Privacy Act compliance checklist for property managers
A property manager handling tenant and landlord data should be able to answer "yes" to eight core questions. They map to the Australian Privacy Principles, so each one is traceable to the law, not a guess.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
The 8-point checklist
| # | Check | Maps to | What "good" looks like |
|---|---|---|---|
| 1 | A current, published privacy policy that matches how you actually operate | APP 1 (content per APP 1.4) | Covers what you collect, why, how to access/correct, complaints, overseas disclosure |
| 2 | A clear collection notice when you take someone's info | APP 5 | Given at (or before) collection; says what and why |
| 3 | You collect only what you need | APP 3 | No over-asking on rental applications |
| 4 | You use/share info only for its purpose (or with consent), and marketing follows APP 7 | APP 6 / APP 7 | No quiet repurposing; every marketing message carries a simple opt-out |
| 5 | The data is secure | APP 11.1 | Access controls, secure storage, staff aware |
| 6 | A documented data-breach plan | APP 1.2 with Part IIIC | Reasonable steps to complete the assessment within 30 days (s 26WH(2)); statement to the Commissioner, then notification, as soon as practicable (ss 26WK(2), 26WL) |
| 7 | A process for access & correction requests | APP 12–13 | You can respond within a reasonable time |
| 8 | You destroy or de-identify info when no longer needed, and know if it goes overseas | APP 11.2 / APP 8 | Reasonable steps to destroy or de-identify, unless an Australian law or court order requires you to keep it (APP 11.2(d)); you know where your CRM stores data |
(This checklist doesn't cover the Spam Act, Do-Not-Call, or state tenancy-database rules such as Residential Tenancies Act 2010 (NSW) ss 211-218; those apply on top. Note the limit the other way: searching or listing on TICA or NTD does not remove a small-business exemption, because what s 6E(2) prescribes, via Privacy Regulations 2025 s 7(1)-(2), is operating a residential tenancy database.)
How do you score?
The checks you cannot answer yes to are your gaps. Before that, though: an agency whose annual turnover was A$3 million or less is generally a small business operator and outside the APPs, unless an exception applies, such as those in s 6D(4). The free 2-minute self-audit scores you across all eight, and Am I covered? settles the exemption question first.
Common questions
What's on a property manager's privacy compliance checklist?
Eight core checks: a current published privacy policy (APP 1), a clear collection notice (APP 5), collecting only what you need (APP 3), using and sharing information only for its purpose (APP 6), keeping data secure (APP 11.1), a documented data-breach plan (APP 1.2 with Part IIIC), a process for access and correction requests (APP 12–13), and destroying or de-identifying information when no longer needed while knowing if it goes overseas (APP 11.2 / APP 8).
How long does a property manager have to assess a data breach?
Section 26WH(2) puts the duty on you: a reasonable and expeditious assessment, and all reasonable steps to complete it within 30 days of becoming aware. Thirty days is the ceiling, not the target, and in Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224 the Federal Court set A$800,000 of the penalty against the slow assessment alone. If you then have reasonable grounds to believe there was an eligible breach, s 26WK(2) requires a statement to the Commissioner as soon as practicable, and s 26WL(2) requires notice to the affected individuals, or to those at risk, or, if neither is practicable, publication of the statement.
Can I reuse tenant data for marketing?
Only for the purpose you collected it, or with consent. Note which principle governs: APP 6.7 carves direct marketing out of APP 6 for an organisation and hands it to APP 7, which requires a simple way to opt out, a prominent opt-out statement in some cases, and consent where you did not collect the information from the person directly. For email and SMS the Spam Act 2003 displaces APP 7 under APP 7.8.
Does this checklist cover everything a property manager must do?
No. It doesn't cover the Spam Act, the Do-Not-Call Register, or state tenancy-database rules such as Residential Tenancies Act 2010 (NSW) ss 211-218; those apply on top. The reverse is worth knowing too: using a tenancy database does not remove a small-business exemption, because what s 6E(2) prescribes, via Privacy Regulations 2025 s 7(1)-(2), is operating one.
Score your agency in 2 minutes →
General information, not legal advice. Sources: OAIC (oaic.gov.au); Privacy Act 1988 (Cth).