Can a real-estate agency refuse a tenant's access request?
Only on one of the ten grounds in APP 12.3(a) to (j), and only to the extent that the ground actually applies. If you refuse, or refuse to give access in the way the person asked for, APP 12.9 requires a written notice with your reasons and how to complain. Refusal is rarely the end of the obligation: APP 12.5 still requires such steps (if any) as are reasonable in the circumstances to give access in a way that meets both sides.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
Which refusal grounds are actually available to a real-estate agency?
First, before you consider any of them: satisfy yourself who is actually asking. Verification comes before both access and refusal, and the way to do it is set out in the verification section of tenant access requests: what an agency must hand over. Refusing a genuine request and releasing a file to an impersonator are two different failures, and only one of them is fixable.
A real-estate agency is an organisation, so your grounds are the ten in APP 12.3(a) to (j). The separate grounds in APP 12.2 belong to Commonwealth agencies and are keyed to the Freedom of Information Act 1982 (Cth) and other Commonwealth laws providing access to documents. They are not available to you, and reaching for them is the same agency-versus-organisation trap that catches agencies on response times.
The ones that realistically arise in an agency file:
- APP 12.3(a): the entity reasonably believes that giving access would pose a serious threat to the life, health or safety of any individual, or to public health or public safety. Note which way the ground runs: the threat has to be created by giving access, and the belief has to be one you can explain. "Any individual" does include the person asking, and the OAIC's own example under this ground is a provider who believes access "may cause that person significant distress or lead to self-harm". What it is not is a general safety veto over a tenant's own file. Where the real concern is that giving one person their file would expose another person's location or details, that is 12.3(b), and it is a redaction problem before it is a refusal. Take advice.
- APP 12.3(b): unreasonable impact on the privacy of other individuals. The common one, because agency files are full of third parties: the landlord, the co-tenant, the neighbour who complained, the tradesperson.
- APP 12.3(c): the request is frivolous or vexatious. A high bar, and a request made during a dispute is not frivolous merely because it is inconvenient.
- APP 12.3(d): the information relates to existing or anticipated legal proceedings between you and the individual, and would not be accessible by the process of discovery in those proceedings. Both limbs have to hold, and "anticipated" is the OAIC's "real prospect of proceedings being commenced, as distinct from a mere possibility", not a dispute you expect to argue.
- APP 12.3(e): access would reveal your intentions in relation to negotiations with the individual, in a way that would prejudice those negotiations.
- APP 12.3(f): giving access would be unlawful. See the AML/CTF point below, which becomes live for agencies when the suspicious-matter reporting obligations start on 1 July 2026.
- APP 12.3(g): denying access is required or authorised by or under an Australian law or a court or tribunal order. Do not reach for this on a hunch. You need to be able to name the law or the order.
- APP 12.3(h): you have reason to suspect that unlawful activity, or misconduct of a serious nature, relating to the entity's functions or activities has been, is being or may be engaged in, and giving access would be likely to prejudice the taking of appropriate action. A previous version of this page narrowed the first element too far. The statute says the entity's functions or activities, not "your own conduct", so application fraud against your agency or criminal damage to a property you manage plainly relates. The limb that usually fails is the second: you have to show that giving access would be likely to prejudice the taking of appropriate action, not merely that a suspicion exists. Ordinary arrears will not get you there.
- APP 12.3(i): giving access would be likely to prejudice one or more enforcement-related activities conducted by, or on behalf of, an enforcement body. The operative element is the likely prejudice. The mere fact that an enforcement body is looking at something is not the ground.
- APP 12.3(j): access would reveal evaluative information generated within the entity in connection with a commercially sensitive decision-making process.
Treating "this is inconvenient" or "we are in a dispute" as a general ground is the most common mistake. Being in a dispute is not itself a ground. The dispute-related grounds, 12.3(d) legal proceedings and 12.3(e) negotiations, are narrow, and you have to be able to point to the specific harm.
Why 12.3(f) and (g) suddenly matter to agencies
Until recently these two read as theoretical for a real-estate business. They no longer do.
From 31 March 2026, an agency providing sales-side designated services is a reporting entity under the AML/CTF Act 2006 (Cth). That brings section 123, the tipping-off provision, into your file. Where a suspicious matter report has been made, disclosing certain information about it can be an offence carrying imprisonment for 2 years or 120 penalty units, or both (s 123(1)), which means giving access to that material could be unlawful and engage APP 12.3(f), or be prohibited by an Australian law and engage APP 12.3(g).
⚠️ Do not read that as a shield over the whole AML file. The 2024 amendments (Act No. 110, 2024) narrowed s 123: under s 123(1)(d) the offence now reaches only a disclosure that would, or could reasonably be expected to, prejudice an investigation. It is no longer a blanket prohibition on mentioning anything AML-related, and using it as a general reason to withhold a customer's file would be a refusal without a ground. If an access request touches material connected to a suspicious matter report, get advice on that specific request before you answer it, and do not answer it in a way that itself signals the report exists.
Sources: Privacy Act 1988 (Cth), APP 12.2 and APP 12.3(a) to (j) (Schedule 1); Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) s 123, as amended by the 2024 reforms, which commenced for real-estate designated services on 31 March 2026 with the AML obligations from 1 July 2026 · AUSTRAC · OAIC APP Guidelines chapter 12 · OAIC APP guidelines · legislation.gov.au
If a ground applies, can we withhold the whole file?
Usually not. The APP 12.3 grounds apply only to the extent that they are made out, so a ground that touches part of a document does not justify withholding all of it, and a ground that touches one document does not justify withholding the file.
APP 12.5 then requires you to take such steps (if any) as are reasonable in the circumstances to give access in a way that meets both your needs and the individual's. In practice that means partial access, redaction of the material the ground actually protects, or a summary. APP 12.6 adds the option of giving access through a mutually agreed intermediary, which is a genuinely useful route where the sensitivity is about how the information lands rather than about the information itself.
Practical approach: work document by document rather than folder by folder, remove the other person's identifying details rather than their substance where you can, and keep an unredacted copy with a note of what was removed and why. Over-redaction reads as refusal by another route, and a page of black boxes invites a complaint just as a flat refusal does.
Sources: Privacy Act 1988 (Cth), APP 12.3, APP 12.5 and APP 12.6 (Schedule 1) · OAIC APP Guidelines chapter 12 · OAIC APP guidelines
What do we have to tell the person if we refuse?
APP 12.9 requires a written notice, and note that it is triggered by two things: refusing access, and refusing to give access in the manner the person asked for. Telling a tenant "we will not email it, come into the office and read it" engages the same duty as a refusal.
The notice must set out the reasons for the refusal, except to the extent that, having regard to the grounds for refusal, it would be unreasonable to give them. That exception is tied to the ground relied on, not a general escape from explaining yourself. It must also set out the mechanisms available to complain, and any other matter prescribed by the regulations.
Where you refuse under APP 12.3(j), the commercially sensitive evaluative-information ground, APP 12.10 provides that the reasons for the refusal may include an explanation for the commercially sensitive decision. It is an option about what the reasons may contain, not a substitution that discharges the notice duty on its own.
If the person remains dissatisfied they can complain to you and then to the Office of the Australian Information Commissioner, and under s 40(1A) the Commissioner must not investigate a complaint the person did not put to you first, unless it was not appropriate for them to. A considered written notice is the cheapest place for this to end. Failing to give it is also a cleaner breach than the refusal itself: s 13(1)(a) makes an act that breaches an APP an interference with the privacy of an individual, and whether you sent a notice is a matter of record while your ground is arguable.
Sources: Privacy Act 1988 (Cth), APP 12.9(a) to (c) and APP 12.10 (Schedule 1) · OAIC APP Guidelines chapter 12 · OAIC APP guidelines · OAIC privacy complaints
→ The free 2-minute audit covers the request-handling gaps that turn a routine file request into a complaint.