Skip to content

The 13 Australian Privacy Principles: what each one means for a real-estate agency

The 13 Australian Privacy Principles (APPs) are set out in Schedule 1 of the Privacy Act 1988 (Cth). They bind "APP entities", which for a real-estate business means an agency that is an organisation covered by the Act, and they run in the order information moves through a business: be open about how you handle it (APP 1 and APP 2), collect it properly and say so (APP 3 to APP 5), use, disclose and market with it only on a proper basis (APP 6 to APP 9), keep it accurate and secure (APP 10 and APP 11), and let people see and fix it (APP 12 and APP 13). The one thing to take from them: the APPs attach to the personal information itself, so a rental application, an open-home sign-in sheet and a CRM record carry the same duties.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price

Orientation only, not a compliance assessment. General information and tools, not legal advice.

APP 1: Open and transparent management of personal information

APP 1 is the governance principle, and it applies at all times rather than at a moment of collection. It has two working parts. You must take "reasonable steps" to implement the practices, procedures and systems that make you comply with the APPs and let you deal with privacy enquiries and complaints (APP 1.2). You must also have a "clearly expressed and up to date" privacy policy covering the matters APP 1.4 lists, make it available free of charge (APP 1.5), and give it in the form asked for where that is reasonable (APP 1.6).

In an agency, the failure is rarely a missing policy. It is a policy that does not match the office: it says nothing about the tenancy-database or referencing service the rent roll actually uses, nothing about the inspection app, and nothing about the offshore provider behind the CRM. APP 1 is also where one named person becomes accountable for privacy, which is what makes the rest of the list survive staff turnover.

From 10 December 2026, APP 1.7 adds a further requirement: privacy policies must disclose qualifying automated decision-making, where a computer program uses personal information to make, or substantially and directly support, a decision that could reasonably be expected to significantly affect a person's rights or interests. Automated tenancy screening or application scoring is where that most plausibly bites in real estate. It is not in force yet.

Sources: Privacy Act 1988 (Cth), APP 1.2 to 1.6, and APP 1.7 from 10 December 2026 (Schedule 1); Privacy and Other Legislation Amendment Act 2024 (Cth) · OAIC APP Guidelines chapter 1 · OAIC APP 1 · Ours: do agents need a privacy policy and a collection notice · privacy policy vs collection notice · what a privacy policy must cover · the 10 December 2026 automated-decision rule

APP 2: Anonymity and pseudonymity

APP 2 gives individuals the option of not identifying themselves, or of using a pseudonym, when dealing with you about a particular matter. It is an option, not an absolute right, and it switches off where an Australian law or a court or tribunal order requires you to deal with identified individuals, or where it is impracticable to deal with someone who has not identified themselves.

The clean anonymous case in an agency is the casual enquiry: what is the rent, is it still available, when is the next inspection, what are the levies. None of that needs a name. The common failure is not a refusal but a form, where price or availability sits behind mandatory name, email and phone fields. An option removed by design is still removed.

The exceptions do real work on the other side. You cannot assess an application, hold a bond, manage a tenancy or serve a notice anonymously, so impracticability plainly applies there. And on the sales side, AML/CTF customer due diligence from 1 July 2026 is a law requiring you to identify the customer. Note that impracticable is a higher bar than inconvenient, and it is judged against the particular matter rather than your whole business.

Sources: Privacy Act 1988 (Cth), APP 2.1 and APP 2.2 (Schedule 1) · OAIC APP Guidelines chapter 2 · OAIC APP 2 · Ours: dealing anonymously or under a pseudonym

APP 3: Collection of solicited personal information

APP 3 limits what you may ask for in the first place. Collect personal information only where it is "reasonably necessary" for one or more of your functions or activities (APP 3.2), collect it by "lawful and fair means" (APP 3.5), and collect it from the individual rather than around them unless that is unreasonable or impracticable (APP 3.6). Sensitive information, which includes health, biometric and criminal-record information, needs consent as well as reasonable necessity, subject to limited exceptions (APP 3.3 and APP 3.4).

This is the principle with the sharpest real-estate edge, because the tenancy application is where over-collection happens. Fields that help you build a picture of an applicant rather than assess the application are the risk: dependants, relationship status, visa expiry, bankruptcy or retirement status, gender. In IRE Pty Ltd (Privacy) [2026] AICmr 24 the Commissioner found breaches of APP 3.2 and APP 3.5 by a rental-application platform over exactly that kind of field set.

Two practical points. Face matching or a fingerprint at a sign-in is biometric, so it is sensitive information and consent is required. And a platform default is still your collection: "the software came like that" answers nothing.

Sources: Privacy Act 1988 (Cth), APP 3.2, 3.3, 3.4, 3.5 and 3.6 (Schedule 1); IRE Pty Ltd (Privacy) [2026] AICmr 24; 7-Eleven Stores Pty Ltd (Privacy) [2021] AICmr 50 (APP 3.3 and APP 5) · OAIC APP Guidelines chapter 3 · OAIC APP 3 · Ours: what you can ask for on a rental application · fixing an over-collecting application form

APP 4: Dealing with unsolicited personal information

APP 4 covers information that arrives without you asking for it. Within a reasonable period you must decide whether you could lawfully have collected it under APP 3 (APP 4.1). If you could not have, and it is not a Commonwealth record, you must destroy it or de-identify it as soon as practicable, but only where doing so is "lawful and reasonable" (APP 4.3). If you keep it because you could have collected it, it is held under the ordinary rules from then on (APP 4.4).

Agencies receive unsolicited personal information constantly. An applicant attaches a medical letter, a full bank statement or a family member's payslip that nobody requested. A landlord forwards a whole file about a former tenant. A seller's enquiry arrives with a divorce order attached. A referee volunteers information about a third person.

The discipline is a decision rather than a default. Ask whether you could have collected it, and if not, delete it and note that you did. The "lawful and reasonable" qualifier matters too: a live dispute or a legal retention duty can properly stop you destroying something.

Sources: Privacy Act 1988 (Cth), APP 4.1, 4.3 and 4.4 (Schedule 1) · OAIC APP Guidelines chapter 4 · OAIC APP 4 · Ours: an applicant sent documents we never asked for

APP 5: Notification of the collection of personal information

APP 5 is the collection notice. When you collect personal information you must take "reasonable steps" either to notify the individual of the matters APP 5.2 lists, or to ensure they are aware of them, at or before the time of collection or, if that is not practicable, as soon as practicable afterwards. The listed matters run from who you are and why you are collecting, through the consequences of not providing the information and who you usually disclose it to, to how a person accesses, corrects or complains, and whether disclosure to overseas recipients is likely.

An agency does not have one collection point, it has several, and each needs a notice fitted to it: the rental application, the open-home sign-in, the front counter, the website enquiry form, the appraisal request, and AML onboarding on the sales side from 1 July 2026. The notice is not the privacy policy. The policy describes your handling generally; the notice tells this person, at this moment, about this collection.

The pitfall is a notice that names no recipients. If applications go to a referencing service, a tenancy-database operator or the landlord, APP 5.2 expects that to be said.

Sources: Privacy Act 1988 (Cth), APP 5.1 and APP 5.2 (Schedule 1) · OAIC APP Guidelines chapter 5 · OAIC APP 5 · Ours: what APP 5 actually requires · tenancy application notice · open-home sign-in notice · website enquiry notice · reception notice · AML onboarding notice

APP 6: Use or disclosure of personal information

APP 6 governs what happens to information after you hold it. You may use or disclose it for the primary purpose you collected it for. Anything else is a secondary purpose and needs a basis: consent (APP 6.1(a)), or that the person would reasonably expect it and it is related to the primary purpose, and directly related for sensitive information (APP 6.2(a)), or that it is "required or authorised by or under an Australian law" or a court or tribunal order (APP 6.2(b)), or a permitted general situation under s 16A (APP 6.2(c)), or an enforcement-related disclosure (APP 6.2(e)), where APP 6.5 requires you to make a written note.

For an agency the everyday questions are: can the file go to the landlord, the insurer, the debt collector, the tribunal, the solicitor, the tradesperson, the new managing agent. The s 16A situation that usually answers those is item 4, where use or disclosure is reasonably necessary to establish, exercise or defend a legal or equitable claim.

One trap worth knowing. Marketing is not an APP 6 question for an agency, because APP 6.7 says APP 6 does not apply to use or disclosure by an organisation for direct marketing. That goes to APP 7. Listing a tenant on a tenancy database is also constrained by State or Territory residential tenancy legislation, separately from the APPs.

Sources: Privacy Act 1988 (Cth), APP 6.1, 6.2, 6.5 and 6.7 (Schedule 1) and s 16A · OAIC APP Guidelines chapter 6 · OAIC APP 6 · Ours: who you can share tenant and client information with · when consent is actually needed · marketing to tenants from lease data

APP 7: Direct marketing

APP 7 starts from a prohibition on using or disclosing personal information for direct marketing, then allows it in defined circumstances, and where it applies you must always offer a simple means of opting out and honour it. A person can also ask you where you got their details (APP 7.6).

The part that trips people up is APP 7.8: APP 7 does not apply "to the extent that" the Spam Act 2003 (Cth), the Do Not Call Register Act 2006 (Cth) or other prescribed legislation applies. So APP 7 is displaced rather than stacked for those channels. For a marketing email or SMS the Spam Act governs the message, including consent, identification of the sender and a working unsubscribe, and a line buried in a collection notice is not Spam Act consent. For marketing calls to owners, the Do Not Call Register rules govern the call. APP 7 continues to govern the data behind the campaign and the general right to opt out of direct marketing.

In an agency this lands on the appraisal SMS to open-home attendees, the newsletter built from an old sign-in book, and cold-calling owners off a list.

Sources: Privacy Act 1988 (Cth), APP 7.6 and APP 7.8 (Schedule 1); Spam Act 2003 (Cth); Do Not Call Register Act 2006 (Cth) · OAIC APP Guidelines chapter 7 · OAIC APP 7 · Ours: email and SMS marketing under APP 7 and the Spam Act · appraisal SMS to open-home leads · cold-calling owners and the DNC Register

APP 8: Cross-border disclosure of personal information

Before you disclose personal information to a recipient outside Australia, APP 8 requires you to take "reasonable steps" to ensure the overseas recipient does not breach the APPs, unless one of the APP 8.2 exceptions applies. Alongside it sits an accountability rule in s 16C of the Act, which can leave you answerable for the overseas recipient's handling as though you had done it yourself. That is the part that changes behaviour: outsourcing the work does not outsource the responsibility.

The border is often crossed without a decision being made. The CRM or inspection app is hosted offshore. The support desk that can see client records is in another country. A virtual assistant handling applications or arrears works overseas. An AI tool used to draft listing copy or summarise applications sends data to servers abroad.

The practical steps are a list of who is offshore and where, a contract that actually binds them to APP-equivalent handling, and disclosure of the likely countries in your privacy policy and collection notices, which APP 1.4 and APP 5.2 already require.

Sources: Privacy Act 1988 (Cth), APP 8.1 and APP 8.2 (Schedule 1) and s 16C · OAIC APP Guidelines chapter 8 · OAIC APP 8 · Ours: offshore CRMs and overseas disclosure · AI tools and overseas disclosure

APP 9 deals with identifiers issued by government. An organisation must not adopt a government related identifier as its own identifier for a person (APP 9.1), and must not use or disclose one except in the narrow circumstances listed (APP 9.2), one of which is where use or disclosure is reasonably necessary to verify the person's identity (APP 9.2(a)). Driver-licence numbers and Medicare numbers are government related identifiers. Consent does not cure an APP 9 problem.

The distinction that matters in an agency is between adopting and using. Keying your applicant spreadsheet, your scanned-ID folder names or your account references to a licence number is adoption, and it is prohibited. Sighting a licence to verify who someone is, and recording that it was sighted, by whom and when, is a use.

So use your own tenancy or client reference as the key, and resist transcribing identifier numbers into fields you will later search on. Tax file numbers are stricter again: they carry their own rules under the TFN Rule and offence provisions in tax legislation, and an agency has almost no reason to hold one.

Sources: Privacy Act 1988 (Cth), APP 9.1, 9.2 and 9.2(a) (Schedule 1); Privacy (Tax File Number) Rule 2015 · OAIC APP Guidelines chapter 9 · OAIC APP guidelines · Ours: government identifiers, licence numbers, Medicare and TFNs · handling the ID documents AUSTRAC makes you collect

APP 10: Quality of personal information

APP 10 has two limbs with deliberately different standards. On collection, take "reasonable steps" to ensure the personal information you collect is accurate, up to date and complete (APP 10.1). On use or disclosure the bar is higher: having regard to the purpose, it must be accurate, up to date, complete and also "relevant" (APP 10.2).

The higher bar is the one an agency should notice, because disclosure is where wrong data does damage. A ledger note that overstates arrears becomes a bad reference. A stale mobile number sends a notice to someone who never receives it. Two CRM records merge and mix up two people with similar names. A rejected applicant's file carries a comment that was never verified. A tenancy-database listing built on data nobody rechecked can follow a person for years.

The workable habit is to confirm before you rely: check identity, income and reference details are current before an approval or refusal decision, and check a record is right at the moment you are about to send it somewhere, not just at the moment you collected it.

Sources: Privacy Act 1988 (Cth), APP 10.1 and APP 10.2 (Schedule 1) · OAIC APP Guidelines chapter 10 · OAIC APP 10 · Ours: keeping tenant and owner records accurate · APP 10.2 does most of its work at the point of disclosure, so see who you can share tenant and client information with and the 2026 obligations map

APP 11: Security of personal information

APP 11 also has two limbs. While you hold personal information, take "reasonable steps" to protect it from "misuse, interference and loss" and from "unauthorised access, modification or disclosure" (APP 11.1). Once you no longer need it for any purpose permitted by the APPs, take reasonable steps to destroy it or de-identify it (APP 11.2), unless it is a Commonwealth record or you are required by or under an Australian law, or a court or tribunal order, to retain it.

What is reasonable scales with the sensitivity of the information and with the size and resources of the business, so a small office is not held to a bank's standard. It is held to a standard it could actually have met. The failures that show up in agencies are ordinary: a shared login, a departed property manager whose CRM access still works, scanned ID sitting in a mailbox indefinitely, printed applications on the counter, no multi-factor authentication on email.

Retention is where you must look beyond the Privacy Act. There is no single national number of years. State and Territory legislation can require particular records to be kept for a set period, and AML/CTF record-keeping runs seven years for agencies providing designated services on the sales side. Check the period that applies where you operate.

Sources: Privacy Act 1988 (Cth), APP 11.1 and APP 11.2 (Schedule 1); AML/CTF Act 2006 (Cth) · OAIC APP Guidelines chapter 11 · OAIC APP 11 · Ours: what security APP 11.1 actually requires · how long to keep personal information · the data-breach response plan

APP 12: Access to personal information

If a person asks for the personal information you hold about them, APP 12 requires you to give it to them, unless one of the grounds for refusal in APP 12.3 applies. Those grounds are specific rather than general: a serious threat to life, health or safety, an unreasonable impact on another person's privacy, a frivolous or vexatious request, information relating to existing or anticipated legal proceedings, prejudice to negotiations, unlawfulness, and commercially sensitive evaluative information, among others. An organisation must respond within a reasonable period (APP 12.4(a)(ii); the hard 30-day deadline at APP 12.4(a)(i) binds Commonwealth agencies), which the OAIC's view is ordinarily no more than 30 days. If you charge, the charge must not be "excessive" (APP 12.8), and if you refuse you must give written reasons and tell the person how to complain (APP 12.9).

In an agency the request usually arrives from a declined applicant asking what was recorded about them, or from a tenant in a dispute wanting their file. Two practical notes. A tenancy file often contains the landlord's personal information as well, and APP 12.3 addresses that rather than authorising a blanket refusal, so the usual answer is to give access to their information and redact another person's. Separately, State and Territory residential tenancy legislation gives its own access routes for tenancy-database listings, which sit alongside APP 12.

Sources: Privacy Act 1988 (Cth), APP 12.1, 12.3, 12.4, 12.8 and 12.9 (Schedule 1) · OAIC APP Guidelines chapter 12 · OAIC APP 12 · Ours: what an agency must hand over · when you can refuse a request · how long you have to answer · whether a landlord can see a tenant's file · the property manager's privacy checklist

APP 13: Correction of personal information

APP 13 requires you to take "reasonable steps" to correct personal information so that it is accurate, up to date, complete, relevant and not misleading. It is triggered by a request, and also by your own awareness that a record is wrong, so it is not purely reactive. If you have already given the wrong information to someone else, the person can ask you to notify that recipient, and you must take reasonable steps to do so unless it is impracticable or unlawful (APP 13.2). If you refuse to correct, you must give written reasons and the complaint mechanisms available (APP 13.3), and the person can ask you to associate a statement with the record noting that they consider it inaccurate (APP 13.4). Respond within a reasonable period (APP 13.5(a)(ii) for an organisation, mirroring APP 12.4).

The correction that matters most in an agency is the one that has already travelled. A payment note that wrongly shows arrears may have gone to the landlord, a referencing service, an incoming agent and a tenancy-database operator. Correcting your own record and stopping there leaves the error live everywhere else, which is exactly what APP 13.2 addresses.

State and Territory residential tenancy legislation also provides its own routes for amending or removing database listings. Where both apply, work through both.

Sources: Privacy Act 1988 (Cth), APP 13.1, 13.2, 13.3, 13.4 and 13.5 (Schedule 1) · OAIC APP Guidelines chapter 13 · OAIC APP 13 · Ours: correcting a tenant's personal information · a disputed tenancy-database listing · the property manager's privacy checklist

What an agency actually does with all thirteen

Reading thirteen principles is not the work. Turning them into a small number of artefacts is, and the order matters because each step feeds the next.

First, settle coverage. Whether the Privacy Act binds your agency turns on turnover and on a handful of specific carve-ins, so work that out before anything else. Agencies providing property-sale services also come under AML/CTF obligations from 1 July 2026, which drags the identity information they handle for those obligations into the Act.

Then map where information enters. List every collection point: application, sign-in, counter, web form, appraisal request, AML onboarding. That list is what APP 3 is tested against and what your APP 5 notices have to cover.

Then write the three documents the APPs actually ask for. A privacy policy that matches how your office really works (APP 1), a collection notice per collection point (APP 5), and a data-breach response plan for when APP 11 fails.

Then build the two processes people forget. One route for access and correction requests with a named person behind it (APP 12 and APP 13), and one working opt-out that is honoured across every marketing channel (APP 7).

Then keep a short register. Who you disclose to and why (APP 6), which providers are offshore and where (APP 8), and what you destroy and when, checked against the retention rules in your State or Territory (APP 11.2).

Then diary the dates. 1 July 2026 for AML/CTF on the sales side, and 10 December 2026 for the APP 1.7 automated decision-making disclosure.

If you want a faster read on which of these you are missing, the free self-audit walks the same ground in a couple of minutes.

What are the 13 Australian Privacy Principles?

They are the thirteen principles in Schedule 1 of the Privacy Act 1988 (Cth) that govern how covered entities handle personal information: APP 1 open and transparent management, APP 2 anonymity and pseudonymity, APP 3 collection of solicited personal information, APP 4 dealing with unsolicited personal information, APP 5 notification of collection, APP 6 use or disclosure, APP 7 direct marketing, APP 8 cross-border disclosure, APP 9 government related identifiers, APP 10 quality, APP 11 security, APP 12 access, and APP 13 correction. They are principles rather than prescriptive rules, which is why so many of them turn on "reasonable steps" judged in your circumstances.

Do all 13 APPs apply to a real-estate agency?

Where the Privacy Act binds an agency, all thirteen apply, but they do not all carry the same weight day to day. Some are constant duties, such as APP 1 governance and APP 11 security. Some trigger on an event, such as APP 5 at each collection, APP 4 when unsolicited information arrives, and APP 12 and APP 13 when someone asks. Some may rarely arise, for example parts of APP 9 if you never record identifier numbers. A few of the APPs are written differently for agencies, meaning Commonwealth government agencies, than for organisations, and a real-estate business is an organisation.

Which APPs cause the most trouble in real estate?

Judging by the regulator's published determinations and its stated focus, the pressure points are APP 3 over-collection on application forms, APP 5 notices that do not name the recipients information actually goes to, APP 11 security and retention, and APP 8 where a CRM, support desk or virtual assistant sits offshore. Marketing questions land on APP 7 and the Spam Act rather than APP 6. That is a pattern in enforcement and guidance, not a claim about how any particular agency operates.

Has the small-business exemption been removed?

No. As at July 2026 the small-business exemption remains in the Privacy Act 1988 (Cth). Removing it has been recommended and is under consideration, but it is not law, and nobody should be told otherwise. What has changed is narrower: specific carve-ins can pull an otherwise exempt small business into the Act, including AML/CTF designated services from 1 July 2026 for the personal information handled in connection with those obligations, operating a residential tenancy database, being related to a body corporate that is not a small business operator, and trading in personal information.

What changes on 10 December 2026?

APP 1.7 commences, adding an automated decision-making disclosure to the privacy policy obligation. Where a computer program uses personal information to make, or substantially and directly support making, a decision that could reasonably be expected to significantly affect a person's rights or interests, the policy must say so and describe the kinds of information and decisions involved. In real estate the candidate is automated tenancy screening or application scoring. It does not ban automated decisions and it does not require you to change tools. Whether your particular software crosses the line is fact-specific.

Are the Australian Privacy Principles the same in every State and Territory?

The APPs themselves are Commonwealth law and apply uniformly. What differs by jurisdiction is the law sitting around them. Residential tenancy legislation in each State and Territory sets its own rules on tenancy databases, including what may be listed and how a listing is challenged or removed. Record-retention periods for agency and trust records are set by State and Territory law, which is why APP 11.2 cannot be reduced to a single national number of years. Agent licensing and trust-account rules are also State-based. So the principle is national and the detail underneath it often is not.