Skip to content

What must a real-estate agency do when a tenant says our records about them are wrong?

Take such steps (if any) as are reasonable in the circumstances to correct the information. APP 13.1 has two triggers, and the request is only one of them: the duty arises where you are satisfied the information is inaccurate, out of date, incomplete, irrelevant or misleading having regard to a purpose for which it is held, or where the individual asks you to correct it. Correction is free, you must respond within a reasonable period, and if you decline you must give written reasons and, if asked, take reasonable steps to associate a statement of the person's disagreement with the record.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price

Orientation only, not a compliance assessment. General information and tools, not legal advice.

When does the duty actually start?

On either of two events, and this is the part most agencies read past.

APP 13.1(b)(i): you are satisfied that, having regard to a purpose for which you hold it, the information is inaccurate, out of date, incomplete, irrelevant or misleading. Nobody has to ask you. If you spot a wrong figure in a ledger while doing something else, the duty is live from that moment.

APP 13.1(b)(ii): the individual requests you to correct the information. That is the trigger on its own. You do not have to agree with the tenant for the duty to start, and "we do not accept the record is wrong" is not a reason to do nothing. It is the answer to a different question, which is what steps are reasonable, and if you land on none you still owe the person the written notice under APP 13.3.

What the duty then requires in both cases is such steps (if any) as are reasonable in the circumstances. That qualifier is real, and it is what stops a request being a guaranteed outcome. But it attaches to the steps, not to whether the duty exists.

What kinds of records does this actually catch in an agency?

More than a wrong phone number. The five descriptions in APP 13.1(b)(i) are inaccurate, out of date, incomplete, irrelevant and misleading, and the last three do a lot of work in a property-management file:

Note the qualifier that does real work here: the test is applied having regard to the purpose for which the information is held. Whether an old income record is "irrelevant" depends entirely on what you still hold it for. That is also why the duty is one of reasonable steps rather than a guaranteed outcome.

Because a correction request usually arrives with heat behind it, it helps to separate the two questions: is the record accurate for the purpose we hold it, and is the person upset. Only the first is what APP 13 asks you.

Sources: Privacy Act 1988 (Cth), APP 13.1 (Schedule 1) · OAIC APP Guidelines chapter 13 · OAIC APP guidelines · legislation.gov.au

How long do we have to respond to a correction request?

APP 13.5(a)(ii) requires an organisation to respond within a reasonable period after the request is made. The OAIC applies the same benchmark it uses for access: as a general guide, a reasonable period should not ordinarily exceed 30 calendar days.

Where the correction concerns a tenancy-database listing, the state clock is far shorter than anything in the Privacy Act, and it does not wait for a request: 7 days from when you become aware, in every state and territory. Check that first.

APP 13.5(b) means you cannot charge for making the request, for correcting the information, or for associating a statement with it.

Sources: Privacy Act 1988 (Cth), APP 13.5(a)(ii) and APP 13.5(b) (Schedule 1) · OAIC APP Guidelines chapter 13, paragraph 13.63 · OAIC APP guidelines

Do we have to tell the landlord or the database that we corrected something?

APP 13.2 covers one specific case: where you have corrected information you previously disclosed to another APP entity, and the individual asks you to notify them, you must take such steps (if any) as are reasonable in the circumstances to do so unless it is impracticable or unlawful.

⚠️ Do not route the tenancy-database duty through APP 13.2. APP 13.2 only bites if the individual asks. The state and territory duty to tell a database operator about a wrong listing does not depend on anyone asking you: it runs from the moment you become aware, and the period is 7 days in all eight jurisdictions. Residential Tenancies Act 2010 (NSW) s 214(2), Residential Tenancies Act 1997 (Vic) s 439G(2), Residential Tenancies and Rooming Accommodation Act 2008 (Qld) s 459A(2), Residential Tenancies Act 1987 (WA) s 82G(2), Residential Tenancies Act 1995 (SA) s 99H(2), Residential Tenancy Act 1997 (Tas) s 48ZA(2), Residential Tenancies Act 1997 (ACT) s 93(2), Residential Tenancies Act 1999 (NT) s 130(2). If you become aware a listing you made is wrong, the clock has already started, and waiting for a request is how agencies miss it.

That distinction matters in property management, because the two parties you disclose to are treated differently. A tenancy-database operator is an APP entity for its database activities whatever its turnover, so it sits squarely inside APP 13.2. An individual residential landlord usually is not an APP entity at all, so notifying them is good practice rather than something APP 13.2 compels.

There is still an independent reason to do it. APP 10.2 requires such steps (if any) as are reasonable in the circumstances to ensure that information you use or disclose is accurate, up to date, complete and relevant, having regard to the purpose of the use or disclosure. If you corrected a ledger error you had already reported to an owner, the corrected version needs to chase the same path the error took, or the wrong figure keeps circulating.

Keep a disclosure record per matter, so that "who did we send this to" is a lookup rather than an archaeology exercise.

Sources: Privacy Act 1988 (Cth), APP 10.2 and APP 13.2 (Schedule 1); s 6E(2) and the Privacy Regulations 2025 (Cth) ss 5 and 7(1)-(2), commenced 1 April 2026, under which an operator of a residential tenancy database is treated as an organisation regardless of turnover, with that treatment confined to the prescribed database acts and practices, so the coverage is for their database activities, and under which such a database must both hold tenancy-occupation information and be accessible to someone other than the operator; the relevant state or territory Residential Tenancies Act as pinned above · OAIC APP Guidelines chapters 10 and 13 · OAIC APP guidelines

What if we do not agree that the information is wrong?

You can decline to correct it. APP 13.3 then requires a written notice setting out the reasons for the refusal, except to the extent it would be unreasonable to do so, and the mechanisms available to complain.

If the individual then asks, APP 13.4 requires you to take reasonable steps to associate a statement of their disagreement with the information, in a way that makes it apparent to users of the information. It is a reasonable-steps duty about how the statement is associated, not a guarantee that every future reader will see it.

The statement of disagreement is the release valve that keeps a genuine factual dispute from becoming a complaint, and almost no agency uses it. A tenant insists an arrears note is wrong, your ledger says otherwise, so instead of a stand-off you record your reasons in writing and attach their statement to the record. Attach it in the CRM where the note actually lives, not in a separate folder, because that is what "apparent to users" means in practice.

Refusing without the written notice is a cleaner breach than the disagreement itself.

Sources: Privacy Act 1988 (Cth), APP 13.3(a) to (c) and APP 13.4 (Schedule 1) · OAIC APP Guidelines chapter 13 · OAIC APP guidelines · OAIC privacy complaints

→ The free 2-minute audit maps where tenant data actually sits, which is the thing that makes a correction reach every copy of the record.