info@lookup.com.au 1300 553 559 Remote Assist
    Lookup Logo
    Real Estate & Property Business Outcome

    Protecting Personal Information in a Property Business

    Real estate businesses hold some of the most sensitive personal information an ordinary Australian will ever hand over. The question is not whether you hold it — it is whether you hold only what you need, and whether you can control who sees it.

    Abstract editorial illustration representing deliberate collection of less personal information through a filtering funnel, with restricted access bounded by a single controlled entry point in a property business.

    A rental application is one of the most sensitive information packages an ordinary Australian hands over. It typically contains a full identity document, proof of income, employment details, rental history, personal references and sometimes bank statements. Property businesses receive them constantly — often by email — and rarely decide deliberately what happens to them afterwards.

    The same business may also hold identity documents from property buyers, financial details from landlords, trust account records, inspection photographs and years of correspondence. The information arrives, sits somewhere, and in most cases no one has made a deliberate decision about how long it stays or who can see it. The default is retention by accident rather than by design.

    The question this page addresses is practical, not theoretical: how does a property business hold only what it needs, and control who can see it? LOOKUP does not provide privacy or legal advice. The guidance here is about the technology environment — identity, access, storage, retention and recovery — that determines whether a business can actually answer that question.

    What a property business actually holds

    Before a business can control personal information, it needs to understand what it actually has. A typical Australian property business holds far more sensitive information than most of its staff realise.

    Rental applications

    Completed applications containing identity details, employment information, income evidence, rental history and personal references — often for every prospective tenant who applied, not just the successful one.

    Identity documents

    Passports, driver's licences, Medicare cards and other identity documents provided as part of applications, tenancy agreements, sales contracts and trust account processes.

    Payslips and bank statements

    Proof of income and financial position — payslips, bank statements, tax assessments — provided to demonstrate affordability or financial capacity for a lease or purchase.

    Tenancy histories

    Records of previous tenancies, including addresses, durations, bond outcomes, property manager references and any disputes or issues recorded during the tenancy.

    Landlord financial details

    Bank account details for rent disbursement, tax file information, ownership structures, correspondence about expenses, and in some cases identification of beneficial owners.

    Correspondence

    Emails and messages containing personal information — tenant complaints, maintenance requests, negotiation details, settlement instructions and communication with solicitors and conveyancers.

    Trust account records

    Records of rent collected, bonds held, deposits taken and disbursements made — all tied to identifiable individuals and subject to their own regulatory requirements.

    Inspection records

    Inspection reports, photographs of properties (which may show personal belongings), entry and exit condition reports, and notes about tenants' living circumstances.

    The volume is the point. A single property management portfolio involves identity documents for every landlord, every current and recent tenant, and an unknown number of unsuccessful applicants whose information was collected but never needed. Multiply that across years of operation and the information footprint is substantial — and in most businesses, no one has a complete picture of where it all sits.

    The sensitivity is also the point. A rental application contains enough information to open a bank account, apply for credit or impersonate someone. A passport scan sitting in an unattended inbox is not a minor administrative matter — it is a serious exposure that most property businesses handle casually because they have always handled it casually.

    The information is also distributed. Some of it lives in the property management platform. Some lives in the CRM. Some lives in trust accounting software. Some lives in email. Some lives on shared drives. Some lives on individual staff members' devices. When a tenant asks what information the business holds about them — a question they are entitled to ask — the business often cannot answer without a manual search across multiple systems, and even then the answer may be incomplete.

    The problem is usually collection, not just storage

    Most property businesses focus on how they store personal information. The harder question — and the one that matters more — is whether they should have collected it in the first place.

    Australian privacy regulation expects businesses to collect only personal information that is reasonably necessary for their functions or activities. The principle is straightforward: if you do not need it, you should not be holding it. The Office of the Australian Information Commissioner has published guidance on personal information in the tenancy context and has raised concerns about property technology collecting more personal information than is needed.

    The practical implication is significant. Many property businesses collect identity documents, financial evidence and personal references from every prospective tenant who applies for a property — not just the successful applicant. Those applications sit in inboxes and shared folders long after the tenancy has been allocated. The business is holding sensitive information it never needed to retain, for people who never became tenants, with no deliberate decision about when it will be disposed of.

    The same applies to buyer enquiry forms, inspection attendee lists and online application portals that collect more fields than the business actually uses. Each unnecessary field is an unnecessary risk. Information never collected cannot be lost, misused, forwarded to the wrong person, demanded in a breach, or discovered years later by someone who should not have access to it.

    The technology environment should support deliberate collection. That means application forms that ask for only what is needed, intake processes that route information to a controlled destination rather than a general inbox, and retention policies that dispose of unsuccessful applications after a defined period rather than leaving them indefinitely. Collection is the first decision point — and in most property businesses, it is the one that has received the least attention.

    What a property business actually has to control

    Protecting personal information is not only about storage. It depends on decisions made at collection, at access, and at the moment someone leaves.

    Personal Information
    Collection
    Retention
    Access Control
    Identity Documents
    Email
    Devices
    Offboarding
    Retrieval

    Where it goes wrong

    Most property businesses do not mishandle personal information deliberately. They mishandle it because their systems were built for sales efficiency, not for information governance. The following patterns are common.

    Applications sitting in inboxes indefinitely

    Rental applications and identity documents received by email sit in personal inboxes and sent items for years. No one has decided how long they should be kept, and no one is responsible for deleting them. The inbox has become an accidental archive of sensitive personal information.

    Identity documents forwarded between staff

    A passport scan is emailed to the property manager, forwarded to the admin team, cc'd to the principal and sent to the conveyancer. Each forward creates a new copy in a new location. No one owns the master, and no one can guarantee all copies will be found or deleted.

    The whole team can open everything

    Access to client folders and identity documents is broad and inherited. Any staff member with a general login — including casual admin, new starters and contractors — can see every tenant's identity documents, financial details and correspondence.

    Information retained long after a tenancy ends

    Tenant files are kept indefinitely because no one has made a retention decision. A tenant who left long ago still has their identity documents, payslips and bank statements sitting in a shared folder that no one has reviewed since they vacated.

    Contractors and departed staff retaining access

    Contractors who finished a project months ago still have logins. Staff who left the business still have active accounts. Shared mailboxes mean access is never truly removed because the person's credentials were never the only way in.

    No record of who viewed what

    There is no audit trail showing who has accessed identity documents, when they accessed them, or whether they needed to. If information is misused, the business has no way to investigate — because the system was never configured to record access.

    Consider what happens in a typical property management team during a routine week. A prospective tenant submits an online application containing their driver's licence, passport, payslips and a bank statement. The application arrives in the property manager's inbox. The property manager forwards it to the office administrator for reference checks. The administrator saves the attachments to a shared folder called "Applications 2026" that was created by someone who has since left. The property manager also forwards the identity documents to a reference contact to verify — an action that sends someone's passport scan to a third party without any access control.

    The application is unsuccessful. The tenant is told they were not selected. The application is not deleted. It sits in the property manager's inbox, in the administrator's inbox, in the shared folder and in the sent items of the reference-check email. Months later, every copy still exists. No one knows they exist. No one is responsible for them. If the prospective tenant asked what personal information the business held about them, the business would struggle to give a complete answer — and would almost certainly not find every copy.

    Now multiply that by the number of applications a property management team receives in a year. A rental portfolio processes many times more applications than it has properties, and most applicants never become tenants, so the business accumulates identity records for a large number of people it never had a relationship with. The information sits in inboxes and shared folders, uncontrolled, unreviewed and undeleted, because the system was never designed to do anything else.

    The same pattern applies to landlord information. A landlord's bank account details, ownership structure and correspondence about rental income sit in the property management platform, in email and in shared folders. When a landlord asks the business to update their bank details, the old details are not removed — they remain in email threads and saved attachments. The business is holding financial information it no longer needs, in locations it cannot fully control, accessible to people who no longer need to see it.

    The exposure is not theoretical. It is the daily reality of how property businesses operate, and it exists because the technology environment was never designed to treat personal information as something that needs to be deliberately managed. The information flows in, and nothing flows out. That is the problem.

    What good looks like

    The target state is not a different business. It is the same property business, running on the same systems, but with an information environment that has been deliberately designed rather than left to accumulate. Good looks like this:

    Deliberate collection

    The business collects only what it genuinely needs. Application forms ask for information that will actually be used. Unsuccessful applications are disposed of after a defined period, not retained indefinitely by accident.

    A controlled destination, not an inbox

    Personal information flows into a governed location — a SharePoint site, a controlled folder, a structured intake process — rather than sitting in personal inboxes where no one controls retention or access.

    Access limited to those who need it

    Staff can access identity documents and financial details only where there is a legitimate business reason. Broad, inherited access has been reviewed and reduced. A new admin assistant cannot see every tenant's passport because they happen to have a mailbox login.

    Retention decided, not accidental

    Records are retained for the period the business has determined is appropriate and disposed of securely when that period expires. Retention is a policy applied by the system, not a decision that has to be remembered by an individual.

    Access removed immediately when someone leaves

    When a staff member or contractor departs, their access is removed promptly and consistently. There is no gap between departure and revocation, and shared accounts have been eliminated so that access is tied to individuals.

    The ability to answer 'who could see this?' with evidence

    If asked who has accessed a specific client's identity documents, the business can answer from an audit trail — not from memory. Access is logged, and the log is reviewable.

    The difference between the exposed state and the target state is not a different set of software. It is the same Microsoft 365 environment, the same property platform, the same CRM — but configured and governed so that personal information flows into controlled locations rather than accumulating in inboxes. Good looks like a business where a principal can answer the question "where are this tenant's identity documents?" in seconds, not minutes, and where the answer does not depend on who is in the office that day.

    It also looks like a business that can demonstrate its position without scrambling. When identity documents are stored in a governed SharePoint site with appropriate permissions, when access is reviewed periodically, when retention is applied by policy rather than by habit, and when departed staff are offboarded promptly and consistently, the position is visible in the system itself. The business does not need to build a case — it needs to show what is already there.

    In practice, this means a property manager who receives a rental application does not leave it in their inbox. The application is routed to a governed location — either automatically or through a clear process the property manager follows without thinking about it. Identity documents are stored with permissions that restrict access to the property manager and the principal, not the entire office. When the application is unsuccessful, a retention policy removes the documents after the period the business has defined. When the tenant vacates, their file is reviewed, retained for the appropriate period and then disposed of securely. No one has to remember to do any of this, because the system handles it.

    Good also means the business has a clear answer to the question of who is responsible for each part of the process. The principal knows what the business collects and why. The property management team knows where identity records belong and who can access them. The IT environment — whether managed internally or by a provider like LOOKUP — supports the process rather than being a separate concern. Responsibility is not diffuse. It is assigned, visible and supported by systems that make the right action the easy action.

    The target state is achievable without replacing the systems a property business already relies on. It does not require a new property management platform, a new CRM or a new trust accounting system. It requires the environment around those systems — Microsoft 365, identity, devices, email, backup and governance — to be configured so that information is controlled, access is appropriate, retention is deliberate and records are retrievable. That is the gap LOOKUP fills.

    The Framework

    How this maps to the LOOKUP Business Modernisation Framework™

    Protecting personal information in a property business follows the same eight-stage sequence — so that collection is deliberate, access is controlled, and retention is governed before anything is automated.

    01
    Discover

    Understand the current environment

    02
    Secure

    Protect identities, devices and information

    03
    Modernise

    Remove legacy technology constraints

    04
    Standardise

    Create consistent systems and processes

    05
    Optimise

    Improve workflows and productivity

    06
    Prepare

    Establish governance and AI readiness

    07
    Implement

    Introduce technology deliberately

    08
    Improve

    Measure, review and continuously improve

    01
    Discover

    Understand the current environment

    02
    Secure

    Protect identities, devices and information

    03
    Modernise

    Remove legacy technology constraints

    04
    Standardise

    Create consistent systems and processes

    05
    Optimise

    Improve workflows and productivity

    06
    Prepare

    Establish governance and AI readiness

    07
    Implement

    Introduce technology deliberately

    08
    Improve

    Measure, review and continuously improve

    Discover

    Map where tenant identity documents, rental applications and landlord financial details currently sit across inboxes, shared drives, property platforms and Microsoft 365, and identify who can access each location.

    Secure

    Put multi-factor authentication, conditional access and least-privilege permissions in place so that identity documents and client records are protected from unauthorised access.

    Modernise

    Move tenant identity records from inboxes and personal drives into governed SharePoint sites with controlled sharing, appropriate permissions and retention policies applied.

    Standardise

    Establish consistent onboarding and offboarding so that access to personal information is granted promptly when someone joins and removed immediately when someone leaves.

    Optimise

    Review SharePoint permissions regularly, test whether identity records can be retrieved on request, and verify that retention policies are disposing of unsuccessful applications as intended.

    Prepare

    Build the governance foundations — documented collection limits, access reviews, retention policies and audit logging — that the business needs before introducing automation.

    Implement

    Deploy workflows that route identity documents to governed locations automatically, apply retention labels, and log access so the business can answer who viewed what.

    Improve

    Review the information protection environment periodically as the business grows, ensuring collection stays deliberate and access stays controlled across every office.

    The access problem in a mobile, multi-site business

    Property teams do not sit in a single office behind a single firewall. Sales agents work from their cars, from open inspections, from home and from multiple branch locations. Property managers move between offices, properties and the field. Administrative staff may work remotely. Every one of them is accessing personal information — identity documents, financial details, correspondence — from a different device on a different network in a different location.

    That mobility is not a problem in itself. It is how property businesses work. But it means that device management and identity control are not optional extras — they are the practical foundation of information protection. If a sales agent's laptop is lost or stolen, and that laptop has unencrypted copies of identity documents in a local folder or email cache, the exposure is immediate. If a property manager logs into Microsoft 365 from a personal device that has not been enrolled or managed, the business has no control over what happens to the information that device can access.

    The same applies to multi-site businesses. Each branch may have its own approach to devices, its own local IT support, its own shared drive structure and its own habits around onboarding and offboarding. A principal who asks "who across all our offices can access tenant identity documents?" may get a different answer from each branch — or no answer at all, because no one has ever looked. The information environment is fragmented, and fragmentation is the enemy of control.

    The solution is not to stop people working remotely or to centralise everyone in one office. It is to ensure that every device accessing business information is managed, that every user is authenticated with multi-factor authentication, that access is granted based on role and need rather than convenience, and that the business can see — from a single position — who has access to what across every location. That is what device management and identity control provide. They are the foundation, not the finishing touch.

    How LOOKUP helps

    LOOKUP works on the Microsoft 365 environment around the specialist systems a property business uses. We do not replace property management platforms, CRMs or trust accounting systems. We coordinate with them.

    The work that supports personal information protection is the same work that supports good information governance generally:

    Identity and access control

    Multi-factor authentication, least-privilege access, joiner-mover-leaver processes, and removal of departed staff and contractor access so that only the right people can see sensitive information.

    Email protection

    Email security, phishing protection, and controls that reduce the risk of identity documents sitting uncontrolled in inboxes and being forwarded to unintended recipients.

    SharePoint and OneDrive governance

    Governed locations for identity records and client information, controlled sharing, permission reviews, and retention policies that make retention deliberate rather than accidental.

    Device management

    Managed laptops and mobile devices with encryption and remote-wipe capability, so that personal information on devices in the field is protected if a device is lost or stolen.

    Backup and tested recovery

    Backup that is tested, not assumed. The ability to recover client records on request — or after an incident — is a requirement, not a nice-to-have.

    Coordination with specialist platforms

    Coordination with property management, CRM and trust accounting vendors to ensure the surrounding environment supports — not undermines — information protection.

    For a broader view of how LOOKUP approaches technology for property businesses, see our Real Estate & Property Services industry page. For the Microsoft 365 environment specifically, see how we approach Microsoft 365 governance, and for security baselines, our work on the Essential Eight. The Australian Signals Directorate publishes the Essential Eight as a baseline set of mitigation strategies.

    What stays with the business

    The boundary needs to be stated plainly, because it matters.

    1.The business decides what personal information it collects and why.
    2.The business decides how long it keeps information and when it disposes of it.
    3.The business decides how it responds to a privacy enquiry, access request or complaint.
    4.LOOKUP does not provide privacy or legal advice.

    What LOOKUP does is build the technology environment that supports the decisions the business makes — identity, access, governed storage, email protection, device management and tested recovery. The business sets the policy. LOOKUP makes sure the systems can actually enforce it.

    For property businesses now navigating AML/CTF obligations alongside privacy responsibilities, the technology foundations are shared. Identity, access, information governance and recordkeeping support both regimes. See our guidance on meeting AML/CTF obligations in a property business for the regulatory side of the same information environment.

    Frequently asked questions

    A property business typically holds rental applications, identity documents such as passports and driver's licences, payslips, bank statements, tenancy histories, landlord financial details, trust account records, inspection reports and correspondence. The volume is constant and the sensitivity is high, because each application can contain enough information to impersonate someone or commit fraud.

    Retention periods depend on the purpose for which the information was collected, the legal or regulatory requirements that apply, and the business's own privacy policy. LOOKUP does not provide privacy or legal advice on specific retention periods. What matters from a technology perspective is that retention is a deliberate, policy-driven decision rather than an accident of inaction where documents sit in inboxes indefinitely.

    No, access to identity documents and financial details should be limited to staff who have a legitimate business reason to view them. Broad, inherited access — where any staff member with a general mailbox login can see every client's sensitive information — is a common exposure point. Access should be reviewed periodically and reduced to what each role genuinely requires.

    Email is not a safe place to store identity documents long-term, because messages sit in inboxes indefinitely, get forwarded between staff and accumulate in sent items with no access control. A safer approach is to route identity information into a governed location with appropriate permissions and retention, rather than leaving it to accumulate in personal mailboxes where no one controls who can see it or how long it stays.

    No technology product makes a business privacy compliant on its own. Compliance depends on what the business collects, why it collects it, how long it keeps it, how it secures it, and how it responds to privacy enquiries. Microsoft 365 provides the tools — identity, permissions, governed storage, email protection and retention policies — but the business must configure and use them deliberately to support its privacy obligations.

    Remove the access immediately and review what the former employee could have seen or downloaded before their departure. Departed staff and contractors retaining access to identity documents and client information is one of the most common exposure points in property businesses. A consistent offboarding process — one that removes accounts, revokes permissions and confirms access is closed — should be standard, not exceptional.

    Sources & Further Reading

    The following primary and authoritative sources support the research, guidance and industry context discussed on this page:

    Office of the Australian Information Commissioner — Notifiable Data Breaches Scheme — 2024

    Official OAIC guidance on the Notifiable Data Breaches scheme, covering eligibility assessments, notification requirements and the obligations of entities holding personal information under the Privacy Act.

    View Source →

    Australian Cyber Security Centre (ASD) — Essential Eight Mitigation Strategies — 2024

    The ASD's published baseline set of mitigation strategies designed to help organisations protect their systems against a range of cyber threats, including identity, access and information protection controls.

    View Source →

    Evidence Standard

    LOOKUP references recognised industry, government, professional and technology sources when discussing research, regulation and industry trends. Research findings are paraphrased and linked to their original sources wherever practical. LOOKUP's professional observations and recommendations are presented separately from third-party research.

    Can You Say With Confidence Who Can See Your Clients' Personal Information?

    If your technology cannot show you where identity documents live, who has accessed them, and whether departed staff still have access, that is a technology problem worth fixing. Book a strategy session with LOOKUP to assess your current environment and build a practical path forward.

    PK

    Peter Kantarelis

    Founder, LOOKUP — Business Technology Strategist

    Peter Kantarelis is the Founder of LOOKUP and a business technology strategist helping Australian organisations modernise technology, strengthen cyber security and prepare for practical AI adoption. He regularly works with business owners and leadership teams to improve productivity, reduce operational risk and implement technology that delivers measurable business outcomes. The LOOKUP Business Modernisation Framework™ reflects more than 25 years of helping Australian businesses make better technology decisions.

    View More Insights →