Skip to content

The OAIC's 2026 privacy sweep: what it checked, and what your policy needs now

In 2026 the OAIC ran a privacy compliance sweep that named rental and property a target sector, and recent determinations against property and RentTech operators show the regulator is actively enforcing, so agencies should get their privacy policies and collection practices in order now.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price

Orientation only, not a compliance assessment. General information and tools, not legal advice.

What is the 2026 OAIC privacy sweep?

In 2026 the Office of the Australian Information Commissioner (OAIC) ran a privacy compliance sweep: a coordinated review of how a group of organisations handle personal information. The sweep looked at around 60 organisations across six sectors that collect personal information in person, and the rental and property sector was named as one of the target sectors. The OAIC put the scope in its own words when it announced the sweep on 9 December 2025:

"The OAIC will review the privacy policies of approximately 60 entities from the following 6 sectors"

The six sectors were rental and property, chemists and pharmacists, licensed venues, car rental companies, car dealerships, and pawnbrokers and second-hand dealers. Real estate was not an afterthought in the announcement: it was the worked example the OAIC chose.

"For example, real estate agents asking for phone numbers at open houses, or car rental agencies presenting customers with lengthy forms."

Privacy Commissioner Carly Kind gave the reason in the same release:

"When confronted with in-person requests for their personal information from retailers, licenced venues, car hire companies or real estate agents, consumers often don't have access to all the information they might need to make an informed decision."

>

Carly Kind, Privacy Commissioner, OAIC media release, 9 December 2025

The OAIC has not published the results of the sweep. That does not change what an agency should do, because APP 1.4 is a standing obligation under the Privacy Act 1988 (Cth) rather than a sweep requirement.

The focus of the sweep was narrow but important: it assessed organisations' privacy policies against Australian Privacy Principle 1.4 (APP 1.4). APP 1.4 sets out what a privacy policy must actually contain: the kinds of personal information an entity collects and holds, how it collects and holds it, why it collects it, how an individual can access or correct their information or make a complaint, and whether information is likely to be disclosed overseas. A privacy policy that is missing, out of date, or silent on these points is squarely the kind of thing this sweep was designed to catch.

The stakes are not merely reputational. For a lower-tier breach such as a non-compliant privacy policy, the OAIC can issue an infringement notice directly, without going to court, for a fraction of the court maximum, while a court can impose more for this lower tier, up to $72,800 for an individual or $364,000 for a company, in serious interferences with privacy (s 13G). Since 10 December 2024 a separate mid-tier civil penalty (s 13H) covers an interference that is not serious. These are ceilings, not the typical outcome; many matters attract no penalty at all . For a real estate agency that has never had its privacy policy reviewed against the current Australian Privacy Principles, the sweep was a clear signal that a compliant, up-to-date policy is now table stakes.

You can read the OAIC's announcement here: Privacy compliance sweep to put privacy policies under the spotlight.

What enforcement is backing up the sweep?

A sweep on its own might be easy to shrug off. What makes 2026 different is that the OAIC has been handing down determinations against operators in the property sector, showing it is willing to enforce, rather than only review. Neither of the two operators below is a typical estate agency: one is a RentTech platform and the other was a property-leads business. But both cases show the regulator's direction of travel on how personal information may be collected in the property world, and the principles apply directly to how agencies run their own collection.

IRE Pty Ltd (the 2Apply / InspectRealEstate platform)

In IRE Pty Ltd (Privacy) [2026] AICmr 24 (1 April 2026), the OAIC found that IRE, the operator of the 2Apply and InspectRealEstate rental-application platform, collected personal information that was not reasonably necessary for its functions. That included prospective renters' gender, student status, citizenship status, visa expiry, and details of dependants including their names and ages. The OAIC also found the information was collected by unfair means, and it was the first time the regulator formally considered "dark patterns" and Online Choice Architecture under the Privacy Act. The Commissioner has indicated it expects all RentTech providers to adapt their practices.

Read the determination on AustLII, and the OAIC's statement: RentTech platforms must stop unfair and excessive personal information collection, says Privacy Commissioner.

Property Lovers Pty Ltd

In Property Lovers Pty Ltd (Privacy) [2024] AICmr 249 (22 November 2024), the OAIC found that Property Lovers unfairly collected the personal information of vulnerable individuals (scraping details from court lists to generate leads), breaching APPs 1.3, 3.5, 5 and 10.2.

The Commissioner treated the material collected as sensitive information in its own right:

"both the facial images and faceprints are sensitive information within the meaning of s 6(1)" · Property Lovers Pty Ltd (Privacy) [2024] AICmr 249 at [84]

The company was ordered to cease the collection, destroy its leads lists within 30 days, update its privacy policy, and publish a written apology. It is a stark example of lead-generation practices being treated as unlawful collection.

Read the determination on AustLII, and the OAIC's statement: OAIC finalises investigation into Property Lovers and fastproperty.ai.

What does this mean for your agency?

Read together, the sweep and the determinations point to four practical priorities for any agency that collects personal information from vendors, buyers, landlords and, especially, prospective tenants.

What should you do now?

A short, honest self-audit of your privacy readiness is a sensible next step; it's a low-cost way to find the gaps before a regulator, or a complaint, finds them for you.

Common questions

What is the OAIC's 2026 privacy sweep?

A coordinated review of how organisations handle personal information. It looked at around 60 organisations across six sectors that collect personal information in person, named the rental and property sector as a target, and assesses privacy policies against Australian Privacy Principle 1.4.

Does the sweep apply to real estate agencies?

Yes. The rental and property sector was named a target sector. The sweep assessed whether your privacy policy meets APP 1.4: what you collect, how and why, how someone can access, correct or complain, and any overseas disclosure. A missing or out-of-date policy is exactly what it's designed to catch.

Has the OAIC actually enforced against property operators?

Yes. In IRE Pty Ltd [2026] AICmr 24 (the 2Apply / InspectRealEstate platform) the OAIC found personal information collected that was not reasonably necessary, by unfair means; and in Property Lovers Pty Ltd [2024] AICmr 249 it found unfair collection of vulnerable people's data and ordered the leads lists destroyed.

What should an agency do in response?

Collect only what is reasonably necessary (APP 3), have a current APP 1.4-compliant privacy policy, give a proper APP 5 collection notice, and strip excessive fields out of your rental-application forms.