Skip to content
Domexa Technologies

Blog

Handling Tenant Data Responsibly

An agency holds ID numbers, phone numbers, employment details and payment histories for hundreds of people. That is a duty, and most of meeting it is unglamorous housekeeping.

Money & records22 March 2026Editorial Team3 min read

A property agency is a data business that happens to hold keys. Between application forms, lease files and payment records you are holding, for hundreds of people: full names, ID numbers, phone numbers, next of kin, employer details, sometimes bank details, and a complete history of what they earn and when they struggle to pay.

Kenya's Data Protection Act, 2019 sets out obligations for anyone holding personal data like that. This is not legal advice, and if you hold data at scale you should take some. But the practical shape of doing it properly is not complicated.

Collect less

The strongest protection against a data problem is not holding the data. Before adding a field to an application form, ask what decision it informs. Do you need a copy of the ID, or is sighting it and recording the number enough? Do you need the employer's address? Do you need next of kin for every applicant, or only for signed tenants?

Every field you don't collect is a field that cannot leak, cannot be misused by a departing member of staff, and cannot be requested back from you.

Know where it lives

Most agencies cannot answer this quickly, and it is the question everything else depends on. Write the list down: the management system, the shared drive, the WhatsApp groups where scanned IDs get sent, the personal phones with tenant numbers saved, the filing cabinet, the accountant's laptop.

The informal copies are the ones that cause incidents. A scanned ID forwarded to a WhatsApp group so a caretaker can confirm someone is a resident is now on an unknown number of devices, for good.

Limit who can see what

A caretaker logging a repair does not need the ledger. A cashier does not need employment details. Give each role the narrowest access that lets them do the job, and remove access the day someone leaves, not at the end of the month.

Shared logins make this impossible and should be the first thing to go. If four people use one account, you have no access control and no ability to say who did anything.

Keep a trail, and don't let it be edited

Being able to show who changed what, and when, is both a data protection measure and an ordinary business control. A record that can be silently altered is not evidence of anything. Corrections should be new entries that leave the original visible, not overwrites.

Say what you do, and be able to honour it

People whose data you hold can ask what you have about them, ask you to correct it, and ask you to delete it where you have no lawful reason to keep it. Two practical consequences: you need a retention position: how long you keep the file of someone who applied and was not offered a unit, or a tenant who left three years ago. You also need to be able to find everything about one person when asked.

When something goes wrong

Have a plan before you need it. Who is told, in what order, and how quickly. An incident handled openly and fast is a bad week. The same incident discovered by the affected people first is a different kind of problem entirely.

The short version

Collect less than you think you need. Know every place it lives, including the informal ones. Give people the narrowest access that works. Keep a trail nobody can quietly edit. Decide how long you keep things, and then delete them.

Software helps with the middle three. The first and the last are decisions, and they are yours.