Skip to content

Can we keep a scan or photocopy of a tenant's driver licence or passport?

Collecting the copy and continuing to hold it are two different questions under two different principles. APP 3.2 governs whether you may collect it. APP 11.2 governs how long you may keep it: take such steps as are reasonable to destroy or de-identify it once you no longer need it for any permitted purpose, unless you are required by or under an Australian law, or a court or tribunal order, to retain it. Sighting a document is not the same as keeping it, and for tenancy screening the sighting is usually what you actually needed.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price, rising to A$649 on 1 Oct 2026

Orientation only, not a compliance assessment. General information and tools, not legal advice.

Why does an ID scan carry more risk than the rest of the file?

Because they are the raw material of identity theft. A licence or passport scan is what someone needs to open credit in another person's name, and that is exactly what the notification test turns on: a data breach is notifiable only where a reasonable person would conclude the unauthorised access or disclosure would be likely to result in serious harm (Privacy Act 1988 (Cth), s 26WE(2)), and the first of the serious-harm factors in s 26WG is the kind and sensitivity of the information involved.

They also accumulate quietly: in email threads, in shared drives, in a CRM attachment field. Where are yours, who can open them, and whose job is it to destroy them?

Did we need the copy, or did we need the verification?

Ask this first, because it usually resolves the problem without any argument about retention.

For tenancy screening, what you generally need is confidence that the applicant is who they say they are. Recording that ID was sighted and matched, by whom and on what date, achieves that without creating a durable copy of a government document. APP 3.2 limits collection to what is reasonably necessary, and the copy is a separate collection from the check. The Commissioner applied that limit to rental applications in Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 (1 April 2026), finding at [95] that the 2Apply platform could perform its functions on a lesser amount of identification and proof-of-income documents. The respondent was the platform operator rather than an agency, and the OAIC records the determination as under review in the Administrative Review Tribunal. See what the 2Apply decision changes on a rental application. The Commissioner applied that limit to rental applications in Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 (1 April 2026), finding at [95] that the 2Apply platform could perform its functions on a lesser amount of identification and proof-of-income documents. The respondent was the platform operator rather than an agency, and the OAIC records the determination as under review in the Administrative Review Tribunal. See what the 2Apply decision changes on a rental application. The Commissioner applied that limit to rental applications in Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 (1 April 2026), finding at [95] that the 2Apply platform could perform its functions on a lesser amount of identification and proof-of-income documents. The respondent was the platform operator rather than an agency, and the OAIC records the determination as under review in the Administrative Review Tribunal. See what the 2Apply decision changes on a rental application.

Where you do keep copies:

Sources: Privacy Act 1988 (Cth), APP 3.2, APP 11.1 and APP 11.2 (Schedule 1); Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 at [94] to [95] · OAIC APP Guidelines chapters 3 and 11 · OAIC APP guidelines

Should we just delete all the old ID scans?

No. Check what you are required to keep before you destroy anything, because over-retention can be corrected and a destroyed record cannot be brought back.

APP 11.2 requires reasonable steps to destroy or de-identify information you no longer need unless you are required by or under an Australian law, or a court or tribunal order, to retain it. That carve-out is real and it bites here:

The correct sequence is: review against your retention obligations, identify what is genuinely free of them, then destroy that. Not the other way around.

Sources: Privacy Act 1988 (Cth), APP 11.2 (Schedule 1); Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) s 6, definition of real estate, which excludes at paragraph (f) "a leasehold interest under a lease for a term (excluding options for further terms) of 30 years or less", and Part 10 s 108, which requires retention for 7 years after the giving of the document only where the document was "given to the reporting entity by or on behalf of the customer" (s 108(1)(a)) and the reporting entity "commences, or has commenced, to provide the service to the customer" (s 108(1)(b)); state agent-licensing legislation (varies by jurisdiction) · OAIC APP Guidelines chapter 11 · OAIC APP guidelines · AUSTRAC

How long is "no longer needed" for a tenancy application?

There is no single national number, and anyone quoting one for tenant personal information is overreaching.

Two different things get confused here. Agent business records (agency agreements, trust records) attract minimum retention periods under state agent-licensing law. Tenant personal information is different again, and the position is not uniform across the states, so check your own before settling a retention rule.

⭐ Queensland is the clearest example, and it runs the same way APP 11.2 does. Under the Residential Tenancies and Rooming Accommodation Act 2008 (Qld) s 457E, an unsuccessful applicant's information must be destroyed within 3 months (s 457E(1)(c)), and a tenant's information must be stored securely, accessed only for managing the premises, and destroyed securely within 7 years after the tenancy ends (s 457E(2)).

⚠️ Read that as a deadline to destroy, not a licence to keep. A seven-year outer limit is not an instruction to hold everything for seven years, and it says nothing about how long you may keep a copy of an identity document, which APP 11.2 answers separately and sooner. Where no law requires retention, APP 11.2 points toward destruction once the purpose has passed.

⚠️ We have verified the Queensland position and not the other states', so do not read the above as the national rule. Applying an agent-record retention period to a rejected applicant's file is how offices end up over-retaining for years, which is itself the breach.

Unsuccessful applicants are the clearest case. Once the property is let and any dispute window has passed, there is rarely a permitted purpose for holding their identity documents.

Sources: Privacy Act 1988 (Cth), APP 11.2 (Schedule 1); state agent-licensing legislation (varies) · OAIC APP Guidelines chapter 11 · See also how long to keep personal information and ID documents, AUSTRAC and privacy

→ The free 2-minute audit covers what your agency is holding, where, and whether anything actually gets destroyed.