Skip to content

How do we destroy old tenant records properly, and when does the duty start?

APP 11.2 requires such steps as are reasonable in the circumstances to destroy or de-identify personal information once you no longer need it for any purpose permitted under the APPs, unless you are required by or under an Australian law, or a court or tribunal order, to retain it. So the duty is triggered by the purpose ending, not by a date, and the retention carve-out genuinely releases you where another law applies. Putting applications in the recycling is not destruction.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price

Orientation only, not a compliance assessment. General information and tools, not legal advice.

When does the duty to destroy actually start?

When the information is no longer needed for any purpose permitted under the APPs, and not before.

That phrasing does real work in both directions. It is wider than "the tenancy ended", because you may still need records for a dispute, a reference, a tax obligation or an insurance claim. And it is narrower than "we might want it one day", because a vague future use is not a permitted purpose.

The clearest case in a real-estate business is the unsuccessful applicant. Once the property is let and any dispute window has passed, there is rarely any permitted purpose left for holding their identity documents, payslips and rental history. Those files are the ones that quietly accumulate for years, and they are pure liability: no revenue, no operational use, maximum harm if exposed.

⚠️ The carve-out that releases you: where an Australian law, or a court or tribunal order, requires retention, you keep the records and APP 11.2 is satisfied. AML/CTF record-keeping on the sales side, state agent-licensing record-keeping, and live or reasonably foreseeable tribunal, discrimination or insurance matters all fall here. Never run a blanket purge to satisfy a privacy principle. Review first, then destroy what is genuinely free.

Sources: Privacy Act 1988 (Cth), APP 11.2 (Schedule 1) · OAIC APP Guidelines chapter 11 · OAIC APP guidelines · See also AML record-keeping versus APP 11

What counts as destruction?

Enough that the information cannot practicably be recovered or reconstructed. The Act does not prescribe a method, so what is reasonable scales with sensitivity, and identity documents sit at the top of that scale.

Paper. Cross-cut shred or use a secure destruction service. A recycling bin behind the office is not destruction, and applications in a skip are a foreseeable exposure rather than a bad-luck event.

Email. Delete from the mailbox and from deleted items, and remember that forwarding created copies in other people's mailboxes and in sent items. This is where most "we destroyed it" claims fail.

Systems. Delete the attachment from the record, not just the record's reference to it. Check whether your provider retains deleted items in a recycle bin, and for how long, then empty it.

Backups. To the extent it is practicable to reach them. Where it genuinely is not, record that, and satisfy yourself the retention cycle will clear it. Reasonable steps accepts that backups are hard; it does not accept that nobody thought about them.

Devices. A laptop or phone being replaced or sold needs a full wipe, not a file delete.

Record what you destroyed and when. A destruction you cannot evidence is one you will be assumed not to have performed.

Sources: Privacy Act 1988 (Cth), APP 11.2 (Schedule 1) · OAIC APP Guidelines chapter 11 · OAIC APP guidelines

Is de-identification an alternative?

Yes, APP 11.2 allows destruction or de-identification, but it has to be genuine.

Removing a name from a document that still contains an address, a licence number, an employer and a date of birth has not de-identified anybody, because the person remains reasonably identifiable. That is the test, and it is applied to the information as it actually sits, including against other information you hold that could be combined with it.

For most agency records, destruction is simpler and more defensible than trying to de-identify. De-identification earns its place where you want to keep aggregate operational data, for example how long properties took to let, without keeping the applicants.

Sources: Privacy Act 1988 (Cth), section 6 (de-identified) and APP 11.2 (Schedule 1) · OAIC APP Guidelines chapters B and 11 · OAIC APP guidelines

What do we do with an old CRM we have migrated off?

This is the forgotten holding, and it is usually the largest one.

A decommissioned system, an old server in a cupboard, an exported spreadsheet kept "just in case", or a legacy account nobody has logged into for two years all still contain personal information you hold. APP 11.1 security applies to them while they exist, and APP 11.2 applies to whether they should.

Work through it in this order: confirm the current system holds what you actually need; identify any legal retention obligation over the old data; then destroy the rest, including the export somebody saved to a desktop during the migration. Ask the old provider in writing to confirm deletion on their side and keep the confirmation.

The same applies to a rent roll you sold. Transferring the management does not automatically mean you should keep your copy.

Sources: Privacy Act 1988 (Cth), APP 11.1 and APP 11.2 (Schedule 1) · OAIC APP Guidelines chapter 11 · See also selling a rent roll

How is this different from destroying unsolicited information?

Different principle, different clock, and it is worth keeping them apart.

APP 11.2 is about information you legitimately hold, and the trigger is that you no longer need it. That is a judgement you make, and in practice you control the timing.

APP 4.3 is about information you never asked for and could not have collected under APP 3. It requires destruction or de-identification as soon as practicable, subject to that being lawful and reasonable. That is a faster and less discretionary clock.

So a rejected applicant's file you did request runs on APP 11.2. A medical file they attached that you never asked for runs on APP 4.3 and should go sooner.

Sources: Privacy Act 1988 (Cth), APP 4.3 and APP 11.2 (Schedule 1) · OAIC APP Guidelines chapters 4 and 11 · See also information you did not ask for

What does a workable destruction routine look like?

Three things, none of which require a policy document nobody reads.

1. Give the duty an owner and a date. Tenant personal information has no keep-mandate, so if nobody is scheduled to destroy it, it will simply accumulate. This is the bucket where doing nothing is the breach. 2. Do it by category, not by file. Unsuccessful applications after the letting and any dispute window. Identity copies once verification is complete and no legal retention applies. Former-tenant files once the tenancy, bond and any claim are closed. 3. Record the reason when you keep something. Where you are retaining under the law-requires-retention carve-out, note which regime. The carve-out is available to you, but only if you can say what you are relying on.

Sources: Privacy Act 1988 (Cth), APP 11.2 (Schedule 1) · OAIC APP Guidelines chapter 11 · See also how long to keep personal information

→ The free 2-minute audit separates what you are required to keep from what you are simply still holding.