A tenant has asked for everything we hold about them. Do we have to give it to them?
Yes, in the ordinary case. APP 12.1 requires an organisation to give an individual access to the personal information it holds about them on request, and an organisation may only refuse on one of the ten grounds in APP 12.3(a) to (j). Before you collate anything, satisfy yourself the request actually comes from that individual or from someone authorised to act for them.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
How do we confirm the request really comes from the tenant?
Do this first, before you collate anything. You must be satisfied the request comes from the individual, or from someone authorised to act for them.
Verify proportionately. Matching details you already hold is usually enough, and you should collect only the minimum needed to do it, because an identity check is itself a collection of personal information.
Be careful about the channel you send to, and be careful in both directions. Most access requests come from former tenants whose email address, phone number and postal address have all changed since the file was created, so the details sitting on the tenancy record are not a safe default. They may be exactly the details a former partner still controls. Equally, do not simply act on new contact details supplied in the request itself. Where a request gives you new details, confirm the change independently through a channel you already have before you send anything. And where a solicitor, tenants' advocate or attorney is acting, what you verify is the authority, not the channel: correspondence to a firm's own address is normal and is not a warning sign.
The reason this matters more in property management than in most industries is the content of the file. It holds identity-document scans, income evidence, bank details and often a forwarding address. The foreseeable failure is not a stranger guessing: it is a former partner who knows enough of the file to sound convincing. Releasing to them would be an unauthorised disclosure under APP 6, a security failure under APP 11.1, and quite possibly an eligible data breach under Part IIIC of the Act.
Treat a request for a forwarding address, a co-tenant's details or inspection photographs as one that needs verification before release, not after.
Sources: Privacy Act 1988 (Cth), APP 6, APP 11 and APP 12 (Schedule 1); Part IIIC (notifiable data breaches) · OAIC APP Guidelines chapter 12, paragraphs 12.15 to 12.17 · OAIC APP guidelines
What does an access request actually look like in an agency?
It will not arrive labelled as an APP 12 request. It arrives as "can you send me my file", and it usually arrives in the middle of a dispute about a bond, a repair, arrears or a notice to vacate. That timing is the first problem, because the person who receives it is often the property manager who is a party to that dispute.
The second problem is that the information is scattered. A tenant's personal information sits in the CRM record, the original application, the ledger, inspection reports and photos, the maintenance thread, the email chain, and often the SMS history on a work phone. All of it is within scope if it holds personal information about the person making the request. Information held for you in a supplier's system, such as a cloud CRM or a renttech platform, is still information you hold, so your process has to be able to reach it.
The tension of the underlying dispute is not a reason to slow the request down. Delay is the failure mode that turns a routine file request into an OAIC complaint. Decide now who in the office owns these requests and where the checklist lives, before one arrives.
Can someone else make the request for the tenant?
Yes, and this is where a literal reading of "it has to come from the individual" causes a real error. A request made on the individual's behalf by a solicitor, a tenants' advocate, a community legal centre, a support worker, or an attorney under an enduring power is that individual's APP 12 request, and tenant requests very often arrive exactly this way.
Ask for evidence of the authority. Do not ask why they want it, and do not treat the involvement of an advocate as a reason to be more restrictive.
What is genuinely outside APP 12 is a request by someone seeking another person's information for their own purposes. A landlord asking for a tenant's file is not making an APP 12 request, because APP 12 is a right of access to your own personal information. Whether you may share tenant information with an owner at all is a separate question under APP 6.
Sources: Privacy Act 1988 (Cth), APP 6 and APP 12 (Schedule 1) · OAIC APP Guidelines chapter 12, paragraphs 12.15 to 12.17 · OAIC APP guidelines
What does APP 12 require?
APP 12.1 requires an APP entity that holds personal information about an individual to give that individual access to it on request, subject to the exceptions in the principle. An organisation may refuse only on one of the grounds in APP 12.3(a) to (j). The separate grounds in APP 12.2 apply to Commonwealth agencies and are keyed to the Freedom of Information Act 1982 (Cth) and other Commonwealth laws providing access to documents, so they are not available to a real-estate agency.
APP 12.4(a)(ii) requires an organisation to respond within a reasonable period. Responding means giving access or notifying a refusal, so an acknowledgement is not a response and does not stop the clock. An agency that is still compiling when the reasonable period runs out has done neither of the two things that count. If a large compilation is going to run past the reasonable period, say so in writing before it expires, give the person a date, and give access to the part you have already assembled rather than holding everything until the last document is found. Giving access in the manner requested sits separately in APP 12.4(b), where that is reasonable and practicable, and APP 12.5 requires such steps (if any) as are reasonable in the circumstances to give access in a way that meets both your needs and the individual's where the manner asked for is not workable.
Sources: Privacy Act 1988 (Cth), APP 12.1 to 12.5 (Schedule 1) · OAIC APP Guidelines chapter 12, paragraph 12.67 (the organisation limb; 12.66 is the agency limb) · OAIC APP guidelines · legislation.gov.au
Can we charge a tenant or applicant for access to their information?
An organisation may charge for giving access under APP 12.8, but the charge must not be excessive and must not apply to the making of the request. The widespread belief that access is always free comes from APP 12.7, which prohibits Commonwealth agencies from charging at all. That limb does not apply to you: you are an organisation, so APP 12.8 is your provision.
For almost every request a real-estate agency receives, the right answer is still to charge nothing. The information is usually a CRM export, an application and an email thread, so a fee is hard to justify as anything other than friction, and friction is what a regulator looks at when someone complains. Where a request is genuinely large, for example years of inspection photographs and video, a modest cost-recovery charge for the compilation can be defensible if you set it out in advance and can explain how it was calculated. Do not make payment a condition of even beginning work. APP 12.8 prohibits charging for the making of the request, so treating a fee as the price of starting risks breaching that prohibition rather than merely reading as poor practice.
Note the contrast with correction: APP 13.5(b) means you cannot charge for making a correction request, for correcting the information, or for associating a statement of disagreement with it.
Sources: Privacy Act 1988 (Cth), APP 12.7, APP 12.8 and APP 13.5(b) (Schedule 1) · OAIC APP Guidelines chapters 12 and 13 · OAIC APP guidelines
Does an access request cover our internal notes, emails and the landlord's comments?
Generally yes. APP 12 covers the personal information you hold about the person, and the definition of personal information in section 6 of the Privacy Act does not care whether the information is flattering, informal, or recorded in a file note rather than on a form. An opinion about a person is personal information about that person.
This is the answer that changes behaviour, so it is worth saying plainly to staff: assume every CRM note, inspection comment and internal email about a tenant could one day be read by that tenant. A note reading "difficult, avoid renewing", or a landlord's forwarded opinion about an applicant, is in scope.
The correct response is not to stop keeping records, which would create accuracy problems of its own under APP 10. It is to write notes that are factual, relevant and defensible: record the behaviour and the date rather than the character judgment.
Where a document also contains a third party's personal information, for example the landlord's own comments and contact details, APP 12.3(b) (unreasonable impact on the privacy of other individuals) is engaged. Because the APP 12.3 grounds apply only to the extent that they are made out, that generally means redacting the third party's material and releasing the rest, rather than withholding the document.
Sources: Privacy Act 1988 (Cth), section 6 (personal information, includes opinions) and APP 10, APP 12.3(b) and APP 12.5 (Schedule 1) · OAIC APP Guidelines chapter 12 · OAIC APP guidelines
A rejected rental applicant wants to know why. Do we have to tell them?
The Privacy Act does not give a general right to an explanation of a leasing decision, but it does give a right of access under APP 12 to the personal information you hold about the applicant, which in practice is where the reasons usually live.
So the honest framing for staff is that you may not owe an explanation, but you may well have to hand over the file that contains one. That is a strong argument for making sure the file supports the decision: dated, factual, and tied to the criteria you actually applied.
⚠️ If you searched a tenancy database, you may already owe the applicant a written notice, whether or not they ever ask. This one sits in state and territory tenancy law, not the Privacy Act, and it is the duty agencies miss most often, because far more agencies search databases than ever list on them.
In all eight jurisdictions, where you search a residential tenancy database and the search discloses a listing about the applicant, you must give that person written notice of the listing within 7 days: Residential Tenancies Act 2010 (NSW) s 211(2), Residential Tenancies Act 1997 (Vic) s 439D(2), Residential Tenancies and Rooming Accommodation Act 2008 (Qld) s 458B(2), Residential Tenancies Act 1987 (WA) s 82D(2), Residential Tenancies Act 1995 (SA) s 99E(2), Residential Tenancy Act 1997 (Tas) s 48X(2), Residential Tenancies Act 1997 (ACT) s 90(2), Residential Tenancies Act 1999 (NT) s 127. What the notice must contain differs by jurisdiction, so do not work from one template. Both pinned jurisdictions require four items, and they are not the same four.
NSW s 211(2): that personal information about the applicant is in the database; particulars of the landlord or agent who listed it, and the right to seek a copy from that person; how to contact the database operator and obtain information from it; and how and in what circumstances the applicant can have the information removed or amended.
SA s 99E(2): the name of the database; that personal information about the applicant is in it; the name of each person who listed it (s 99E(3) limits this to persons the database itself identifies as the lister); and how and in what circumstances it can be removed or amended.
⚠️ Note what SA does not require and NSW does: operator contact details, and how to obtain a copy. And note what both require and agencies most often leave out: who listed the information, and how to get it removed or amended. Those are the two items the tenant actually needs.
Six of the eight back that duty with a penalty, and the exposure is not token: up to $35,000 in South Australia. Seven of the eight, all but New South Wales, separately require you to disclose up front, at or before the point of taking an application, which databases you usually use and how the applicant can contact them.
The practical consequence is that the rejected applicant asking "why" is often asking after the point at which you already owed them something in writing on a 7-day clock. Put both notices into the application workflow, not into the rejection conversation, and keep a dated record that they went out.
Two adjacent points matter. The landlord ordinarily makes the selection, so the agency should not invent a reason on the landlord's behalf, and any note recording the landlord's instruction is itself personal information about the applicant. And where the file contains evaluative information generated within the entity in connection with a commercially sensitive decision-making process, APP 12.3(j) can support withholding that specific material, and APP 12.10 provides that the reasons given in the refusal notice may include an explanation for the commercially sensitive decision.
If the applicant believes information you relied on was wrong, that becomes an APP 13 correction request.
A note on automated screening: the automated decision-making transparency rule commencing 10 December 2026 inserts APP 1.7 to 1.9 and is not yet in force. Be clear about what it will and will not do. It imposes a privacy-policy disclosure duty: where a computer program is used in the circumstances described, the entity must say so in its privacy policy and set out the kinds of personal information used and the kinds of decisions made. It does not regulate the tool, and it gives an individual no right to an explanation of a decision made about them. Do not tell a rejected applicant that the rule will entitle them to one.
The threshold reaches a program that makes a decision, or that does something substantially and directly related to making one, where the decision could reasonably be expected to significantly affect an individual's rights or interests. That second limb is aimed squarely at upstream scoring and ranking rather than only at the final click, and it is untested, so do not assume a tool that "only sorts" or "only shortlists" falls outside it. Work out now which programs touch your application decisions, and revisit the question before the rule commences.
Sources: Privacy Act 1988 (Cth), APP 12.3(j), APP 12.10 and APP 13 (Schedule 1); Privacy and Other Legislation Amendment Act 2024 (Cth), Act No. 128 of 2024, Schedule 1 Part 15, inserting APP 1.7 to 1.9, commencing 10 December 2026; state and territory tenancy-database search-notice provisions as pinned above · OAIC APP Guidelines chapter 12 · OAIC APP guidelines
→ Not sure whether your agency has an access-request process at all? The free 2-minute audit is the fastest way to find out, and that gap is the usual one.