What must your privacy policy contain? The APP 1.4 checklist
The OAIC's 2026 privacy sweep assessed about 60 entities' privacy policies against Australian Privacy Principle 1.4, and named rental and property first of six target sectors. APP 1.4 requires your policy to state the kinds of personal information you collect and hold, how and why you handle it, how someone can access, correct or complain, and whether you are likely to disclose information overseas. The sweep is over. APP 1.4 is not, and s 13K(1)(b)(ii) names it by number as a provision the OAIC can issue an infringement notice for.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
What did the sweep actually check?
The Office of the Australian Information Commissioner (OAIC) announced the sweep on 9 December 2025 as the regulator's "first-ever compliance sweep", and it began in the first week of January 2026. The OAIC said it would "review the privacy policies of approximately 60 entities from the following 6 sectors that may collect information in-person for compliance with requirements under APP 1.4". Rental and property is listed first, as "collection of individuals' personal information during property inspections", and Privacy Commissioner Carly Kind named "real estate agents" in her own quote. APP 1.4 lists the minimum contents of a privacy policy under the Privacy Act 1988 (Cth). It is a document test: the regulator reads your published policy against that list.
On 20 May 2026 the Australian Information Commissioner reported the outcome: "Our Privacy Sweep of sixty entities earlier this year found instances of non-compliance in a significant proportion." That is across all six sectors and no per-sector breakdown is published, so nothing here says your agency was reviewed or would have failed. Ask the question the sweep asked instead. Open your own policy: does it name tenant applications, open-home sign-in sheets, ID copies or an overseas CRM? APP 1.4(a) asks for the kinds of personal information you collect and hold, not a generic list.
What's on the APP 1.4 checklist for a real estate agency?
APP 1.4 requires your privacy policy to address each item below. Apply each one concretely to how an agency actually operates.
- The kinds of personal information you collect and hold. Name the real categories: tenant application data, income and rental history, identity documents, open-home and inspection sign-in details, vendor and landlord records, and enquiry or lead data.
- How you collect and hold that information. Cover your channels (application portals, sign-in sheets, forms, phone, email) and how it is stored and secured, including any cloud or CRM system.
- The purposes for which you collect, hold, use and disclose it. Tie each purpose to a genuine function: assessing a tenancy, managing a listing, meeting AML obligations for sales work, or managing a rent roll.
- How someone can access and seek correction of their information. Give a clear route and contact point for access and correction requests (APP 12 and APP 13).
- How someone can complain, and how you will handle it. State how to lodge a complaint and how the agency responds, including that they can escalate to the OAIC.
- Whether you are likely to disclose personal information overseas. APP 1.4(f), with the countries under 1.4(g) where practicable. Offshore location is not the test: information given to an overseas provider you keep under effective control by contract may be a use, not a disclosure (OAIC APP Guidelines 8.14). Check your CRM and virtual-assistant contracts, then state the position.
At a glance
| APP 1.4 requirement | What it means | Real estate example |
|---|---|---|
| Kinds of personal information | Categories you collect and hold | Tenant applications, ID copies, open-home sign-ins, vendor and landlord records |
| How you collect and hold it | Channels plus storage and security | Application portal, sign-in sheets, cloud CRM |
| Purposes | Why you collect, use and disclose it | Assess tenancy, manage listing, AML for sales, run rent roll |
| Access and correction | How a person requests and fixes their data | Named contact for APP 12 and APP 13 requests |
| Complaints | How to complain and how you respond | Complaint route plus escalation to the OAIC |
| Overseas disclosure | Whether you are likely to disclose to overseas recipients, and where | Overseas CRM, cloud host or offshore virtual assistant |
Why does the sweep matter for agencies?
The sweep was not merely a paperwork exercise. APP 1.4 is one of the few Australian Privacy Principles named by number in a penalty provision: s 13K(1)(b)(ii) lists "Australian Privacy Principle 1.4 (contents of APP privacy policy)", which is why the OAIC can issue an infringement notice for a non-compliant policy directly, without a court. That notice is 60 penalty units for a body corporate and 12 for an individual (s 80UB; Regulatory Powers Act s 104(2)), or A$21,840 and A$4,368 at the current A$364 unit. A court can impose up to 200 penalty units on an individual and 1,000 on a body corporate at that tier (s 13K(4); Regulatory Powers Act s 82(5)(a)), but only on the Commissioner's application: a determination under s 52(1) contains no penalty limb at all (s 80U). The realistic risk is being asked to show a compliant, current policy and not having one.
A short, honest self-audit is a low-cost way to find the gaps before a regulator or a complaint does. Privaproof gives you an educational free self-audit to see where your policy stands, and a living Kit with a real-estate privacy policy kept current as guidance changes, so the wording keeps pace with the law instead of you redrafting it. For the broader picture, see the 2026 OAIC privacy sweep for real estate.
Common questions
Does the OAIC sweep apply to my real estate agency?
Rental and property was first of the six sectors named, but the sweep covered about 60 entities across all six and has ended, so nothing here predicts yours will be reviewed. Whether the Privacy Act binds your agency is a separate question with more routes in than two: turnover over A$3m in any financial year since 2002 (s 6D(4)(a), a one-way test a later fall does not undo), a related covered body corporate (s 6D(9)), disclosing personal information for a benefit, providing a health service, the s 6EA opt-in, or activities connected with the AML/CTF Act (s 6E). If any applies, APP 1.4 applies to your policy, sweep or no sweep.
Is a privacy policy the same as a collection notice?
No. A privacy policy is a standing document that satisfies APP 1.4 and describes your practices generally. A collection notice is given at or before the point you collect information under APP 5 and is specific to that collection. You need both. See do real estate agents need a privacy policy and a collection notice and the APP 5 collection notice guide.
Which APP 1.4 items can a template not fill in for you?
Two of them turn on facts only your agency knows. APP 1.4(a), the kinds of personal information you collect and hold, is not satisfied by a generic list that never mentions tenant application data, ID copies or open-home sign-ins. APP 1.4(f) and (g), overseas recipients and their countries, are not satisfied by silence about a cloud CRM or an offshore assistant. Open your policy and check for both.
Do I need to name the overseas countries in my policy?
APP 1.4(f) requires you to state whether you are likely to disclose personal information to overseas recipients, and APP 1.4(g) to name the countries where practicable. Offshore location does not settle it: the OAIC's guidelines say giving personal information to an overseas contractor "may be a use, rather than a disclosure" where you keep it under your effective control by binding contract (APP Guidelines 8.14). So the question for your CRM host, cloud storage or virtual assistant is whether your contract gives you that control. If not, silence about it is the APP 1.4(f) gap.
This is general information, not legal advice. Privaproof provides tools and general information; it is not a law practice. Sources: OAIC, Privacy compliance sweep to put privacy policies under the spotlight, 9 December 2025; Australian Information Commissioner, IAPP KnowledgeNet keynote, 20 May 2026; Australian Privacy Principle 1.4 and ss 6D, 13K, 52, 80U, 80UB, Privacy Act 1988 (Cth); Regulatory Powers (Standard Provisions) Act 2014 ss 82, 104.