Skip to content
       

Blog

Three Months and Seven Years: Queensland's Rental Data Destruction Rules

Three Months and Seven Years: Queensland's Rental Data Destruction Rules

Somewhere on a Queensland property manager's phone is a photograph of a bathroom, taken during a routine inspection eight months ago. It is also in the agency's inspection software, in an email to the owner, and in a PDF report saved to a shared drive.

Queensland's rental laws treat photographs taken during inspections as personal information subject to a statutory destruction requirement. The legislation does not prescribe exactly how secure destruction must work, and the Residential Tenancies Authority notes that the Act does not specifically reference information stored in database or cloud driven systems.

The rules took effect on 1 May 2025. More than a year on, the operational consequences are still easy to underestimate.

What Changed On 1 May 2025

Queensland's 1 May 2025 changes covered the tenancy application process, entry frequency and limits, requests for fixtures and structural changes, disclosure of benefits, and the collection, storage and disposal of personal information. They form part of a reform programme that has been rolling through Queensland since 2021.

The personal information rules introduced something new. The RTA states that on 1 May 2025 a requirement to destroy personal information after seven years was introduced.

The same package standardised applications. Property managers and owners must use the Rental application (Form 22) for general and moveable dwelling tenancies, and Form R22 for rooming accommodation. The form must not ask for anything beyond what those forms contain. At least two different methods must be offered for submitting an application, one of which must not be restrictive. Non-compliance across these requirements is an offence with a maximum penalty of 20 penalty units.

The Two Clocks

There are two destruction obligations, and most agencies have heard about one.

  1. For a tenancy, the RTA states that all personal information related to the tenancy must be securely destroyed within seven years after the end of the residential tenancy or rooming accommodation agreement, and that the Act provides no exception.

  2. For applicants who never became tenants, the clock is far shorter, and the trigger matters. The RTA states that personal information collected from applicants who do not become tenants must be destroyed within three months of the commencement of the successful tenant's residential tenancy agreement. The wording on Form 22 itself tells applicants the same thing: if the application is unsuccessful, the information must be destroyed within three months of the relevant tenancy commencing, unless the applicant consents to it being held longer.

Read that trigger carefully, because it is more workable than it first appears.

The clock does not start when each application arrives. It starts when the lease begins. That means one date per property rather than nineteen scattered dates, which is the difference between an obligation a system can enforce and one it cannot. The maximum penalty for non-compliance is 20 penalty units.

The Sentence The RTA Wrote About Your Cloud

Here is what makes this a systems problem rather than a policy one.

The RTA states that the Act does not define what it means to securely destroy information, but that it typically means the information is permanently erased or destroyed in a way that makes it impossible to access or reconstruct. Securely shredding paper documents or deleting digital files are the examples given.

Then this. The RTA states that the Act does not specifically reference information stored in database or cloud driven systems, only that personal information must be securely destroyed.

Read that twice if you run a rent roll on modern software.

The obligation does not create an express carve-out for information simply because it sits in a CRM, an inspection app, an application platform, a document store or an email archive. The practical question is whether your business can identify where personal information is held and securely destroy it when the required timeframe arrives.

A property management business that cannot enumerate every system holding applicant and tenant data will struggle to answer that question, because it cannot know what it has failed to destroy. A leasing process where an application has a status, an owner and a defined end date can at least produce an answer. One where applications accumulate in a shared inbox cannot.

The Photographs Nobody Thought About

The RTA's guidance on destruction includes an item most agencies will not have considered: this includes photographs taken during inspections.

Entry condition photos. Exit condition photos. Routine inspection photos. Maintenance photos sent by a tradesperson. Each of them personal information subject to the destruction requirement.

Think about where inspection imagery actually lives in a typical Queensland agency. In the inspection app. In the report PDF. In the email that delivered the report to the owner. In the owner's own inbox, now beyond your control. In the phone gallery of the property manager who took them, possibly on a personal device, possibly no longer employed by you.

The condition report workflow was built to create evidence and keep it. Nothing in it was built to make evidence go away on a schedule. Agencies that treat condition reporting as a dated record with a lifecycle rather than as a folder of images have a much smaller problem to solve.

What You Cannot Ask For In The First Place

Destruction is the back end of the obligation. The front end is collecting less.

The RTA's fact sheet identifies information a property manager or owner cannot request from an applicant, including legal action taken by the applicant such as dispute resolution or QCAT matters, notices to remedy a breach given to or by the applicant, rental bond history including any claims on a bond, and statements of credit accounts or bank transaction details.

Two related points sit alongside it. Property managers and owners are prohibited from keeping a copy or recording the details of any identity document sighted in person without the applicant's consent. And where an applicant volunteers additional information beyond what can be requested, the RTA states that accepting it does not put the property manager or owner in breach.

The cheapest way to comply with a destruction obligation is to hold less in the first place.

The Transitional Rules Need Careful Handling

This is where the guidance requires attention rather than assumption.

RTA guidance states that the seven year destruction requirement does not apply to tenancy agreements that ended before 1 May 2025. However, RTA guidance published in different places describes the treatment of agreements spanning that date differently. One description refers to agreements active as at, or commenced after, 1 May 2025. Another refers to agreements that commenced on or after 1 May 2025.

A tenancy that began in 2023 and was still running in May 2025 sits between those two formulations. If you manage long-running tenancies, or you are building a destruction schedule that has to classify an entire back catalogue, check the current legislative position before you apply a rule to that cohort.

Queensland's rules also sit alongside rather than instead of other law. The RTA's fact sheet states that property managers and owners must also comply with Federal, and in some instances state, legislation relating to the collection, storage and destruction of personal information.

This Is Now A Pattern

Victoria introduced its own destruction and de-identification requirements for information collected through rental applications and agreements, effective 31 March 2026. Queensland got there ten months earlier, with harder numbers attached.

Queensland and Victoria now both impose data lifecycle obligations on property management businesses, expressed differently and with different clocks. For a multi-state operator, that is more than two separate compliance tasks. It is a design constraint on how applicant and tenant information is stored, retained and removed across the business, because one process built to the strictest applicable standard is far easier to run than several calibrated to several jurisdictions.

Two Dates Worth Knowing Right Now

Separate from the data rules, a deadline is eight days away for anyone managing rooming accommodation.

The RTA has stated that prescribed house rules listed in Schedule 5 of the Residential Tenancies and Rooming Accommodation Regulation 2009 continue to apply until 31 August 2026, and that from 1 September 2026 all prescribed house rules must meet the new requirements under the Residential Tenancies and Rooming Accommodation Regulation 2025.

If you operate rooming accommodation, co-living or student housing in Queensland, check your house rules against the current Regulation this week rather than next.

Worth reading alongside it: the RTA has published an updated compliance and enforcement action plan setting out its regulatory compliance priorities, approach and enforcement actions for 2026-27. If you are deciding where to spend limited compliance attention this financial year, the regulator has just told you where it intends to spend its own.

What To Do This Month

  1. List every system, application, inbox and device holding applicant or tenant personal information. You cannot destroy what you have not located.

  2. Establish what your application platform and inspection software actually do on deletion, and whether deleted means removed or merely hidden. Ask in writing.

  3. Attach the three month applicant clock to lease commencement as a scheduled step in your leasing workflow, since that is where the Act starts it.

  4. Decide what happens to inspection photographs, including any sitting on personal devices.

  5. If you manage rooming accommodation, review your house rules before 1 September 2026.

Conclusion

Most of Queensland's rental reform has been about the relationship between a lessor and a tenant. This part is about the relationship between an agency and its own systems.

You can train someone to give correct notice. You cannot reasonably expect someone to remember, seven years after a tenancy ends, that a photograph of a bathroom exists in four places. That has to be built rather than remembered, which is why this quiet reform will end up costing more attention than the ones that made the news.

Frequently Asked Questions

1. When did Queensland's personal information destruction rules start?
On 1 May 2025, as part of a package that also changed the tenancy application process, entry frequency and limits, requests for fixtures and structural changes, and disclosure of benefits.

2. How long can we keep a tenant's personal information?
The RTA states that all personal information related to the tenancy must be securely destroyed within seven years after the end of the residential tenancy or rooming accommodation agreement, and that the Act does not provide an exception.

3. What about applicants who never became tenants?
The RTA states their personal information must be destroyed within three months of the commencement of the successful tenant's residential tenancy agreement, unless the applicant consents to it being held longer. Note the trigger is lease commencement, not the date each application was received.

4. Do the destruction rules include inspection photographs?
Yes. The RTA states that personal information subject to the destruction requirement includes photographs taken during inspections. Consider where those images exist across inspection software, report files, document storage, email and any personal devices used to capture them.

5. Does this apply to our older tenancy files?
RTA guidance states the requirement does not apply to tenancies that ended before 1 May 2025. Guidance published in different places describes agreements spanning that date differently, so check the current legislative position before applying a destruction schedule to long-running or pre-2025 agreements.

6. Does deleting a file from our software count as secure destruction?
The Act does not define secure destruction. The RTA states it typically means the information is permanently erased or destroyed so that it cannot be accessed or reconstructed, giving shredding paper and deleting digital files as examples, and notes that the Act does not specifically reference information stored in database or cloud driven systems. Confirm with your software provider what deletion actually does in their system.

Important Notice

This article applies to Queensland only. Residential tenancy law in Australia is state and territory legislation, and rules on application forms, personal information, entry and record handling differ between Australian states and territories.

Information was checked against Residential Tenancies Authority guidance, fact sheets and forms published at rta.qld.gov.au, and Queensland Government material published at housing.qld.gov.au, available as at 24 August 2026. The governing legislation is the Residential Tenancies and Rooming Accommodation Act 2008 (Qld), supported by the Residential Tenancies and Rooming Accommodation Regulation 2025. RTA guidance describes the transitional treatment of agreements spanning 1 May 2025 differently in different places, and this article does not resolve that difference. The RTA notes that while it makes every reasonable effort to ensure its published information is accurate at the time of publication, changes in circumstances after publication may affect accuracy. Property managers and owners must also comply with Federal and, in some instances, state legislation relating to the collection, storage and destruction of personal information, which is outside the scope of this article.

Always verify current requirements with the Residential Tenancies Authority before acting. This content is general information only and does not constitute legal advice. RIOO is not a law firm.