Digital security shield representing protection of sensitive rental applicant data
Technology
Technology8 min read

Applicant Data: What Landlords Must Secure, Keep, and Destroy

A rental application collects more sensitive data than most small businesses ever handle. Federal and state law say something about how it is protected and how it is thrown away.

The File You Did Not Plan to Build

A single rental application collects a set of data that most small businesses never touch. A Social Security number, a date of birth, a driver's license or passport image, employer and income details, bank statements, prior addresses, emergency contacts, and then the screening output itself: a credit report, a criminal background check, an eviction history. If a landlord with six units runs twenty applications a year, the file cabinet or the inbox is holding identity-theft-grade information on dozens of people, most of whom never became tenants.

That last point is the one that gets overlooked. Approved applicants become tenants with an ongoing relationship and a reason for the file to exist. Rejected applicants are just data sitting in a folder with no business purpose attached to it, and the volume compounds every leasing season. The same is true of the applicant who withdrew, the co-applicant who never signed, and the guarantor whose information was collected for a deal that fell through.

There is no single federal rental data privacy statute, which is why this area gets ignored. What exists instead is a set of overlapping obligations: a federal rule specifically about destroying consumer report information, a patchwork of state disposal and breach notification laws, and the general expectation that a business protects what it holds. The practical exposure for a landlord is less about a regulator showing up and more about what happens when a laptop, an email account, or a filing cabinet is compromised and the people in that file find out.

The Federal Disposal Rule Applies to Landlords

The Fair Credit Reporting Act provision at 15 U.S.C. 1681w, added by the Fair and Accurate Credit Transactions Act, directed federal agencies to write rules on the disposal of consumer report information. The Federal Trade Commission's version is the Disposal Rule at 16 CFR part 682. It applies to any person who maintains or possesses consumer information for a business purpose, and the FTC's own business guidance names landlords among the covered entities alongside employers, creditors, and insurers. Running a tenant screening report puts a landlord squarely inside it.

The requirement is a performance standard rather than a prescribed method. The rule requires reasonable measures to protect against unauthorized access to or use of the information in connection with its disposal. The examples the rule gives are concrete: burning, pulverizing, or shredding papers so the information cannot practicably be read or reconstructed, and destroying or erasing electronic media so the same is true. It also contemplates hiring a disposal contractor, in which case due diligence on that contractor is part of the reasonable measures.

What does not satisfy the standard is equally clear. A stack of applications in a recycling bin, a box of files left in a garage after a sale, a laptop sold or donated with the drive intact, or a deleted folder on a shared drive that is recoverable through ordinary means are the failure patterns. Dragging a file to the trash is not erasure, and emptying the trash on a modern operating system usually removes the pointer to the data rather than the data itself. For electronic records, either use a tool that overwrites or securely deletes, or use full-disk encryption from the start so that destroying the key destroys the usable data.

What Counts as Consumer Information

The rule's scope is narrower than the whole applicant file and broader than the report itself. It covers consumer information, meaning information about an individual that is identifiable to that person and is derived from a consumer report. The screening report is covered, and so are the notes, spreadsheets, summaries, and internal scoring records that draw on it. A printed report with a name cut off it is still covered if the information can be linked back to the person.

Documents the applicant handed over directly, such as pay stubs or a copy of an ID, are not derived from a consumer report and therefore may sit outside this particular rule. That is a distinction without much practical value. Those documents are exactly what state disposal and breach statutes are written about, and no landlord benefits from running two different destruction processes for two halves of the same folder. Treat the whole applicant file as sensitive and dispose of all of it the same way.

State Rules Go Further, and They Vary

A substantial majority of states have their own secure disposal statutes requiring businesses to destroy or render unreadable records containing personal information, and industry surveys commonly count roughly thirty or more states with such a law on the books. New York and North Carolina are frequently cited examples, and the typical formulation mirrors the federal standard: shred, erase, or otherwise modify the personal information so it cannot practicably be read or reconstructed. Because the definitions of personal information and the covered entities differ from state to state, this is a rule to check locally rather than assume.

Breach notification is more uniform in existence and less uniform in detail. All fifty states, the District of Columbia, and several territories have breach notification laws requiring notice to affected individuals when defined categories of personal information are compromised, and there is no general federal breach notification statute for this kind of business. What varies is what triggers notice, how fast it has to go out, whether the state attorney general must also be notified, and whether credit monitoring must be offered. A landlord operating in more than one state may be looking at more than one set of timelines for the same incident.

Two other layers can apply depending on scale and activity. Comprehensive state privacy laws such as California's create access, deletion, and security obligations for businesses that meet defined revenue or data-volume thresholds, which most small landlords will not but larger management companies may. Many states also have specific Social Security number statutes restricting display, transmission, or unnecessary collection. A landlord who never stores an SSN after the screening report is ordered avoids most of that surface area entirely.

How Long to Keep It

Retention is a balance between two failure modes: destroying the record that would have proved you handled an application correctly, and keeping a file with no purpose that becomes a liability the day it leaks. The Fair Credit Reporting Act does not set a general retention period for a user of a consumer report, so the period has to be reasoned from the claims that could arise.

Several timelines are worth having in view. FCRA claims are generally subject to the limitations period at 15 U.S.C. 1681p, which runs two years from the date the plaintiff discovers the violation and no more than five years from the date the violation occurred. A HUD fair housing complaint generally must be filed within one year of the discriminatory act, with a private federal lawsuit generally available within two years. Applications, screening criteria, decision records, and adverse action documentation are the evidence in both kinds of dispute, which argues for keeping the decision record for a period measured in years rather than months.

The supporting documents are a different question from the decision record. Once a decision is made and a screening file is closed, there is rarely a reason to keep the bank statements, the ID image, or the full report for as long as the record of what was decided and why. A workable approach is a written retention schedule that separates the two, sets a defined period for each, applies the same period to approved and rejected applicants, and actually triggers destruction rather than describing it. A schedule nobody executes is worse than no schedule, because it documents an intention the files contradict.

Controls That Fit a Small Portfolio

The highest-value controls are not expensive. Collect the Social Security number through a secure form rather than email or text, and stop storing it once the report is ordered if your process does not need it. Keep applicant documents in one access-controlled system rather than scattered across an inbox, a phone camera roll, and a desktop folder. Turn on multi-factor authentication for the email account and the software that holds the files, because a compromised email account is the most common path into everything else. Encrypt laptops and phones with full-disk encryption so a stolen device is a property loss rather than a breach.

Limit who can see what. A leasing agent showing units does not need access to completed screening reports, and a contractor certainly does not. When a report has to be discussed, share the decision rather than forwarding the file. Anything sent to a vendor should be covered by a written agreement that addresses security and disposal, and that includes a shredding service. For landlords using screening software, the questions worth asking a provider are where data is stored, who at the company can see it, what the retention and deletion behavior is, and whether documents are encrypted at rest. TenantFort keeps applicant documents in access-controlled storage tied to the organization that collected them, which is the same thing a landlord should be asking of any platform in this category.

When Something Goes Wrong

Incidents at this scale are usually mundane. A phishing email captures the email password, a box of files disappears during a move, a property manager's laptop is stolen from a car, a shared link is set to public. The response that matters is the first day: work out what data was exposed and whose, stop the ongoing access by changing credentials and revoking sessions, and write down the timeline while it is still accurate.

Then check the notification obligation against the state where the affected individuals live rather than where you operate, because most breach statutes key on the resident's state. Deadlines and thresholds differ, several states require notice to the attorney general above a certain number of affected people, and a few impose specific content requirements on the notice itself. This is the point to involve counsel rather than to draft an email, because a notification that is late, incomplete, or sent to the wrong parties creates a second problem on top of the first.

The broader takeaway is that data handling is part of screening rather than an IT chore bolted on afterward. The decision to collect something, the decision to keep it, and the decision to destroy it are all screening decisions with legal consequences. This article is general information rather than legal advice. State disposal, breach notification, Social Security number, and privacy laws vary substantially and change frequently, so confirm the current requirements in each state where your applicants live and consult a local attorney before setting a retention policy or responding to an incident.

Frequently Asked Questions

Do I really have to shred rejected rental applications?

If the file contains information derived from a consumer report, the FTC Disposal Rule at 16 CFR part 682 requires reasonable measures to prevent unauthorized access in connection with disposal, and shredding, burning, or pulverizing papers is the example the rule gives. Most states add their own secure disposal requirement covering personal information generally. Throwing applications in the trash or recycling is the specific practice these rules exist to prevent.

Is deleting a file enough for electronic records?

Usually not. Ordinary deletion removes the reference to the data rather than the data itself, and it is often recoverable with widely available tools. The rule asks that electronic media be destroyed or erased so the information cannot practicably be read or reconstructed. Use secure deletion or overwriting for files, physically destroy or properly wipe drives before disposing of hardware, and use full-disk encryption so that a device leaving your control is not a disclosure.

How long should I keep screening files?

There is no general federal retention period for a landlord who uses a consumer report, so reason from the claims that could arise. FCRA claims run two years from discovery and no more than five years from the violation, a HUD fair housing complaint generally must be filed within one year, and a private fair housing lawsuit generally within two. Keeping the decision record and adverse action documentation for a period measured in years while disposing of supporting documents sooner is a defensible structure, applied identically to approved and rejected applicants.

Can I email a screening report to my business partner?

Be careful on two fronts. Under the FCRA, a consumer report should go only to people who need it to make the rental decision, not to a broader circle. On the security side, email is a poor container for a document with a Social Security number and a credit file in it, since a compromised inbox exposes everything ever sent through it. Share the decision rather than the report where possible, and use an access-controlled system when the document itself has to be seen.

What do I do if applicant data is exposed?

Contain it first by changing credentials and revoking access, then determine exactly what was exposed and for whom, and document the timeline immediately. Notification duties generally follow the state where each affected individual resides, and the deadlines, attorney general notice thresholds, and required content vary. Because a defective notification creates its own liability, involve counsel before sending anything.

Ready to screen smarter?

TenantFort automates screening, catches fraud, and keeps you compliant. Start with 5 free screenings.