a different content.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
Why does the duty tighten at the moment information leaves the office?
Because relevance and purpose enter the test. Holding a stale mobile number in your CRM is one thing. Passing a stale arrears figure to a landlord, lodging a database listing from an unreconciled ledger, or issuing a notice to a former address is a use or disclosure, and APP 10.2 measures it against the purpose you are using it for and asks whether it was relevant to that purpose as well as accurate.
That is what turns ordinary admin sloppiness into a compliance problem: not the untidy record, but the moment you act on it.
The habits that satisfy it are unglamorous. Reconcile before you report. Confirm contact details at renewal and each inspection cycle. Correct at the point the error is noticed rather than routing it to someone else. Make sure a correction in one system reaches the others.
What is reasonable scales with the consequences of the information being wrong, which is why tenancy-database and arrears data attract far more care than a marketing list.
Sources: Privacy Act 1988 (Cth), APP 10.1 and APP 10.2 (Schedule 1) · OAIC APP Guidelines chapter 10 · OAIC APP guidelines
What happens if we act on out-of-date information about a tenant or owner?
Acting on information you should have checked can be a failure to take reasonable steps under APP 10.2.
The scenarios repeat across the industry: a breach notice sent to a former address, a landlord told a tenant is in arrears when the payment had cleared, a database listing lodged from a ledger nobody reconciled, a rejection based on a superseded reference. Each is a use or disclosure of information that was not accurate at the moment it was relied on, and the harm lands on the person rather than on the file.
Build one check into the workflows where the consequence is highest. Before any notice, any landlord report and any external listing, confirm the record is current.
Where the error caused a disclosure to the wrong person, for example a notice containing personal information sent to a former address, consider whether the Notifiable Data Breaches scheme is engaged. Assess whether it is likely to result in serious harm, and note that the assessment clock in s 26WH(2) is 30 days from having reasonable grounds to suspect, which the OAIC treats as a ceiling, not a target.
Sources: Privacy Act 1988 (Cth), APP 10.2 (Schedule 1) and s 26WH(2) · OAIC APP Guidelines chapter 10 · OAIC notifiable data breaches · See also data-breach response for real estate
Do we have to check that what a rental applicant tells us is actually true?
APP 10 is not a duty to investigate people, and it does not make you the guarantor of an applicant's honesty.
This is the misreading that pushes offices toward collecting more than they need, on the theory that accuracy requires verification and verification requires documents. It runs straight into APP 3.2, which limits collection to what is reasonably necessary. The two reconcile easily: verify proportionately, using the least revealing evidence that answers the question, and record what you verified and when.
Where you cannot verify something, note that it is unverified rather than presenting it downstream as established fact. Passing an unverified claim to a landlord as though it had been checked is where APP 10.2 actually bites, because both relevance and purpose are in play at the moment of disclosure.
Reasonable steps scale with sensitivity and consequence, so identity and affordability warrant more care than a preferred move-in date.
Sources: Privacy Act 1988 (Cth), APP 3.2, APP 10.1 and APP 10.2 (Schedule 1) · OAIC APP Guidelines chapters 3 and 10 · OAIC APP guidelines
What happens once someone tells us a record is wrong?
The duty shifts to APP 13, which requires such steps (if any) as are reasonable in the circumstances to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading, having regard to the purpose for which it is held. That duty runs both on request and on your own initiative once you become aware, so noticing the error yourself engages it too.
Under APP 13.2, where you have corrected information you previously disclosed to another APP entity and the individual asks you to notify them, take reasonable steps to do so unless it is impracticable or unlawful. A tenancy-database operator is an APP entity for these activities whatever its turnover. A private landlord usually is not, so notifying an owner is supported by APP 10.2 rather than compelled by APP 13.2.
Sources: Privacy Act 1988 (Cth), APP 10.2, APP 13.1 and APP 13.2 (Schedule 1) · OAIC APP Guidelines chapters 10 and 13 · OAIC APP guidelines
→ The free 2-minute audit checks whether a correction made in one of your systems actually reaches the others.