Can we keep a scan or photocopy of a tenant's driver licence or passport?
Collecting the copy and continuing to hold it are two different questions under two different principles. APP 3.2 governs whether you may collect it. APP 11.2 governs how long you may keep it: take such steps as are reasonable to destroy or de-identify it once you no longer need it for any permitted purpose, unless you are required by or under an Australian law, or a court or tribunal order, to retain it. Sighting a document is not the same as keeping it, and for tenancy screening the sighting is usually what you actually needed.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
Why does an ID scan carry more risk than the rest of the file?
Because they are the raw material of identity theft. A licence or passport scan is what someone needs to open credit in another person's name, and that is exactly what the notification test turns on: a data breach is notifiable only where a reasonable person would conclude the unauthorised access or disclosure would be likely to result in serious harm (Privacy Act 1988 (Cth), s 26WE(2)), and the first of the serious-harm factors in s 26WG is the kind and sensitivity of the information involved.
They also accumulate quietly: in email threads, in shared drives, in a CRM attachment field. Where are yours, who can open them, and whose job is it to destroy them?
Did we need the copy, or did we need the verification?
Ask this first, because it usually resolves the problem without any argument about retention.
For tenancy screening, what you generally need is confidence that the applicant is who they say they are. Recording that ID was sighted and matched, by whom and on what date, achieves that without creating a durable copy of a government document. APP 3.2 limits collection to what is reasonably necessary, and the copy is a separate collection from the check. The Commissioner applied that limit to rental applications in Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 (1 April 2026), finding at [95] that the 2Apply platform could perform its functions on a lesser amount of identification and proof-of-income documents. The respondent was the platform operator rather than an agency, and the OAIC records the determination as under review in the Administrative Review Tribunal. See what the 2Apply decision changes on a rental application. The Commissioner applied that limit to rental applications in Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 (1 April 2026), finding at [95] that the 2Apply platform could perform its functions on a lesser amount of identification and proof-of-income documents. The respondent was the platform operator rather than an agency, and the OAIC records the determination as under review in the Administrative Review Tribunal. See what the 2Apply decision changes on a rental application. The Commissioner applied that limit to rental applications in Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 (1 April 2026), finding at [95] that the 2Apply platform could perform its functions on a lesser amount of identification and proof-of-income documents. The respondent was the platform operator rather than an agency, and the OAIC records the determination as under review in the Administrative Review Tribunal. See what the 2Apply decision changes on a rental application.
Where you do keep copies:
- Keep them in one controlled location rather than scattered across email and drives.
- Restrict who can open them.
- Put an actual destruction step in the process, with an owner, because a destruction duty only bites if somebody does it.
Sources: Privacy Act 1988 (Cth), APP 3.2, APP 11.1 and APP 11.2 (Schedule 1); Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 at [94] to [95] · OAIC APP Guidelines chapters 3 and 11 · OAIC APP guidelines
Should we just delete all the old ID scans?
No. Check what you are required to keep before you destroy anything, because over-retention can be corrected and a destroyed record cannot be brought back.
APP 11.2 requires reasonable steps to destroy or de-identify information you no longer need unless you are required by or under an Australian law, or a court or tribunal order, to retain it. That carve-out is real and it bites here:
- AML/CTF does not reach a tenant's ID at all. A lease for a term of 30 years or less, options for further terms excluded, is carved out of the definition of real estate in s 6 of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), so ordinary leasing is not a designated service and no AML record-keeping duty attaches to it. On the sales side it is different, and conditional: where a document relating to the provision of a designated service is given to you by or on behalf of the customer (s 108(1)(a)) and you commence, or have commenced, to provide that service (s 108(1)(b)), s 108(2) requires you to retain it, or a copy, for 7 years after the giving of the document. Both limbs have to be met, so this is not "anything a client sends you".
- State agent-licensing record-keeping obligations apply to certain business records and differ by jurisdiction.
- A live tribunal, discrimination, insurance or debt matter can bring a legal requirement or a court or tribunal order into play, and that is what APP 11.2(d) responds to. Note the limit: the carve-out is engaged by a law or an order, not by a dispute you merely expect, so treat a foreseeable matter as a reason to pause and check rather than as a retention requirement in itself.
The correct sequence is: review against your retention obligations, identify what is genuinely free of them, then destroy that. Not the other way around.
Sources: Privacy Act 1988 (Cth), APP 11.2 (Schedule 1); Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) s 6, definition of real estate, which excludes at paragraph (f) "a leasehold interest under a lease for a term (excluding options for further terms) of 30 years or less", and Part 10 s 108, which requires retention for 7 years after the giving of the document only where the document was "given to the reporting entity by or on behalf of the customer" (s 108(1)(a)) and the reporting entity "commences, or has commenced, to provide the service to the customer" (s 108(1)(b)); state agent-licensing legislation (varies by jurisdiction) · OAIC APP Guidelines chapter 11 · OAIC APP guidelines · AUSTRAC
How long is "no longer needed" for a tenancy application?
There is no single national number, and anyone quoting one for tenant personal information is overreaching.
Two different things get confused here. Agent business records (agency agreements, trust records) attract minimum retention periods under state agent-licensing law. Tenant personal information is different again, and the position is not uniform across the states, so check your own before settling a retention rule.
⭐ Queensland is the clearest example, and it runs the same way APP 11.2 does. Under the Residential Tenancies and Rooming Accommodation Act 2008 (Qld) s 457E, an unsuccessful applicant's information must be destroyed within 3 months (s 457E(1)(c)), and a tenant's information must be stored securely, accessed only for managing the premises, and destroyed securely within 7 years after the tenancy ends (s 457E(2)).
⚠️ Read that as a deadline to destroy, not a licence to keep. A seven-year outer limit is not an instruction to hold everything for seven years, and it says nothing about how long you may keep a copy of an identity document, which APP 11.2 answers separately and sooner. Where no law requires retention, APP 11.2 points toward destruction once the purpose has passed.
⚠️ We have verified the Queensland position and not the other states', so do not read the above as the national rule. Applying an agent-record retention period to a rejected applicant's file is how offices end up over-retaining for years, which is itself the breach.
Unsuccessful applicants are the clearest case. Once the property is let and any dispute window has passed, there is rarely a permitted purpose for holding their identity documents.
Sources: Privacy Act 1988 (Cth), APP 11.2 (Schedule 1); state agent-licensing legislation (varies) · OAIC APP Guidelines chapter 11 · See also how long to keep personal information and ID documents, AUSTRAC and privacy
→ The free 2-minute audit covers what your agency is holding, where, and whether anything actually gets destroyed.