Skip to content

When does a real-estate agency actually need consent?

Mostly, you don't. For ordinary personal information you reasonably need (names, contact details, rental-application basics), the Privacy Act asks you to notify people (a collection notice under APP 5), not to obtain signed consent. Genuine consent is required in narrower cases: collecting sensitive information (health, criminal record, biometric information used for automated identification), using information for an unrelated secondary purpose, and some direct marketing.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price, rising to A$649 on 1 Oct 2026

Orientation only, not a compliance assessment. General information and tools, not legal advice.

Consent and a collection notice do different jobs, and treating them as one document is what produces signatures you don't need and gaps where the notice should be. A collection notice (Australian Privacy Principle 5) is something you give people at the point you collect their details, telling them who you are, what you're collecting, why, and who you share it with. Consent is something you get from people, and under s 6(1) consent means express consent or implied consent, so "signed" was never the test. For most of what an agency collects, the law asks for the notice. Does your rental application collect a signature where APP 5 only asks you to notify? (See Privacy policy vs collection notice.)

For most everyday collection, you don't need consent; you need a lawful reason to collect and a clear notice. Under APP 3.2, an organisation may collect personal information (other than sensitive information) that is reasonably necessary for one or more of its functions or activities. Taking a tenant's name, contact details, employment and rental history on an application; recording a vendor's details when you take a listing; logging attendees at an open home, this is personal information you reasonably need to do your job, so APP 3.2 lets you collect it without asking permission. APP 5.1 then asks you to take such steps as are reasonable in the circumstances to notify, which is the APP 5 collection notice. Collecting from someone else, a previous landlord say, turns on APP 3.6, which for an organisation asks whether collecting from the individual is unreasonable or impracticable, not whether they consented.

Consent becomes a real requirement in a small number of defined situations. The four that matter for an agency are:

Outside situations like these, "get everyone to sign a consent form" is not what the Act asks for, and a blanket signed consent doesn't cure a missing collection notice.

What counts as sensitive information in real estate?

Sensitive information is a closed list in s 6(1) of the Privacy Act, and it's a higher bar than ordinary personal information, collecting it generally needs consent. It covers health and genetic information, racial or ethnic origin, religious, philosophical or political beliefs and memberships, union or professional membership, sexual orientation or practices, criminal record, biometric information to be used for automated verification or identification, and biometric templates. If it is not on that list it is not sensitive information, however private it feels. Three places it does turn up in an agency:

A driver licence or passport collected for verification is personal information, and it is not sensitive information: no identity document appears on the closed s 6(1) list. What you do with it can change that. Run the photo through an automated face match and you are using biometric information for automated biometric verification, which is paragraph (d) of the definition, and any template you keep is paragraph (e), so APP 3.3 consent attaches. When sensitive information genuinely is in play, get the person's consent, collect only what you reasonably need, and say why. (For ID collected under AML customer due diligence, a "required or authorised by law" pathway can apply instead, see Do you need consent to collect ID for AML checks?: real-estate services became designated services on 31 March 2026, and the customer due diligence obligations apply from 1 July 2026.)

APP 6 governs reuse, and it is where a genuine consent question arises. You collect information for a primary purpose, say, processing a rental application. You can use it for that. A secondary purpose is allowed only if the person consents (APP 6.1(a)), or an APP 6.2 exception applies: usually that they would reasonably expect the use and it is related to the primary purpose (directly related, for sensitive information), or that it is required or authorised by law. Passing a rejected applicant's details to a related agency for a different property may be within expectations; selling or trading your tenant database generally is not, and the exemption is at stake too: s 6D(4)(c) says a business that discloses personal information about an individual for a benefit, service or advantage is not a small business operator, and s 6D(7) preserves that status only where the individual consented or legislation required the disclosure. The safe habit: collect for a stated purpose, and don't quietly repurpose the data for something the person wouldn't see coming.

Marketing to your database sits under its own rules, and "just add them to the newsletter" steps over two regimes at once. Under APP 7.2, an organisation may use personal information (other than sensitive information) it collected directly from the person for direct marketing where they'd reasonably expect it, you give a simple opt-out, and they haven't already opted out. But under APP 7.4 you must not use sensitive information for direct marketing without consent. There's no reasonable-expectation shortcut there. Separately, the Spam Act 2003 (enforced by ACMA, not the OAIC) governs marketing emails and SMS: the message needs consent, express or in limited cases inferred (Sch 2 cl 2), under s 16, accurate sender identification (s 17) and a functional unsubscribe (s 18). To that extent APP 7.8 stands APP 7 down, so email and text marketing is effectively a consent-and-unsubscribe regime. (Marketing phone calls and faxes fall under the Do Not Call Register regime.)

Where consent is required, a signature on a form isn't automatically enough, and isn't always necessary: s 6(1) defines consent as express consent or implied consent. The OAIC's APP Guidelines (Chapter B, B.38) treat valid consent as having four elements: the person is adequately informed before consenting, the consent is voluntary, it is current and specific, and the person has the capacity to understand and communicate it. So bundled consent (a single "I agree" sweeping in unrelated things) is weak, and the OAIC says silence is difficult to establish as consent (B.42). If a use genuinely needs consent, ask for it clearly, for that specific thing, at the right time.

Common myths

No. For ordinary personal information you reasonably need (application details, contact information, open-home sign-ins) APP 3.2 lets you collect it and APP 5.1 requires you to take reasonable steps to notify, which is the collection notice, not consent. Reserve consent for sensitive information, unrelated secondary uses, overseas disclosure you rely on consent for, and marketing.

Not necessarily. On the OAIC's APP Guidelines (Chapter B, B.38) consent must be informed, voluntary, current and specific. A blanket signature or a bundled "I agree" doesn't stretch to cover uses the person was never told about, and it doesn't replace the collection notice you were required to give.

They do different jobs. A collection notice tells people what you're doing (APP 5); a consent form records their agreement to something that genuinely needs it. List your own collection points and mark them off: APP 5 puts a notice at each one, and a consent step belongs only at the narrow cases above.

"Health or criminal-record details are fine to collect if the tenant volunteered them."

Be careful, and check which principle applies. Health information and criminal record are sensitive information (s 6(1)), and where you asked for them APP 3.3 requires consent plus a reasonable need. Where you did not ask, which is often the case when a tenant volunteers a health reason, APP 4 applies: you must decide within a reasonable period whether you could have collected it under APP 3, and if not, destroy or de-identify it as soon as practicable, where lawful and reasonable (APP 4.1, 4.3). Volunteering it is not an open licence to keep it for other purposes.

"Adding buyers and vendors to our marketing list is automatic once they've dealt with us."

Not for email and SMS. The Spam Act 2003 requires consent for the message (s 16) and a functional unsubscribe in it (s 18), APP 7.2 requires a simple opt-out, and APP 7.4 requires consent before you ever use sensitive information for marketing.


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice. Laws and regulator guidance change. Where consent genuinely applies to your situation, or you're unsure, get advice for your specific circumstances. Not sure which of your collection points need a notice and which need consent? Start with the free 2-minute self-audit. Sources: OAIC, APP Guidelines Chapter B: key concepts (consent); OAIC, Chapter 3: APP 3 collection of solicited personal information; OAIC, Chapter 5: APP 5 notification of the collection; OAIC, Chapter 6: APP 6 use or disclosure; OAIC, Chapter 7: APP 7 direct marketing; Privacy Act 1988 (Cth) s 6 "sensitive information", s 6D and Schedule 1; Spam Act 2003 (Cth); ACMA, spam and telemarketing rules.