Data Security and Tenant Information: What Landlords Are Responsible For
You're holding ID numbers, phone numbers, and payment history for every tenant you've ever had. That makes you a data custodian whether you think of yourself as one or not.
Think about what a landlord with even a modest portfolio is actually sitting on: full names, national ID numbers, phone numbers, next-of-kin details, employment information for some, bank or M-Pesa transaction history for all of them, and in many cases copies of ID documents collected at move-in and never properly disposed of afterward.
That's not a small amount of sensitive personal information. It's the kind of data set that, if handled carelessly, exposed accidentally, or accessed by the wrong person, could cause real harm to the people who trusted you with it, harm ranging from identity theft to harassment to financial fraud.
Most landlords don't think of themselves as data custodians. They think of themselves as landlords who happen to keep some paperwork. The distinction matters more than it sounds.
Where This Data Actually Lives, and Where It Leaks
It's worth being specific about the ordinary, everyday ways tenant data ends up exposed, because none of these involve anything as dramatic as a hack:
- A WhatsApp group where ID copies get shared for verification purposes, and then just sit in the group's media folder indefinitely, visible to anyone who was ever added to that group, including former tenants, former staff, or anyone who later gets added for an unrelated reason.
- A spreadsheet with tenant financial history, shared via email or a cloud drive link with weak or no access restrictions, forwarded once to an accountant, and now effectively uncontrolled.
- A phone that gets lost or changes hands, with years of tenant chat history, ID photos, and payment confirmations stored in it, and no passcode or encryption protecting any of it.
- A former staff member who retains access to shared accounts, folders, or group chats well after they've left, simply because nobody went through and removed them.
- Paper files, ID copies and signed leases, stored in an office drawer with no real access control, sometimes outliving the tenancy by years for no particular reason.
None of these require malicious intent. Most are just the ordinary byproduct of running a rental business informally, without ever deciding deliberately how tenant data should be handled.
Why This Is a Real Responsibility, Not Just Good Practice
Kenya has data protection obligations that apply to anyone collecting and processing personal information, and the general direction is consistent with how most modern data protection frameworks work globally: if you collect someone's personal information, you're expected to have a legitimate reason for holding it, to keep it reasonably secure, to use it only for the purpose you collected it for, and to not keep it indefinitely once there's no longer a reason to.
This isn't a call to go hire a compliance lawyer for a ten-unit building. It's a reminder that "I didn't think about it" is a weak position to be in if a tenant's information is ever mishandled, exposed, or misused, and they come asking how it happened. The specific legal mechanics matter less here than the practical standard: would you be comfortable explaining, to a tenant whose ID number or financial history leaked, exactly how your systems were supposed to prevent that?
What Responsible Handling Actually Looks Like
None of this requires sophisticated infrastructure. It requires a handful of deliberate habits:
Collect only what you actually need
A copy of a national ID for verification purposes is reasonable. Keeping a tenant's full employment history, bank statements, or other documents beyond what's genuinely required for the tenancy is not, and it's additional exposure with no corresponding benefit.
Control who can see what
This is the same principle as role-based staff access applied specifically to sensitive personal information. A caretaker logging a maintenance issue has no legitimate need to see a tenant's ID number or full payment history. If your system, or your habits, don't actually separate these, you're exposing more than necessary to more people than necessary.
Secure the storage, not just the collection
A WhatsApp group is not secure document storage, regardless of how convenient it feels in the moment. Photos and documents shared there persist indefinitely, are visible to every group member past and present, and have no real access control once shared. Sensitive documents need a structured storage layer with actual permissions attached.
Have an actual process for staff departures
When someone who had access to tenant information leaves, whether a manager, caretaker, or anyone else, their access should be revoked immediately, not eventually. This is one of the simplest, highest-leverage security practices available and one of the most commonly skipped.
Don't keep data forever by default
A former tenant's full file, ID copy included, doesn't need to sit in your system unchanged for a decade after they've moved out. There's often a reasonable retention need for financial records, but personal documents beyond that window are just accumulating risk with no upside.
Tenants Are Paying More Attention Than Landlords Assume
It's easy to assume tenants don't think much about how their data is stored. Increasingly, that's not true, particularly among younger, more digitally literate tenants in Nairobi and other urban centers, who are used to seeing privacy policies, used to being asked for consent, and reasonably uneasy about handing over an ID copy into a WhatsApp group with forty other members they don't know.
A landlord who can point to an actual system, with scoped access, with secure document storage, with a sensible retention approach, is offering something that increasingly reads as a quiet point of trust, not just an operational nicety.
The Realistic Standard to Hold Yourself To
You don't need a legal department. You need to be able to answer, honestly, who can currently see a given tenant's personal information, why they can see it, and what happens to that access when their role changes or ends. If you can answer that clearly today, you're already ahead of a large share of the market. If you can't, it's worth treating as a gap to close, not a hypothetical risk to worry about someday.
Makeja Homes stores tenant and lease documents with role-scoped access and a full audit trail of who viewed or changed what. Start your free 30-day trial at makejahomes.co.ke/start and see how access is structured by default.
Ready to try it yourself?
Free 30-day trial. No credit card. Set up in under 10 minutes.
Start free trial →