Do You Need a Privacy Notice for Open-Home Sign-In?
Yes. The moment an attendee writes their name, phone or email on your sign-in sheet or app, you are collecting personal information, and Australian Privacy Principle 5 says you must make them aware of key facts at or before that point. The real-estate-specific catch: if you plan to add those contacts to a marketing or buyer database, you have to say so up front, not later.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
Why is the sign-in sheet the one to get right?
The open-home sign-in is the single collection point the public most visibly associates with real estate, and it is an easy one for a regulator or a complaint to point at. Every inspection produces a list of names, phone numbers and emails, often with a note about whether the person is a buyer or a renter. That is personal information, so the collection rules apply in full.
Two things make it higher-risk than it looks. First, most attendees have no relationship with your agency yet, so they have not seen your privacy policy and have no reason to expect their details to travel anywhere beyond a security list. Second, agencies routinely reuse the list for marketing (new-listing alerts, vendor reports, follow-up calls) without ever telling the person that was on the cards. That gap between what people expect and what actually happens is exactly what a collection notice is meant to close.
What must your open-home collection notice cover?
Under APP 5 you need to make each attendee aware of a short set of facts, in plain language, at or before sign-in (or as soon as practicable after). Tailor the generic list to the open-home context:
| APP 5 point | On an open-home sheet or app this means |
|---|---|
| Who you are and how to contact you | Your agency name and a contact point (not just the agent's mobile) |
| That you are collecting, and the circumstances | You are recording attendees at this inspection |
| The purposes | Security and duty of care, vendor reporting, and (if true) contacting you about this and similar properties |
| Whether required or authorised by law | Sign-in is generally not legally required, so do not imply it is |
| Main consequences of not providing it | Be honest: usually the person can still inspect (frame it as optional where that is the case) |
| Your usual disclosures | For example, that attendance may be reported to the vendor |
| Access, correction and complaints | A pointer to your privacy policy, which explains how to access, correct and complain |
| Likely overseas disclosure | If your CRM or sign-in app stores data offshore, say so and, where practicable, where |
The notice does not need to be long. It needs to be visible before the person signs, written in language they will actually read, and honest about marketing.
What pitfalls cause complaints?
A bare list with no notice. A clipboard with columns and no explanation of who gets the data or why is the most common failure. If there is no notice at the point of collection, you have missed the APP 5 obligation regardless of how careful you are afterwards.
Silent marketing. Adding attendees to a nurture list, SMS campaign or buyer-match database when the sheet said nothing about marketing is where people feel misled and complain. If contacting them about other listings is a purpose, name it before they sign.
A shared paper sheet everyone can read. A single page where each attendee sees the names, numbers and emails of everyone before them is a privacy problem in its own right: you are disclosing one attendee's details to the next. Prefer a method that keeps each entry private, such as a tablet app that clears between entries or individual slips, so people are not reading each other's information off the page.
Address and buyer-interest fields. The more you collect (home address, price range, "buyer or renter"), the more your notice and your handling need to match. Collect what you actually use, and make sure your stated purposes cover it.
Common questions
Is an open-home sign-in even legal, and do I have to have one?
Sign-in is common for security and duty-of-care reasons, but it is generally not something the law compels attendees to complete. Because it is usually optional, your notice should not imply that inspecting the property depends on handing over full contact details. If you do run a sheet or app, the collection notice obligation applies to whatever you collect.
Can I use the contacts to market other properties?
Only if you have made that purpose clear at collection and you meet the direct-marketing rules, including an easy way to opt out. The safe path is to state marketing as a purpose on the sign-in notice itself, so attendees know before they provide their details rather than discovering it when the first SMS arrives.
Does a QR code or sign-in app change anything?
No. Digital sign-in is still collection, so the same APP 5 facts must be presented, ideally on the first screen before the person enters anything. Two extra things to check: where the app provider stores the data (if offshore, your notice should flag likely overseas disclosure), and that entries are not visible to the next attendee.
A single, RE-specific sign-in notice, backed by a privacy policy that actually matches how your agency handles the data, is what turns this from a risk into a routine. The Privaproof Kit gives you that notice and the surrounding policy as one real-estate-specific system, kept current as the rules move, so every open home is covered without you drafting it from scratch. Both the sign-in notice and the privacy policy it sits on are reviewed by Matthew Hodgkinson, an Australian practising solicitor (Papillon Lawyers). See also collection notices for real estate under APP 5 and privacy compliance for real-estate agencies.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice. Sources: OAIC APP 5 notification; OAIC Australian Privacy Principles.