A rental applicant sent us documents we never asked for. What do we have to do?
Work out whether the information is unsolicited, because that decides which principle applies. If you did not ask for it, APP 4.1 requires you to determine within a reasonable period whether you could have collected it under APP 3. If you could have, APP 4.4 means you simply hold it under the ordinary rules. If you could not have, APP 4.3 requires you to destroy or de-identify it as soon as practicable, but only where that is lawful and reasonable, so a legal retention duty or a live dispute can properly stop you.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
What is the difference between solicited and unsolicited information?
This is the whole answer, so it is worth being precise.
"Solicits" means you requested it. A request is an active step to collect. If you asked for proof of income, income evidence is solicited, and APP 3 governs whether you were entitled to collect it.
Unsolicited means you took no active steps to collect it. The applicant volunteered a document nobody on your team asked for. That does not become solicited merely because you accepted it, opened it, or filed it. Receiving is not requesting.
Where it is genuinely unclear which side of the line something falls on, the OAIC's guidance is to err on the side of caution and treat it as unsolicited. That is the cautious answer in a useful direction, because APP 4 sets a faster and more definite process than leaving the information to sit in a file under APP 11.
One practical consequence worth noting: your own forms decide this. If your points-based identity list names a document, anything supplied because that list names it was requested, so it is solicited and APP 3 applies. Review the list before you decide which principle you are under.
Sources: Privacy Act 1988 (Cth), section 6(1) (definition of "solicits") and APP 3, APP 4 (Schedule 1) · OAIC APP Guidelines chapter 4, paragraphs 4.6, 4.7 and 4.9 · OAIC APP guidelines
Do we have to destroy personal information we received but never requested?
Only if you could not have collected it under APP 3, and only where destroying it is lawful and reasonable.
The sequence in APP 4 runs like this:
1. APP 4.1: within a reasonable period, determine whether you could have collected the information under APP 3, had you asked for it. 2. APP 4.2: you may use and disclose the information for the purpose of making that determination. Reading it in order to decide is permitted. 3. APP 4.3: if you determine you could not have collected it, and it is not contained in a Commonwealth record, destroy or de-identify it as soon as practicable, but only if it is lawful and reasonable to do so. 4. APP 4.4: if you determine you could have collected it, then APPs 5 to 13 apply to it as though you had collected it under APP 3. Nothing is destroyed and the ordinary rules take over.
⚠️ The "lawful and reasonable" qualifier in APP 4.3 does real work and it releases you in the cases that matter. If the document is evidence in a live or reasonably foreseeable tribunal, discrimination or insurance matter, or if another law requires you to retain it, destruction is not the right answer and APP 4.3 does not demand it. Record the reason, and diarise a review for when the reason ends. Destroying evidence to satisfy a privacy principle is a worse problem than holding it.
Sources: Privacy Act 1988 (Cth), APP 4.1 to APP 4.4 (Schedule 1) · OAIC APP Guidelines chapter 4 · OAIC APP guidelines
An applicant attached their whole medical file. Can we keep it?
Almost certainly not, and this is the clearest worked example of the APP 4 chain.
Health information is sensitive information under section 6. Under APP 3.3 you generally cannot collect sensitive information unless the individual consents and it is reasonably necessary for your functions. A tenancy assessment does not need an applicant's medical history, so had you asked for it, you could not lawfully have collected it.
That answers APP 4.1: you could not have collected it under APP 3. So APP 4.3 applies and you destroy or de-identify it as soon as practicable, subject to the lawful-and-reasonable qualifier.
Two practical points. The applicant volunteering it does not supply the consent APP 3.3 requires, because consent has to be informed and specific to a collection you are actually making. And if the applicant sent it to explain a request, for example a modification or an assistance animal, deal with the request on the information you need rather than on the underlying condition, and destroy the rest.
Sources: Privacy Act 1988 (Cth), section 6 (sensitive information) and APP 3.3, APP 4.3 (Schedule 1) · OAIC APP Guidelines chapters 3 and 4 · OAIC APP guidelines
Someone copied us into an email by mistake. What are our obligations?
The information is unsolicited, so APP 4 applies to you in the ordinary way: decide whether you could have collected it, and if not, destroy or de-identify it as soon as practicable where lawful and reasonable.
Three things worth adding, because this scenario has a second party in it:
- Do not circulate it. Forwarding a misdirected email to colleagues to point out the error is a use and a disclosure of someone else's personal information, and it is the step that turns a stranger's mistake into your problem.
- Tell the sender. Nothing in the Privacy Act compels it, but the sender may have a notifiable data breach on their hands, and their assessment clock is running from the moment they have reasonable grounds to suspect. Telling them promptly is what lets them use the remedial-action route in section 26WF, which can mean the breach never becomes notifiable at all.
- Delete it properly, including from your deleted items and any backup you control, to the extent that is practicable.
If the misdirected information came from inside your own business, that is a different question and it is your breach to assess, not someone else's.
Sources: Privacy Act 1988 (Cth), APP 4 (Schedule 1); Part IIIC, sections 26WE, 26WF and 26WH · OAIC APP Guidelines chapter 4 · OAIC notifiable data breaches · See also data-breach response for real estate
Someone left a reference letter about a different applicant. What do we do with it?
Treat it as unsolicited information about a person who is not your correspondent, which raises the care level rather than lowering it.
You never asked for it, so APP 4.1 applies. You could not have collected a third party's reference in the ordinary course of assessing a different application, so APP 4.3 points to destruction or de-identification as soon as practicable, subject to lawful and reasonable.
Do not use it to inform any decision about anyone, do not mention it to the applicant it concerns, and do not return it to the person who left it if doing so would disclose it further. Destroy it securely and note what you did.
Sources: Privacy Act 1988 (Cth), APP 4.1 and APP 4.3 (Schedule 1) · OAIC APP Guidelines chapter 4 · OAIC APP guidelines
Can we use unsolicited information to assess an application?
Only if you determine you could have collected it under APP 3 in the first place.
APP 4.2 lets you use and disclose the information for the limited purpose of making that determination. It does not let you use it for the decision while you are deciding whether you are allowed to have it.
If the determination comes back yes, APP 4.4 applies APPs 5 to 13 as though you had collected it under APP 3, and you can use it for the purpose you collected it for like any other information. If it comes back no, you cannot use it at all, and using it anyway is a straightforward contravention of APP 6 on top of the failure to destroy.
The practical risk here is subtle: an applicant volunteers something unflattering, it shapes a decision, and nobody records that it was ever considered. Decide first, then use or destroy.
Sources: Privacy Act 1988 (Cth), APP 4.2, APP 4.4 and APP 6 (Schedule 1) · OAIC APP Guidelines chapters 4 and 6 · OAIC APP guidelines
If we keep unsolicited information, does it become subject to all the APPs?
Yes, and this is the part people miss. Where you determine you could have collected the information under APP 3, APP 4.4 applies APPs 5 to 13 to it as if you had collected it under APP 3.
That switches on real duties, not just a filing obligation:
- APP 5: take reasonable steps to notify the individual of the collection and the circumstances of it. If you keep a list of people whose details arrived unsolicited, the notification duty runs to each of them.
- APP 10: reasonable steps to keep it accurate, up to date and complete, and relevant when you use or disclose it.
- APP 11: secure it, and destroy or de-identify it once you no longer need it for a permitted purpose, unless you are required by law to retain it.
- APP 12 and 13: it is within an access request, and it is correctable.
So keeping unsolicited information is a decision with a cost, not the passive option. That is usually a good reason to destroy what you did not need.
Sources: Privacy Act 1988 (Cth), APP 4.4 and APPs 5, 10, 11, 12 and 13 (Schedule 1) · OAIC APP Guidelines chapter 4 · OAIC APP guidelines
Do we need to give a collection notice for unsolicited information we keep?
If APP 4.4 applies, yes. APP 5 is one of the principles it switches on, so the notification duty applies as though you had collected the information under APP 3.
What that looks like in practice is modest. Where the person who sent it is the person the information is about, and they know you have it, reasonable steps may be a short line in your acknowledgement confirming what you have kept and why. Where the information is about someone else, notification is harder and the better answer is usually that you could not have collected it, which routes you to destruction instead.
Note that APP 5 requires reasonable steps in the circumstances, not a guaranteed outcome, and what is reasonable takes account of how practicable notification actually is.
Sources: Privacy Act 1988 (Cth), APP 4.4 and APP 5 (Schedule 1) · OAIC APP Guidelines chapters 4 and 5 · OAIC APP guidelines
How do we destroy unsolicited documents securely?
The Act requires you to destroy or de-identify, and to take reasonable steps in doing so. It does not prescribe a method, so what is reasonable scales with the sensitivity of the material and the risk if it survives.
For a real-estate business the practical version is:
- Paper: cross-cut shred, do not bin. Applications and identity documents in a recycling bin are a foreseeable exposure.
- Email: delete from the mailbox and from deleted items, and remember that forwarding it to yourself or to a colleague created copies you also have to remove.
- Systems: delete the attachment from the CRM record, not just the reference to it, and check whether your cloud provider retains deleted items and for how long.
- Backups: to the extent it is practicable to reach them. Where it genuinely is not, record that, and make sure the retention cycle will clear it.
- Note what you destroyed and when. A destruction you cannot evidence is one you will be assumed not to have done.
De-identification is an alternative to destruction, but it has to be genuine. Removing a name from a document that still contains an address, a licence number and an employer has not de-identified anybody.
Sources: Privacy Act 1988 (Cth), APP 4.3 and APP 11.2 (Schedule 1) · OAIC APP Guidelines chapters 4 and 11 · OAIC APP guidelines
→ Not sure what your office is holding that nobody asked for? The free 2-minute audit is built to surface exactly that.