Tenant data: what to keep, for how long, and where
A letting agency holds identity documents, salary certificates and cheque images for thousands of people, and every market in the region now has a law about that. What you can justify collecting, and when it has to go.
Ask a property manager what data they hold and the answer is usually "leases and payments". Then look in the shared drive. There are passport scans, Emirates ID or Iqama copies, visa pages, salary certificates, employment letters, bank statements, images of cheques carrying account numbers and signatures, marriage certificates filed to prove a family relationship for a two-bedroom, and photographs of the inside of people’s homes taken at check-out.
That is a serious personal data holding, assembled without anyone deciding to assemble it. Until recently the region had little to say about it. That is no longer true.
This is an overview for people designing systems and processes, not legal advice. Several of these laws arrived before the detailed regulations that implement them, so the practical position in a given market can differ from the statute, and free zones may run their own regime.
It is not one law, and it is not optional
The region legislated on this in a cluster. The UAE has a federal personal data protection law from 2021, alongside the older and more detailed regimes in the DIFC and ADGM, which apply if the business is established there. Saudi Arabia’s Personal Data Protection Law was issued in 2021, amended in 2023, and became fully enforceable in September 2024, supervised by SDAIA. Egypt passed its data protection law in 2020. Bahrain, Qatar, Morocco, Jordan and others each have their own.
They differ in the detail and agree on the shape, which is what makes it possible to design one process for a regional portfolio: collect for a stated purpose, keep no more than that purpose needs, hold it no longer than necessary, secure it, be able to tell the person what you have, and report a breach quickly.
- A stated, lawful purpose for each category of data, decided before it is collected.
- A retention period, after which it goes.
- Access limited to the people whose job requires it.
- Rules on moving data outside the country, which are not the same rules everywhere.
- A breach notification obligation measured in hours — seventy-two is the common figure.
- Rights for the individual: to know what is held, to have it corrected, and in defined circumstances to have it deleted.
The Emirates ID question
The habit across the region is to photograph every document a prospective tenant carries, at first contact, before anyone knows whether they will take the unit. Six months later the agency holds full identity files for two hundred people who rented nothing.
The discipline that fixes most of the exposure is one question asked per document: what am I going to do with this, and does the answer survive being written down? A copy of an identity document to complete a registration filing that requires it is a purpose. A copy taken because it is what the last agency did is not, and it is exactly the file that shows up in a breach.
- At enquiry: name and a way to reach them. Nothing else has a purpose yet.
- At application: what is genuinely needed to assess the tenancy, and no more.
- At signing: what the contract, the registration authority and the tax rules require — this is where identity documents legitimately belong.
- During the tenancy: what the tenancy generates. Maintenance photographs of a unit are not photographs of a household, and the difference is worth training people on.
- For everyone who did not proceed: a deletion date, applied automatically rather than remembered.
Cheque images deserve their own line. A photograph of a cheque carries an account number, a signature and a bank. It is stored because presenting and disputing cheques requires it, which is a real purpose — and it makes the cheque register one of the most sensitive tables in the system, not one of the most administrative.
Retention is two clocks, not one
The most common mistake is to treat "delete when no longer needed" as inconsistent with the tax and accounting rules that require records to be kept for years. They are not in conflict; they apply to different things, and separating them is what makes a retention policy possible.
The accounting record — invoices, receipts, ledger entries, the contract itself — has a statutory life. In the UAE, tax records are generally kept for five years, and records relating to real estate for considerably longer. Saudi Arabia requires six years for VAT records. Those periods are floors set by the tax authority and they are not negotiable.
The supporting personal data is a different clock. A salary certificate collected to assess an application, or a passport scan taken to satisfy a registration that has since completed, has no accounting life of its own. Once its purpose has ended and any period the regulator requires has run, it should go — and it should go on a schedule rather than when someone happens to tidy the drive.
- Financial records: keep for the statutory period, which is set by the tax authority and differs by market.
- Registration filings: keep while the tenancy runs and for whatever period the authority sets afterwards.
- Application material for applicants who did not proceed: short, and automatic.
- Identity documents after a completed registration: keep only what the market genuinely requires be retained.
- Maintenance photographs: keep while the work order and any warranty on it are live, then go.
Where it lives became a legal question
Several of these laws restrict moving personal data out of the country, or make it conditional on the destination offering adequate protection or on specific contractual safeguards. In practice that turns a hosting decision into a compliance decision, and it is one that has to be answered before a contract is signed rather than during a regulator’s enquiry.
What a buyer should be asking a vendor is short, and the answers should be immediate: which country holds the production database, which country holds the backups, which sub-processors touch the data and where they are, and whether a deployment inside a particular jurisdiction is possible if the tenant’s own regulator requires it.
Backups are the part that gets forgotten. A database inside the country with backups replicated to another continent has moved the data, and a retention policy that deletes from production while a backup keeps a copy for a year has not deleted anything. Both are ordinary findings in an audit and both are architectural, not procedural.
The parts a system has to make possible
Most of the obligations are process, but a handful cannot be met at all unless the software was built for them. These are the ones worth checking before buying rather than discovering afterwards.
- Access scoped by role, so a maintenance coordinator does not see salary certificates and a resident does not see the building.
- An audit trail that records who read what, not only who changed what — a data protection enquiry asks about access, and an append-only log is the only credible answer.
- Export of one person’s data, on request, without an engineer writing a query.
- Deletion that actually deletes, including from backups within a stated cycle, and that can be reported on.
- Documents held under access control rather than in a shared folder with a link that works for anyone who has it.
- A record of which staff account did what, so a breach can be scoped in hours rather than reconstructed from memory.
The WhatsApp group
Every operator in the region runs on WhatsApp groups, and it is genuinely the fastest way to get a leaking pipe fixed at nine in the evening. It is also, at the moment someone photographs a tenant’s ID into a group of eleven people, an uncontrolled transfer of personal data to a set of devices nobody manages, retained indefinitely, backed up to whichever cloud each phone happens to use.
The realistic answer is not to ban it. It is to move the documents out of it — keep the conversation, put the identity documents, the cheques and the statements behind an access-controlled system, and give staff somewhere to put a file that is faster than photographing it into a chat. A rule that is slower than the thing it replaces is a rule that will be broken by the end of the week.
Why this is worth doing before anyone makes you
Enforcement in the region is young and uneven, and it would be dishonest to claim a fine is imminent for a mid-sized agency in most of these markets. The argument for doing it now is not the regulator.
It is that the exposure is real and it belongs to someone else. A property manager holds the documents that let a person be impersonated — identity, address, employer, income, bank and signature — for every household in the portfolio. A leak is not an administrative embarrassment; it is a set of people whose identity documents are now in circulation because a letting agency kept them for no reason it could state. That is a good enough reason on its own, and it happens to also be the position the law is converging on.
Common questions
- Can a landlord keep a copy of a tenant’s passport or Emirates ID?
- Where a specific purpose requires it — completing a registration the authority mandates, or a legal obligation on the landlord — yes, for as long as that purpose and any statutory retention period last. Collecting identity documents from every enquiry, or keeping them indefinitely after a registration has completed, is much harder to justify under the data protection laws now in force across the region.
- How long must a property manager keep tenancy records?
- Two different periods apply. Financial and tax records have a statutory minimum set by the tax authority — generally five years in the UAE, with longer periods for real estate records, and six years in Saudi Arabia. Supporting personal data collected for a purpose that has ended, such as an application from someone who did not take the unit, has no such life and should be deleted on a schedule.
- Does tenant data have to be hosted inside the country?
- Not universally, but several laws in the region restrict cross-border transfers or make them conditional on the destination’s protections or on contractual safeguards. Treat it as a question to answer before signing with a vendor: where the production database sits, where the backups sit, which sub-processors touch the data, and whether an in-country deployment is available if a regulator requires one.
- How quickly does a data breach have to be reported?
- Quickly, and the common figure across the region’s laws is seventy-two hours from becoming aware of it, with notification to the regulator and, where the risk to individuals is high, to the affected people as well. Meeting that in practice depends on being able to scope the breach fast, which is why an audit trail recording access — not only changes — matters more than it looks.