Blog · Data Governance

Big data privacy: real estate, multifamily, and the law

Big data privacy: real estate has stopped treating it as an abstract legal topic and started treating it as an operating question. Every application, smart lock, and resident portal in your portfolio is collecting personally identifiable information under a patchwork of state laws with different thresholds and different start dates. As property-level data becomes easier to use for decision-making, multifamily professionals must carefully tread the line between data-driven innovation and legal compliance. (1)

DEFINITIONS

What counts as big data in multifamily real estate?

The evolution of big data in real estate, particularly within the multifamily sector, is a tale of transformative power and complex privacy considerations. Generally speaking, Oracle defines big data as data that "contains greater variety, arriving in increasing volumes and with more velocity" (2). Big data in multifamily real estate spans a broad spectrum, from granular insights into tenant demographics and leasing patterns, to overarching trends in property maintenance and the wider rental market. (3)

Data of this magnitude and detail can reveal invaluable insights, yet its handling and use raise the big data privacy question. Real estate owners and managers who understand the legal and reputational challenges involved have taken the first step towards a data-driven approach that is both ethical and legally compliant.

Where the data actually comes from

The volume is not theoretical. Applications, screening, lease documents, ledgers, work orders, access control, package rooms, and utility submetering each generate records tied to an identifiable person, and each typically lives in a different system with a different retention setting. Knowing what you hold — and in which system — is a prerequisite for answering any privacy question about it. That inventory problem is where big data privacy, real estate operations, and reporting converge. It is one reason a governed data pipeline and standardization layer matters as much for compliance as it does for reporting.

ETHICS

The ethical concerns underneath data privacy law

The utilization of big data necessitates a firm grasp of privacy laws and a deep respect for tenants' privacy rights. Ethics is where big data privacy, real estate, and fair housing overlap. Residents, and prospective residents, must necessarily provide apartment managers certain personally identifiable information, or PII, to apply for housing.

Personally identifiable information is defined by the U.S. government as "Information which can be used to distinguish or trace an individual's identity, such as their name, social security number, biometric records, etc. alone, or when combined with other personal or identifying information which is linked or linkable to a specific individual, such as date and place of birth, mother's maiden name, etc." (4)

Much PII is necessarily collected in order to provide residents with housing, and even to enhance their housing experience. The use of the data collected is the separate, and more important, consideration. Three ethical questions are worth reviewing before any legal analysis begins:

  • The rights of residents to have privacy of their personal information.
  • The safety of resident data from security breaches.
  • The potential for collected resident data to be utilized to discriminate or provide less than equitable housing.
Collecting the information is rarely the question. What you do with it afterward is.
LEGAL EXPOSURE

What privacy laws apply to resident data?

Ethics aside, for ownership groups and management companies in the multifamily space the issue of legal risk is paramount. The guiding legislation on big data privacy, real estate included, starts with the General Data Protection Regulation (GDPR) in Europe, as well as several state laws in the United States, including the California Consumer Privacy Act (CCPA), the Virginia Consumer Data Protection Act (VCDPA), Colorado's Privacy Act (CPA) and half a dozen more. (5) These laws impose standards for businesses dealing with the personal data of residents of their respective states, covering aspects from collection and storage to usage and protection.

Do the privacy law thresholds even apply to you?

Any discussion of legal liability begins with a determination of whether any relevant laws apply. Privacy laws related to consumer data collection have been primarily determined by state legislatures. The challenge for multifamily operators is the need to track whether they meet the applicable thresholds in an ever-growing number of states with different start dates.

In California, a company is subject to CCPA if it is a for-profit entity that does business in California and meets one of the following: it has gross annual revenue of over $25 million; it buys, sells, or shares the personal information of 100,000 or more California residents, households, or devices; or it derives 50% or more of its annual revenue from selling California residents' personal information. (6) Utah, Virginia, Connecticut and Colorado have similar thresholds with slight variations. (7)

The effective dates diverge as well. Only California and Virginia went into effect on January 1, 2023, whereas Connecticut and Colorado became effective on July 1, 2023, and Utah will become effective on December 31, 2023.

Different states, different data rights

Adding to the complexity of tracking requirements and timelines are the parameters each state has chosen for defining consumers' rights and violations of those rights. The CCPA gives Californians the right to know what personal data is collected, the purpose of its collection and use, and whether it will be sold or disclosed to third parties. (8) Since California's initial release of the CCPA, significant pushback from industry has put into question practices like including employees in the pool of covered consumers and adding more onerous record-keeping requirements. Virginia chose to remove many of the more controversial California requirements in its privacy act, permitting companies to rely upon current business practices for tracking and monitoring. (9)

While violations of relevant state statutes can result in stiff financial penalties, so far no state has permitted consumers to sue businesses directly for violations outside of data breaches. Still, reputational risk alone for failure to comply with privacy laws for resident data makes it critical for multifamily property owners and managers to incorporate big data privacy — real estate's newest compliance discipline — into their data practices, and to state those practices plainly in their published policies.

CASE STUDIES

What are the legal risks of collecting tenant data?

The consequences of potential data misuse become starkly evident when looking at real-world legal cases. Three are worth knowing by name. Each is a lesson in big data privacy; real estate was the setting for two of them.

01

Biometric data from smart locks — New York

A property management company was sued by five residents for allegedly using smart lock systems to collect biometric data from tenants without their explicit consent. While not delivering any legal precedent, the case drew significant attention and underscored the legal and reputational risks associated with privacy violations. (10)

02

Data retention failure under GDPR — Germany

In Europe the GDPR requirements have been aggressively enforced, resulting in significant fines for non-compliance. A real estate company in Germany faced a 14.5M euro fine, nearly $16 million USD, under GDPR for insufficient data retention policies. (11) The enforcement action served as a stark reminder of the global nature of data protection laws and the severe repercussions of non-compliance. Note what the fine was for: not a breach, but keeping data longer than the policy allowed.

03

Facial recognition and standing — Patel v. Facebook Inc.

The Ninth Circuit in California ruled that Facebook users could sue the company over its use of facial recognition technology. (12) Facebook settled in 2020 with a $550 million payout to Illinois residents who were subject to the company's violation of the Illinois Biometric Information Privacy Act. While this case didn't directly involve multifamily property management, it highlights the growing scrutiny around collecting personal data and its potential implications for owners and managers in multifamily settings.

The German fine landed on a retention schedule, not a breach. Holding data too long is itself an exposure.
PRACTICE

What are the best practices for multifamily data privacy?

Multifamily owners and managers can navigate these legalities through a few key practices for big data privacy. Real estate operators who adopt them reduce both legal and reputational exposure.

Get informed consent, and say what you mean

First, discuss and implement a plan around informed consent from tenants before collecting and using their data. This requires clear and comprehensive communication about data practices, as stipulated under laws like CCPA and GDPR. Consent buried in a lease addendum that nobody reads satisfies neither the regulator nor the resident.

Keep privacy policies current with how you actually use data

Maintaining updated privacy policies that reflect changes to an owner or operator's use of data can also address the potential for liability. Google updated its privacy policy on July 1, 2023, inserting a key clause that changes how it collects data from its users for the development of its artificial intelligence tools. The updated policy allows use of publicly accessible information in AI creation, which means anything posted online will now become part of the company's AI products. (13) Recent lawsuits by artists and public figures are challenging the use of their work that appears in the public domain to train large language models as copyright infringement. (14) The status of these cases adds to the uncertainty around the monetization of public data.

Anonymize, encrypt, and revisit the data protocol

For added safety, multifamily operators may consider employing techniques such as data anonymization and encryption to safeguard tenant data from the risk of security breaches. At a minimum, owners should stay abreast of technological advancements and continuously update their data handling protocols accordingly. As smart home technologies become increasingly prevalent in multifamily settings, owners must be mindful of the legal considerations related to biometric data in particular. When you evaluate a vendor, the questions to ask are the same ones you would want asked of you — what is collected, where it is stored, who can access it, how long it is retained, and what happens on termination. Those answers belong in writing, which is why we publish our own data security practices rather than describing them on request.

OUTLOOK

Where big data privacy, real estate, and multifamily go next

Looking towards the future, it's clear that big data will continue to be a driving force in multifamily real estate, further underscoring the relevance of related legal concerns. It's therefore crucial for multifamily operators to stay updated with evolving data protection laws, technological advancements, and tenant expectations.

To this end, it's worth noting the proposal of new privacy laws such as those in Oklahoma, New York and Massachusetts, which indicate a trend towards opt-in requirements for companies to sell consumers' data, as well as other significant consumer data protections. (15) Navigating this dynamic landscape will require a commitment to continuous monitoring and adaptation.

Conclusion

Navigating the intersection of big data privacy, real estate law, and multifamily operations is a challenging yet vital task. As multifamily professionals harness big data to fuel their performance and enhance operations, they must ensure strict legal compliance to protect tenant rights and their own business interests. This delicate balance, while complex to achieve, is the linchpin of secure, compliant, and sustainable communities.

References

  • (1) Marr, B. (2015, January 30). Big Data: Using SMART Big Data, Analytics, and Metrics To Make Better Decisions and Improve Performance.
  • (2) What Is Big Data? (2023). Oracle.com
  • (3) A Primer on U.S. Housing Markets and Housing Policy., Green, Richard K., Malpezzi, Stephen. 2003. Washington, DC: Urban Institute Press. (2007, April 16). Science Direct.
  • (4) Which States Have Consumer Data Privacy Laws? (2023, May 3). Bloomberg Law.
  • (5) personally identifiable information — Glossary. CSRC.nist.gov.
  • (6) Sabin, S. (2023, January 3). Consumers, companies start to navigate new state privacy laws going into effect in 2023. Axios.
  • (7) California Consumer Privacy Act (CCPA). (2018, October 15). State of California — Department of Justice — Office of the Attorney General.
  • (8) Utah: UCPA — FAQs. (2022, December 7). DataGuidance. Utah requires $25 million in revenue and: (1) controls or processes personal data of 100,000 or more consumers; or (2) derives over 50% of the entity's gross revenue from the sale of personal data and controls or processes personal data of 25,000 or more consumers. Colorado Privacy Act (CPA). (2021). coag.gov. Colorado law applies as well to for-profit and non-profits who process the personal data of more than 100,000 individuals in any calendar year; or derive revenue or receive discounts on goods or services in exchange for the sale of personal data of 25,000 or more individuals. Code of Virginia. (2023). Virginia Law. Virginia applies to entities who control the personal data of at least 100,000 consumers in a calendar year or at least 25,000 consumers, while deriving over 50 percent of gross revenue from the sale of that data. The Connecticut Data Privacy Act. (2022). CT.gov. Connecticut applies to companies who control or process the personal data of at least (1) 100,000 Connecticut consumers (excluding data processed solely for processing payment transactions); or (2) 25,000 Connecticut consumers and derive over 25% of their gross revenue from the sale of personal data.
  • (9) Virginia Consumer Data Protection Act (VCDPA). Bloomberg Law.
  • (10) Hell's Kitchen Landlord Sued For Keyless Entry System Agrees To Provide Keys. (2019, May 9). Gothamist.
  • (11) Ritzer, & Filkina. (2019, November 12). First multi-million GDPR fine in Germany: €14.5 million for not having a proper data retention schedule in place. Data Protection Report.
  • (12) Patel v. Facebook, Inc., 932 F.3d 1264. (2019, August 8). Casetext.
  • (13) DiBenedetto. (2023, July 4). Google could use public data for AI training, according to new policy. Mashable.
  • (14) Small. (2023, July 10). Sarah Silverman Sues OpenAI and Meta Over Copyright Infringement. The NY Times.
  • (15) Sanderson. (2021, May 25). Privacy Trends: Four State Bills to Watch that Diverge from California and Washington Models. Future of Privacy Forum.
FAQ

Frequently asked questions

01
What privacy rules apply to resident data?

In the United States, consumer privacy rules have been set primarily by state legislatures, including the CCPA in California, the VCDPA in Virginia, and Colorado's Privacy Act, with more states following. Operators with European exposure also face GDPR. Each law sets its own applicability thresholds and effective date, so the first question is always whether a given statute reaches your entity at all.

02
What are the legal risks of collecting tenant data?

Violations of state statutes can carry stiff financial penalties, and GDPR enforcement in Europe has produced significant fines, including one against a German real estate company for insufficient data retention policies. So far no U.S. state has permitted consumers to sue businesses directly for violations outside of data breaches, but litigation over biometric collection and facial recognition shows where scrutiny is heading. Reputational risk alone is reason enough to build compliance into data practices.

03
What are best practices for multifamily data privacy?

Obtain informed consent before collecting and using resident data, and communicate data practices clearly as CCPA and GDPR require. Keep privacy policies current with how data is actually used, since policy language is what regulators and residents will be reading. Anonymization and encryption reduce breach exposure, and data handling protocols should be revisited as smart home and biometric technologies spread through the portfolio.

Know what resident data you hold, and where it lives.

Privacy compliance starts with an accurate inventory of property data across every system — the same standardized foundation that makes portfolio reporting possible.

See plans and pricing