Business Daily reported last week that landlords and letting agents, particularly in Nairobi's higher-value rental market, are increasingly seeking employment letters, payslips, KRA PIN details, salary information and other financial records from prospective tenants.

Landlords have a legitimate interest in determining whether somebody taking on a substantial lease is likely to meet the financial obligations involved. The privacy issue is therefore not whether affordability checks should exist, but how much personal information is actually necessary to establish affordability.

Kenya's Data Protection Act provides the correct starting point. Personal data should be collected for a specific and legitimate purpose, be relevant to that purpose and be limited to what is necessary. The Data Protection Regulations reinforce that principle by requiring organisations to consider whether a purpose can be achieved without processing unnecessary personal information and to avoid creating needless copies or collection points.

Applied to renting, this creates an important distinction between proving an attribute and surrendering the document from which the attribute is derived. If the purpose is to establish that a prospective tenant has sufficient and reasonably stable income to afford a particular rent, a landlord may need credible evidence of that fact.

A complete payslip can reveal much more, including employee numbers, tax information, deductions, benefits, pension details, loan obligations and other financial information that may contribute little to the tenancy decision.

The same concern applies to tax and banking records. A document may contain information relevant to one question together with several other identifiers and financial details that the recipient does not actually need. Requesting the whole document because it is convenient can therefore turn a legitimate verification process into unnecessary data accumulation.

That matters because every additional document creates another security obligation. A property agent receiving hundreds of national identity documents, employment letters, payslips, tax records and bank statements is not merely building a tenancy file.

The agent is creating an identity repository containing information that could become valuable to fraudsters if an email account, laptop, cloud folder, WhatsApp account or property-management system is compromised.

NIST's current digital-identity guidance makes this connection explicit. It argues that data minimisation reduces the amount of personal information exposed to unauthorised access or use and recommends collecting only what is needed for identity proofing and authorisation decisions. It even points to yes-or-no attribute validation as one way of confirming a fact without transmitting the underlying identifier unnecessarily.

That principle is directly relevant to housing. A landlord may need to know that an applicant satisfies an affordability threshold. The landlord does not necessarily need to know every financial fact appearing on the document used to establish it. The challenge is therefore to design screening around the decision being made rather than around whichever documents have traditionally been easiest to request.

Kenya's property sector also needs to think carefully about retention. Information that was reasonably necessary during an application does not automatically remain necessary indefinitely. An unsuccessful applicant may never become a tenant, yet copies of identification, payslips and financial documents can remain in email threads, messaging applications or cloud folders long after the decision has been made.

The Office of the Data Protection Commissioner has already made clear that organisations handling personal information must understand what they collect, why they collect it, where it is stored, who receives it, how long it is retained and how it is eventually disposed of. Property management has also been among sectors receiving greater compliance attention.

That should lead to more disciplined practices in rental screening. Applicants should know what information is being requested and why. Agents should define who may access it, how long it will remain on file and what happens when an application is unsuccessful. Sensitive financial documents should not simply accumulate in personal email and messaging accounts without clear access controls and deletion procedures.

The longer-term opportunity is more interesting than simply securing today's paperwork more carefully. Digital identity is moving towards selective disclosure, where a person can prove a required fact without revealing every detail contained in the underlying credential. The World Wide Web Consortium's Verifiable Credentials architecture is designed around this possibility, allowing holders to disclose selected attributes or prove derived facts rather than handing over an entire credential.

The principle can be understood easily through age verification. A person entering an age-restricted service may need to prove that they are over 18. They do not necessarily need to reveal their full date of birth, home address and identification number merely because all those details happen to appear on the same document.

Affordability verification could eventually work similarly. A trusted institution or authorised verification service could attest that an applicant's income has been verified and meets a defined rental-affordability threshold. The landlord would receive a reliable answer to the question relevant to the lease while the applicant's exact salary, deductions and unrelated financial information remain undisclosed.

This is not speculative privacy theory. Privacy-preserving attribute credentials, selective-disclosure mechanisms and zero-knowledge proofs are active areas of standards development and academic research. The European Digital Identity Wallet is also being designed around selective disclosure so that users can share only the attributes necessary for particular transactions rather than presenting complete identity documents.

Kenya should not rush into a technological solution without governance, however. A digital affordability credential could create new problems if it becomes an opaque scoring system that automatically excludes people whose income does not fit conventional employment patterns. Entrepreneurs, freelancers, informal-sector workers and households where several people contribute to rent may not have a conventional payslip even when they can comfortably meet the lease.

The objective should therefore be verification without unnecessary disclosure, not automation without judgment.

Applicants should also have a way to correct inaccurate information and understand the basis of significant adverse decisions. A privacy-preserving system that produces unfair or unchallengeable outcomes would solve one governance problem while creating another.

Comparative experience reinforces the need for care. Privacy regulators in jurisdictions including Canada and New Zealand already provide specific guidance for landlords and property managers because tenancy applications can involve large quantities of personal and financial information. Current research on digital rental platforms likewise warns that increasing data collection can create privacy, discrimination and security risks for renters.

Kenya should learn from that before tenant screening becomes another area where excessive data collection is normalised simply because digital tools make collection easy.

Landlords do not need to abandon financial due diligence. A person entering a high-value lease can reasonably be expected to establish identity and demonstrate an ability to meet the contractual obligation. But proportionality should govern how that assurance is obtained.

The relevant question is not how much information a landlord can collect. It is how little information is sufficient to make the decision responsibly. Kenya's rental market should therefore move towards a simple privacy principle: verify the fact required for the tenancy and collect no more than that decision genuinely needs. That approach protects landlords' legitimate financial interests while reducing the amount of sensitive information tenants must surrender simply to obtain a home.

Proof that someone can pay the rent should not require them to hand over their entire financial life.

ICT, cybersecurity and digital governance professional