How Landlords Should Handle Tenant Personal Data Under the PDPO: Collection, Storage and Destruction
If you let property in Hong Kong, you end up holding a pile of a tenant's personal data around signing time — an ID copy, income proof, bank statements, a previous-landlord reference, the tenancy agreement itself. Plenty of landlords just collect it and stash it somewhere, or snap a photo that sits in their phone's camera roll, without ever realising they've already become a data user under the Personal Data (Privacy) Ordinance (PDPO, Cap. 486).
This article calmly unpacks three things: how to collect a tenant's data proportionately, how to store it securely once you have it, and how to destroy it responsibly once the tenancy is over. The aim isn't to scare you — it's to help you be a landlord who doesn't cross the line, at the lowest possible cost. Because in a single line, lawful to collect is not lawful to republish, and the data in your hands is itself a responsibility.
1. You Are a "Data User": Collect Proportionately, Don't Photograph Everything
The moment you collect, hold and process a tenant's personal data for the purpose of letting, you are a data user under the PDPO and you are answerable for that data. The first principle is simple: collection should have a purpose and be proportionate.
The most common landlord mistake is wanting everything — the instant a tenant turns up, you ask for the ID card, the passport, the credit card, every household member's details and six months of bank statements. The real question is: does this particular tenancy genuinely need all of that?
- Collect only what this tenancy actually needs — verifying identity, assessing ability to pay rent, and what's required to sign are reasonable; data unrelated to this tenancy shouldn't be scooped up along the way.
- Don't over-collect copies — verifying identity is one thing; keeping a long-term, high-resolution copy of an ID card is another. If you can verify it in person, do that — you don't always need to retain a copy.
- Be clear about the purpose and use — at the point of collection, tell the tenant what the data is for (e.g. signing, identity verification, tenancy management), how it will be used, and whether it will be passed to any third party.
Key point: proportionate collection isn't just lawful — it helps you. The less you collect, the lighter your later burden of safeguarding and destroying it. Hoarding a stack of sensitive data you don't need is just loading an unnecessary risk onto yourself.
Here's a simple "should vs shouldn't" comparison:
| Scenario | ✅ Should | ❌ Shouldn't |
|---|---|---|
| Verifying identity | Verify documents in person, note only what's necessary | Photograph every document in high-res and keep it on your phone forever |
| Income proof | Look at it, confirm ability to pay, done | Demand six months of full statements and keep them permanently |
| Scope of collection | Collect only what this tenancy requires | Gather every household member's and guarantor's details in one sweep |
| Telling the purpose | State the use and storage up front | Say nothing, so the tenant has no idea where their data went |
2. Store It Securely: Who Can See It, and Where It Lives
Once you've collected data, the second job is storing it securely. Data leaks usually aren't the work of hackers — more often they're down to careless custody: an ID copy gets photographed, forwarded around on WhatsApp, and ends up who-knows-where.
What a landlord can realistically do comes down to a few very basic habits:
- Reduce the number of copies — don't keep the same sensitive document scattered across your phone, computer, cloud and paper files. The more copies, the harder it is to control.
- Limit who can access it — think it through: besides you, who else can see this data? The estate agent, family, friends? People who don't need to see it shouldn't be able to.
- Don't casually send it over messaging apps — forwarding an ID copy around a group chat or an ordinary chat is the single most common source of leaks.
- Lock paper away — signed agreements and photocopies shouldn't sit out on a desk or in a shared space.
⚠️ A leaked tenant ID copy can be used to open accounts or commit fraud. When that happens, the tenant isn't the only one harmed — as the party holding the data, you may have to explain why your custody was so careless. Storing securely isn't a polite phrase; it's a real responsibility.
3. Don't "Repurpose" It: The Easiest Line to Cross
This section is the heart of the whole PDPO spirit, and it's exactly where landlords most often cross the line.
One of the PDPO's key principles is purpose limitation: data you collected for purpose A must not be taken and used for purpose B. In other words, the tenant data you collected "for this tenancy" may only be used for this tenancy — you can't "while you're at it" repurpose it for something else.
The classic examples of crossing the line:
- Posting a tenant's data and a tenancy dispute, names attached, online or in a landlord group chat, claiming you want to "warn other landlords."
- Passing data collected "for the tenancy" to other landlords for "reference," so they can "filter this person out."
- Using tenant data for something beyond this tenancy (marketing, digging up dirt, retaliation).
Even if you feel you're "in the right" or "doing everyone a favour," these already go beyond the original purpose of collection and carry PDPO — and even defamation — risk. The Privacy Commissioner can step in. To understand the legal limits of landlords "sharing information" and building DIY blacklists, see Does Hong Kong Have a Tenant Blacklist? The Reality of Landlord Info-Sharing and Its Legal Limits.
Key point: lawful to collect is not lawful to republish. Keep what you find or hold for your own tenancy decision, and don't re-circulate it. Name collisions are common — one "warning" from you might harm an innocent person, and in turn land you with the legal risk.
This is precisely the thinking behind WeCredit's design. WeCredit's tenancy record and bankruptcy record lookups mask by default — names, addresses, evidence and submitter details are hidden, and only a vetted risk alert is shown. Why? Because lawful inspection and public re-circulation are two different things. The platform gives you a risk reference, but never exposes anyone's personal data in full, and it avoids wrongly pointing at someone because of a name collision. That "mask by default" logic is the very same purpose-limitation principle you, as a landlord, are meant to observe. For why public record searches must be masked, see Bankruptcy and Public Record Searches: Lawful Uses and the Masking Principle.
4. Destroy It When Done: Retain "Only As Long As You Need To"
Many landlords assume that once they've collected a tenant's data, they should "keep it forever" in case something comes up. The PDPO principle is the opposite: data should only be retained for as long as you still have a genuine, reasonable need for it; once that need is gone, it should be responsibly destroyed or erased.
How do you judge whether you "still need to keep it"? Think of it like this:
- During the tenancy — keeping it for tenancy management (collecting rent, contacting the tenant, handling tenancy matters) is reasonable.
- For a reasonable period after the tenancy ends — you may still need to deal with the deposit, tax or potential disputes, so short-term retention has a justification.
- Beyond that — once there's no reasonable need at all, you shouldn't go on holding a tenant's sensitive data indefinitely.
Exactly how long that "reasonable period" is depends on the situation (tax, potential limitation periods, and so on). There's no one-size-fits-all number; rely on the latest official guidance, and consult a professional if needed. The mindset is what matters: retention isn't "longer = safer." The longer you keep it and the more copies exist, the greater the risk.
Responsible destruction broadly means:
- Paper — shred it; don't drop whole documents into a bin or recycling box.
- Electronic files — actually delete them, including copies in your phone's camera roll, cloud backups and messaging apps — not just "out of sight, out of mind."
- Don't "keep it just in case" — "it might be useful one day" isn't a reasonable basis for retaining sensitive personal data.
⚠️ The duty to destroy doesn't vanish because you "forgot." If you choose to go on holding the data, you go on being responsible for its security. The simplest way to take the pressure off is to destroy it cleanly the moment you no longer need it.
5. Tenants Have Rights Too: Access and Correction
The final section turns to the tenant's side. The PDPO doesn't only govern how you collect, store and destroy — it also gives the data subject certain rights, and as a data user you have a duty to respond to them reasonably.
- Right of access — a tenant is entitled to know what personal data of theirs you hold, and how it's used.
- Right of correction — if the data you hold is wrong, the tenant is entitled to ask you to correct it.
- Respond reasonably — when you receive such a request, handle it seriously and reasonably; don't ignore it.
This principle carries two reminders for landlords: first, the data you keep should be accurate; second, if it's wrong, be willing to fix it. And if you've ever seen an incorrect tenancy record about someone — on a platform or via a third party — the data subject actually has the right to request access, correction or even deletion. For how to exercise those rights, see Got a Wrong Tenancy Record? How to Correct or Remove It in Hong Kong.
Key point: good data handling runs both ways — you collect proportionately, store securely and destroy when done, and the tenant has the right to access and correct. An approach that balances landlord and tenant is the only one that's genuinely steady and sustainable. WeCredit builds this principle into the product: mask by default, vetted, and keeping channels open for the data subject to access and correct (see the Privacy Policy). For how tenancy records actually work and how to use them, see How to Check Tenancy Records in Hong Kong: Risk Alerts and How to Use Them Properly.
FAQ
Q1: Do I have to photograph a tenant's ID copy before I can sign?
Not necessarily. Verifying identity is reasonable, but "verifying" and "keeping a long-term high-res copy" are two different things. If you can verify it in person and note only what's necessary, you don't need to retain a sensitive copy that you'll later be responsible for safeguarding and destroying. The less you collect, the lighter the burden.
Q2: Once I've collected a tenant's data, can I share it with other landlords for reference?
Not advisable. Data you collected "for this tenancy" goes beyond its original purpose the moment you hand it to other landlords, and it carries PDPO and defamation risk. Risk information should be kept for your own tenancy decision, not re-circulated.
Q3: After the tenancy ends, how long should I keep a tenant's data?
Keep it only for as long as you have a reasonable need (e.g. handling the deposit, tax or potential disputes), then destroy it responsibly. There's no one-size-fits-all period — it depends on the situation, so rely on the latest official guidance and consult a professional if needed.
Q4: Why doesn't WeCredit just display all the personal data?
Because lawful inspection and public re-circulation are two different things. Masking names, addresses, evidence and submitter details by default both respects PDPO purpose limitation and reduces the risk of harming an innocent person through a name collision — the same principle you, as a landlord, are meant to follow.
Q5: A tenant says the data I hold is wrong and asks me to correct it — can I just ignore it?
You shouldn't. The PDPO gives the data subject rights of access and correction, and as a data user you have a duty to respond reasonably. Accurate data benefits you too; for how a data subject can request access, correction or deletion, see Got a Wrong Tenancy Record? How to Correct or Remove It in Hong Kong.
Written by the WeCredit Editorial Team — a Hong Kong tenancy record lookup, risk alert and compliance review tool (reviewed, privacy-masked and impartial). Free to republish with author credit and a link back to the original.
📱 App: iOS / Android · 🔗 More articles: https://wecredithk.com/blog/
⚖️ Disclaimer: This article is for general reference only and does not constitute legal advice, a credit rating or a final determination of fact. For specific situations, consult a lawyer or relevant professional, and rely on the latest official guidance.