Skip to content

Privacy Act compliance checklist for property managers

A property manager handling tenant and landlord data should be able to answer "yes" to eight core questions. They map to the Australian Privacy Principles, so each one is traceable to the law, not a guess.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price

Orientation only, not a compliance assessment. General information and tools, not legal advice.

The 8-point checklist

#CheckMaps toWhat "good" looks like
1A current, published privacy policy that matches how you actually operateAPP 1 (content per APP 1.4)Covers what you collect, why, how to access/correct, complaints, overseas disclosure
2A clear collection notice when you take someone's infoAPP 5Given at (or before) collection; says what and why
3You collect only what you needAPP 3No over-asking on rental applications
4You use/share info only for its purpose (or with consent), and marketing follows APP 7APP 6 / APP 7No quiet repurposing; every marketing message carries a simple opt-out
5The data is secureAPP 11.1Access controls, secure storage, staff aware
6A documented data-breach planNDB schemeAssess within 30 days (max); notify as soon as practicable
7A process for access & correction requestsAPP 12–13You can respond within a reasonable time
8You destroy info when no longer needed, and know if it goes overseasAPP 11.2 / APP 8Secure destruction; you know where your CRM stores data

(This checklist doesn't cover the Spam Act, Do-Not-Call, or state tenancy-database rules; those apply on top.)

How do you score?

Most agencies that haven't done privacy work land with only a few of these in place. The free 2-minute self-audit scores you across all eight and shows the gaps to fix first.

Common questions

What's on a property manager's privacy compliance checklist?

Eight core checks: a current published privacy policy (APP 1), a clear collection notice (APP 5), collecting only what you need (APP 3), using and sharing information only for its purpose (APP 6), keeping data secure (APP 11.1), a documented data-breach plan (NDB scheme), a process for access and correction requests (APP 12–13), and destroying information when no longer needed while knowing if it goes overseas (APP 11.2 / APP 8).

How long does a property manager have to assess a data breach?

Under the Notifiable Data Breaches scheme, assess a suspected eligible breach within 30 days (maximum) and notify as soon as practicable.

Can I reuse tenant data for marketing?

Only for the purpose you collected it, or with consent. Note which principle governs: APP 6.7 carves direct marketing out of APP 6 for an organisation and hands it to APP 7, which requires a simple way to opt out, a prominent opt-out statement in some cases, and consent where you did not collect the information from the person directly. For email and SMS the Spam Act 2003 displaces APP 7 under APP 7.8.

Does this checklist cover everything a property manager must do?

No. It doesn't cover the Spam Act, the Do-Not-Call Register, or state tenancy-database rules; those apply on top.

Score your agency in 2 minutes →


General information, not legal advice. Sources: OAIC (oaic.gov.au); Privacy Act 1988 (Cth).