Privacy Act compliance checklist for property managers
A property manager handling tenant and landlord data should be able to answer "yes" to eight core questions. They map to the Australian Privacy Principles, so each one is traceable to the law, not a guess.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
The 8-point checklist
| # | Check | Maps to | What "good" looks like |
|---|---|---|---|
| 1 | A current, published privacy policy that matches how you actually operate | APP 1 (content per APP 1.4) | Covers what you collect, why, how to access/correct, complaints, overseas disclosure |
| 2 | A clear collection notice when you take someone's info | APP 5 | Given at (or before) collection; says what and why |
| 3 | You collect only what you need | APP 3 | No over-asking on rental applications |
| 4 | You use/share info only for its purpose (or with consent), and marketing follows APP 7 | APP 6 / APP 7 | No quiet repurposing; every marketing message carries a simple opt-out |
| 5 | The data is secure | APP 11.1 | Access controls, secure storage, staff aware |
| 6 | A documented data-breach plan | NDB scheme | Assess within 30 days (max); notify as soon as practicable |
| 7 | A process for access & correction requests | APP 12–13 | You can respond within a reasonable time |
| 8 | You destroy info when no longer needed, and know if it goes overseas | APP 11.2 / APP 8 | Secure destruction; you know where your CRM stores data |
(This checklist doesn't cover the Spam Act, Do-Not-Call, or state tenancy-database rules; those apply on top.)
How do you score?
Most agencies that haven't done privacy work land with only a few of these in place. The free 2-minute self-audit scores you across all eight and shows the gaps to fix first.
Common questions
What's on a property manager's privacy compliance checklist?
Eight core checks: a current published privacy policy (APP 1), a clear collection notice (APP 5), collecting only what you need (APP 3), using and sharing information only for its purpose (APP 6), keeping data secure (APP 11.1), a documented data-breach plan (NDB scheme), a process for access and correction requests (APP 12–13), and destroying information when no longer needed while knowing if it goes overseas (APP 11.2 / APP 8).
How long does a property manager have to assess a data breach?
Under the Notifiable Data Breaches scheme, assess a suspected eligible breach within 30 days (maximum) and notify as soon as practicable.
Can I reuse tenant data for marketing?
Only for the purpose you collected it, or with consent. Note which principle governs: APP 6.7 carves direct marketing out of APP 6 for an organisation and hands it to APP 7, which requires a simple way to opt out, a prominent opt-out statement in some cases, and consent where you did not collect the information from the person directly. For email and SMS the Spam Act 2003 displaces APP 7 under APP 7.8.
Does this checklist cover everything a property manager must do?
No. It doesn't cover the Spam Act, the Do-Not-Call Register, or state tenancy-database rules; those apply on top.
Score your agency in 2 minutes →
General information, not legal advice. Sources: OAIC (oaic.gov.au); Privacy Act 1988 (Cth).