Skip to content

What must your privacy policy contain? The APP 1.4 checklist

The OAIC's 2026 privacy sweep assessed about 60 entities' privacy policies against Australian Privacy Principle 1.4, and named rental and property first of six target sectors. APP 1.4 requires your policy to state the kinds of personal information you collect and hold, how and why you handle it, how someone can access, correct or complain, and whether you are likely to disclose information overseas. The sweep is over. APP 1.4 is not, and s 13K(1)(b)(ii) names it by number as a provision the OAIC can issue an infringement notice for.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price, rising to A$649 on 1 Oct 2026

Orientation only, not a compliance assessment. General information and tools, not legal advice.

What did the sweep actually check?

The Office of the Australian Information Commissioner (OAIC) announced the sweep on 9 December 2025 as the regulator's "first-ever compliance sweep", and it began in the first week of January 2026. The OAIC said it would "review the privacy policies of approximately 60 entities from the following 6 sectors that may collect information in-person for compliance with requirements under APP 1.4". Rental and property is listed first, as "collection of individuals' personal information during property inspections", and Privacy Commissioner Carly Kind named "real estate agents" in her own quote. APP 1.4 lists the minimum contents of a privacy policy under the Privacy Act 1988 (Cth). It is a document test: the regulator reads your published policy against that list.

On 20 May 2026 the Australian Information Commissioner reported the outcome: "Our Privacy Sweep of sixty entities earlier this year found instances of non-compliance in a significant proportion." That is across all six sectors and no per-sector breakdown is published, so nothing here says your agency was reviewed or would have failed. Ask the question the sweep asked instead. Open your own policy: does it name tenant applications, open-home sign-in sheets, ID copies or an overseas CRM? APP 1.4(a) asks for the kinds of personal information you collect and hold, not a generic list.

What's on the APP 1.4 checklist for a real estate agency?

APP 1.4 requires your privacy policy to address each item below. Apply each one concretely to how an agency actually operates.

At a glance

APP 1.4 requirementWhat it meansReal estate example
Kinds of personal informationCategories you collect and holdTenant applications, ID copies, open-home sign-ins, vendor and landlord records
How you collect and hold itChannels plus storage and securityApplication portal, sign-in sheets, cloud CRM
PurposesWhy you collect, use and disclose itAssess tenancy, manage listing, AML for sales, run rent roll
Access and correctionHow a person requests and fixes their dataNamed contact for APP 12 and APP 13 requests
ComplaintsHow to complain and how you respondComplaint route plus escalation to the OAIC
Overseas disclosureWhether you are likely to disclose to overseas recipients, and whereOverseas CRM, cloud host or offshore virtual assistant

Why does the sweep matter for agencies?

The sweep was not merely a paperwork exercise. APP 1.4 is one of the few Australian Privacy Principles named by number in a penalty provision: s 13K(1)(b)(ii) lists "Australian Privacy Principle 1.4 (contents of APP privacy policy)", which is why the OAIC can issue an infringement notice for a non-compliant policy directly, without a court. That notice is 60 penalty units for a body corporate and 12 for an individual (s 80UB; Regulatory Powers Act s 104(2)), or A$21,840 and A$4,368 at the current A$364 unit. A court can impose up to 200 penalty units on an individual and 1,000 on a body corporate at that tier (s 13K(4); Regulatory Powers Act s 82(5)(a)), but only on the Commissioner's application: a determination under s 52(1) contains no penalty limb at all (s 80U). The realistic risk is being asked to show a compliant, current policy and not having one.

A short, honest self-audit is a low-cost way to find the gaps before a regulator or a complaint does. Privaproof gives you an educational free self-audit to see where your policy stands, and a living Kit with a real-estate privacy policy kept current as guidance changes, so the wording keeps pace with the law instead of you redrafting it. For the broader picture, see the 2026 OAIC privacy sweep for real estate.

Common questions

Does the OAIC sweep apply to my real estate agency?

Rental and property was first of the six sectors named, but the sweep covered about 60 entities across all six and has ended, so nothing here predicts yours will be reviewed. Whether the Privacy Act binds your agency is a separate question with more routes in than two: turnover over A$3m in any financial year since 2002 (s 6D(4)(a), a one-way test a later fall does not undo), a related covered body corporate (s 6D(9)), disclosing personal information for a benefit, providing a health service, the s 6EA opt-in, or activities connected with the AML/CTF Act (s 6E). If any applies, APP 1.4 applies to your policy, sweep or no sweep.

Is a privacy policy the same as a collection notice?

No. A privacy policy is a standing document that satisfies APP 1.4 and describes your practices generally. A collection notice is given at or before the point you collect information under APP 5 and is specific to that collection. You need both. See do real estate agents need a privacy policy and a collection notice and the APP 5 collection notice guide.

Which APP 1.4 items can a template not fill in for you?

Two of them turn on facts only your agency knows. APP 1.4(a), the kinds of personal information you collect and hold, is not satisfied by a generic list that never mentions tenant application data, ID copies or open-home sign-ins. APP 1.4(f) and (g), overseas recipients and their countries, are not satisfied by silence about a cloud CRM or an offshore assistant. Open your policy and check for both.

Do I need to name the overseas countries in my policy?

APP 1.4(f) requires you to state whether you are likely to disclose personal information to overseas recipients, and APP 1.4(g) to name the countries where practicable. Offshore location does not settle it: the OAIC's guidelines say giving personal information to an overseas contractor "may be a use, rather than a disclosure" where you keep it under your effective control by binding contract (APP Guidelines 8.14). So the question for your CRM host, cloud storage or virtual assistant is whether your contract gives you that control. If not, silence about it is the APP 1.4(f) gap.


This is general information, not legal advice. Privaproof provides tools and general information; it is not a law practice. Sources: OAIC, Privacy compliance sweep to put privacy policies under the spotlight, 9 December 2025; Australian Information Commissioner, IAPP KnowledgeNet keynote, 20 May 2026; Australian Privacy Principle 1.4 and ss 6D, 13K, 52, 80U, 80UB, Privacy Act 1988 (Cth); Regulatory Powers (Standard Provisions) Act 2014 ss 82, 104.