Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Practical Steps And Common Mistakes
- 1. Map what you collect and why
- 2. Check whether the collection is reasonably necessary
- 3. Fix your privacy policy and collection notices
- 4. Review supplier and contractor contracts
- 5. Set retention and deletion rules
- 6. Control internal access
- 7. Prepare for complaints and data breaches
- 8. Avoid these recurring mistakes
- 9. Keep the business context in view
- Key Takeaways
Commercial landlords often collect more customer information than they realise. A shopping centre operator might gather Wi-Fi sign-up details, CCTV footage, car park number plate data, competition entries, concierge records or feedback forms, then treat it all as routine admin. That is where privacy problems start.
Common mistakes include collecting far more information than is actually needed, using information later for marketing without proper consent, and failing to explain clearly who is collecting the data and why. Another frequent issue is assuming privacy law only applies to tenants, not to shoppers, visitors, contractors or loyalty program members.
If you are a landlord, centre manager, asset owner or business operating a commercial site, you need to know when privacy obligations apply, what personal information you can collect, and how to handle complaints or data breaches. This guide explains what collecting customer information as a commercial landlord means in Australia, where the risks usually arise, and what practical steps make the biggest difference before you sign contracts or roll out new systems.
Overview
When a commercial landlord collects information about visitors, customers or tenants' customers, privacy law can apply even if the collection seems minor or automated. The main questions are why the information is being collected, whether the collection is reasonably necessary, how people are told about it, and what happens to the data afterwards.
- Identify exactly what personal information you collect, including CCTV, Wi-Fi data, car park records, app data and enquiry forms
- Work out who is legally collecting it, the landlord, a centre manager, a contractor or a tenant
- Check whether the Privacy Act 1988 (Cth) and the Australian Privacy Principles are likely to apply to your business
- Make sure your collection notice and privacy policy match what actually happens on site
- Limit use of the data to the purpose originally disclosed, unless you have a lawful basis for a secondary use
- Review contracts with security providers, marketing platforms, parking operators, software vendors and other service providers
- Set up a process for access requests, complaints, correction requests and eligible data breach response
What Collecting Customer Information Commercial Landlord Means For Australian Businesses
For Australian businesses, collecting customer information as a commercial landlord usually means handling personal information in a way that is more regulated than many operators expect.
Personal information is broadly information or an opinion about an identified individual, or an individual who is reasonably identifiable. In a commercial property context, that can cover obvious items like names, phone numbers and email addresses, but it can also include less obvious data if it can be linked back to a person.
What counts as customer information in this setting?
The term customer information is not limited to a tenant's customer database. It may include information gathered directly by the landlord or centre operator from members of the public who visit a site or interact with its services.
Examples often include:
- names and contact details collected through competitions, event registrations or gift card promotions
- visitor details collected through concierge desks, booking systems or enquiry forms
- CCTV footage showing identifiable people
- vehicle registration data collected through boom gates, parking apps or ticketless parking systems
- Wi-Fi sign-up data and location analytics
- customer complaints, incident reports and lost property records
- app or loyalty program information linked to shopping centre activity
- records of accessibility requests or security incidents
Some of this information may also become sensitive information in limited cases, for example where records reveal health details, disability information, biometric data or religious affiliation. Sensitive information generally attracts a higher standard for collection and use.
Which privacy laws matter?
The main federal law is the Privacy Act 1988 (Cth), including the Australian Privacy Principles, often called the APPs. Not every commercial landlord will be caught in every situation, because the Act has thresholds and exceptions, but many medium and larger operators are covered. Some smaller businesses are also covered, especially if they trade in personal information, provide certain services, or are part of a larger corporate group.
Even where a small business exemption may be relevant, that should not be treated as a free pass. Landlords still face practical risks under contracts, confidentiality obligations, surveillance rules, marketing laws, and general reputational expectations. Tenants, investors and enterprise partners also increasingly expect proper privacy governance as part of ordinary commercial compliance.
Who is actually collecting the information?
This is where businesses often get caught. A commercial site may involve a landlord, a property manager, a shopping centre management company, a parking operator, an events contractor, a security provider and retail tenants, all collecting overlapping information from the same people.
You need to be clear on questions like:
- who decides why the information is collected
- who controls the systems that store it
- who can access it
- who responds if a person asks for access or makes a complaint
- whether one party is collecting for itself, for another party, or jointly
If these roles are blurred, your privacy disclosures can become inaccurate and your contracts may not allocate responsibility properly.
Why purpose matters
A landlord cannot safely collect information just because it might be useful later. Under the APP framework, collection should generally be reasonably necessary for the entity's functions or activities, and people should usually be told why it is being collected.
That matters in real business decisions. For example, using car park data to manage time limits may be easier to justify than building hidden marketing profiles from number plate movements. Collecting an email address for an event booking is different from adding that person to a broad retail advertising database unless that later use was properly disclosed and permitted.
Transparency is not optional
People should not have to guess that a landlord is collecting their data. If your site uses CCTV, facial recognition style analytics, tracking technology, digital directories, ticketless parking, guest Wi-Fi or promotional sign-ups, your notices need to be clear enough for an ordinary person to understand.
In practice, that usually means using layered notices across the site and online, such as:
- signage where collection happens
- a privacy policy that accurately describes data practices
- specific collection notices for promotions, forms or apps
- contractual privacy wording with suppliers and service operators
When This Issue Comes Up
Privacy issues usually appear when a landlord adds convenience, security or marketing tools to a property and forgets that each tool may involve a new act of collection, use or disclosure.
The legal risk often starts before launch, not after a complaint. If you only review privacy once a tenant, customer or regulator raises concerns, you are already on the back foot.
Shopping centres and mixed-use precincts
Large retail sites often collect data from foot traffic analytics, customer service desks, event registrations, loyalty campaigns, Wi-Fi systems and parking facilities. These sites also have multiple stakeholders, which makes it harder to explain who is collecting what.
A common example is a centre campaign where shoppers enter a promotion run by centre management, but the data is then shared with retailers or external marketing platforms more broadly than expected.
Commercial office buildings
Office landlords and managers may collect visitor registration data, building access records, security footage and contractor details. The immediate purpose may be building safety, but the same data can be tempting to reuse for analytics, occupancy planning or direct engagement.
That is where purpose creep happens. A safety record can quietly turn into a business intelligence tool without the documentation keeping up.
Parking and access technology
Automated parking systems are a major pressure point. Number plate recognition, payment apps and linked account profiles can create detailed records about people visiting a site.
Before you spend money on setup, check:
- whether the parking operator is collecting data in its own right or on your behalf
- how long number plate and payment records are stored
- whether the data is shared with enforcement, debt recovery or analytics providers
- what notices are displayed at entry points and payment points
Events, activations and competitions
Landlords often run school holiday programs, product promotions, community events and prize draws to increase traffic. These are classic moments where businesses collect names, contact details, photos and marketing preferences quickly and informally.
The mistake is treating the form as a marketing exercise only. You also need to think about privacy notices, consent wording, image use permissions, age-related issues where children are involved, and any third party sponsors receiving data.
CCTV and site security
CCTV can be legitimate, but it is not exempt from privacy concerns just because it relates to security. If cameras record identifiable people, the way footage is collected, stored, accessed and disclosed matters.
The risk increases when footage is kept too long, used for unrelated purposes, or shared too casually with tenants, insurers, investigators or social media teams.
Tenant-landlord data sharing
Commercial landlords sometimes ask tenants for customer data to support centre-wide promotions, trading analysis or visitor profiling. That can create problems for both sides if the legal basis for sharing is unclear.
Before you sign a contract that requires data sharing, work out:
- whether the tenant is allowed to disclose that information
- whether the landlord will become a separate collector or recipient of the information
- how customers were originally told their data would be used
- who is responsible for complaints, corrections and security obligations
Practical Steps And Common Mistakes
The safest approach is to map your data flows first, then match your notices, systems and contracts to what actually happens on the ground.
Many privacy failures are operational, not theoretical. The issue is usually not that a business never heard of privacy law. The issue is that teams rolled out a parking platform, event form or analytics tool without aligning signage, privacy wording, access controls and supplier obligations.
1. Map what you collect and why
Start with a practical audit. List every point where a visitor, shopper, contractor or tenant representative gives information to the property or is recorded by it.
Your audit should cover:
- what data is collected
- where it is collected
- why it is collected
- who collects it
- where it is stored
- who it is shared with
- how long it is kept
This sounds basic, but many businesses discover duplicate systems, unclear ownership and old practices that no longer match the current purpose.
2. Check whether the collection is reasonably necessary
Do not collect extra fields just because a software platform includes them by default. If a competition only needs a name and email address, asking for date of birth, suburb, shopping habits and family details may be hard to justify.
Data minimisation is one of the easiest ways to reduce risk. Less data means fewer disclosure issues, lower storage burden and simpler complaint handling.
3. Fix your privacy policy and collection notices
Your privacy documents need to describe your actual practices, not generic template language. A policy that mentions website enquiries but says nothing about CCTV, parking systems or event activations will not do much to help if someone challenges your collection.
Make sure your notices explain matters such as:
- the identity of the collecting entity
- the purpose of collection
- what happens if the information is not provided, where relevant
- who the information may be disclosed to
- how a person can access or correct their information
- how complaints can be made
If you use direct marketing, be especially careful that consent and opt-out processes are clear and match the relevant electronic marketing rules.
4. Review supplier and contractor contracts
If a third party runs your security systems, parking technology, Wi-Fi network, CRM, email campaign or event registration platform, your contract should deal with privacy and data handling clearly.
Key contract points often include:
- who owns or controls the data
- what the supplier can and cannot do with it
- security standards and access controls
- subcontracting limits
- breach notification obligations
- return or deletion of data at the end of the contract
- assistance with access requests, complaints and investigations
This is especially important where data is hosted overseas or where multiple entities in a property group can access shared platforms.
5. Set retention and deletion rules
Keeping data forever is a common mistake. If footage, visitor logs or campaign records are no longer needed for the purpose they were collected for, indefinite retention creates unnecessary exposure.
Retention periods should reflect the type of record, the business purpose, security needs, and any legal reasons to keep it longer. The point is to have a genuine data retention policy, not an accidental archive.
6. Control internal access
Not everyone in the business needs access to customer or visitor information. Limit access to people who need it for their role, and make sure teams know what they can and cannot do with the data.
This matters in everyday situations, such as a retailer informally asking centre management for CCTV clips, or a marketing team wanting parking data for a campaign without checking the original purpose.
7. Prepare for complaints and data breaches
A privacy issue becomes much more expensive when there is no response plan. Covered entities may have obligations under the Notifiable Data Breaches scheme if an eligible data breach occurs.
Your response process should deal with:
- who investigates a suspected breach
- how affected systems are contained
- who assesses legal notification obligations
- who communicates with affected individuals, tenants, contractors and regulators
- how evidence and decision-making are documented
8. Avoid these recurring mistakes
Commercial landlords commonly run into the same problems repeatedly.
- Assuming a contractor's privacy policy covers the landlord as well
- Using broad, vague consent language that does not reflect the actual use of data
- Collecting customer information for one purpose and quietly reusing it for another
- Failing to update signage when a new technology system is introduced
- Sharing tenant or shopper data within a corporate group without checking the original disclosure position
- Storing old campaign data and CCTV footage without a retention rule
- Treating privacy as an IT issue only, instead of a legal and operational issue
9. Keep the business context in view
Privacy is not separate from the rest of your commercial setup. The way you structure your operations affects who collects information, who contracts with suppliers and who carries risk.
That may involve reviewing your business structure, management agreements, commercial leases, contractor terms, promotional terms and conditions, direct marketing practices, trade mark use in campaigns and broader regulatory compliance. If you are expanding across multiple sites or launching new digital services, sort this out before rollout rather than patching it later.
FAQs
Does a commercial landlord need a privacy policy?
Often yes, especially if the landlord or site operator is subject to the Privacy Act or collects personal information through websites, events, parking systems, CCTV or visitor services. Even where the law is less clear, a well-drafted privacy policy is often commercially sensible.
Can a landlord share customer information with retail tenants?
Not automatically. The answer depends on why the information was collected, what the person was told at the time, whether any consent was obtained, and what the relevant contracts say.
Is CCTV footage personal information?
It can be, if an individual is identifiable or reasonably identifiable from the footage. That means collection, storage, access and disclosure of footage should be handled carefully.
Do parking systems and number plate recognition raise privacy issues?
Yes. Number plate data can become personal information depending on the context, particularly where it is linked to accounts, payments or identifiable visit patterns. Clear notices and supplier contracts are important here.
What if a customer complains about how their information was collected?
You should have a process to receive the complaint, investigate what happened, check your notices and contracts, and respond within a reasonable timeframe. If your business is covered by the Privacy Act, complaint handling should align with your APP obligations and any regulatory requirements.
Key Takeaways
- Commercial landlords can collect personal information in many ordinary site activities, including CCTV, Wi-Fi, parking, events and visitor management
- The main legal issues are whether the collection is reasonably necessary, whether people were told clearly, and whether later use or sharing matches the original purpose
- Unclear roles between landlords, centre managers, contractors and tenants are a major source of privacy risk
- Accurate privacy policies, collection notices and supplier contracts matter just as much as the technology itself
- Retention rules, access controls, complaint handling and data breach response processes should be set before problems arise
- Before you sign contracts or launch new systems, map the data flow and check that your privacy position matches day-to-day operations
If your business is dealing with collecting customer information commercial landlord and wants help with privacy policies, collection notices, supplier contracts, data breach response, you can reach us on 1800 730 617 or team@sprintlaw.com.au for a free, no-obligations chat.






