Can someone deal with a real-estate business anonymously or under a pseudonym?
APP 2.1 says individuals must have the option of not identifying themselves, or of using a pseudonym, when dealing with you in relation to a particular matter. It is a duty on you, and APP 2.2 switches it off in two situations: where an Australian law or a court or tribunal order requires or authorises you to deal with individuals who have identified themselves, or where it is impracticable for you to deal with someone who has not identified themselves or who has used a pseudonym. So you can require identification where you genuinely need it, and the everyday anonymous case is the casual enquiry about price or availability.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
When can we require someone to identify themselves?
Whenever one of the two exceptions in APP 2.2 applies to that matter. The useful question is not whether your agency needs identity somewhere, it is whether you need it for the matter in front of you: could you answer this enquiry, or run this inspection, without knowing who the person is?
APP 2.2(a): you are required or authorised by or under an Australian law, or a court/tribunal order, to deal with individuals who have identified themselves. The shorthand drops "authorised", and it matters: where a law authorises rather than requires identification, OAIC APP Guidelines chapter 2 at 2.16 says you keep a discretion to deal anonymously anyway. The clearest example is AML/CTF customer due diligence on the property sales side. Table 5 item 1 is "brokering the sale, purchase or transfer of real estate", so an ordinary tenancy is not that designated service.
APP 2.2(b): it is impracticable to deal with individuals who have not identified themselves or who have used a pseudonym. Both limbs are in the clause, and this is the exception that does the everyday work. You cannot assess a tenancy application from an anonymous applicant, because you cannot verify income, contact referees, run the checks or enter into a lease with someone whose identity you do not know. You cannot manage a tenancy, hold a bond or serve a notice anonymously either.
Note the shape of the test. It is judged against the particular matter, not your whole business. Inconvenience is not irrelevant: OAIC APP Guidelines chapter 2 at 2.21 accepts the burden of "inconvenience, time and cost" where it "would be excessive in all the circumstances", but calls that "more likely to be a transitional rather than an ongoing justification". "We prefer to know who we are talking to" is a preference.
Sources: Privacy Act 1988 (Cth), APP 2.1 and APP 2.2(a) to (b) (Schedule 1); AML/CTF Act 2006 (Cth) · OAIC APP Guidelines chapter 2 · OAIC APP guidelines · AUSTRAC
Can someone ask about a rental or a listing without giving their details?
Yes, and this is the clean case. Asking what the rent is, whether a property is still available, when the next inspection is, or what the strata levies are does not require anybody to identify themselves, so APP 2.1 applies and the option must genuinely be available.
The common failure is not a refusal, it is a form. Both of these are the OAIC's own examples, chapter 2 at 2.14: a form should state "that personal identification boxes (such as name and address) are not mandatory fields", and an automated call message should tell callers "they are not required to provide personal information". If your site makes name, email and phone mandatory before it will show a price, the option has been removed by design.
Two practical fixes that cost nothing: publish the answers to the routine questions so people do not have to ask, and make the enquiry form's contact fields genuinely optional where the enquiry can be answered without them. A third is the one with no artefact behind it. OAIC APP Guidelines chapter 2 at 2.12 treats it as implicit in APP 2 that individuals "are made aware of their opportunity to deal anonymously or by pseudonym". Does anything you publish say so? A third is the one with no artefact behind it. OAIC APP Guidelines chapter 2 at 2.12 treats it as implicit in APP 2 that individuals "are made aware of their opportunity to deal anonymously or by pseudonym". Does anything you publish say so?
Sources: Privacy Act 1988 (Cth), APP 2.1 (Schedule 1) · OAIC APP Guidelines chapter 2 · OAIC APP guidelines
Does APP 2 mean we have to let people stay anonymous through a whole tenancy?
No. APP 2.1 gives the option in relation to a particular matter, so it is assessed transaction by transaction rather than as a status somebody keeps.
That is why the same person can legitimately be anonymous at one stage and identified at the next. An anonymous enquiry about rent is one matter. Submitting an application is a different matter, where impracticability under APP 2.2(b) plainly applies. Signing a lease is another again.
What you cannot do is use the later requirement to backfill the earlier one, for example refusing to answer a price question until someone registers, on the basis that they would have to identify themselves eventually if they applied.
Sources: Privacy Act 1988 (Cth), APP 2.1 (Schedule 1) · OAIC APP Guidelines chapter 2 · OAIC APP guidelines
Can we require a real name at an open home?
Recording a name and a contact number for people entering an occupied home is ordinarily defensible, because knowing who has been through a property you are responsible for is a genuine function, and doing it anonymously is impracticable. It is also the collection the regulator went looking at: in the sweep it began in the first week of January 2026, the OAIC listed rental and property first among six in-person sectors, as "collection of individuals' personal information during property inspections". What it assessed there was privacy policies, against APP 1.4. It is also the collection the regulator went looking at: in the sweep it began in the first week of January 2026, the OAIC listed rental and property first among six in-person sectors, as "collection of individuals' personal information during property inspections". What it assessed there was privacy policies, against APP 1.4.
Two limits worth keeping in view. First, what you may collect is a separate question governed by APP 3.2: an organisation must not collect personal information unless it is "reasonably necessary for one or more of the entity's functions or activities", so the sign-in is not an invitation to gather more than a name and a contact. Second, collecting at the door triggers APP 5, whose timing words are "at or before the time or, if that is not practicable, as soon as practicable after" the collection.
Requiring a photo ID document is a further step again, and a harder one to justify. That is covered separately.
Sources: Privacy Act 1988 (Cth), APP 2.2(b), APP 3.2 and APP 5 (Schedule 1) · OAIC APP Guidelines chapters 2, 3 and 5 · OAIC APP guidelines · See also can you require photo ID at an open home and the open-home sign-in collection notice
Can someone sign in at an open home under a pseudonym?
APP 2.1 covers pseudonyms as well as anonymity, and the two are different options rather than one. OAIC APP Guidelines chapter 2 at 2.3: "APP 2 requires that both options be made available to individuals dealing with an APP entity unless one of the two exceptions applies." So offering a pseudonym does not discharge APP 2 on its own. A pseudonym still lets you count and contact attendees, which is usually the function you actually needed.
Where you can show that dealing with a pseudonymous attendee is impracticable for a particular purpose, APP 2.2(b) applies and you can require the real name for that purpose. Wanting a clean database is not that. Needing to link the attendee to a verified identity, for example because they are proceeding to an application or an AML-regulated transaction, may be.
In practice this rarely bites, because someone using a pseudonym at an open home and then applying for the property will be identified at the application stage anyway.
Sources: Privacy Act 1988 (Cth), APP 2.1 and APP 2.2(b) (Schedule 1) · OAIC APP Guidelines chapter 2 · OAIC APP guidelines
Can we refuse to deal with someone who will not identify themselves?
Only where an exception in APP 2.2 applies to that matter. If it does, you are not refusing an entitlement, you are dealing with a situation the principle does not cover.
The safe sequence in an office is: identify the matter, ask whether you can actually perform it without knowing who the person is, and if you cannot, say so and explain why. "We need your name because we cannot process an application without verifying who is entering into the lease" names the matter and the impracticability, which is exactly what APP 2.2(b) turns on. "It is our policy" names neither, and a policy is not one of the two exceptions.
Where you can perform the matter anonymously and choose not to, that is a breach of APP 2.1, however reasonable it feels commercially. APP 2.1 is also on the short list in s 13K(1)(b) of principles whose breach is a "civil penalty provision for which infringement notices or compliance notices can be issued", capped at 200 penalty units. Most APPs are not on that list.
Sources: Privacy Act 1988 (Cth), APP 2.1 and APP 2.2 (Schedule 1) · OAIC APP Guidelines chapter 2 · OAIC APP guidelines
Can we require registration before releasing property details?
Be careful here, because this is the most common APP 2 problem in the industry and it is usually built into a system rather than decided by a person.
Where the details are already public, in the listing, on a portal, on a sign board, requiring registration to receive them is difficult to justify as impracticability. You are able to provide them; you would prefer to capture a lead first.
Where genuine work is involved, the analysis changes. Booking a private inspection, holding a property, or providing a document pack that has to be prepared and tracked are matters where dealing with an unidentified person may well be impracticable, and a contact point is part of doing the thing.
The distinction to hold: the harder the question is to answer without knowing who is asking, the stronger your APP 2.2(b) position.
Sources: Privacy Act 1988 (Cth), APP 2.1 and APP 2.2(b) (Schedule 1) · OAIC APP Guidelines chapter 2 · OAIC APP guidelines
Can we ask for a phone number just to book an inspection?
Usually yes, because a booking is a matter you cannot sensibly perform without a way to contact the person if the time changes or the property is let. That is APP 2.2(b) impracticability doing its ordinary work.
The limit is APP 3.2: collect what the booking needs and no more. A name and one contact point is the booking. An address, a date of birth, an employer, a budget and a pre-approval status is a lead-qualification form wearing a booking's clothes, and each additional field needs its own justification.
Sources: Privacy Act 1988 (Cth), APP 2.2(b) and APP 3.2 (Schedule 1) · OAIC APP Guidelines chapters 2 and 3 · OAIC APP guidelines
What does "impracticable" actually mean?
It is the exception that decides most real questions, so it is worth understanding rather than reaching for.
Impracticable is judged against the particular matter. It asks whether you are genuinely unable to deal with an unidentified or pseudonymous person for that purpose, taking account of what the matter requires. Cost and inconvenience are relevant, but preference is not, and a system built to capture identity does not by itself make anonymity impracticable. OAIC APP Guidelines chapter 2 at 2.21 says so directly: unless a law or order requires or authorises identification, "entities are expected to design and maintain information collection systems that incorporate anonymous and pseudonymous options".
A useful internal test: could you complete this specific interaction, to the standard you owe, without knowing who the person is? If yes, the option stands. If no, write down why once, and apply it consistently rather than deciding case by case at the counter.
Where you rely on APP 2.2(a) instead, be able to name the law or the order that requires or authorises it. "AML requires it" is only true for the sales-side designated services that are actually regulated, and it is not a general answer for a leasing office. Chapter 2 at 2.18 then limits what you take from it: the requirement "may be satisfied by sighting, but not collecting", the information.
Sources: Privacy Act 1988 (Cth), APP 2.2(a) and APP 2.2(b) (Schedule 1); AML/CTF Act 2006 (Cth) · OAIC APP Guidelines chapter 2 · OAIC APP guidelines
→ The free 2-minute audit checks the enquiry and sign-in points where agencies most often collect more than the matter requires.