Skip to content

A rental applicant sent us documents we never asked for. What do we have to do?

Work out whether the information is unsolicited, because that decides which principle applies. If you did not ask for it, APP 4.1 requires you to determine within a reasonable period whether you could have collected it under APP 3. If you could not have, APP 4.3 requires you to destroy or de-identify it as soon as practicable, but only if it is lawful and reasonable to do so, so a legal retention duty or a binding order can properly stop you. Wherever APP 4.3 does not apply, APP 4.4 puts APPs 5 to 13 over the information as if you had collected it.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price, rising to A$649 on 1 Oct 2026

Orientation only, not a compliance assessment. General information and tools, not legal advice.

What is the difference between solicited and unsolicited information?

This is the whole answer, so it is worth being precise.

"Solicits" means you requested it. A request is an active step to collect. If you asked for proof of income, income evidence is solicited, and APP 3 governs whether you were entitled to collect it.

Unsolicited means you took no active steps to collect it. The applicant volunteered a document nobody on your team asked for. That does not become solicited merely because you accepted it, opened it, or filed it. Receiving is not requesting.

Where it is genuinely unclear which side of the line something falls on, the OAIC's guidance is to err on the side of caution and treat it as unsolicited. That is the cautious answer in a useful direction, because APP 4 sets a faster and more definite process than leaving the information to sit in a file under APP 11.

One practical consequence worth noting: your own forms decide this. If your points-based identity list names a document, anything supplied because that list names it was requested, so it is solicited and APP 3 applies. Anything sent on top of what you asked for should be treated as unsolicited (OAIC APP Guidelines paragraph 4.8). Review the list before you decide which principle you are under.

Sources: Privacy Act 1988 (Cth), section 6(1) (definition of "solicits") and APP 3, APP 4 (Schedule 1) · OAIC APP Guidelines chapter 4, paragraphs 4.6, 4.7 and 4.9 · OAIC APP guidelines

Do we have to destroy personal information we received but never requested?

Only if you could not have collected it under APP 3, and only where destroying it is lawful and reasonable.

The sequence in APP 4 runs like this:

⚠️ The "lawful and reasonable" qualifier in APP 4.3 does real work, and it is why a retention duty beats a destruction duty. Where an Australian law or a binding court or tribunal order requires you to keep the document, destroying it is not lawful and APP 4.3 does not demand it (OAIC APP Guidelines paragraph 4.22). Past that, reasonableness is a question of fact and the OAIC says the factors should be applied cautiously, so record why you kept it and diarise a review for when the reason ends. What you keep is not outside the rules: APP 4.4 then applies APPs 5 to 13 to it (paragraph 4.28).

Sources: Privacy Act 1988 (Cth), APP 4.1 to APP 4.4 (Schedule 1) · OAIC APP Guidelines chapter 4 · OAIC APP guidelines

An applicant attached their whole medical file. Can we keep it?

Almost certainly not, and this is the clearest worked example of the APP 4 chain.

Health information is sensitive information under section 6. Under APP 3.3 you generally cannot collect sensitive information unless the individual consents and it is reasonably necessary for your functions. A tenancy assessment does not need an applicant's medical history, so had you asked for it, you could not lawfully have collected it.

That answers APP 4.1: you could not have collected it under APP 3. So APP 4.3 applies and you destroy or de-identify it as soon as practicable, subject to the lawful-and-reasonable qualifier.

Two practical points. The applicant volunteering it is not by itself the consent APP 3.3 requires, and consent is only half the test: the necessity limb has to be met as well, and a tenancy assessment does not meet it. And if the applicant sent it to explain a request, for example a modification or an assistance animal, deal with the request on the information you need rather than on the underlying condition, and destroy the rest.

Sources: Privacy Act 1988 (Cth), section 6 (sensitive information) and APP 3.3, APP 4.3 (Schedule 1) · OAIC APP Guidelines chapters 3 and 4 · OAIC APP guidelines

Someone copied us into an email by mistake. What are our obligations?

The information is unsolicited, so APP 4 applies to you in the ordinary way: decide whether you could have collected it, and if not, destroy or de-identify it as soon as practicable where lawful and reasonable. This sits inside the largest non-criminal cause of notified breaches in Australia: human error accounted for 37% of breaches notified to the OAIC (193 notifications) in January to June 2025, and the OAIC received 1,205 notifications across the 2025 calendar year, the most since the scheme began in 2018. This sits inside the largest non-criminal cause of notified breaches in Australia: human error accounted for 37% of breaches notified to the OAIC (193 notifications) in January to June 2025, and the OAIC received 1,205 notifications across the 2025 calendar year, the most since the scheme began in 2018.

Three things worth adding, because this scenario has a second party in it:

If the misdirected information came from inside your own business, that is a different question and it is your breach to assess, not someone else's.

Sources: Privacy Act 1988 (Cth), APP 4 (Schedule 1); Part IIIC, sections 26WE, 26WF and 26WH · OAIC APP Guidelines chapter 4 · OAIC notifiable data breaches · OAIC, NDB statistics for January to June 2025 (4 November 2025) and notifications at an all-time high in 2025 (6 July 2026) · See also data-breach response for real estate

Someone left a reference letter about a different applicant. What do we do with it?

Treat it as unsolicited information about a person who is not your correspondent, which raises the care level rather than lowering it.

You never asked for it, so APP 4.1 applies. You could not have collected a third party's reference in the ordinary course of assessing a different application, so APP 4.3 points to destruction or de-identification as soon as practicable, subject to lawful and reasonable.

Do not use it to inform any decision about anyone, do not mention it to the applicant it concerns, and do not return it to the person who left it if doing so would disclose it further. Destroy it securely and note what you did.

Sources: Privacy Act 1988 (Cth), APP 4.1 and APP 4.3 (Schedule 1) · OAIC APP Guidelines chapter 4 · OAIC APP guidelines

Can we use unsolicited information to assess an application?

Only if you determine you could have collected it under APP 3 in the first place.

APP 4.2 lets you use and disclose the information for the limited purpose of making that determination. It does not let you use it for the decision while you are deciding whether you are allowed to have it.

If the determination comes back yes, APP 4.4 applies APPs 5 to 13 as though you had collected it under APP 3, and you can use it for the purpose you collected it for like any other information. If it comes back no, APP 4.2 does not stretch any further: using it for the decision is outside the only use APP 4 allows you, and the information is information APP 4.3 requires you to destroy or de-identify where that is lawful and reasonable.

The practical risk here is subtle: an applicant volunteers something unflattering, it shapes a decision, and nobody records that it was ever considered. Decide first, then use or destroy.

Sources: Privacy Act 1988 (Cth), APP 4.2, APP 4.4 and APP 6 (Schedule 1) · OAIC APP Guidelines chapters 4 and 6 · OAIC APP guidelines

If we keep unsolicited information, does it become subject to all the APPs?

Yes, and this is the part people miss. Wherever APP 4.3 does not apply, APP 4.4 applies APPs 5 to 13 to the information as if you had collected it under APP 3. That covers what you could have collected, and equally what you kept because destroying it would have been unlawful or unreasonable (OAIC APP Guidelines paragraph 4.28).

That switches on real duties, not just a filing obligation:

So keeping unsolicited information is a decision with a cost, not the passive option. That is usually a good reason to destroy what you did not need.

Sources: Privacy Act 1988 (Cth), APP 4.4 and APPs 5, 10, 11, 12 and 13 (Schedule 1) · OAIC APP Guidelines chapter 4 · OAIC APP guidelines

Do we need to give a collection notice for unsolicited information we keep?

If APP 4.4 applies, yes. APP 5 is one of the principles it switches on, so the notification duty applies as though you had collected the information under APP 3.

What that looks like in practice is modest. Where the person who sent it is the person the information is about, and they know you have it, reasonable steps may be a short line in your acknowledgement confirming what you have kept and why. Where the information is about someone else, notification is harder and the better answer is usually that you could not have collected it, which routes you to destruction instead.

Note that APP 5 requires reasonable steps in the circumstances, not a guaranteed outcome, and what is reasonable takes account of how practicable notification actually is.

Sources: Privacy Act 1988 (Cth), APP 4.4 and APP 5 (Schedule 1) · OAIC APP Guidelines chapters 4 and 5 · OAIC APP guidelines

How do we destroy unsolicited documents securely?

Where APP 4.3 bites, the Act requires you to destroy or de-identify, and APP 11.2 supplies the reasonable-steps standard for doing it. Neither prescribes a method, so what is reasonable scales with the sensitivity of the material and the risk if it survives.

For a real-estate business the practical version is:

De-identification is an alternative to destruction, but it has to be genuine. Removing a name from a document that still contains an address, a licence number and an employer has not de-identified anybody.

Sources: Privacy Act 1988 (Cth), APP 4.3 and APP 11.2 (Schedule 1) · OAIC APP Guidelines chapters 4 and 11 · OAIC APP guidelines

→ Not sure what your office is holding that nobody asked for? The free 2-minute audit is built to surface exactly that.