How to fix your rental application form after the 2Apply decision
The 2Apply decision (IRE Pty Ltd [2026] AICmr 24) found a rental-application platform collected more personal information than reasonably necessary under APP 3.2 and by unfair means under APP 3.5, including deceptive design. To fix your form, stop asking for fields you cannot justify, remove the dark patterns, and know a platform does not move the obligation off your agency.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
What did the 2Apply decision actually find?
In IRE Pty Ltd (Privacy) [2026] AICmr 24, the OAIC found that IRE, operator of the 2Apply and InspectRealEstate rental-application platform, collected personal information that was not reasonably necessary for its functions, breaching APP 3.2, and that it collected by unfair means, breaching APP 3.5. It was the first time the regulator formally considered "dark patterns" and Online Choice Architecture under the Privacy Act. You can read the determination on AustLII and the OAIC's statement, RentTech platforms must stop unfair and excessive personal information collection.
The Commissioner said so twice, in terms:
"considers, for the first time, an entity's Online Choice Architecture" · [2026] AICmr 24 at [15]
"this is the first time I have done so in the context of APP 3.5" · at [111]
Plenty of law-firm commentary explains the case. Far less tells an agency what to change on Monday. The rest of this page is the practical fix.
Which fields should you stop asking for?
The determination flagged specific fields as going beyond what was reasonably necessary to assess a tenancy. The core rule is APP 3.2: collect personal information only where it is reasonably necessary for a function or activity, here, deciding whether to grant a lease. If the same approve or decline decision can be made without an item, collecting it is not reasonably necessary.
- Gender is not needed to assess whether someone can meet a tenancy.
- Student status does not determine affordability on its own; ask for income evidence instead.
- Citizenship status is generally irrelevant to a lease decision and carries discrimination risk.
- Visa expiry date goes beyond what a reasonable affordability and suitability check requires.
- Previous living history beyond the rental references needed to check tenancy history is over-collection.
The safer default is to collect only identity, contact details, evidence of ability to pay, and rental history, and to sight rather than retain ID where you can.
Which dark patterns should you remove?
The decision treated deceptive design itself as unfair collection under APP 3.5. Review your form and portal for these patterns and remove them.
- Confirmshaming, where declining an optional field is worded to make the applicant feel guilty or anxious.
- Biased framing, where optional data is presented as required, or the "share more" choice is visually pushed over the minimal one.
- Bundled consent, where one tick covers several unrelated uses, so an applicant cannot agree to the tenancy assessment without also agreeing to marketing or data-sharing.
- Pre-ticked boxes and hard-to-find opt-outs that manufacture agreement rather than obtain it.
Consent that is bundled or manufactured is not freely given, which is why the design of the form, not just its field list, is part of getting collection right.
At a glance
| Fix | APP | What to do |
|---|---|---|
| Stop excessive fields | APP 3.2 | Remove gender, student status, citizenship, visa expiry, extended living history |
| Apply the necessity test | APP 3.2 | Keep only identity, contact, ability to pay, rental history |
| Remove dark patterns | APP 3.5 | Strip confirmshaming, biased framing, bundled consent, pre-ticked boxes |
| Unbundle consent | APP 3.5 | Separate tenancy assessment from marketing or data-sharing |
| Give a proper notice | APP 5 | Provide a collection notice at or before collection |
| Own the obligation | APP 3, 5 | The agency stays responsible even on a third-party platform |
Does using a platform move the obligation off your agency?
Your agency decides which fields applicants must complete and how the form is framed, so your agency remains responsible for collecting only what is reasonably necessary and for giving a compliant APP 5 collection notice. A key trap is assuming that because a RentTech platform collects the data, the platform carries the privacy obligation. The 2Apply finding was against the platform operator, but the Commissioner framed it as a sector-wide signal, and it does not relieve the agency using the tool. If your provider still presents excessive fields or biased design, that is your risk to manage, including by turning fields off, choosing a different configuration, or raising it with the vendor.
What should you do now?
Audit your rental application field by field and delete anything you cannot tie to a genuine, reasonably necessary purpose. Then fix the framing so no optional field is disguised as required and no consent is bundled. Finally, pair the form with a proper collection notice under APP 5, given at or before collection, not buried in a policy no one reads. The APP 5 collection notice guide shows what the notice must cover.
Privaproof gives you an educational free self-audit to see where your current form stands, and a living Kit with a done-for-you application form and collection notice kept current as guidance changes, so you meet your obligations without drafting the wording yourself.
Common questions
Which rental application fields did the 2Apply decision flag?
At [94] the Commissioner listed gender, the names and ages of dependants, student status, bankruptcy status, retirement status, citizenship status and visa expiry as beyond what was reasonably necessary to assess a tenancy. The safer default is to collect only identity, contact details, evidence of ability to pay, and rental history, and to justify anything else against the APP 3.2 necessity test.
Does using 2Apply or another platform make me compliant?
No. Using a platform does not move the obligation off your agency. You choose the fields and framing, so you stay responsible under APP 3.2 and APP 5 for collecting only what is reasonably necessary and giving a proper collection notice. Vet the platform and turn off fields you cannot justify.
What is a dark pattern on a rental application?
A dark pattern is deceptive design that pushes applicants to share more than they need to. Examples include confirmshaming, presenting optional fields as required, bundled consent and pre-ticked boxes. The 2Apply decision treated this kind of design as unfair means of collection under APP 3.5.
Was the agency or the platform penalised in the 2Apply case?
The finding was against IRE, the platform operator, not the individual agencies using it, and the remedy centred on declarations rather than a fine. The Commissioner framed it as a sector-wide signal, so agencies should treat it as guidance on their own forms rather than assume it does not apply to them.
This is general information, not legal advice. Privaproof provides tools and general information; it is not a law practice. Sources: IRE Pty Ltd (Privacy) [2026] AICmr 24 on AustLII; OAIC RentTech statement; Australian Privacy Principles 3 and 5, Privacy Act 1988 (Cth).