In this article

Kooky
Builder of Shaka, the payment router that pays every agent their commission on closing date.
About Kooky and Shaka →A property manager's mailbox is a filing cabinet. On an ordinary Monday it holds rental applications with licences and payslips attached, a ledger for an owner, a condition report with photographs of someone's bedroom, and a note about a former tenant who left owing rent. When that mailbox is taken over by an outsider, or a laptop goes missing from a car, or a ledger is sent to the wrong owner, the principal's first question is whether anyone has to be told.
In Queensland the answer runs through two sets of rules, and the order matters. The first is the Residential Tenancies and Rooming Accommodation Act 2008, which since 1 May 2025 has told every property manager and owner what may be collected from a rental applicant, how it must be stored and when it must be destroyed. Those rules decide how much is sitting in the office when something goes wrong. The second is the federal Notifiable Data Breaches scheme in the Privacy Act 1988, which decides whether a breach must be reported, to whom and how fast. This guide takes an agency's files one by one, sets out the Queensland duties that attach to them as the Residential Tenancies Authority (RTA) explains them, and then walks through the federal scheme as the Office of the Australian Information Commissioner (OAIC) describes it. It gives the general rules. Whether one incident is notifiable depends on its facts.
RTA guidance on rental applications and personal information under the Residential Tenancies and Rooming Accommodation Act 2008; OAIC guide to the Notifiable Data Breaches scheme.
What sits in a Queensland agency's files
A breach is measured by what was in the file. Before any law is applied, it helps to list what a Queensland office that sells and manages property actually keeps, and which rule speaks to each kind of record.
Related readAgency records in Queensland: what to keep, how long, in what form| Record | What is in it | Rule that bites |
|---|---|---|
| Rental applications | Form 22 or Form R22, with up to two documents each for identity, financial ability and suitability | Tenancy Act: secure storage, limited access, destruction within set periods |
| Tenancy files | The agreement, the entry condition report, rent payment records, inspection photographs | Tenancy Act: kept at least one year after the agreement ends, destroyed within seven years |
| Tenancy database listings | A former tenant's name with an amount owing or a tribunal termination | Tenancy Act: listing conditions, correction within set days, removal after three years |
| Buyer and seller identity records | Identity documents gathered, from 1 July 2026, where the agency reports under the anti-money laundering law | Privacy Act applies to those records, whatever the agency's turnover |
| Staff records | Records containing tax file number information | Privacy Act applies to that information |
Sources: RTA pages on applying for a rental property, personal information and tenancy databases; OAIC, Data breach preparation and response, Part 4.
Two more groups of records belong on any honest list, although the pages read for this guide set no privacy rule that is particular to them. A managing agency's trust account records carry owners' names and the bank accounts their rent is paid into, and its landlord files carry management appointments and correspondence. For those, the question after an incident is the federal one alone: is the agency inside the Privacy Act, and is serious harm likely.
The rental application: what Queensland allows in the file
The RTA's factsheet for property managers and owners sets out the application rules that started on 1 May 2025. An application for a general tenancy or a moveable dwelling is made on Form 22, and an application for rooming accommodation on Form R22. The form requirement does not apply to the lessors the Act calls relevant lessors, for general tenancy agreements only.
The form limits what comes in. A property manager or owner may ask for no more than two documents in each of three categories: documents that verify identity, documents that show the applicant's financial ability to pay the rent, and documents that go to suitability as a tenant. An applicant may choose to hand over more, but may not be asked to.
Some material may not be requested at all. The factsheet lists the applicant's history of legal action or dispute resolution, notices to remedy a breach, rental bond history or claims on a bond, and statements of credit accounts or bank transaction details.
The same factsheet deals with how the application arrives. Applicants must be given at least two different ways to submit it, and one of them must not be restrictive. The RTA counts as restrictive an online-only platform, a method that requires submission through a third party other than a real estate agent, and any method that costs the applicant money. In its article of 22 July 2025 on compliance, the RTA put the maximum penalty for failing to use the standard form, and for failing to offer the two methods, at 20 penalty units each.
Related readRent apps, payment fees and tenant data: the Queensland tenancy rulesFor a breach, these limits work in the agency's favour. An application that follows the form holds at most six requested documents, and no bank transaction listing that the agency asked for.
Identity documents: sighted or copied
Identity documents are the records with the most obvious value to a stranger, and Queensland gives them their own rule. The RTA's factsheet says an applicant may give copies of identity documents or allow the property manager or owner to sight the originals in person. Where the originals are sighted, the property manager or owner is prohibited from keeping a copy or recording the details of the document without the applicant's consent.
The RTA's July 2025 article explains where the line falls. It names passports, driver licences and birth certificates among the documents concerned. Notes may be made of the type of document, its number, and the fact that it was sighted. Taking a photocopy, a scan or a photograph of the original counts as keeping a copy, and keeping a copy without consent is an offence with a maximum penalty of 20 penalty units.
A file that records "driver licence sighted" exposes far less in a breach than a file that holds an image of the licence. Where the applicant sends copies by email or through a platform, the storage and destruction rules below apply to them.
Storage, access and the two destruction dates
The RTA's page on personal information states the Queensland duties in three parts.
Purpose. A property manager or owner may collect personal information only if it is relevant to the application process or to managing the premises. The RTA includes photographs taken at inspections in the term, and its July 2025 article describes personal information as information or an opinion about a specific person. The information may not be used for another purpose without consent.
Related readDelivering seller disclosure in Queensland: email, links and proofSecurity and access. The information must be kept secure, whether it is held on paper or digitally, and access is restricted to the people who need it to assess the applicant or manage the property.
Destruction. An unsuccessful applicant's personal information must be destroyed within three months of the start of the successful tenant's agreement. A tenant's personal information must be destroyed within seven years of the agreement ending. The RTA's July 2025 article says the seven-year rule applies to tenancy agreements that were active on, or began after, 1 May 2025.
The page gives 20 penalty units as the maximum penalty for non-compliance. It also notes a minimum pulling the other way: copies of the tenancy agreement, the entry condition report and the rent payment records are kept for at least one year after the agreement ends. A tenancy file therefore has a floor of one year and a ceiling of seven.
Read with a breach in mind, the three-month rule is the one that changes the outcome. A busy listing can draw dozens of applications and produce one tenant. If the unsuccessful applications are destroyed on time, an intruder who gets into the system a year later finds one household's documents for that property. If they were never cleared, the intruder finds all of them, and the agency has a second problem beside the breach: information it was required by Queensland law to have destroyed.
These duties apply to property managers and owners as such. The RTA's pages do not tie them to turnover, so a small agency that is outside the federal Privacy Act for most purposes is still bound by them.
Related readTenancy notices by email in Queensland: consent, forms, counting daysTenancy database listings
A tenancy database is described by the RTA as a record that holds personal information about someone who has lived in a rental property. The databases are privately run and are not kept by the RTA. An agency touches them twice: when it checks an applicant and when it lists a former tenant.
A listing is itself a disclosure of personal information, and the Act controls it closely. On the RTA's account a person may be listed only if they were named on the tenancy agreement, the agreement has ended, there is an approved reason, and reasonable steps were taken to tell the person about the proposed listing. The approved reasons are an amount owing that is more than the rental bond, in the circumstances the Act sets out, and a termination by the Queensland Civil and Administrative Tribunal for objectionable behaviour or repeated breaches. Where no bond was paid, the amount owing must be more than one week's rent.
The duties continue after the listing is made. The RTA says a property manager or owner who learns that a listing is inaccurate must notify the database within 7 days, the operator must amend or remove the information within 14 days of being told, records of those notifications are kept for one year, and a listing must be removed after three years. A debt that has been paid requires the listing to be removed. An applicant must be told in writing which database lists them, what the listing is about and how it can be amended or removed.
Related readWho regulates property technology in Queensland: a map of the watchdogsThe RTA gives the penalty for breaching the database rules as up to 50 penalty units per offence for an individual, with higher penalties for corporations. It adds that a complaint about a listing can also be taken to the OAIC.
What the Queensland rules do not say
The RTA pages read for this guide describe duties to collect narrowly, store securely and destroy on time. They do not describe a duty on a property manager or owner to notify applicants or tenants when the information is lost or accessed. The RTA's page on personal information refers readers to two bodies for privacy complaints, the Office of the Information Commissioner Queensland and the OAIC, and names the Commonwealth Privacy Act 1988 beside the State's Information Privacy Act 2009.
The duty to notify comes from the federal scheme. So the next question for a Queensland agency is whether it is inside that scheme at all.
Is the agency inside the federal scheme?
The Notifiable Data Breaches scheme was added to the Privacy Act by the Privacy Amendment (Notifiable Data Breaches) Act 2017 and is run by the OAIC. It follows the reach of the Privacy Act. The OAIC's guide says the entities that must comply are those with obligations under Australian Privacy Principle 11 to protect personal information, which means Australian Government agencies and private sector organisations with annual turnover of more than $3 million.
An agency under that figure is outside the scheme for most of what it holds. The guide then lists small business operators that are covered all the same, some as a whole and some only for a particular activity. Three of those cases turn up in real estate.
Related readBody corporate by email and e-vote: Queensland's digital rulebook| Agency | Covered | For which records |
|---|---|---|
| Annual turnover above $3 million | Yes | All the personal information it holds: applications, tenancy files, owner and buyer records. |
| Small agency reporting under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (real estate agents from 1 July 2026) | In part | The records connected with that reporting, such as identity documents. |
| Any agency holding records with tax file number information | In part | The tax file number information. |
| Small business that operates a residential tenancy database | In part | That activity. |
| Other small agency at or under $3 million | No | Outside the scheme for the rest of its files. |
Source: OAIC, Data breach preparation and response, Part 4: Notifiable Data Breach scheme. Coverage of a particular business depends on its circumstances.
The tenancy database row needs reading with care. The guide names the businesses that operate residential tenancy databases. An agency that searches a database or lists a former tenant on one is a user, and on the guide's wording is not the operator.
The anti-money laundering row has a partial effect. The identity documents and customer records gathered to meet those duties are protected by the Privacy Act and the breach scheme whatever the agency's turnover. The same agency's rental applications are not brought in by that route. The result is that, from 1 July 2026, when agents who broker sales become reporting entities, a small Queensland agency can owe a federal notification for a breach of its sales identity records and none for a breach of its rental applications, while the Queensland storage and destruction duties apply to the applications throughout.
When an incident becomes an eligible data breach
For an agency that is covered, the OAIC's guide sets three requirements, and all must be met. There must be unauthorised access to personal information, unauthorised disclosure of it, or loss of it. The incident must be likely to result in serious harm to one or more individuals. And the entity must not have been able to prevent the likely serious harm through remedial action. On the last point the guide is direct: where remedial action means the breach would not be likely to result in serious harm, it is not an eligible data breach and no notification is required.
The guide describes serious harm broadly, as serious physical, psychological, emotional, financial or reputational harm, with identity theft, significant financial loss and threats to a person's safety among its examples. Section 26WG of the Privacy Act lists matters to weigh, including the kind of information, its sensitivity, whether it is protected by security measures, who has obtained it or could obtain it, and the nature of the harm.
The scenarios below are this magazine's illustrations of that reasoning in a property management office. They are not rulings and are not taken from the regulator.
| Incident | Likely serious harm? | Usual direction |
|---|---|---|
| A property manager's mailbox is taken over and holds months of Form 22 applications with licence copies and payslips | Identity documents and income details in unknown hands. | Points towards notification. |
| An owner's rent ledger is emailed to the wrong owner, who deletes it and confirms in writing | The question is whether the remedial action has removed the likelihood of serious harm. | May not be eligible once remedied. |
| An encrypted laptop holding tenancy files is stolen from a car | Security measures are one of the listed factors. | Depends on how strong the protection is. |
Illustrative scenarios prepared for this guide, applying the factors in section 26WG of the Privacy Act 1988. Each real incident turns on its own facts.
The first scenario is where the Queensland rules and the federal test meet. The number of people affected is the number of applications still in the mailbox. An office that sights identity documents in person, holds two documents per category and clears unsuccessful applications inside three months has a short list of people to assess. An office that has done none of those things has a long one.
The 30 days and the two notifications
The scheme sets a sequence. It starts when the agency becomes aware of grounds to suspect a breach, not when it is certain of one. The first step in the figure is a practical one, and it is the same remedial action that can take a breach outside the scheme. The other four come from the OAIC's guide.
- ContainReset the mailbox password, disable the lost device, recall the ledger. Remedial action can prevent the serious harm altogether.
- AssessDecide whether the breach is an eligible one, within 30 calendar days after the day the agency became aware of the grounds for suspicion.
- Prepare the statementIf the breach is eligible, write the statement with its four required elements.
- Tell the CommissionerGive the statement as soon as practicable after becoming aware of the eligible data breach, on the OAIC's online form.
- Tell the people affectedNotify the applicants, tenants or owners as soon as practicable after completing the statement.
The 30 days are calendar days, and they belong to the assessment only. For the two notifications the guide uses a different measure, "as soon as practicable", and gives no number of hours or days. An agency that knows on day three that its breach is eligible has no reason in the scheme's wording to wait for day 30.
What the notice says, and who sends it
The statement has four required elements: the identity of the entity and the details people need to reach it, a description of the eligible data breach, the particular kind or kinds of information concerned, and recommendations about the steps individuals should take in response. For a rental applicant the third element is the useful one. A notice that says a licence copy and two payslips were exposed tells the reader what to do next. A notice that says "personal information" does not.
The guide allows three ways to reach people. The agency can notify each individual the information relates to. It can notify only those at risk of serious harm, which means two applicants in the same breach can properly be treated differently. Or, if neither is practicable, it can publish a copy of the statement on its website and take reasonable steps to publicise it. For unsuccessful applicants whose details were destroyed on time there is nobody to write to, because their documents were not there to be taken.
When the breach happens at the application platform
An agency and the platform that stores its rental applications often hold the same information. The OAIC's guide says that for jointly held information only one entity needs to notify individuals and the Commissioner, and the others need not assess a breach one entity has already assessed. The guide read for this article does not say which entity it must be, so the incident clause of the platform agreement settles it.
Penalties on both sides
A Queensland agency that mishandles tenancy information faces two scales of penalty. On the State side the RTA's pages give maximums of 20 penalty units for the application, identity document and personal information offences described above, and up to 50 penalty units per offence for an individual under the tenancy database rules. The RTA's pages state the maximums in penalty units.
On the federal side the scale is of another order. On 8 October 2025 the Federal Court ordered Australian Clinical Labs to pay $5.8 million over a 2022 breach at its Medlab Pathology business, which the OAIC described the next day as the first civil penalties ordered under the Privacy Act. Of that sum, $4.2 million was for failing to take reasonable steps to protect personal information, $800,000 for failing to carry out a reasonable and expeditious assessment, and $800,000 for failing to notify the Commissioner as soon as practicable. The case concerned a large pathology company and not a property office, but two of its three components priced the duties in the previous two sections: the assessment and the notice.
For a tenant, an applicant or an owner, the combined effect is this. Queensland law limits what the agency may hold about them and for how long, whatever the agency's size. Federal law adds a right to be told about a serious breach, but only where the agency, or the particular record, is inside the Privacy Act. A small agency outside the scheme has no duty under it to notify, and nothing in the scheme prevents it from telling people anyway.
In a property management office, the size of a breach is decided months earlier, by what was collected and what was destroyed on time.