By Proppi Editorial Team12 min read

What Rental Applicant Privacy Records Should New Zealand Landlords Keep in 2026?

A New Zealand landlord guide to rental applicant privacy records: staged collection, privacy statements, specific consent, credit and reference checks, secure access, retention, deletion, and access or correction requests.

Part of the Rental Rule Changes Watch 2026 series.

A New Zealand rental applicant privacy file should prove that the landlord collected only what was needed at each stage, told the applicant why, obtained specific authority before third-party checks, limited access, used accurate information for the stated purpose, answered access or correction requests, and securely deleted information when no lawful retention purpose remained. Keep statutory tenancy records separately from application material that the Privacy Act 2020 no longer allows you to retain.

This guide applies to New Zealand landlords and property managers handling rental applicant and tenant information. It does not describe Australian privacy or tenancy rules.

The primary sources were reviewed on 20 July 2026. The Office of the Privacy Commissioner’s rental guidance, Tenancy Services’ pre-tenancy guidance, the current Privacy Act 2020, and section 123A of the current Residential Tenancies Act 1986 were checked on that date.

What Rental Applicant Privacy Records Should New Zealand Landlords Keep?

Keep a decision trail, not an unrestricted copy of everything an applicant supplied.

RecordWhat it should prove in New Zealand
Collection-stage registerWhich information was requested at viewing, application, shortlist, and offer stages
Privacy statement versionWhat the applicant was told about purpose, use, access, and disclosure
Application form versionWhich fields were required or optional when the person applied
Specific authority for third-party checksWhich credit provider or referee could be contacted, and for what purpose
Check logWhich preferred applicant was checked, when, by whom, and with what result
Selection recordWhich relevant information was actually relied on
Access-permission recordWhich staff, owner, contractor, or system role could see applicant information
Access or correction request fileRequest date, due date, search completed, response, and any correction
Retention decisionThe lawful reason and review date for each information category
Secure-disposal recordWhat was deleted or destroyed, when, and under which retention rule
Residential Tenancies Act retention recordsRequired advertisements and prospective-tenant correspondence kept on their own basis

Key Takeaway

Privacy compliance is not proved by keeping more. It is proved by matching each item of personal information to a necessary purpose, a stated use, controlled access, and a defensible retention or deletion decision.

What Can Be Collected at Each Application Stage?

The Office of the Privacy Commissioner’s rental guidance, reviewed on 20 July 2026, says landlords should collect only the minimum personal information needed for finding tenants and managing a tenancy.

The permitted scope changes as an application progresses:

StageInformation the guidance supports collectingRecord to keep
Arranging a viewingName and contact detailsViewing register and privacy notice
Application and initial shortlistInformation needed to assess likely suitabilityApplication version and selection criteria
Negotiating an offerAuthorised credit, criminal-record, or referee checks where relevantSpecific authority and check log
Selected tenantInformation needed to prepare and manage the tenancyTenancy file with role-based access
During the tenancyInformation needed for rent, inspections, repairs, notices, and other managementEvent record tied to the tenancy purpose

The Office of the Privacy Commissioner says a full application may be optional before a viewing, but should not be required at that stage. Tenancy Services’ pre-tenancy guidance also says a landlord must have a lawful tenancy-related purpose, must not collect more than necessary, and should only run credit checks on preferred applicants.

The fact is the stage-based collection limit. The practical implication is that one form should not automatically expose every field at every stage.

Record:

  1. the stage at which each field becomes visible
  2. whether the field is required or optional
  3. the stated purpose for the field
  4. the consequence, if any, of not providing optional information
  5. the form and privacy-statement version shown to the applicant

What Should the Privacy Statement Prove?

The Privacy Act 2020 requires transparency when personal information is collected.

A useful application record should preserve the statement that told the applicant:

  • why the information was being collected
  • who would receive or hold it
  • whether providing it was mandatory or voluntary
  • what could happen if required information was not provided
  • how the information would be used
  • the applicant’s right to request access and correction
  • how to contact the landlord or property manager about the information

Keep the statement with a version date. A link to a privacy page that changes later does not prove what the applicant saw when they applied.

Consent is not a substitute for necessity. The Office of the Privacy Commissioner’s consent guidance for landlords says consent should be informed and specific, should not bundle unrelated uses, and cannot waive a person’s Privacy Act rights.

For each optional check or disclosure, record:

  • the named source or recipient
  • the exact purpose
  • the information covered
  • how consent was recorded
  • when it was given
  • whether it was later withdrawn

When Can Credit and Reference Checks Be Run?

The Office of the Privacy Commissioner says landlords can ask for authority for a credit or criminal-record check on an application form, but should only carry out the check when negotiating an offer of a tenancy. It says referee details and authority may be collected earlier, but references should not be checked at the initial shortlist stage.

Tenancy Services says credit checks should only be carried out on preferred applicants.

The check file should therefore show:

  1. preferred-applicant status and date
  2. specific authority for the named source
  3. check type and purpose
  4. date requested and date received
  5. person who accessed the result
  6. relevant conclusion used in the decision
  7. applicant explanation or correction where accuracy was questioned
  8. retention or deletion date

Do not copy an entire credit report into a general property folder. Preserve only the lawful record needed for the decision and any required dispute trail, with access limited to people who need it.

What Information Should Not Be Collected?

The Office of the Privacy Commissioner says it is unnecessary, irrelevant, and unreasonably intrusive to ask rental applicants for information such as:

  • political opinions or religious beliefs
  • sexual orientation or gender identity
  • whether they have experienced family violence
  • detailed spending habits shown by transaction-level bank statements
  • employment history
  • social media URLs

The guidance distinguishes current employment or one relevant form of affordability evidence from a person’s full employment history or spending profile. It also says that, in addition to a credit report, one other form of affordability evidence should generally be enough, such as a payslip, employer letter, or evidence of previous rent payments.

This is a collection rule, not a reason to create a larger prohibited-information log. Keep the approved form fields and a short field-purpose register. Do not reproduce sensitive information merely to record that it should not have been collected.

How Should Applicant Information Be Secured?

Principle 5 of the Privacy Act 2020 requires reasonable security safeguards. The Office of the Privacy Commissioner says tenant information should be held in a secure system and accessed only by authorised people.

For a property manager, the evidence file should show:

ControlEvidence
Role-based accessWhich job roles can view applications, checks, tenancy records, or billing
Owner accessWhat the property owner can see and why
External provider accessProvider purpose, contract, permissions, and deletion arrangements
Separate personal-information fileApplicant data is separated from general property documents
Access reviewDate old staff, contractors, and owners were removed
Export and download controlsWho can export reports or save local copies
Incident responseHow suspected loss, unauthorised access, or disclosure is recorded

The Office of the Privacy Commissioner says a landlord or property manager remains responsible when information is stored by a cloud provider. Both a property manager and an owner may have security duties if each holds a copy.

The legal fact is the security obligation. The practical implication is to avoid uncontrolled email attachments, shared drive links, and owner downloads that remain accessible after the selection decision.

How Long Should Application Information Be Kept?

There is no single New Zealand retention period for every rental-application record.

Information privacy principle 9 says an agency must not keep personal information longer than required for the purposes for which it may lawfully be used.

The Office of the Privacy Commissioner says:

  • information about people who only viewed and did not apply generally should not be kept
  • unsuccessful applications generally should not be retained for long
  • an unsuccessful application may be kept briefly where an issue could be raised about the selection process
  • an application may be retained at the applicant’s request so it can be used for another property
  • information must be securely disposed of when there is no longer a lawful reason to keep it

That privacy rule sits beside specific tenancy retention duties.

Section 123A of the Residential Tenancies Act 1986 requires a New Zealand landlord to keep specified records during the tenancy and for 12 months after it ends. Those records include the tenancy advertisement and notices or correspondence with prospective tenants in relation to the tenancy.

Use a category-by-category schedule:

Information categoryRetention approach
Viewing contact detailsDelete when the viewing follow-up purpose ends
Unsuccessful application fieldsKeep only briefly where a documented selection issue remains, then delete
Optional future-property applicationRetain only at the applicant’s request and review that instruction
Credit or reference reportDelete when the lawful assessment or dispute purpose ends
Tenancy advertisementKeep for the Residential Tenancies Act period
Required prospective-tenant correspondenceKeep the correspondence covered by section 123A, not unrelated application data
Selected tenant’s tenancy recordsApply the relevant tenancy, tax, and privacy retention basis to each record category

Do not use the 12-month tenancy rule as a blanket reason to retain every document submitted by every unsuccessful applicant. Equally, do not delete a record that another law requires you to keep. Record the specific basis for each category.

How Should Access and Correction Requests Be Recorded?

The Privacy Act 2020 gives applicants and tenants rights to ask for their personal information and request correction.

The Office of the Privacy Commissioner says an agency must respond promptly and generally no later than 20 working days after receiving a request. Limited extensions and lawful withholding grounds can apply.

Keep:

  1. request text and received date
  2. applicant identity-verification step
  3. systems, inboxes, and people searched
  4. due date and any extension notice
  5. information provided
  6. information withheld, legal basis, and complaint-right notice
  7. correction made or reason it was declined
  8. statement of correction attached where requested and possible
  9. recipients notified of the correction where reasonably practicable

The Office of the Privacy Commissioner says information must not be destroyed after an access request is received. Put a deletion hold on relevant records until the request is resolved.

What Should Happen After a Privacy Breach?

The Office of the Privacy Commissioner’s rental guidance says a breach that has caused or is likely to cause serious harm is a notifiable privacy breach. The Privacy Commissioner and affected people must be notified as soon as practically able unless an exception applies; the guidance says notification to the Commissioner should be made no later than 72 hours after the agency becomes aware of a notifiable breach.

Keep the incident facts separate from conclusions:

  • when the incident was discovered
  • information and people affected
  • systems, links, or recipients involved
  • containment action
  • serious-harm assessment
  • advice obtained
  • notification decision and time
  • messages sent to affected people
  • remediation and access-control changes

Do not wait for complete certainty before starting the incident record or obtaining privacy advice.

Practical Filing Pattern

For a New Zealand rental application workflow, keep a restricted applicant-privacy area with:

  1. collection-stage-register
  2. application-form-versions
  3. privacy-statement-versions
  4. specific-consents-and-authorities
  5. preferred-applicant-checks
  6. selection-records
  7. access-permissions
  8. access-and-correction-requests
  9. retention-schedule-and-review-dates
  10. secure-disposal-log
  11. privacy-incidents
  12. residential-tenancies-act-records

Store statutory tenancy correspondence under its own retention rule. Do not use a general property-document folder as the access model for applicant identity, financial, credit, or referee information.

Source Note

This article is specific to New Zealand. It relies on the Office of the Privacy Commissioner, Tenancy Services, the Privacy Act 2020, and the Residential Tenancies Act 1986. It is general information about rental applicant record handling, not legal, privacy, employment, credit-reporting, or tenancy advice.

Last reviewed: 20 July 2026. Confirm the current position with the Office of the Privacy Commissioner, Tenancy Services, and current New Zealand legislation.

The Short Version

  1. Collect only the information needed at the current rental-application stage.
  2. Preserve the privacy statement and specific authority for any credit or reference check.
  3. Run third-party checks only at the appropriate preferred-applicant or offer stage.
  4. Keep applicant information in a restricted system and record access, correction, retention, and deletion decisions.
  5. Apply Privacy Act 2020 deletion rules and Residential Tenancies Act 1986 retention duties by record category rather than keeping every application indefinitely.

Suggested citation

Proppi Editorial Team, "What Rental Applicant Privacy Records Should New Zealand Landlords Keep in 2026?", Proppi, 2026-07-20.

Sources used

Running rentals in New Zealand?

Proppi reads your tenancy agreements, Healthy Homes records, and Inland Revenue-relevant documents into the property file — then surfaces every notice date, deadline, and bright-line property rule event with a page citation, as work for approval.