Can we use a tenant's driver-licence number as their file or reference number?
No. A driver-licence number is a government-related identifier: s 6(1) covers any identifier assigned by an agency or a State or Territory authority. APP 9.1 prohibits an organisation from adopting one as its own identifier of the individual, and it has only two exceptions: where required or authorised by or under an Australian law or a court or tribunal order, or the narrow regulation-making case in APP 9.3. There is no identity-verification exception to the adoption rule, and consent cannot cure an APP 9 problem, because an individual cannot consent to the adoption, use or disclosure of their government-related identifier.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
What counts as "adoption", and what does not?
This distinction decides which rules you are under, so it is worth getting exactly right.
Adoption is collecting the identifier and then organising the information you hold about that person by reference to it. In a real-estate business that looks like the licence number as the unique key in an applicant spreadsheet, as the folder name for scanned ID, or as the account reference in your system. That is what APP 9.1 prohibits.
Searching your CRM by licence number, or quoting it to verify someone, is a use, not adoption. Uses and disclosures are governed by APP 9.2, and APP 9.2(a) does permit use or disclosure that is reasonably necessary to verify the individual's identity for the purposes of your activities or functions. "Reasonably necessary" is an objective test, not a matter of what is convenient for your process.
So the practical rule is straightforward: use your own tenancy or client reference as the key. APP 9 does not stop you recording a licence number, only organising your file by reference to it. Where you verify identity, record that ID was sighted, by whom and on what date, rather than transcribing the number into a field you will later search on.
Sources: Privacy Act 1988 (Cth), s 6(1), APP 9.1 and APP 9.2(a) (Schedule 1) · OAIC APP Guidelines chapter 9, paragraphs 9.3, 9.13, 9.15, 9.24, 9.27 and 9.28 · OAIC APP guidelines
Does APP 9 tell us whether we can collect the identifier at all?
No, and this trips people up. APP 9 does not specifically address the collection of government-related identifiers. Collection is governed by APP 3.
The chain that answers the question runs the other way and is stronger for it: if you could not lawfully use or disclose the identifier under APP 9.2, then collecting it was not reasonably necessary for your functions, so the collection breaches APP 3.2.
Sources: Privacy Act 1988 (Cth), APP 3.2 and APP 9 (Schedule 1) · OAIC APP Guidelines chapter 9, paragraphs 9.15 and 9.16 · OAIC APP guidelines
Can we ask a tenant for their tax file number or Medicare number?
These two are not the same answer. A tax file number you should not be asking for at all, and it is more serious than a privacy question: requiring or requesting a person to quote their TFN without authorisation is an offence under s 8WA of the Taxation Administration Act 1953 (Cth), and unauthorised recording, use or disclosure is an offence under s 8WB. Each carries 100 penalty units or imprisonment for 2 years, or both.
Scope that correctly, though. s 8WA(1AA) disapplies the offence where a taxation law provides for the number to be quoted, which is how a business lawfully collects TFNs from its own employees. What has no basis is asking a tenant or applicant for one as part of a tenancy application.
Note also that s 8WA(2) permits you to request a document that happens to bear a TFN provided the person is not prevented from removing the number from the document, which is what makes the redaction advice below lawful rather than an over-correction. And s 8WB(1)(a) makes maintaining a record of a TFN an offence, which is what sharpens the destroy step.
In practice the failure is not asking, it is accepting, and the two common cases are analysed differently:
- A tax notice with the TFN visible, sent as proof of income, is genuinely unsolicited. You asked for evidence of income, not for a TFN. APP 4 applies: assess whether you could have collected it under APP 3, and if not, destroy or de-identify it as soon as practicable where lawful and reasonable. Better still, tell applicants to redact TFNs before sending.
- A Medicare card supplied because your own points-based ID list names it is a different case, and it is not automatically a breach. No provision prohibits collecting a Medicare number outright, and APP 9.2(a) permits use or disclosure reasonably necessary to verify identity, which is exactly what a points-based ID check is doing. The OAIC gives driver licences and passports as exactly that use (chapter 9, paragraph 9.26). What you should not do is adopt the number as your own reference, keep the card image longer than the verification needed, or collect more identifiers than the check requires. Record that ID was sighted rather than storing the number, and apply APP 11.2 to anything you no longer need.
Tax file number handling is also governed by the Privacy (Tax File Number) Rule 2015, which remains in force with sunsetting deferred to 1 April 2027. It binds any file number recipient, which s 11(1) defines as anyone in possession or control of a record containing tax file number information, lawfully or not, so r 9 applies whether or not you are an APP entity: where a TFN arrives inside information sent for an unrelated purpose, you must not use, disclose or record it inconsistently with the Rule. It binds any file number recipient, which s 11(1) defines as anyone in possession or control of a record containing tax file number information, lawfully or not, so r 9 applies whether or not you are an APP entity: where a TFN arrives inside information sent for an unrelated purpose, you must not use, disclose or record it inconsistently with the Rule.
Sources: Taxation Administration Act 1953 (Cth), ss 8WA, 8WA(1AA), 8WA(2) and 8WB; Privacy Act 1988 (Cth), ss 11(1) and 18, APP 3.2, APP 4, APP 9.2 and APP 11.2 (Schedule 1); Privacy (Tax File Number) Rule 2015, r 9 · OAIC APP Guidelines chapters 3, 4 and 9, paragraph 9.26 · OAIC tax file numbers · OAIC APP guidelines
Does AML customer due diligence change this?
It changes the basis for verifying identity, not the adoption rule. Brokering a sale is a designated service (AML/CTF Act s 6(5A), Table 5, item 1), and s 28 requires you to establish the customer's identity on reasonable grounds and verify KYC information against reliable and independent data. Because a law requires that verification, it sits under APP 9.2(c) as well as the identity limb in APP 9.2(a), and what you must give AUSTRAC sits under APP 9.2(b). Note who the customer is: Table 5 item 1 names both the seller and the buyer.
It still does not license adopting the number as your own key, and it does not turn a broader identifier set into a necessary one: collect the identifiers the check actually requires, and no more. It also does not reach your rent roll: a lease of 30 years or less is outside the s 6 definition of real estate.
Sources: AML/CTF Act 2006 (Cth), s 6 definition of real estate, s 6(5A) Table 5 item 1 and s 28; Privacy Act 1988 (Cth), APP 9.2(a), 9.2(b) and 9.2(c) (Schedule 1) · AUSTRAC · See also ID documents, AUSTRAC and privacy
→ The free 2-minute audit flags the identifiers a real-estate business is most likely to be holding without a basis.