Can we use a tenant's driver-licence number as their file or reference number?
No. APP 9.1 prohibits an organisation from adopting a government-related identifier as its own identifier for an individual, and it has only two exceptions: where required or authorised by or under an Australian law or a court or tribunal order, or where prescribed by regulations. There is no identity-verification exception to the adoption rule, and consent cannot cure an APP 9 problem, because an individual cannot consent to the adoption, use or disclosure of their government-related identifier.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
What counts as "adoption", and what does not?
This distinction decides which rules you are under, so it is worth getting exactly right.
Adoption is collecting the identifier and then organising the information you hold about that person by reference to it. In a real-estate business that looks like the licence number as the unique key in an applicant spreadsheet, as the folder name for scanned ID, or as the account reference in your system. That is what APP 9.1 prohibits.
Searching your CRM by licence number, or quoting it to verify someone, is a use, not adoption. Uses and disclosures are governed by APP 9.2, and APP 9.2(a) does permit use or disclosure that is reasonably necessary to verify the individual's identity. "Reasonably necessary" is an objective test, not a matter of what is convenient for your process.
So the practical rule is straightforward: use your own tenancy or client reference as the key. Where you verify identity, record that ID was sighted, by whom and on what date, rather than transcribing the number into a field you will later search on.
Sources: Privacy Act 1988 (Cth), APP 9.1 and APP 9.2(a) (Schedule 1) · OAIC APP Guidelines chapter 9, paragraphs 9.3, 9.13, 9.15, 9.27 and 9.28 · OAIC APP guidelines
Does APP 9 tell us whether we can collect the identifier at all?
No, and this trips people up. APP 9 does not specifically address the collection of government-related identifiers. Collection is governed by APP 3.
The chain that answers the question runs the other way and is stronger for it: if you could not lawfully use or disclose the identifier under APP 9.2, then collecting it was not reasonably necessary for your functions, so the collection breaches APP 3.2.
That is the reasoning to apply to any "should we be taking this number" question.
Sources: Privacy Act 1988 (Cth), APP 3.2 and APP 9 (Schedule 1) · OAIC APP Guidelines chapter 9, paragraphs 9.15 and 9.16 · OAIC APP guidelines
Can we ask a tenant for their tax file number or Medicare number?
These two are not the same answer. A tax file number you should not be asking for at all, and it is more serious than a privacy question: requiring or requesting a person to quote their TFN without authorisation is an offence under s 8WA of the Taxation Administration Act 1953 (Cth), and unauthorised recording, use or disclosure is an offence under s 8WB.
Scope that correctly, though. A business lawfully collects TFNs from its own employees, and withholding obligations can bring landlords and owners into scope for some payments. What has no basis is asking a tenant or applicant for one as part of a tenancy application.
Note also that s 8WA(2) permits you to request a document that happens to bear a TFN provided the person is free to remove or obscure it, which is what makes the redaction advice below lawful rather than an over-correction. And s 8WB(1)(a) makes maintaining a record of a TFN an offence, which is what sharpens the destroy step.
In practice the failure is not asking, it is accepting, and the two common cases are analysed differently:
- A tax notice with the TFN visible, sent as proof of income, is genuinely unsolicited. You asked for evidence of income, not for a TFN. APP 4 applies: assess whether you could have collected it under APP 3, and if not, destroy or de-identify it as soon as practicable where lawful and reasonable. Better still, tell applicants to redact TFNs before sending.
- A Medicare card supplied because your own points-based ID list names it is a different case, and it is not automatically a breach. Nothing prohibits collecting a Medicare number, and APP 9.2(a) permits use or disclosure reasonably necessary to verify identity, which is exactly what a points-based ID check is doing. The OAIC gives driver licences and passports as examples of that use. What you should not do is adopt the number as your own reference, keep the card image longer than the verification needed, or collect more identifiers than the check requires. Record that ID was sighted rather than storing the number, and apply APP 11.2 to anything you no longer need.
Tax file number handling is also governed by the Privacy (Tax File Number) Rule 2015, which remains in force with sunsetting deferred to 1 April 2027.
Sources: Taxation Administration Act 1953 (Cth), ss 8WA and 8WB; Privacy Act 1988 (Cth), APP 3.2, APP 4, APP 9.2 and APP 11.2 (Schedule 1); Privacy (Tax File Number) Rule 2015 · OAIC APP Guidelines chapters 3, 4 and 9 · OAIC tax file numbers · OAIC APP guidelines
Does AML customer due diligence change this?
It changes the basis for verifying identity, not the adoption rule. Where you provide AML/CTF designated services on the property sales side, identity verification is required by that regime, which is a different legal basis from tenancy screening and should be handled and explained separately.
It still does not license adopting the number as your own key, and it does not turn a broader identifier set into a necessary one: collect the identifiers the check actually requires, and no more.
Sources: AML/CTF Act 2006 (Cth); Privacy Act 1988 (Cth), APP 9 (Schedule 1) · AUSTRAC · See also ID documents, AUSTRAC and privacy
→ The free 2-minute audit flags the identifiers a real-estate business is most likely to be holding without a basis.