Can a real-estate agency refuse a tenant's access request?
Only on one of the ten grounds in APP 12.3(a) to (j), and only to the extent that the ground actually applies. If you refuse, or refuse to give access in the way the person asked for, APP 12.9 requires a written notice with your reasons and how to complain. Refusal is rarely the end of the obligation: APP 12.5 still requires such steps (if any) as are reasonable in the circumstances to give access in a way that meets both sides.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
Which refusal grounds are actually available to a real-estate agency?
First, before you consider any of them: satisfy yourself who is actually asking. Verification comes before both access and refusal, and the way to do it is set out in the verification section of tenant access requests: what an agency must hand over. Refusing a genuine request and releasing a file to an impersonator are two different failures, and only one of them is fixable.
A real-estate agency is an organisation, so your grounds are the ten in APP 12.3(a) to (j). The separate grounds in APP 12.2 belong to Commonwealth agencies and are keyed to the Freedom of Information Act 1982 (Cth) and other Commonwealth laws providing access to documents. They are not available to you, and reaching for them is the same agency-versus-organisation trap that catches agencies on response times.
The ones that realistically arise in an agency file:
- APP 12.3(a): the entity reasonably believes that giving access would pose a serious threat to the life, health or safety of any individual, or to public health or public safety. Note that the belief has to be reasonable and you have to be able to explain it. ⚠️ Note also which way the ground runs: the threat must come from giving access to the person asking. It is not a basis for refusing a victim of family violence access to her own record "for her safety". Where the concern is that giving one person their file would expose another person's location or details, that is usually 12.3(b), and it is a redaction problem before it is a refusal. Take advice.
- APP 12.3(b): unreasonable impact on the privacy of other individuals. The common one, because agency files are full of third parties: the landlord, the co-tenant, the neighbour who complained, the tradesperson.
- APP 12.3(c): the request is frivolous or vexatious. A high bar, and a request made during a dispute is not frivolous merely because it is inconvenient.
- APP 12.3(d): the information relates to existing or anticipated legal proceedings between you and the individual, and would not be accessible by discovery in those proceedings.
- APP 12.3(e): access would reveal your intentions in relation to negotiations with the individual, in a way that would prejudice those negotiations.
- APP 12.3(f): giving access would be unlawful. See the AML/CTF point below, which is the live one for agencies from 1 July 2026.
- APP 12.3(g): denying access is required or authorised by or under an Australian law or a court or tribunal order. Do not reach for this on a hunch. You need to be able to name the law or the order.
- APP 12.3(h): you have reason to suspect that unlawful activity, or misconduct of a serious nature, relating to the entity's functions or activities has been, is being or may be engaged in, and giving access would be likely to prejudice the taking of appropriate action. A previous version of this page narrowed the first element too far. The statute says the entity's functions or activities, not "your own conduct", so application fraud against your agency or criminal damage to a property you manage plainly relates. The limb that usually fails is the second: you have to show that giving access would be likely to prejudice the taking of appropriate action, not merely that a suspicion exists. Ordinary arrears will not get you there.
- APP 12.3(i): giving access would be likely to prejudice one or more enforcement-related activities conducted by, or on behalf of, an enforcement body. The operative element is the likely prejudice. The mere fact that an enforcement body is looking at something is not the ground.
- APP 12.3(j): access would reveal evaluative information generated within the entity in connection with a commercially sensitive decision-making process.
Treating "this is inconvenient" or "we are in a dispute" as a general ground is the most common mistake. Being in a dispute is not itself a ground. The dispute-related grounds, 12.3(d) legal proceedings and 12.3(e) negotiations, are narrow, and you have to be able to point to the specific harm.
Why 12.3(f) and (g) suddenly matter to agencies
Until recently these two read as theoretical for a real-estate business. They no longer do.
From 1 July 2026, an agency providing sales-side designated services is a reporting entity under the AML/CTF Act 2006 (Cth). That brings section 123, the tipping-off provision, into your file. Where a suspicious matter report has been made, disclosing certain information about it can be an offence, which means giving access to that material could be unlawful and engage APP 12.3(f), or be prohibited by an Australian law and engage APP 12.3(g).
⚠️ Do not read that as a shield over the whole AML file. The 2025 reforms narrowed s 123 to disclosures that would, or could reasonably be expected to, prejudice an investigation. It is no longer a blanket prohibition on mentioning anything AML-related, and using it as a general reason to withhold a customer's file would be a refusal without a ground. If an access request touches material connected to a suspicious matter report, get advice on that specific request before you answer it, and do not answer it in a way that itself signals the report exists.
Sources: Privacy Act 1988 (Cth), APP 12.2 and APP 12.3(a) to (j) (Schedule 1); Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) s 123, as amended by the 2024 reforms commencing for real-estate designated services on 1 July 2026 · AUSTRAC · OAIC APP Guidelines chapter 12 · OAIC APP guidelines · legislation.gov.au
If a ground applies, can we withhold the whole file?
Usually not. The APP 12.3 grounds apply only to the extent that they are made out, so a ground that touches part of a document does not justify withholding all of it, and a ground that touches one document does not justify withholding the file.
APP 12.5 then requires you to take such steps (if any) as are reasonable in the circumstances to give access in a way that meets both your needs and the individual's. In practice that means partial access, redaction of the material the ground actually protects, or a summary. APP 12.6 adds the option of giving access through a mutually agreed intermediary, which is a genuinely useful route where the sensitivity is about how the information lands rather than about the information itself.
Practical approach: work document by document rather than folder by folder, remove the other person's identifying details rather than their substance where you can, and keep an unredacted copy with a note of what was removed and why. Over-redaction reads as refusal by another route, and a page of black boxes invites a complaint just as a flat refusal does.
Sources: Privacy Act 1988 (Cth), APP 12.3, APP 12.5 and APP 12.6 (Schedule 1) · OAIC APP Guidelines chapter 12 · OAIC APP guidelines
What do we have to tell the person if we refuse?
APP 12.9 requires a written notice, and note that it is triggered by two things: refusing access, and refusing to give access in the manner the person asked for. Telling a tenant "we will not email it, come into the office and read it" engages the same duty as a refusal.
The notice must set out the reasons for the refusal, except to the extent that, having regard to the grounds for refusal, it would be unreasonable to give them. That exception is tied to the ground relied on, not a general escape from explaining yourself. It must also set out the mechanisms available to complain, and any other matter prescribed by the regulations.
Where you refuse under APP 12.3(j), the commercially sensitive evaluative-information ground, APP 12.10 provides that the reasons for the refusal may include an explanation for the commercially sensitive decision. It is an option about what the reasons may contain, not a substitution that discharges the notice duty on its own.
If the person remains dissatisfied, they can complain to your agency first and then to the Office of the Australian Information Commissioner, so a considered written notice is also the cheapest way to end the matter. Failing to give the notice is a cleaner breach than the refusal itself.
Sources: Privacy Act 1988 (Cth), APP 12.9(a) to (c) and APP 12.10 (Schedule 1) · OAIC APP Guidelines chapter 12 · OAIC APP guidelines · OAIC privacy complaints
→ The free 2-minute audit covers the request-handling gaps that turn a routine file request into a complaint.