Last month the Human Rights Review Tribunal handed down a decision that should change how every real estate agent, property manager, and landlord in New Zealand thinks about what they post online. It cost one Facebook group administrator $7,500 — not for what he posted, but for what he refused to hand over.
The case is Sheehan v Wilson [2026] NZHRRT 10, and it is, by the Tribunal’s own account, the first time a New Zealand tribunal or court has had to determine the liability of a social media group in proceedings under the Privacy Act. I think it’s one of the most quietly consequential compliance decisions of the year for the property sector. Here’s why.
The facts
A closed Facebook group — “Bad Tenants, New Zealand (Landlords Only)” — operated as an informal blacklist. Landlords shared information about tenants that named them, identified their locations, and revealed other details about them. Media reports put the membership at around 3,100; tellingly, the administrator, Wayne Wilson, was the only member the plaintiff was ever able to identify.
In January 2021, a former tenant named Adam Sheehan read about groups like this in the news. He had experienced something familiar to many renters: properties he thought he’d secured suddenly becoming unavailable, with no explanation, followed by periods of insecure accommodation and homelessness. He suspected his name was on a list. So he did exactly what the Privacy Act entitles him to do — he sent an IPP 6 access request to Wilson, as administrator, asking whether the group held information about him and whether it had been made available to members.
Approximately two hours later, he was blocked from the group’s page.
What followed was a five-year procedural saga: a complaint to the Privacy Commissioner, an access direction that went unanswered, a first Tribunal proceeding in 2022 that failed on a technicality (more on that below), a rebrand of the group to the almost comically euphemistic “Landlord Property Mangers [sic] Seeking Tenants Advice”, and finally this year’s decision. Wilson never filed a statement of reply, never engaged with the Tribunal at any stage, and never attended a hearing. The Tribunal proceeded without him.
What the Tribunal actually decided
Three holdings matter here, and each one extends the compliance perimeter further than most people in the industry assume it reaches.
First: a Facebook group can be an “agency” under the Privacy Act 2020. The reasoning is worth getting precise, because it’s broader than the headlines suggest. Under ss 7 and 8 of the Act, a “New Zealand private sector agency” includes an unincorporated body with its central management and control in New Zealand. Bad Tenants qualified on that basis alone: its administrator was NZ-based and its membership comprised exclusively New Zealand landlords. No incorporation, no legal personality, no commercial registration required.
The Tribunal then asked whether the s 27 “domestic affairs” exception could rescue the group — the carve-out that keeps the Privacy Act out of your family group chat. It failed on two independent grounds. Section 27 only applies to individuals, not to bodies of persons, incorporated or otherwise — so a group can never claim it. And in any event, the group’s activities weren’t personal or domestic: they were connected with the tenancy-related business interests of its landlord members and involved the widespread collection and online dissemination of tenants’ personal information. The Tribunal reinforced the point with EU jurisprudence, citing the European Court of Justice’s Wirtschaftsakademie decision, which held Facebook page administrators liable as data controllers under the GDPR framework — using Facebook’s platform doesn’t exempt you from data protection obligations.
Second: an administrator can be made personally answerable as a representative defendant — and members of an unincorporated group are jointly and severally liable. This is the fix for the problem that sank the 2022 proceeding. Back then, the Tribunal declined to enforce the Commissioner’s access direction because Bad Tenants was not a legally recognisable entity — a group of individuals with nobody specific to order around. Sheehan responded by applying to have Wilson appointed as representative defendant on behalf of the group, which the Tribunal granted in a 2024 interlocutory decision. The consequence spelled out in this judgment should focus minds: where an unincorporated body is found liable, liability rests jointly and severally with its members. If you run the group — or are simply in it — you can be the name on the order, and on the damages award.
Third — and this is the part I want every agent to sit with: the breach wasn’t the blacklist. It was the silence. Wilson wasn’t ordered to pay $7,500 for publishing tenant information. He was ordered to pay because the group failed to respond to an access request within the statutory timeframe. Under s 44(1), an agency must respond to an information privacy request as soon as reasonably practicable, and no later than 20 working days. Under s 69(4)(a), failing to respond in time is deemed a refusal — and under s 69(3)(a), a refusal without proper basis is, by itself, an interference with privacy. No need to prove the underlying information was false, or even that it existed. As the Tribunal put it, no response was made at all. It awarded $7,500 in damages for humiliation, loss of dignity and injury to feelings, and ordered Wilson to answer the original request — five years on — within 20 working days.
Ignoring the problem was the problem.
Two remedial details are worth noting for completeness. The Tribunal declined to award damages for loss of a benefit, because it was speculative whether the group ever actually held Sheehan’s information — a reminder that the deemed-refusal breach stands entirely independently of what the agency holds. And it declined to order an apology, partly because the group no longer exists in its original form. Neither softens the core finding.
Why this matters beyond blacklist groups
It’s tempting to read this as a story about one rogue landlord group. I think that’s the wrong frame. The Director of Human Rights Proceedings, who intervened in the proceedings, put it plainly in his public comments: sharing personal information about other people in a Facebook group is no different from sharing it over email.
Now think about how the property industry actually communicates. Agents and property managers operate across an enormous informal surface — Facebook groups, WeChat groups, WhatsApp threads, comment sections, community pages. Tenant names come up. Vendor circumstances come up. Buyer details come up. The prevailing assumption has been that these spaces are somewhere between private conversation and professional conduct — a grey zone where the usual rules apply loosely, if at all.
Sheehan v Wilson says there is no grey zone. If the group is an unincorporated body run from New Zealand and connected to business interests, it’s an agency. What’s posted there — including by members — is personal information held by that agency; the Privacy Commissioner said as much in the access direction itself. And any individual mentioned in it has a statutory right to ask what is held — a right that comes with a 20-working-day clock, and with personal liability attached for whoever is in a position to answer and doesn’t.
For licensed agents, the exposure compounds. A privacy breach doesn’t stay a privacy breach; conduct in an informal channel can feed straight into a Real Estate Agents Act complaint about professional standards. The regulatory frameworks don’t care which app you were using.
The Resaido connection
Readers of this newsletter know the thesis I keep coming back to: an agent’s public statements — across every channel, over time — are a compliance surface. Not just the listing copy and the formal disclosures, but the Facebook comment, the group post, the throwaway line that contradicts what was said somewhere else.
I’ve been building Resaido on that thesis. The core idea is that compliance risk in real estate doesn’t live in any single statement — it lives in the accumulation and the contradictions, scattered across channels nobody is systematically watching. Regulators are catching up to this reality one decision at a time. Sheehan v Wilson is the Privacy Act catching up.
What this case adds to the picture is the access-request dimension. It’s no longer only regulators and complainants scrutinising what agents say online — it’s now clearly established that any individual mentioned in a business-connected online space can demand to see that information, and that stonewalling the request is itself an actionable breach with damages attached. The informal channels just became discoverable, in every sense.
If you’re an agency principal or a property manager, the practical takeaways are unglamorous but urgent: know which online spaces your business touches, treat anything posted there about identifiable people as information you hold, and have an actual process for responding to access requests within the statutory timeframe. The most expensive thing Wilson did was nothing.
Five years and $7,871.75 later, the law is unambiguous. The industry’s habits haven’t caught up yet. That gap is exactly where the next wave of complaints will come from — and exactly what I’m building for.
I write Field Notes on NZ real estate compliance and Build Log on what I’m making. If this was useful, subscribe — and if you’re thinking about what your agency’s online footprint looks like to a regulator, that’s what Resaido is for.
