A rental applicant sent us documents we never asked for. What do we have to do?
Work out whether the information is unsolicited, because that decides which principle applies. If you did not ask for it, APP 4.1 requires you to determine within a reasonable period whether you could have collected it under APP 3. If you could not have, APP 4.3 requires you to destroy or de-identify it as soon as practicable, but only if it is lawful and reasonable to do so, so a legal retention duty or a binding order can properly stop you. Wherever APP 4.3 does not apply, APP 4.4 puts APPs 5 to 13 over the information as if you had collected it.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
What is the difference between solicited and unsolicited information?
This is the whole answer, so it is worth being precise.
"Solicits" means you requested it. A request is an active step to collect. If you asked for proof of income, income evidence is solicited, and APP 3 governs whether you were entitled to collect it.
Unsolicited means you took no active steps to collect it. The applicant volunteered a document nobody on your team asked for. That does not become solicited merely because you accepted it, opened it, or filed it. Receiving is not requesting.
Where it is genuinely unclear which side of the line something falls on, the OAIC's guidance is to err on the side of caution and treat it as unsolicited. That is the cautious answer in a useful direction, because APP 4 sets a faster and more definite process than leaving the information to sit in a file under APP 11.
One practical consequence worth noting: your own forms decide this. If your points-based identity list names a document, anything supplied because that list names it was requested, so it is solicited and APP 3 applies. Anything sent on top of what you asked for should be treated as unsolicited (OAIC APP Guidelines paragraph 4.8). Review the list before you decide which principle you are under.
Sources: Privacy Act 1988 (Cth), section 6(1) (definition of "solicits") and APP 3, APP 4 (Schedule 1) · OAIC APP Guidelines chapter 4, paragraphs 4.6, 4.7 and 4.9 · OAIC APP guidelines
Do we have to destroy personal information we received but never requested?
Only if you could not have collected it under APP 3, and only where destroying it is lawful and reasonable.
The sequence in APP 4 runs like this:
- APP 4.1: within a reasonable period, determine whether you could have collected the information under APP 3, had you asked for it.
- APP 4.2: you may use and disclose the information for the purpose of making that determination. Reading it in order to decide is permitted.
- APP 4.3: if you determine you could not have collected it, and it is not contained in a Commonwealth record, destroy or de-identify it as soon as practicable, but only if it is lawful and reasonable to do so.
- APP 4.4: wherever APP 4.3 does not apply, whether because you could have collected it or because destruction is not lawful and reasonable, APPs 5 to 13 apply to the information as if you had collected it under APP 3.
⚠️ The "lawful and reasonable" qualifier in APP 4.3 does real work, and it is why a retention duty beats a destruction duty. Where an Australian law or a binding court or tribunal order requires you to keep the document, destroying it is not lawful and APP 4.3 does not demand it (OAIC APP Guidelines paragraph 4.22). Past that, reasonableness is a question of fact and the OAIC says the factors should be applied cautiously, so record why you kept it and diarise a review for when the reason ends. What you keep is not outside the rules: APP 4.4 then applies APPs 5 to 13 to it (paragraph 4.28).
Sources: Privacy Act 1988 (Cth), APP 4.1 to APP 4.4 (Schedule 1) · OAIC APP Guidelines chapter 4 · OAIC APP guidelines
An applicant attached their whole medical file. Can we keep it?
Almost certainly not, and this is the clearest worked example of the APP 4 chain.
Health information is sensitive information under section 6. Under APP 3.3 you generally cannot collect sensitive information unless the individual consents and it is reasonably necessary for your functions. A tenancy assessment does not need an applicant's medical history, so had you asked for it, you could not lawfully have collected it.
That answers APP 4.1: you could not have collected it under APP 3. So APP 4.3 applies and you destroy or de-identify it as soon as practicable, subject to the lawful-and-reasonable qualifier.
Two practical points. The applicant volunteering it is not by itself the consent APP 3.3 requires, and consent is only half the test: the necessity limb has to be met as well, and a tenancy assessment does not meet it. And if the applicant sent it to explain a request, for example a modification or an assistance animal, deal with the request on the information you need rather than on the underlying condition, and destroy the rest.
Sources: Privacy Act 1988 (Cth), section 6 (sensitive information) and APP 3.3, APP 4.3 (Schedule 1) · OAIC APP Guidelines chapters 3 and 4 · OAIC APP guidelines
Someone copied us into an email by mistake. What are our obligations?
The information is unsolicited, so APP 4 applies to you in the ordinary way: decide whether you could have collected it, and if not, destroy or de-identify it as soon as practicable where lawful and reasonable. This sits inside the largest non-criminal cause of notified breaches in Australia: human error accounted for 37% of breaches notified to the OAIC (193 notifications) in January to June 2025, and the OAIC received 1,205 notifications across the 2025 calendar year, the most since the scheme began in 2018. This sits inside the largest non-criminal cause of notified breaches in Australia: human error accounted for 37% of breaches notified to the OAIC (193 notifications) in January to June 2025, and the OAIC received 1,205 notifications across the 2025 calendar year, the most since the scheme began in 2018.
Three things worth adding, because this scenario has a second party in it:
- Do not circulate it. Forwarding a misdirected email to colleagues to point out the error is a use and a disclosure of someone else's personal information, and it is the step that turns a stranger's mistake into your problem.
- Tell the sender. Nothing in the Privacy Act compels it, but the sender may have a notifiable data breach on their hands, and their assessment clock is running from the moment they have reasonable grounds to suspect. Telling them promptly is what lets them use the remedial-action route in section 26WF, which can mean the breach never becomes notifiable at all.
- Delete it properly, including from your deleted items and any backup you control, to the extent that is practicable.
If the misdirected information came from inside your own business, that is a different question and it is your breach to assess, not someone else's.
Sources: Privacy Act 1988 (Cth), APP 4 (Schedule 1); Part IIIC, sections 26WE, 26WF and 26WH · OAIC APP Guidelines chapter 4 · OAIC notifiable data breaches · OAIC, NDB statistics for January to June 2025 (4 November 2025) and notifications at an all-time high in 2025 (6 July 2026) · See also data-breach response for real estate
Someone left a reference letter about a different applicant. What do we do with it?
Treat it as unsolicited information about a person who is not your correspondent, which raises the care level rather than lowering it.
You never asked for it, so APP 4.1 applies. You could not have collected a third party's reference in the ordinary course of assessing a different application, so APP 4.3 points to destruction or de-identification as soon as practicable, subject to lawful and reasonable.
Do not use it to inform any decision about anyone, do not mention it to the applicant it concerns, and do not return it to the person who left it if doing so would disclose it further. Destroy it securely and note what you did.
Sources: Privacy Act 1988 (Cth), APP 4.1 and APP 4.3 (Schedule 1) · OAIC APP Guidelines chapter 4 · OAIC APP guidelines
Can we use unsolicited information to assess an application?
Only if you determine you could have collected it under APP 3 in the first place.
APP 4.2 lets you use and disclose the information for the limited purpose of making that determination. It does not let you use it for the decision while you are deciding whether you are allowed to have it.
If the determination comes back yes, APP 4.4 applies APPs 5 to 13 as though you had collected it under APP 3, and you can use it for the purpose you collected it for like any other information. If it comes back no, APP 4.2 does not stretch any further: using it for the decision is outside the only use APP 4 allows you, and the information is information APP 4.3 requires you to destroy or de-identify where that is lawful and reasonable.
The practical risk here is subtle: an applicant volunteers something unflattering, it shapes a decision, and nobody records that it was ever considered. Decide first, then use or destroy.
Sources: Privacy Act 1988 (Cth), APP 4.2, APP 4.4 and APP 6 (Schedule 1) · OAIC APP Guidelines chapters 4 and 6 · OAIC APP guidelines
If we keep unsolicited information, does it become subject to all the APPs?
Yes, and this is the part people miss. Wherever APP 4.3 does not apply, APP 4.4 applies APPs 5 to 13 to the information as if you had collected it under APP 3. That covers what you could have collected, and equally what you kept because destroying it would have been unlawful or unreasonable (OAIC APP Guidelines paragraph 4.28).
That switches on real duties, not just a filing obligation:
- APP 5: take reasonable steps to notify the individual of the collection and the circumstances of it. If you keep a list of people whose details arrived unsolicited, the notification duty runs to each of them.
- APP 10: reasonable steps to keep it accurate, up to date and complete, and relevant when you use or disclose it.
- APP 11: secure it, and destroy or de-identify it once you no longer need it for a permitted purpose, unless an Australian law or a court or tribunal order requires you to retain it.
- APP 12 and 13: it is within an access request, and it is correctable.
So keeping unsolicited information is a decision with a cost, not the passive option. That is usually a good reason to destroy what you did not need.
Sources: Privacy Act 1988 (Cth), APP 4.4 and APPs 5, 10, 11, 12 and 13 (Schedule 1) · OAIC APP Guidelines chapter 4 · OAIC APP guidelines
Do we need to give a collection notice for unsolicited information we keep?
If APP 4.4 applies, yes. APP 5 is one of the principles it switches on, so the notification duty applies as though you had collected the information under APP 3.
What that looks like in practice is modest. Where the person who sent it is the person the information is about, and they know you have it, reasonable steps may be a short line in your acknowledgement confirming what you have kept and why. Where the information is about someone else, notification is harder and the better answer is usually that you could not have collected it, which routes you to destruction instead.
Note that APP 5 requires reasonable steps in the circumstances, not a guaranteed outcome, and what is reasonable takes account of how practicable notification actually is.
Sources: Privacy Act 1988 (Cth), APP 4.4 and APP 5 (Schedule 1) · OAIC APP Guidelines chapters 4 and 5 · OAIC APP guidelines
How do we destroy unsolicited documents securely?
Where APP 4.3 bites, the Act requires you to destroy or de-identify, and APP 11.2 supplies the reasonable-steps standard for doing it. Neither prescribes a method, so what is reasonable scales with the sensitivity of the material and the risk if it survives.
For a real-estate business the practical version is:
- Paper: cross-cut shred, do not bin. Applications and identity documents in a recycling bin are a foreseeable exposure.
- Email: delete from the mailbox and from deleted items, and remember that forwarding it to yourself or to a colleague created copies you also have to remove.
- Systems: delete the attachment from the CRM record, not just the reference to it, and check whether your cloud provider retains deleted items and for how long.
- Backups: to the extent it is practicable to reach them. Where it genuinely is not, record that, and make sure the retention cycle will clear it.
- Note what you destroyed and when. A destruction you cannot evidence is one you will be assumed not to have done.
De-identification is an alternative to destruction, but it has to be genuine. Removing a name from a document that still contains an address, a licence number and an employer has not de-identified anybody.
Sources: Privacy Act 1988 (Cth), APP 4.3 and APP 11.2 (Schedule 1) · OAIC APP Guidelines chapters 4 and 11 · OAIC APP guidelines
→ Not sure what your office is holding that nobody asked for? The free 2-minute audit is built to surface exactly that.