What must your privacy policy contain? The APP 1.4 checklist
The 2026 OAIC privacy sweep assessed privacy policies against Australian Privacy Principle 1.4, which requires your policy to state the kinds of personal information you collect and hold, how and why you handle it, how someone can access, correct or complain, and whether you disclose information overseas. A generic or out-of-date policy is what the sweep was built to catch, and APP 1.4 applies whether or not a sweep is running.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
What is the sweep actually checking?
In 2026 the Office of the Australian Information Commissioner (OAIC) ran a privacy compliance sweep that named the rental and property sector as a target, and the sweep assessed organisations' privacy policies against APP 1.4. APP 1.4 lists the minimum contents of a compliant privacy policy under the Privacy Act 1988 (Cth). It is a document test: the regulator looks at whether your published policy actually says the things the law requires it to say. You can read the OAIC's announcement here: Privacy compliance sweep to put privacy policies under the spotlight.
Most agency privacy policies fail not because they are wrong, but because they are generic. A policy copied from a template years ago rarely names tenant applications, open-home sign-in sheets, ID copies or an overseas CRM, so it does not describe what your agency really collects. That gap is the point of failure APP 1.4 exposes.
What's on the APP 1.4 checklist for a real estate agency?
APP 1.4 requires your privacy policy to address each item below. Apply each one concretely to how an agency actually operates.
- The kinds of personal information you collect and hold. Name the real categories: tenant application data, income and rental history, identity documents, open-home and inspection sign-in details, vendor and landlord records, and enquiry or lead data.
- How you collect and hold that information. Cover your channels (application portals, sign-in sheets, forms, phone, email) and how it is stored and secured, including any cloud or CRM system.
- The purposes for which you collect, hold, use and disclose it. Tie each purpose to a genuine function: assessing a tenancy, managing a listing, meeting AML obligations for sales work, or managing a rent roll.
- How someone can access and seek correction of their information. Give a clear route and contact point for access and correction requests (APP 12 and APP 13).
- How someone can complain, and how you will handle it. State how to lodge a complaint and how the agency responds, including that they can escalate to the OAIC.
- Whether you are likely to disclose personal information overseas. If your CRM, cloud host or an offshore virtual assistant sits outside Australia, say so, and where practicable name the countries.
At a glance
| APP 1.4 requirement | What it means | Real estate example |
|---|---|---|
| Kinds of personal information | Categories you collect and hold | Tenant applications, ID copies, open-home sign-ins, vendor and landlord records |
| How you collect and hold it | Channels plus storage and security | Application portal, sign-in sheets, cloud CRM |
| Purposes | Why you collect, use and disclose it | Assess tenancy, manage listing, AML for sales, run rent roll |
| Access and correction | How a person requests and fixes their data | Named contact for APP 12 and APP 13 requests |
| Complaints | How to complain and how you respond | Complaint route plus escalation to the OAIC |
| Overseas disclosure | Whether data goes offshore, and where | Overseas CRM, cloud host or offshore virtual assistant |
Why does the sweep matter for agencies?
The sweep was not merely a paperwork exercise. For a lower-tier breach such as a non-compliant privacy policy, the OAIC can issue an infringement notice directly, without going to court, for a fraction of the court maximum. A court can impose more for this tier, up to $72,800 for an individual or $364,000 for a company in serious interferences with privacy (s 13G). Since 10 December 2024 a separate mid-tier civil penalty (s 13H) covers an interference that is not serious. These are ceilings, not the typical outcome, and many matters attract no penalty at all. The realistic risk is being asked to show a compliant, current policy and not having one.
A short, honest self-audit is a low-cost way to find the gaps before a regulator or a complaint does. Privaproof gives you an educational free self-audit to see where your policy stands, and a living Kit with a real-estate privacy policy kept current as guidance changes, so you meet your obligations rather than redrafting wording yourself. For the broader picture, see the 2026 OAIC privacy sweep for real estate.
Common questions
Does the OAIC sweep apply to my real estate agency?
The rental and property sector was named a target of the 2026 sweep. Whether the Privacy Act binds your specific agency depends on your circumstances, chiefly turnover and whether you do AML-covered sales work, but any agency that publishes a privacy policy should assume it could be assessed against APP 1.4 and make sure it is current.
Is a privacy policy the same as a collection notice?
No. A privacy policy is a standing document that satisfies APP 1.4 and describes your practices generally. A collection notice is given at or before the point you collect information under APP 5 and is specific to that collection. You need both. See do real estate agents need a privacy policy and a collection notice and the APP 5 collection notice guide.
What is the most common APP 1.4 failure for agencies?
A generic policy that never names what the agency really collects, and silence on overseas disclosure. Many agency policies do not mention tenant application data, ID copies or open-home sign-ins, and do not say that a cloud CRM or offshore assistant may put data overseas. Both are direct APP 1.4 gaps.
Do I need to name the overseas countries in my policy?
APP 1.4 requires you to state whether you are likely to disclose personal information overseas, and where practicable to specify the countries. If your CRM host, cloud storage or a virtual assistant is offshore, your policy should say so. If naming every country is not practicable, say that too, but do not stay silent on the fact of overseas disclosure.
This is general information, not legal advice. Privaproof provides tools and general information; it is not a law practice. Sources: OAIC privacy compliance sweep announcement; Australian Privacy Principle 1.4, Privacy Act 1988 (Cth).