title: "How long should a real-estate agency keep personal information? (retention & destruction, APP 11)" slug: how-long-keep-personal-information-real-estate-app11 type: answer-page status: DRAFT (Phase-1) · APP 11 sourced to OAIC + Privacy Act; AML record-keeping to AUSTRAC · Gate-A lawyer eye on the destroy-copy/keep-record framing before loud maps_to: APP 11.1, APP 11.2, AML/CTF record-keeping (~7 years), Privacy Act s 6E(1A) targets: "how long keep personal information real estate", "app 11 retention destruction real estate", "real estate agency data retention privacy", "destroy personal information app 11 real estate", "how long keep vendor buyer tenant records real estate", "when delete personal information real estate agency" updated: 2026-07-22
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
How long should a real-estate agency keep personal information? (retention & destruction, APP 11)
There's no single number. APP 11 pulls two ways: keep the personal information you hold secure, then destroy or de-identify it once you no longer need it for a permitted purpose. Some records carry a legal keep-period that overrides the destroy duty while it runs. AML customer-due-diligence records, for example, run seven years. The workable answer: keep what a law actually requires, hold it securely, and delete the rest on a defined trigger.
General information, not legal advice. Retention periods depend on your state and your circumstances, so confirm the period that applies to you.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
What does APP 11 actually require about keeping personal information?
APP 11 has two limbs, and retention sits in the second. APP 11.1 says you must take reasonable steps to protect the personal information you hold from misuse, interference, loss, and unauthorised access or disclosure. APP 11.2 says you must take reasonable steps to destroy or de-identify personal information once you no longer need it for any purpose for which it may be used or disclosed under the APPs, unless you are required by an Australian law or a court/tribunal order to retain it, or it sits in a Commonwealth record. So the Privacy Act never sets a "keep it for X years" figure. It sets a principle: hold it while you genuinely need it, protect it the whole time, then let it go.
The default is minimise-and-destroy, not keep-everything
The mindset APP 11 expects is the opposite of most agencies' habits. The default posture under the Privacy Act is that personal information is a liability you dispose of when its job is done, not an asset you hoard. Every extra record you keep past its usefulness is data you now have to secure, data that widens the blast radius if you're breached, and data an individual could ask you to account for. "We keep everything forever, just in case" is not a neutral choice; it's the exact pattern APP 11.2 is aimed at. The discipline is to know, for each type of information you hold, why you still have it and when it goes.
Which records does a real-estate agency actually hold?
The reason "how long" has no single answer is that an agency holds several different kinds of personal information, each with a different driver. A sales file, a rent roll, a pile of unsuccessful rental applications, and a folder of AML identity documents are governed by different rules and different clocks. Before you can set retention, you have to name what you hold:
| Information type | What tends to drive the keep-period |
|---|---|
| Vendor / buyer sales records, trust-account records | State agents & trust-account legislation (fixed statutory minimums, vary by state) |
| Signed leases, condition reports, tenancy files | State tenancy + agency record rules (vary by state) |
| Rental applications, successful | Kept while managing the tenancy, then the state tenancy period |
| Rental applications, unsuccessful | No ongoing need once the tenancy is filled, short retention |
| AML/CTF customer-due-diligence (ID) records | AML/CTF record-keeping, at least seven years |
| Marketing / enquiry lists, open-home sheets | Only while the person is a live prospect, no long keep-driver |
State minimums are mandatory and differ between jurisdictions, so treat this as the shape of the problem, not a schedule. For the state-by-state tenancy figures, see how long a real-estate agency must keep tenant records.
Tenancy-application data is where over-retention bites hardest
If you fix only one thing, fix unsuccessful rental applications. A rental application is the densest collection of personal information your agency ever takes: identity, date of birth, income evidence, bank statements, rental history, referees, sometimes a tenancy-database check. For every property, you collect that from several applicants and can only approve one. The unsuccessful applicants' files have no ongoing purpose the moment the tenancy is filled, yet they routinely sit in inboxes, on 2Apply-style platforms, and on agents' laptops for years. Under APP 11.2 that's over-retention of exactly the most sensitive data you handle. The realistic rule: once a tenancy is decided, destroy or de-identify the unsuccessful applicants' information promptly, unless a genuine dispute or legal requirement means you need to keep it. (What you must tell applicants when you collect it is a separate duty, see the tenancy-application collection notice.)
The AML seven-year record vs APP 11: destroy the copy, keep the record
This is the tension people ask about, and it resolves more cleanly than it looks. From 1 July 2026, agencies drawn into the AML/CTF regime are reporting entities and must keep certain records, including customer-due-diligence records, for at least seven years, and the moment you collect that identity data for AML it is covered by the Australian Privacy Principles regardless of your turnover (the effect of s 6E(1A), so even under the A$3 million small-business threshold, which still exists). APP 11.2 does not force you to breach that: its carve-out expressly exempts information you're required by law to retain, so keeping the AML record for its seven years is fully consistent with APP 11. What APP 11 targets is everything the AML rule never asked you to keep: the duplicate passport scan on an agent's phone, the copy emailed around the office, the identity file left on a shared drive after the seven years lapse. The reconciliation, in a phrase: keep the one record the law requires, destroy the stray extra copies, and destroy the required record too once its seven years are up. For handling that AML identity data specifically, see what to do with the ID documents AUSTRAC makes you collect.
One part of this runs the opposite way to the usual advice, and it is the bit that catches offices out. The standing habit for an identity check is to record the details you relied on and keep no copy of the document itself. The AML/CTF Act's outline of its record-keeping Part puts a second duty alongside that one: "If a customer of a reporting entity gives the reporting entity a document relating to the provision of a designated service, the reporting entity must retain the document for 7 years." So if a client emails you a scan of their licence or passport, that scan is a document the customer gave you, and the seven-year retention attaches to it. You keep it rather than deleting it. The practical answer is to tell clients what to send before they send it, because that one habit is the difference between a clean file and a seven-year custody problem. (Section 104 is a simplified outline, which the Act itself says is a guide only; the operative provisions sit later in Part 10.)
What are realistic prompts to actually destroy?
A retention rule that never fires is not compliance. The reason personal information piles up isn't bad intent; it's that nobody has defined the event that starts the "no longer needed" clock. So set concrete, realistic prompts rather than a vague "review annually":
- Tenancy filled → destroy/de-identify unsuccessful applications (subject to any live dispute).
- Tenancy ended + state minimum passed + no bond claim or tribunal matter pending → dispose of the tenancy file.
- Sale settled + state agents/trust-account minimum passed → dispose of the sales/trust records.
- AML seven-year period ends and the customer relationship is over → destroy the CDD/identity records.
- Prospect goes cold / unsubscribes → clear enquiry and marketing records with no keep-driver.
"Destroy" means reasonable steps proportionate to the sensitivity: secure deletion of electronic files including backups and cloud copies on a realistic cycle, shredding of paper, or de-identification where you want aggregate data but no longer need to identify anyone. Noting what you destroyed and when is part of being able to show you took reasonable steps.
Build a one-page retention schedule (or use one)
The practical answer to "how long" is a schedule, not a number. A workable retention schedule is a short table: each information type, the law or purpose that drives its keep-period, the date the clock starts (usually tenancy end, settlement, or the end of the customer relationship), the destruction trigger, and the method. That turns a genuine legal tension into a routine anyone in the office can follow, and it feeds your other obligations: the data you map here is the data your privacy policy describes and your data breach response plan protects. Privaproof's Kit includes a retention-and-destruction schedule mapped to real-estate record types so you're not building it from a blank page. Not sure where you stand today? The fastest way to find your gaps is the free 2-minute self-audit; it flags whether you have a retention schedule at all and whether old records are being disposed of.
Common questions
Does the Privacy Act say how many years to keep records?
No. The Privacy Act and APP 11 set a principle, not a period: destroy or de-identify personal information once you no longer need it, unless a law requires you to keep it. The actual keep-periods come from other laws: state agents, tenancy and trust-account rules, and the AML/CTF record-keeping rules, which is why the answer varies by record type and by state.
Doesn't APP 11 mean I have to delete everything?
Not the records you're legally required to keep. APP 11.2 carves out personal information you're required by an Australian law or a court/tribunal order to retain. Your state trust-account minimums and the AML seven-year rule are exactly that kind of requirement, so holding those records for their period is consistent with APP 11. The destroy duty bites on information that has no such keep-driver and that you no longer need.
How long do I keep AML identity documents?
At least seven years. AML/CTF record-keeping generally requires customer-due-diligence records to be kept for a minimum of seven years, and from 1 July 2026 that applies to agencies providing designated real-estate services. Keep the record the AML rules require, hold it securely under APP 11, and destroy it once both the seven years have passed and you no longer need it for any purpose. Confirm the exact trigger with AUSTRAC guidance.
What should I do with unsuccessful rental applications?
Destroy or de-identify them promptly once the tenancy is filled, unless a genuine dispute or legal requirement means you still need them. Unsuccessful applications are the highest-sensitivity, lowest-justification data most agencies hold; there's usually no ongoing purpose for them the moment the property is let, so keeping them for years is the over-retention APP 11.2 is aimed at.
If AML makes me keep ID data, can I still be over-retaining it?
Yes, in two ways. Keeping the AML record beyond its seven-year period once the relationship is over is over-retention, and so is keeping extra copies of that same identity data the AML rule never required (duplicates on phones, emails, shared drives). Keep the single record you're required to keep, secure it, and clear the strays.
Sources
- OAIC, Australian Privacy Principles (APP 11: security of personal information)
- OAIC, APP 11 guidelines (destruction and de-identification, APP 11.2)
- Privacy Act 1988 (Cth), s 6E(1A) (information collected by an AML reporting entity); OAIC, privacy for small business (A$3m threshold)
- AUSTRAC, real estate professionals (AML/CTF from 1 July 2026, seven-year record keeping)
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), Part 10 (records), quoted above from the s 104 simplified outline
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Retention periods are set by state and territory law and by the AML/CTF rules and vary, confirm the period that applies to you before setting deletion dates. Last reviewed: 22 July 2026.