The most sensitive personal information in a rental business usually belongs to people who never moved in.
A completed rental application is a small identity kit. Government ID, pay stubs or a letter of employment, banking details, a credit report, an employer's phone number, a former landlord's name. You collect all of it to answer one question: do we lease to this person? Once that question is answered, the file has done its work.
For the applicant you approved, the file gets a second life. It becomes part of a tenancy, attached to a lease, a ledger and a move-out date. For everyone you declined, it becomes nothing at all. It sits in an email thread, a downloads folder, a shared drive nobody has opened since the unit filled. No one owns it, so no one ends it.
Data you cannot use is still data you can lose
This is the part that gets misread. Keeping a declined application is not cautious. Storage is cheap and deleting feels irreversible, so the default is to keep everything forever, and that default converts a finished decision into a standing liability. You will never use that credit report again. You can still lose it: to a compromised mailbox, a departing employee's laptop, a shared drive whose permissions nobody has audited in three years.
Every extra year of retention adds inventory to a breach you have not had yet, and adds nothing to the business. Scattered-site landlords and small agencies feel it hardest, because the files live in personal inboxes rather than in a system with rules.
The law gives you a floor and a ceiling
Under PIPEDA, Schedule 1, Principle 4.5, retention guidelines should include minimum and maximum periods. Information used to make a decision about someone must be kept long enough for that person to access it after the decision is made. Information no longer required for the purpose you identified should be destroyed, erased or made anonymous, and you are expected to have a procedure for doing it.
British Columbia is more specific. Section 35 of BC's Personal Information Protection Act says that if you use someone's personal information to make a decision that directly affects them, you must keep that information for at least one year afterward so they have a reasonable opportunity to access it. The same section requires you to destroy documents containing personal information, or strip the link to the individual, as soon as it is reasonable to assume the purpose is no longer served.
Read those together and the answer stops being a judgment call. A declined application has a minimum life and a maximum life. Deleting it the day you say no is wrong. Keeping it for six years is also wrong. Pick a defensible window inside that range, write it down, and make the deletion happen without anyone having to remember.
Collect less and the problem shrinks
The cheapest fix happens before intake. Most of what makes a declined file dangerous is information you did not need to hold. A screening provider can pull and keep the credit check on their side and return you a result rather than a report. You can verify income by viewing a document instead of keeping a copy. A social insurance number is almost never yours to store.
What you do not collect cannot leak and does not need a retention rule.
Do this today
Pick your window once. Then find the copies: the mailbox, the phone that photographed a pay stub at a showing, the shared drive, the screening vendor's portal, the property management system. Put the window in your application form so applicants know it, and set a recurring reminder for whoever runs leasing to clear everything past the line.
Then check your own province. The floor and the ceiling move, and BC is not the only place that sets them.
