REA’s Gen AI guidance is unusually direct on this point: when you paste data into a Gen AI tool, the provider may see both the input and the output.
That is not a theoretical risk for real estate. It is how vendors’ personal information, buyer details, and confidential negotiation notes leak into systems you do not control — often with a cheerful UI that feels like “just rewriting a letter” or “just summarising the LIM before the open home.”
New Zealand listing offices live on documents: LIMs, builder reports, titles, tenancy schedules, body corporate packs, draft agreements. Gen AI is brilliant at making those documents feel lighter. It is also brilliant at moving confidential content into someone else’s infrastructure without anyone pausing to ask whether that is disclosure.
This piece is for NZ agencies and licensees who want Gen AI speed without creating a Privacy Act or Code of Conduct problem. It is not legal advice. Run edge cases past counsel and your privacy officer.
Hard rule for the office
If you would not email it to a stranger, do not paste it into a consumer Gen AI chat.
The legal stack, without the waffle
Privacy Act 2020 — personal information has rules. The Office of the Privacy Commissioner has published AI guidance against the Information Privacy Principles and a specific page on generative AI.
Code of Conduct rule 9.17 — a licensee must not disclose confidential personal information relating to a client unless an exception applies (written consent, required by law, defending a claim, or consistent with the information privacy principles). Rule 9.16 also bars using confidential client information for someone else’s benefit — or your own. Rule 9.18 limits any permitted disclosure to the appropriate person and only to the extent necessary.
REA Gen AI guidance — government guidance recommends against inputting personal and client information into external AI tools; agencies should think about disclosure, consent and cybersecurity (including CERT NZ material).
Accuracy duties still apply — even a “private” tool that summarises a LIM badly can create rule 5.1 / 6.4 / 10.7 problems if that summary reaches a buyer.
REA’s guidance also flags that agencies and supervisors may be held to account for breaches by staff under their supervision. A salesperson’s “I just used ChatGPT on the LIM” is still an agency systems failure if nobody ever told them not to.
OPC expectations are practical: understand the tool well enough to uphold the IPPs; do a privacy impact assessment before you start; be transparent; ensure human review before acting on outputs; and do not input personal or confidential information unless retention and disclosure by the provider are explicitly controlled.
PropertyLM take
Privacy and accuracy travel together. The same habit that stops you pasting the vendor into a chatbot — human review of sources — is the habit that stops invented LIM risks leaving the office.
Why LIMs are a special trap
A Land Information Memorandum is dense, property-specific, and often full of material issues that need careful disclosure judgement. REA CPD material has long stressed that if you hold a LIM, you are expected to have read it and to highlight material information — not merely forward the PDF and hope. Passing the document along is not the same as understanding it.
Gen AI makes a tempting shortcut: “summarise this 40-page LIM.” Two things go wrong at once:
Privacy / confidentiality: the PDF usually contains identifying detail and may include personal information. Pasting it into a consumer tool can amount to disclosing confidential client information to a third party you do not control.
Accuracy: models drop caveats, invent confidence, or miss the one sentence that matters for flooding, consent, or building work. REA specifically calls out LIM and builder-report summaries as high-risk Gen AI use cases because fluent incompleteness is dangerous.
So the office rule is not “never use AI near due diligence.” It is “never use a consumer chat as the pipe for the raw file — and never trust the summary without the source.”
There is a third, quieter failure mode: re-identification. Even if you strip a name, a street address plus a unique renovation story in a small New Zealand suburb can identify a client as cleanly as a phone number. “Anonymous” is not a magic word.
What not to paste
Full LIM, builder, engineer, or valuation PDFs with identifying detail
Vendor or purchaser names, phone numbers, emails, addresses tied to personal circumstances
Trust account, deposit, or settlement banking details
Unsigned or signed agency agreements and private negotiation notes
Staff HR or recruitment files “just to rewrite a letter”
Body corporate packs, tenancy ledgers, or ID documents
Unpublished appraisal workings and pricing strategy that the vendor has not authorised you to broadcast
Safer patterns that still save time
Strip identifiers first — rewrite prompts around property attributes and public market facts, not people.
Use tools designed for NZ property data — where underlying sales and title sources are known, logged, and not trained promiscuously on your clients’ uploaded PDFs.
Keep a human reviewer — REA expects this for accuracy; privacy benefits travel with the same habit.
Put it in the agency policy — “no client data in consumer Gen AI” is one sentence that prevents most of the damage.
Prefer enterprise tenancies with clear data terms when your agency does approve a general-purpose model — and still ban sensitive uploads until counsel has read the retention settings.
For LIM work: read the source; use AI only for drafting notes you already verified; never let the model become the disclosure.
Train the team on examples — show a bad paste and a good prompt side by side in induction. Abstract rules lose to concrete demos.
Compliance callout
OPC expectation in one line: do not input personal or confidential information into a generative AI tool unless it is explicitly confirmed that inputted information is not retained or disclosed by the provider.
What to do if it already happened
If client data may have gone into an unapproved tool:
Stop the workflow.
Notify your privacy / compliance lead the same day.
Preserve prompts and outputs for the incident file.
Follow Privacy Act notification and client-care steps as advised — do not freestyle a half-apology on email.
Fix the system cause: approved tools, banned inputs, and a refresher that names the exact failure.
PropertyLM’s Newton and Atlas workflows are built around live NZ property sources and human sign-off — not dumping a vendor file into a public chat model and hoping for the best. Speed is fine. Uncontrolled disclosure is not.
A worked example: bad paste vs good prompt
Bad: uploading the full council LIM PDF into a consumer chatbot with “summarise risks for buyers.” You have likely moved confidential client material into an external system, and you may receive a fluent summary that misses the one drainage note that matters.
Better: you read the LIM, note three verified issues in your own words without personal identifiers, and ask an approved tool to help you draft clearer plain-English talking points for the vendor meeting — then you check the draft against the source before anyone else sees it.
Best: your agency policy already bans the upload; your induction already showed this example; your file already shows you read the LIM and disclosed material issues with vendor approval where required.
REA CPD themes around LIMs have been consistent for years: holding the document creates expectations that you have engaged with it. Gen AI does not reduce that expectation. It increases the temptation to fake engagement.
Office script
“We don’t paste client documents into consumer AI. If you need drafting help, strip identifiers, use an approved tool, and check the source.” That script should be boring — and universal.
Where this sits beside marketing use cases
Not every Gen AI use is a LIM paste. Rewriting a public listing description from your own notes is a different risk class from uploading a builder’s report. Policies should distinguish drafting aids from document ingestion. If your one-pager only says “be careful with AI,” people will improvise. If it names banned uploads, people can follow it on a busy Friday.
Supervisors: what to spot-check monthly
Pick five random listing files. Ask: was Gen AI used? Which tool? Any document uploads? Who checked the output? Does the LIM disclosure trail show a human actually read the source? You are not hunting for gotchas — you are proving the policy is real. REA’s guidance puts supervisors in the frame; monthly spot-checks are how that becomes operational rather than aspirational.
If you find consumer-chat uploads of client PDFs, treat it as an incident pathway issue, not only a “training reminder.” Fix access, retrain, and document the correction.
Bottom line for busy licensees
Read the primary sources. Write the policy. Train the team. Label estimates honestly. Check every client-facing draft. Keep confidential files out of consumer prompts. Own the appraisal under rule 10.2. Tools can accelerate good practice; they cannot invent it after the fact when a complaint lands.
PropertyLM’s product bias is deliberate: evidence you can open, workflows that assume human sign-off, and language that stays accurate about what is an estimate, what is an appraisal, and what is still your professional call.
— PropertyLM.
