A tenant's application, lease, payment history and maintenance requests are personal information the moment they're collected, and running a rental business is a commercial activity — which means federal or provincial privacy law governs that data by default, not by opt-in.
Key takeaways
A rental application alone typically carries a name, date of birth, income, employment details, a credit check, and often a Social Insurance Number or government ID copy — before a lease is even signed. That file is personal information under Canadian privacy law from the moment it's collected, and the obligations that come with it don't wait for a complaint to make them relevant.
The starting point is that renting property is a commercial activity, and PIPEDA's default reach is broad: “PIPEDA applies to the collection, use and disclosure of personal information in the course of a commercial activity.” The same OPC explainer draws the provincial exception precisely: “PIPEDA also applies within provinces without substantially similar private sector privacy legislation.” and confirms which provinces have their own general private-sector law standing in PIPEDA's place — “Quebec, British-Columbia, Alberta … have promulgated legislation deemed substantially similar to the federal law.” Outside those three, including Ontario and the rest of the country, PIPEDA is the direct answer for how tenant data must be handled.
This is a different map than the one that applies to a property manager's own employees, covered in our companion piece on worker privacy — the employee-data carve-out is narrower than the customer-data one, and it's worth not conflating the two when a company operates across provinces.
Two Schedule 1 principles do most of the practical work. Purposes have to be nailed down before collection: purposes “shall be identified by the organization at or before the time the information is collected” (Schedule 1, clause 4.2) And what gets collected has to match a purpose a reasonable person would accept: collection is permitted only “for purposes that a reasonable person would consider are appropriate in the circumstances” (s.5(3)) — which is the same test underlying the Ontario Human Rights Commission's narrower rule (covered in depth in our note on automated tenant selection) that a landlord may only ask about rental history, credit references/checks and income for screening purposes.
PIPEDA's breach-reporting duty is triggered by a specific, defined test: report to the Commissioner “if it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual” (s.10.1(1)) and notify the affected individual on the same test, “as soon as feasible after the organization determines that the breach has occurred” (s.10.1(2), (3) and (6)) Significant harm is itself defined broadly — “significant harm includes bodily harm, humiliation, damage to reputation or relationships, loss of employment, business or professional opportunities, financial loss, identity theft, negative effects on the credit record and damage to or loss of property.” (s.10.1(7)) A rental-application file is a near-textbook example of information whose exposure fits that definition directly.
Property-management software, tenant-screening tools and payment platforms all handle tenant data on a landlord's behalf, and PIPEDA's accountability principle is explicit that the responsibility stays put: “An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection.” (Schedule 1, clause 4.1.3) A vendor contract has to actually deliver that protection — see our vendor-diligence checklist for what to check before signing.
The Landlord and Tenant Board process itself generates its own file of personal information once a dispute is filed — worth knowing the mechanics of, since a treadstonelaw.ca note on the Landlord and Tenant Board process walks through prescribed notices, filing and hearings, and how orders and enforcement actually work in Ontario.
Draft vs decide
A property-management platform may: store applications, process payments, log maintenance requests, and generate reports.
Only the landlord or manager decides: what data is actually necessary to collect, how long it's retained after a tenancy ends, and what the response plan is if a vendor or an internal system is breached.
A property management company managing 200 units across Ontario and Alberta stores every rental application — including SIN and government ID copies collected for credit checks — indefinitely, on the theory that “it might be useful later.” A staff laptop containing an exported spreadsheet of 40 current and former applicants' full files is then lost.
Two separate rules apply depending on which units the affected applicants applied for. For the Ontario units, PIPEDA governs directly: the exposure of SIN numbers, ID copies and financial details is squarely inside the s.10.1(7) definition of significant harm — identity theft and financial loss both named explicitly — which means the breach-reporting duty to the Commissioner and to the affected individuals is triggered “as soon as feasible.” For the Alberta units, the provincial PIPA applies instead of PIPEDA directly, with its own breach-notification mechanics, but the underlying data-minimization lesson is identical either way: indefinite retention of ID and SIN data with no purpose tied to an active or recent tenancy is exactly the kind of collection that turns a lost laptop into a reportable breach instead of a minor inconvenience. The fix is a retention policy that actually deletes SIN and ID copies once the purpose they were collected for — the credit check — is complete, rather than keeping the full file indefinitely because deleting it never became anyone's job.
Generally yes — PIPEDA doesn't set a size threshold for commercial activity, and renting units is commercial activity. Size affects practical risk and resourcing, not whether the obligation applies at all.
Consent is one of PIPEDA's core principles alongside identifying the purpose and limiting collection to what's necessary — a credit check is generally an accepted, disclosed part of tenant screening, which is why the Ontario Human Rights Commission's rule permits requesting it directly; the consent question sits alongside, not instead of, that human-rights framework.
No source in this sheet states a fixed number of days for this specific case. PIPEDA's limiting-retention principle points toward keeping it only as long as the original purpose requires, plus any period needed to respond to a complaint about the decision — build a defined retention window into policy rather than defaulting to “keep everything indefinitely.”
A 30-minute call is enough to tell you whether AI pays for itself here.