Premises — property operations platform
SupportStart free
Security, privacy and your data5 min read

Data privacy (RA 10173) for landlords: your duties and how the platform helps you meet them

If you hold a copy of a tenant's ID, you are a personal information controller under Republic Act 10173, whether you have twelve units or twelve hundred. The law is less frightening than it sounds, and most of it is good practice you would want anyway.

By the end of this pageYou will know your duties under the Data Privacy Act in plain terms, which ones the platform handles by design, and which need a decision from you.
Six duties, and who does whatAnimated
1Collect only what you needThe client form asks for what a lease needs and nothingelse; every extra field is one you added.2Tell people whyThe portal invitation links to a notice of what is heldand why; you can edit it.3Keep it secureEncryption at rest, roles, two-factor, audit log — theplatform's side of the bargain.4Let people see and correctTenants see their own record in the portal and can ask forcorrections from it.5Don't keep it foreverPast tenants' files can be purged after your retentionperiod; the platform reminds you.6Know who to tell if it goes wrongA breach must be reported to the NPC within 72 hours; theaudit log is your evidence.

Your part and ours, duty by duty

1. Collect only what you need

The client form asks for what a tenancy requires: name, contact, ID, the unit, the dates, the money. It does not ask for religion, health or anything else the Act calls sensitive. If you add custom fields, you are deciding that you need them — the platform will show them on the tenant's own portal record, which tends to keep that honest.

2. Tell people why

Every portal invitation links to a privacy notice that says what you hold, why, for how long, and how to ask about it. A default notice is provided; edit it in Settings › Business › Privacy notice to match how you actually work. The date a tenant accepted it is recorded.

3. Keep it secure

Encryption at rest, roles that limit who sees what, two-factor, rate limits, an audit log. This is the platform's side and is covered in How Premises keeps your data. Your side is shorter but just as real.

4. Let people see and correct

A tenant's portal shows them their own record. A Request a correction link sends the request to you as a ticket, and the change you make is in the audit log with the request beside it.

5. Don't keep it forever

Set a retention period in Settings › Security — three years after move-out is a common choice. When a past tenant's record passes it, the platform lists it under Needs you with a Purge files action that deletes the ID copies and signed documents while keeping the financial history your accountant and the BIR may still need.

6. Know what to do if it goes wrong

A breach that risks real harm must be reported to the National Privacy Commission within 72 hours, and affected people told. The audit log gives you the facts — what was reached, when, by whom. We will tell you within 24 hours of learning of anything on our side.

This is not legal advice. It is a plain reading of the Act as it applies to a small landlord, written to make the duties concrete. Registration with the NPC, a formal privacy manual and a designated Data Protection Officer depend on your size and what you hold; a lawyer or the NPC's own guidance will tell you whether they apply to you.

Related

Describes the platform as it is today. Something out of date? Tell us. · help 0.12.3