How long should a real-estate agency keep personal information? (retention & destruction, APP 11)
There's no single number. APP 11 pulls two ways: keep the personal information you hold secure, then destroy or de-identify it once you no longer need it for a permitted purpose. APP 11.2(d) switches the destroy duty off for information an Australian law requires you to retain, so a statutory keep-period never collides with it. Those keep-periods differ, and so do their start dates: AML customer-due-diligence records run seven years from the day the business relationship ends (AML/CTF Act s 111(2)). The workable answer: keep what a law actually requires, hold it securely, and delete the rest on a defined trigger.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Retention periods depend on your state and your circumstances, so confirm the period that applies to you.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
What does APP 11 actually require about keeping personal information?
APP 11 has two limbs, and retention sits in the second. APP 11.1 says you must take reasonable steps to protect the personal information you hold from misuse, interference, loss, and unauthorised access or disclosure. APP 11.2 says you must take reasonable steps to destroy or de-identify personal information once you no longer need it for any purpose for which it may be used or disclosed under the APPs, unless you are required by an Australian law or a court/tribunal order to retain it, or it sits in a Commonwealth record. So the Privacy Act never sets a "keep it for X years" figure. It sets a principle: hold it while you genuinely need it, protect it the whole time, then let it go.
The default is minimise-and-destroy, not keep-everything
The mindset APP 11 expects is the opposite of hoarding. The default posture under the Privacy Act is that personal information is a liability you dispose of when its job is done, not an asset you keep. Every extra record you hold past its usefulness is data you now have to secure, data that widens the blast radius if you're breached, and data an individual could ask you to account for. Put it to your own office: for the oldest rental application still on your server, what permitted purpose are you holding it for? If the honest answer is "just in case", that is the exact pattern APP 11.2 is aimed at. The discipline is to know, for each type of information you hold, why you still have it and when it goes.
Which records does a real-estate agency actually hold?
The reason "how long" has no single answer is that an agency holds several different kinds of personal information, each with a different driver. A sales file, a rent roll, a pile of unsuccessful rental applications, and a folder of AML identity documents are governed by different rules and different clocks. Before you can set retention, you have to name what you hold:
| Information type | What tends to drive the keep-period |
|---|---|
| Vendor / buyer sales records, trust-account records | State agents and trust-account legislation, and the clock differs by state (NSW: at least 3 years after the record is made, Property and Stock Agents Act 2002 s 104(2)) |
| Signed leases, condition reports, tenancy files | State agents record rules. Tenancy legislation sets document duties without always setting a period (NSW s 26(3) names no years) |
| Rental applications, successful | Kept while managing the tenancy, then whatever period your state's agents legislation sets for the file |
| Rental applications, unsuccessful | No ongoing need once the tenancy is filled, short retention |
| AML/CTF customer-due-diligence (ID) records | AML/CTF Act s 111(2): seven years from the day the business relationship ends |
| Marketing / enquiry lists, open-home sheets | Only while the person is a live prospect, no long keep-driver |
State minimums are mandatory and differ in the number and in the clock: NSW gives agency records at least 3 years after the record is made (Property and Stock Agents Act 2002 s 104(2)), while the AML customer-due-diligence clock does not start until the business relationship ends (s 111(2)). Treat this as the shape of the problem, not a schedule, and check the figure for the state the property is in.
Tenancy-application data is where over-retention bites hardest
If you fix only one thing, fix unsuccessful rental applications. A rental application is the densest collection of personal information your agency ever takes: identity, date of birth, income evidence, bank statements, rental history, referees, sometimes a tenancy-database check. For every property, you collect that from several applicants and can only approve one. The unsuccessful applicants' files have no ongoing purpose the moment the tenancy is filled. Test it rather than take our word for it: pick a property you let two years ago, search your inbox and your application platform for it, and count the applicants whose bank statements you still hold. Under APP 11.2 anything you find is over-retention of exactly the most sensitive data you handle. The realistic rule: once a tenancy is decided, destroy or de-identify the unsuccessful applicants' information promptly, unless a genuine dispute or legal requirement means you need to keep it. (What you must tell applicants when you collect it is a separate duty, see the tenancy-application collection notice.)
The AML seven-year record vs APP 11: destroy the copy, keep the record
This is the tension people ask about, and it resolves more cleanly than it looks. Agencies providing a designated real-estate service have been reporting entities since 31 March 2026, and the Part 10 record-keeping obligations applied to them from 1 July 2026. Those obligations are not one seven-year rule but three, each with its own start date: transaction records, seven years beginning on the day the record is made (s 107(3)); a document the customer gave you, seven years after the giving of the document (s 108(2)); customer-due-diligence records, seven years beginning when the business relationship ends (s 111(2)). Section 6E(1A) then applies the Privacy Act to a small-business agency in relation to the activities it carries on for the purposes of, or in connection with, activities relating to the AML/CTF Act, so what is covered is the activity, not the identity data alone, and the A$3 million small-business threshold still exists alongside it. APP 11.2 does not force you to breach any of this: APP 11.2(d) switches the destroy duty off for information an Australian law requires you to retain. What APP 11 targets is everything the AML rules never asked you to keep: the duplicate passport scan on an agent's phone, the copy emailed around the office, the identity file still on a shared drive after its own clock has run. The reconciliation, in a phrase: keep the one record the law requires for the period its own section gives it, and destroy the stray copies now. Does your AML pack name which of the three clocks each record sits on? For handling that AML identity data specifically, see what to do with the ID documents AUSTRAC makes you collect.
One part of this runs the opposite way to the usual advice, and it is the bit that catches offices out. The standing habit for an identity check is to record the details you relied on and keep no copy of the document itself, which fits s 111(3)(a): it asks for records demonstrating the type and content of the data collected, not the image. Section 108 sits alongside it and does reach the document, but it has two scope conditions and both matter. The document must relate to the provision, or prospective provision, of a designated service, and you must have commenced to provide that service (s 108(1)). Where both are met, s 108(2) requires you to retain the document or a copy for 7 years after the giving of the document, and s 108(3) makes that a civil penalty provision. So an attachment sent during an enquiry that never becomes an engagement is not caught at all, while a licence scan emailed by a client you go on to act for is. The practical answer is to tell clients what to send before they send it, because once it arrives s 108 has made the choice for you.
What are realistic prompts to actually destroy?
A retention rule that never fires is not compliance. The reason personal information piles up isn't bad intent; it's that nobody has defined the event that starts the "no longer needed" clock. So set concrete, realistic prompts rather than a vague "review annually":
- Tenancy filled → destroy/de-identify unsuccessful applications (subject to any live dispute).
- Tenancy ended + your state's agents-record minimum passed + no bond claim or tribunal matter pending → dispose of the tenancy file.
- Sale settled + state agents/trust-account minimum passed → dispose of the sales/trust records.
- Business relationship ends, then seven years (s 111(2)) → destroy the CDD records; a document the client sent you runs its own seven years from when it was given (s 108(2)).
- Prospect goes cold / unsubscribes → clear enquiry and marketing records with no keep-driver.
"Destroy" means reasonable steps proportionate to the sensitivity: secure deletion of electronic files including backups and cloud copies on a realistic cycle, shredding of paper, or de-identification where you want aggregate data but no longer need to identify anyone. Noting what you destroyed and when is part of being able to show you took reasonable steps.
Build a one-page retention schedule (or use one)
The practical answer to "how long" is a schedule, not a number. A workable retention schedule is a short table: each information type, the law or purpose that drives its keep-period, the date the clock starts (usually tenancy end, settlement, or the end of the customer relationship), the destruction trigger, and the method. That turns a genuine legal tension into a routine anyone in the office can follow, and it feeds your other obligations: the data you map here is the data your privacy policy describes and your data breach response plan protects. Privaproof's Kit includes a retention-and-destruction schedule mapped to real-estate record types so you're not building it from a blank page. Not sure where you stand today? The fastest way to find your gaps is the free 2-minute self-audit; it flags whether you have a retention schedule at all and whether old records are being disposed of.
Common questions
Does the Privacy Act say how many years to keep records?
No. The Privacy Act and APP 11 set a principle, not a period: destroy or de-identify personal information once you no longer need it, unless an Australian law or a court/tribunal order requires you to keep it (APP 11.2(d)). The actual keep-periods come from other laws: state agents and trust-account rules (NSW: at least 3 years after the record is made, Property and Stock Agents Act 2002 s 104(2)) and the AML/CTF record-keeping sections, which is why the answer varies by record type and by state.
Doesn't APP 11 mean I have to delete everything?
Not the records you're legally required to keep. APP 11.2(d) carves out personal information you're required by an Australian law or a court/tribunal order to retain. Your state agents and trust-account minimums and the AML/CTF retention sections are exactly that kind of requirement, so holding those records for their own period is consistent with APP 11. The destroy duty bites on information that has no such keep-driver and that you no longer need.
How long do I keep AML identity documents?
Seven years, but the start date is where offices go wrong. Customer-due-diligence records run seven years beginning when the business relationship ends (AML/CTF Act s 111(2)), not seven years from the day you collected the ID. A document the customer gave you runs seven years after the giving of the document (s 108(2)). Real-estate agencies became reporting entities on 31 March 2026 and the Part 10 record-keeping obligations applied from 1 July 2026. Keep the record the AML rules require, hold it securely under APP 11, and destroy it once its own period has run and you no longer need it for any purpose.
What should I do with unsuccessful rental applications?
Destroy or de-identify them promptly once the tenancy is filled, unless a genuine dispute or legal requirement means you still need them. Unsuccessful applications are the highest-sensitivity, lowest-justification data most agencies hold; there's usually no ongoing purpose for them the moment the property is let, so keeping them for years is the over-retention APP 11.2 is aimed at.
If AML makes me keep ID data, can I still be over-retaining it?
Yes, in two ways. Keeping a record past its own seven years is over-retention, and for customer-due-diligence records that seven years does not begin until the business relationship ends (s 111(2)). So is keeping extra copies of the same identity data the AML rules never required (duplicates on phones, emails, shared drives). Keep the single record you're required to keep, secure it, and clear the strays.
Sources
- OAIC, Australian Privacy Principles (APP 11: security of personal information)
- OAIC, APP 11 guidelines (destruction and de-identification, APP 11.2)
- Privacy Act 1988 (Cth), s 6E(1A) (information collected by an AML reporting entity); OAIC, privacy for small business (A$3m threshold)
- AUSTRAC, real estate professionals (designated services from 31 March 2026, obligations from 1 July 2026)
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), ss 107(3), 108(2) and 111(2) (record retention, Part 10)
- Property and Stock Agents Act 2002 (NSW), s 104(2) (licensee records, at least 3 years after the record is made)
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Retention periods are set by state and territory law and by the AML/CTF rules and vary, confirm the period that applies to you before setting deletion dates. Last reviewed: 22 July 2026.