Latest Posts

Stay in Touch With Us

Got a story worth telling? Send it our way. We read every tip that lands in our inbox.

Livebriefs

  /  All News   /  The RealPage Fallout Is Changing How Landlords Think About Data

The RealPage Fallout Is Changing How Landlords Think About Data

In August 2024, the Department of Justice filed a civil antitrust lawsuit against RealPage, alleging that the company’s revenue management software enabled landlords to collude on apartment pricing in violation of the Sherman Act. RealPage built the algorithm, sold it to property management companies as a tool for setting optimal rents, and operated largely behind the scenes while landlords across the country licensed it to run their pricing. When the legal reckoning came, the bill landed almost entirely on the landlords. Several settled quickly to avoid joint liability, with Greystar, the nation’s largest apartment operator, paying $50 million in a private class action and an additional $7 million in state-level claims. Across multiple rounds of class-action settlements, the total payout from landlords using RealPage’s software has climbed to nearly $360 million, even as RealPage itself paid no fines and admitted no wrongdoing in its own settlement with the DOJ. The operators, not the software company, absorbed the financial consequences of a tool they licensed rather than built, and that asymmetry has become impossible for the rest of the industry to ignore.

That outcome has changed the conversation real estate companies are having internally before they sign a vendor contract, not just after a problem surfaces. “People are asking the right questions,” said Ben Meth, Head of Sales at WithMe. “Operators are asking about whether the value of the data outweighs the risk.” That calculation, weighing the operational benefit of a piece of software against the legal and reputational exposure it could create, was rarely made explicit in vendor selection processes a few years ago. It is becoming standard practice now, particularly for software that touches pricing, resident data, or any information that could be construed as competitively sensitive if shared or aggregated across multiple landlords.

The regulatory backdrop makes that calculation more complicated, because there isn’t a single national standard to comply with. Data privacy law in the United States is a patchwork of state-level statutes, each with its own definitions, thresholds, and enforcement mechanisms, and operators with properties across multiple states have to account for all of them simultaneously. The practical response among sophisticated operators and vendors has been to comply with the most stringent requirement in the network rather than try to track which rules apply where. “Vendors should be prepared to provide documents for transparent data handling,” Meth said. “The California Consumer Privacy Act is one of the strictest policies, so it’s usually best practice to comply with that.” California’s regulations were updated in September 2025 to add new requirements around cybersecurity audits, risk assessments, and automated decision-making technology, with those updates taking effect in January 2026, which means the bar that vendors are being asked to clear keeps moving upward. Building a compliance program around the most demanding jurisdiction rather than the median one gives operators a defensible position regardless of where a specific property happens to sit.

That posture is changing the substance of the conversation between operators and vendors at the point of sale. Where past due diligence conversations might have focused on functionality, integration, and price, the current generation of vendor evaluations increasingly centers on data architecture itself. What data does the platform collect. Where does it go. Who else can see it. What happens to it if the vendor is acquired or the contract ends. “Vendors will need to be really efficient when it comes to explaining how data flows and what the safeguards are,” Meth said. Vendors who can answer those questions clearly, with documentation rather than reassurance, are increasingly differentiating themselves from competitors who treat the question as an inconvenience.

For property management teams on the ground, the most effective risk management strategy is often the simplest one: limiting exposure by limiting contact. The RealPage situation made clear that legal liability can attach to an organization regardless of whether its own staff did anything wrong, simply because the organization used a tool that handled sensitive data in a problematic way. That has pushed many operators toward a model where sensitive data is handled by specialized, trusted third parties rather than passing through the hands of on-site staff who have neither the training nor the operational bandwidth to manage it carefully. “Low touch and minimal effort is better,” Meth said. “The less a property manager has to touch sensitive data, the better.” That principle is reshaping how operators think about which functions to keep in-house and which to delegate to vendors whose entire business model is built around handling that category of information responsibly.

Even with that delegation, no amount of vendor due diligence eliminates the need for staff training, because people are still the ones interacting with these systems every day and making the judgment calls that data protection ultimately depends on. The most resilient compliance programs combine well-architected technology with people who understand what they’re working with and why certain protocols exist. Automation is reducing how much of that training is necessary, but it hasn’t eliminated the need for it. “For some solutions, you will always need training,” Meth said. “Hopefully we can reduce the amount of training needed. The goal is to automate as much as possible.” That balance, between building systems that need less human judgment and accepting that some human judgment will always be required, is where a lot of the current investment in property management technology is concentrated.

What the RealPage experience has fundamentally changed is the default assumption real estate companies bring to their vendor relationships. The settlement’s three-year court-appointed monitor and the ongoing DOJ cases against individual landlords make clear that the legal scrutiny over algorithmic and data-driven real estate software is not concluding with the RealPage settlement. It is the early phase of a longer period of regulatory attention that operators will need to navigate carefully. Real estate companies have learned, at considerable financial cost, that it is not enough to trust that a vendor’s technology is compliant and move on. The liability follows the data wherever it goes, and increasingly, so does the obligation to ask hard questions about where that is.

The post The RealPage Fallout Is Changing How Landlords Think About Data appeared first on Propmodo.

​  

You don't have permission to register