Skip to content

Can we keep a scan or photocopy of a tenant's driver licence or passport?

Collecting the copy and continuing to hold it are two different questions under two different principles. APP 3.2 governs whether you may collect it. APP 11.2 governs how long you may keep it: take such steps as are reasonable to destroy or de-identify it once you no longer need it for any permitted purpose, unless you are required by or under an Australian law, or a court or tribunal order, to retain it. Sighting a document is not the same as keeping it, and for tenancy screening the sighting is usually what you actually needed.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price

Orientation only, not a compliance assessment. General information and tools, not legal advice.

Why are ID folders the highest-risk thing most agencies hold?

Because they are the raw material of identity theft. A folder of licence and passport scans is exactly what someone needs to open credit in another person's name, which is why a compromised mailbox containing them is a serious-harm problem rather than an embarrassment, and why it is the fact pattern that turns into a notifiable data breach.

They are also among the least examined holdings in a typical office. They accumulate in email threads, in shared drives, in a CRM attachment field, and nobody owns them.

Did we need the copy, or did we need the verification?

Ask this first, because it usually resolves the problem without any argument about retention.

For tenancy screening, what you generally need is confidence that the applicant is who they say they are. Recording that ID was sighted and matched, by whom and on what date, achieves that without creating a durable copy of a government document. APP 3.2 limits collection to what is reasonably necessary, and the copy is a separate collection from the check.

Where you do keep copies:

Sources: Privacy Act 1988 (Cth), APP 3.2 and APP 11.1 (Schedule 1) · OAIC APP Guidelines chapters 3 and 11 · OAIC APP guidelines

Should we just delete all the old ID scans?

No. Do not run a blanket purge, and this is where a lot of well-intentioned privacy advice goes wrong.

APP 11.2 requires reasonable steps to destroy or de-identify information you no longer need unless you are required by or under an Australian law, or a court or tribunal order, to retain it. That carve-out is real and it bites here:

The correct sequence is: review against your retention obligations, identify what is genuinely free of them, then destroy that. Not the other way around.

Sources: Privacy Act 1988 (Cth), APP 11.2 (Schedule 1); Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) Part 10, records retained for 7 years (`verify/2026-07-30-amlctf-act-provisions.md`, from the simplified outline at s 104: "If a customer of a reporting entity gives the reporting entity a document relating to the provision of a designated service, the reporting entity must retain the document for 7 years"); state agent-licensing legislation (varies by jurisdiction) · OAIC APP Guidelines chapter 11 · OAIC APP guidelines · AUSTRAC

How long is "no longer needed" for a tenancy application?

There is no single national number, and anyone quoting one for tenant personal information is overreaching.

Two different things get confused here. Agent business records (agency agreements, trust records) attract minimum retention periods under state agent-licensing law. Tenant personal information is different again, and the position is not uniform across the states, so check your own before settling a retention rule.

Queensland is the clearest example, and it runs the same way APP 11.2 does. Under the Residential Tenancies and Rooming Accommodation Act 2008 (Qld) s 457E, an unsuccessful applicant's information must be destroyed within 3 months (s 457E(1)(c)), and a tenant's information must be stored securely, accessed only for managing the premises, and destroyed securely within 7 years after the tenancy ends (s 457E(2)).

⚠️ Read that as a deadline to destroy, not a licence to keep. A seven-year outer limit is not an instruction to hold everything for seven years, and it says nothing about how long you may keep a copy of an identity document, which APP 11.2 answers separately and sooner. Where no law requires retention, APP 11.2 points toward destruction once the purpose has passed.

⚠️ We have verified the Queensland position and not the other states', so do not read the above as the national rule. Applying an agent-record retention period to a rejected applicant's file is how offices end up over-retaining for years, which is itself the breach.

Unsuccessful applicants are the clearest case. Once the property is let and any dispute window has passed, there is rarely a permitted purpose for holding their identity documents.

Sources: Privacy Act 1988 (Cth), APP 11.2 (Schedule 1); state agent-licensing legislation (varies) · OAIC APP Guidelines chapter 11 · See also how long to keep personal information and ID documents, AUSTRAC and privacy

→ The free 2-minute audit covers what your agency is holding, where, and whether anything actually gets destroyed.