Skip to content

Privacy Act compliance checklist for property managers

A property manager handling tenant and landlord data should be able to answer "yes" to eight core questions. They map to the Australian Privacy Principles, so each one is traceable to the law, not a guess.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price, rising to A$649 on 1 Oct 2026

Orientation only, not a compliance assessment. General information and tools, not legal advice.

The 8-point checklist

#CheckMaps toWhat "good" looks like
1A current, published privacy policy that matches how you actually operateAPP 1 (content per APP 1.4)Covers what you collect, why, how to access/correct, complaints, overseas disclosure
2A clear collection notice when you take someone's infoAPP 5Given at (or before) collection; says what and why
3You collect only what you needAPP 3No over-asking on rental applications
4You use/share info only for its purpose (or with consent), and marketing follows APP 7APP 6 / APP 7No quiet repurposing; every marketing message carries a simple opt-out
5The data is secureAPP 11.1Access controls, secure storage, staff aware
6A documented data-breach planAPP 1.2 with Part IIICReasonable steps to complete the assessment within 30 days (s 26WH(2)); statement to the Commissioner, then notification, as soon as practicable (ss 26WK(2), 26WL)
7A process for access & correction requestsAPP 12–13You can respond within a reasonable time
8You destroy or de-identify info when no longer needed, and know if it goes overseasAPP 11.2 / APP 8Reasonable steps to destroy or de-identify, unless an Australian law or court order requires you to keep it (APP 11.2(d)); you know where your CRM stores data

(This checklist doesn't cover the Spam Act, Do-Not-Call, or state tenancy-database rules such as Residential Tenancies Act 2010 (NSW) ss 211-218; those apply on top. Note the limit the other way: searching or listing on TICA or NTD does not remove a small-business exemption, because what s 6E(2) prescribes, via Privacy Regulations 2025 s 7(1)-(2), is operating a residential tenancy database.)

How do you score?

The checks you cannot answer yes to are your gaps. Before that, though: an agency whose annual turnover was A$3 million or less is generally a small business operator and outside the APPs, unless an exception applies, such as those in s 6D(4). The free 2-minute self-audit scores you across all eight, and Am I covered? settles the exemption question first.

Common questions

What's on a property manager's privacy compliance checklist?

Eight core checks: a current published privacy policy (APP 1), a clear collection notice (APP 5), collecting only what you need (APP 3), using and sharing information only for its purpose (APP 6), keeping data secure (APP 11.1), a documented data-breach plan (APP 1.2 with Part IIIC), a process for access and correction requests (APP 12–13), and destroying or de-identifying information when no longer needed while knowing if it goes overseas (APP 11.2 / APP 8).

How long does a property manager have to assess a data breach?

Section 26WH(2) puts the duty on you: a reasonable and expeditious assessment, and all reasonable steps to complete it within 30 days of becoming aware. Thirty days is the ceiling, not the target, and in Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224 the Federal Court set A$800,000 of the penalty against the slow assessment alone. If you then have reasonable grounds to believe there was an eligible breach, s 26WK(2) requires a statement to the Commissioner as soon as practicable, and s 26WL(2) requires notice to the affected individuals, or to those at risk, or, if neither is practicable, publication of the statement.

Can I reuse tenant data for marketing?

Only for the purpose you collected it, or with consent. Note which principle governs: APP 6.7 carves direct marketing out of APP 6 for an organisation and hands it to APP 7, which requires a simple way to opt out, a prominent opt-out statement in some cases, and consent where you did not collect the information from the person directly. For email and SMS the Spam Act 2003 displaces APP 7 under APP 7.8.

Does this checklist cover everything a property manager must do?

No. It doesn't cover the Spam Act, the Do-Not-Call Register, or state tenancy-database rules such as Residential Tenancies Act 2010 (NSW) ss 211-218; those apply on top. The reverse is worth knowing too: using a tenancy database does not remove a small-business exemption, because what s 6E(2) prescribes, via Privacy Regulations 2025 s 7(1)-(2), is operating one.

Score your agency in 2 minutes →


General information, not legal advice. Sources: OAIC (oaic.gov.au); Privacy Act 1988 (Cth).