Real estate agencies hold some of the most sensitive personal data going. Passports, bank statements, proof of address, family situations, financial positions. And in my experience most agencies in New Zealand have never run a single internal security audit. With the tools we all use changing on a weekly basis, that is not a small gap. It is a liability quietly sitting on your books.


Look at what you're actually holding

Step back and inventory it honestly. Through anti-money-laundering and customer due diligence alone, your agency is collecting passports and drivers licences. Through the sale process you handle sale and purchase agreements, finance details, KiwiSaver withdrawal paperwork, sometimes whole bank statements. You know who is going through a divorce, who is selling a deceased estate, who is stretched financially and who is not.

If a hospital or a bank held that profile of data, it would be locked down and audited regularly. In a lot of agencies it is sitting in inboxes, in a shared drive everyone has access to, and in a CRM nobody has ever security-reviewed.


The tooling under your feet keeps moving

Here is what makes 2026 different from a few years ago. The tools are changing faster than anyone's policies can keep up.

We have already watched powerful AI models get released to the public and then pulled within days: Fable being the recent example everyone in tech noticed. That should make every business owner pause. If a model can be live one morning and withdrawn before the end of the week, what exactly do you know about the random AI tool one of your salespeople is pasting a client's financial details into right now? Is it stable? Vetted? Where does that data go? Is it being used to train the next model? Will the company even exist next quarter?

Most agencies cannot answer those questions, because nobody is asking them. The technology raced ahead and the governance never caught up.

The uncomfortable question: right now, today, do you actually know every tool, app and AI service your team is feeding client information into? If the honest answer is no, that is the whole problem in one sentence.


Where real agencies leak data

It is almost never a Hollywood hacker. It is the boring, everyday stuff.


This is a New Zealand legal issue, not just good practice

Under the Privacy Act 2020, if you have a privacy breach that could cause serious harm, you are legally required to notify the Office of the Privacy Commissioner and the affected people. That is not optional, and "we didn't realise the tool stored the data" is not a defence.

Then there is the part the law does not even need to enforce: reputation. New Zealand is a small market. A single mishandled-data story travels through a suburb faster than any listing. Vendors are choosing agents on trust, and trust now quietly includes "will this person be careful with my information". The agencies that take this seriously will be able to say so, and mean it.


Don't leave it as an afterthought

The instinct is to file security under "important but not urgent" and get back to listings. That works right up until the day it very much does not, and by then the data is already gone and the notification letters are already going out.

The good news is that an audit is not a mysterious dark art. It is a structured look at what you hold, where it lives, who can touch it, and which tools it flows through. Most agencies find the biggest risks within the first hour, because nobody had ever simply written them down.


A starting checklist

You do not have to do all of this at once. You do have to start, and you have to stop treating it as someone else's problem.

Concerned about how safe your client data really is? If you're not certain every tool and every file is handled the way it should be, reach out and let's talk through your security requirements, before it becomes a story instead of a checklist.

Discuss your security Read: the documents you shouldn't be uploading ↗