The Ledger
TENANT DATA PRIVACYFiled October 2, 202610 min read

90 Day Tenant Data Privacy Checklist for NYC Class A Buildings

Property manager reviewing tenant privacy records

If you manage a Class A multifamily building with keyless entry, key fobs, or biometric locks in New York City, the Tenant Data Privacy Act applies to you. You must get express consent before collecting reference data, limit what you gather to the minimum necessary, publish a plain-language privacy policy, delete or anonymize authentication data within 90 days, and keep security safeguards like encryption and firmware updates current.


TL;DR:

  • Landlords must obtain written or in-app consent before collecting any reference data or biometric authentication data from tenants, limiting data collection to what is necessary for system operation.
  • Authentication and reference data must be deleted or anonymized within 90 days of collection or when a tenant vacates, withdraws consent, or their access expires, with logs kept of each action.
  • Security safeguards require encryption of stored data, automatic firmware updates, role-based access controls, and breach notification procedures to protect tenant privacy.
  • The privacy policy must clearly state data collection practices, usage, retention periods, third-party access, security measures, and include the vendor’s privacy policy, distributed to tenants in accessible language.
  • Maintaining proper records of consent, data deletion, and vendor audits is essential for compliance, as these documents help defend against privacy breaches or disputes.

Landlordforms
Keep Landlord Records Organized
LandlordForms helps landlords generate accurate documents and organize important tenant information in one place, reducing manual paperwork errors.
Explore LandlordForms

Table of Contents

Who and what the tenant data privacy law covers

The Tenant Data Privacy Act, enacted as Local Law 63 of 2021, applies to owners of smart access buildings, meaning Class A multiple dwellings that use electronic systems to grant entry instead of, or alongside, traditional keys. The law covers owners, tenants, and any third-party operators those owners hire to run the system.

Two categories of data matter here. Authentication data is what verifies identity at the door: a fingerprint scan, a facial recognition template, or a fob signal. Reference data is what the system stores to make that verification possible later, such as the tenant’s name linked to a fob number or an app credential tied to a unit.

  • Fobs, keycards, and mobile app tokens count as authentication tools once tied to a resident’s identity.
  • Biometric scans (fingerprint, face, iris) fall squarely under the law’s authentication data category.
  • Access logs showing who entered and when are reference data subjects to the same protections.
  • Security cameras are excluded unless they are actually used to authenticate entry, not just to record activity.

The statute requires express consent, meaning written consent or consent given through a mobile app, before an owner collects reference data from a tenant. According to HPD’s guidance, owners may collect only the minimum authentication and reference data necessary to operate the system, not whatever a vendor’s default settings happen to gather.

Document consent the same way you’d document a lease signature: dated, attributable to a specific tenant, and stored somewhere retrievable if a dispute arises later.

  • Collect only what the entry system needs to function: a name, unit number, and the credential itself.
  • Avoid gathering data on household members or guests who never signed a consent form.
  • Never sell, lease, or disclose tenant data to third parties outside the system’s operation.
  • Never use access data to harass a tenant, build a case for eviction, or track personal relationships.

Pro Tip: Keep consent forms separate from the lease itself so you can update or reissue them without touching the underlying tenancy agreement.

The 90-day rule for deleting or anonymizing tenant data

The clock starts the moment data is collected or generated. Under Int. 1760-2019, authentication data must be destroyed no later than 90 days after collection unless it’s retained in anonymized form. Reference data follows a similar 90-day window, but the trigger is different: it starts when a tenant vacates, withdraws consent, or their access authorization expires.

Anonymization is a substitute for deletion only when removing the data outright would break the system’s ability to function, such as an aggregate access count used for building maintenance scheduling.

  1. Confirm the trigger event: collection date for authentication data, vacate or withdrawal date for reference data.
  2. Delete or anonymize within 90 days of that trigger, whichever applies.
  3. Log the deletion with a timestamp and the name of the person or system that performed it.
  4. Retain exceptions only where justified: active security incident investigations, legal holds, or unpaid balances tied to access fees.

Security safeguards landlords must have in place

Chapter 30 sets specific minimums for any smart access system: encryption of stored data, the ability for tenants to change their own passwords where passwords are used, and regular firmware updates to patch vulnerabilities as they’re discovered.

Meeting the statutory floor is not the same as having a secure system. Start with discovery: know exactly what data your access system collects, where it’s stored, and who can reach it by consulting a local real-estate professional familiar with operational landlord practices and tenant relations. Microsoft’s guidance on securing tenant resources recommends inventorying systems first and layering role-based access controls on top, so a leasing agent can’t see biometric data a superintendent never needed either.

  • Require encryption at rest and in transit for any stored authentication or reference data.
  • Confirm the vendor pushes firmware updates automatically rather than waiting for a support ticket.
  • Restrict internal access by role: front desk staff, maintenance, and management shouldn’t have identical permissions.
  • Build breach notification timelines and audit rights into every vendor contract, not just the initial sales pitch.

Pro Tip: Ask your smart access vendor for a written breach notification SLA before signing, not after an incident forces the question.

What your tenant privacy policy must include

The law requires owners to give tenants a privacy policy written in plain language, not legal boilerplate copied from a vendor’s terms of service. According to the statutory text, that policy has to spell out specific commitments.

  • The exact data elements collected and how they’re used in day-to-day operations.
  • Which third parties, including vendors and operators, have access to that data.
  • How long data is retained and the schedule for deletion or anonymization.
  • The security safeguards in place and what happens if a breach occurs.
  • The process for adding or removing temporary users, such as guests or subletters, from the system.

Owners also have to make the vendor’s or operator’s own privacy policy available to tenants, not just their own summary. Practice notes on Chapter 30 caution against relying on a generic vendor policy without tailoring it to your building’s actual system.

A lease addendum works for new tenants; a building portal or the access app itself works for reaching everyone else. Keep a signed or timestamped record of distribution so you can show every resident received it.

Enforcement, tenant rights, and where your liability sits

Tenants have a private right of action if their data is sold or disclosed unlawfully. Legal analysis of the statute describes remedies that can include compensatory or statutory damages within a specific monetary range per occupant, plus attorneys’ fees. These remedies sit on top of, not instead of, a tenant’s existing lease obligations: a privacy violation doesn’t excuse unpaid rent, and paying rent doesn’t waive a tenant’s privacy claim.

Your best defense is a paper trail. Keep records that show you did things right, not just a policy that says you would.

  • Signed or app-logged consent records for every tenant with access to the system.
  • Deletion and anonymization logs showing dates, triggers, and who performed the action.
  • Vendor audit reports confirming encryption, firmware update history, and access controls.

A practical compliance checklist for landlords and building managers

Treat this as a sequence, not a wish list. Each step depends on the one before it.

  1. Inventory every system touching tenant data: fobs, app-based entry, biometric scanners, and any log they generate.
  2. Map the data flow: what’s collected, where it’s stored, who can access it, and which vendor manages it.
  3. Set up a documented consent process, whether written forms or in-app acceptance, and store records centrally.
  4. Publish your tenant privacy policy and link the vendor’s or operator’s own policy alongside it.
  5. Automate deletion or anonymization workflows so nothing slips past the 90-day window, and log every outcome.
  6. Rewrite vendor contracts to require breach notification timelines, encryption standards, and audit rights.
  7. Train leasing and maintenance staff on what they can and cannot do with access data.

Pro Tip: Set a recurring calendar reminder tied to each tenant’s move-out date instead of relying on memory to trigger the 90-day deletion clock.

Compliance as risk management, not just paperwork

Treating the Tenant Data Privacy Act as a checklist misses the point. A documented consent record and a clean deletion log are what protect you when a tenant disputes an eviction notice or a vendor has a breach. Landlords who automate this recordkeeping, rather than chasing it after the fact, spend less time defending decisions and more time running their buildings. That’s the same logic behind automating notices, receipts, and other recurring landlord paperwork: fewer manual steps mean fewer gaps a tenant or a court can point to later.

— Igor

How LandlordForms keeps your privacy records organized

Complying with the Tenant Data Privacy Act means generating and storing documents correctly, which is exactly the kind of paperwork LandlordForms was built to handle. Instead of tracking consent forms, deletion logs, and tenant notices across scattered spreadsheets, you can organize tenant records, generate notices, and automate document reuse from one place.

Landlordforms

Start with the free templates at Landlordforms and upgrade when you need multi-unit document automation.

Where to read the primary law and guidance

Where to read the primary law and guidance — overview diagram

For the statutory text and official guidance, see HPD’s tenant data privacy page, the NYC Council legislation, Chapter 30 in the code library, and Hinshaw’s practical summary.

Sources

FAQ

Does the United States have data privacy laws?

The United States has no single federal data privacy law covering tenant information; instead, states and cities set their own rules. New York City’s Tenant Data Privacy Act is one such local law, specifically governing smart access systems in Class A multifamily buildings.

Can landlords monitor tenants through smart access systems?

Landlords can only collect the minimum authentication and reference data necessary to operate the entry system, and using that data to track a tenant’s movements or relationships is explicitly prohibited under the statute. Access logs exist to run the building, not to build a profile of a resident’s habits.

What is a tenant’s right to privacy in a smart access building?

Tenants have the right to express consent before their reference data is collected, a plain-language privacy policy explaining how that data is used, and deletion or anonymization of their data within 90 days of moving out or withdrawing consent. They also have a private right of action if their data is sold or disclosed unlawfully.

What are red flags that a landlord isn’t handling tenant data properly?

Warning signs include no written privacy policy, no clear process for withdrawing consent, and no explanation of how long access data is kept. A landlord who can’t produce a vendor’s privacy policy or explain their deletion timeline likely isn’t meeting the Tenant Data Privacy Act’s requirements.

LandlordForms