Who can a real-estate business share tenant and client information with?
Under APP 6 you may use or disclose personal information for the primary purpose you collected it for. Anything beyond that is a secondary purpose and needs a basis: consent under APP 6.1(a), a reasonably expected and related secondary purpose under APP 6.2(a), a use or disclosure required or authorised by law under APP 6.2(b), a permitted general situation under APP 6.2(c), or an enforcement-related disclosure under APP 6.2(e). One important exception: direct marketing by an organisation is not an APP 6 question at all, because APP 6.7 hands it to APP 7.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
Can we give a tradesperson a tenant's phone number to arrange repairs?
Generally yes. Arranging repairs is part of managing the tenancy, so giving a contractor the minimum contact details needed to book access is ordinarily within the primary purpose and APP 6.1 is satisfied without needing an exception.
Two things the industry gets wrong. First, passing details to a contractor is a disclosure, not merely a supplier-management question. It is a "use" only where you retain effective control through a binding contract limiting the contractor to your purposes, and a verbal work order to a plumber does not meet that.
Second, and more important operationally: verify who you are speaking to. The call asking for a tenant's contact details is a standard pretexting route. Someone claiming to be the tradesperson you booked is how a former partner obtains a person's new address. Call back on the number you hold for that contractor, not the number the caller gives you. Never give out a tenant's forwarding address to a contractor.
Send a work order with a name, a mobile and the address. Not the maintenance thread, not the arrears context, not a note about the tenant being difficult. Where a tenant has asked that their number not be given out, coordinate access yourself.
Sources: Privacy Act 1988 (Cth), APP 6.1 and APP 11.1 (Schedule 1) · OAIC APP Guidelines chapters 6 and B · OAIC APP guidelines
Another agent has rung asking about a former tenant. Can we tell them?
Only within APP 6, and the first question is not what you may say but who you are actually talking to. An unverified inbound call claiming to be an agent from another office is the same pretexting route. Call back on the other agency's published number.
Then check the tenant nominated you as a referee. If they did not, you are disclosing to a third party with no basis.
When you do give a reference, it is about the tenancy you managed, not about where the person is now. Do not confirm a current address, a new managing agent, a workplace or a phone number. That is never necessary to answer a reference question, and it is the disclosure that can put someone in danger.
Stick to what your records support. APP 10.2 requires such steps as are reasonable to ensure information you disclose is accurate, up to date, complete and relevant, having regard to the purpose. A remembered impression is none of those. Do not pass on health information, family circumstances or anything else sensitive.
Sources: Privacy Act 1988 (Cth), APP 6.1, APP 6.2 and APP 10.2 (Schedule 1) · OAIC APP Guidelines chapters 6 and 10 · OAIC APP guidelines
A buyer wants to know why the vendor is selling. Can we tell them?
Not if the reason is the vendor's personal circumstances and they have not agreed you can share it. A divorce, a death, a health problem or financial distress is personal information about the vendor, and disclosing it to a buyer is a secondary purpose they would not reasonably expect.
You can say the vendor's plans are private and speak to the property. Where a reason genuinely helps the campaign, get the vendor's agreement to a specific form of words rather than improvising. Consent must be adequately informed, voluntary, current and specific, and given by someone with capacity, and voluntariness carries real weight where you are also advising them on the campaign.
Health information is sensitive information, which attracts the stricter "directly related" test under APP 6.2(a)(i), and "the buyer worked it out anyway" is not a defence to having confirmed it.
Sources: Privacy Act 1988 (Cth), section 6 and APP 6.1(a), APP 6.2(a) (Schedule 1) · OAIC APP Guidelines chapters 6 and B · OAIC APP guidelines
Can we pass buyer or seller leads to a mortgage broker or a related business?
Not by default, but this is easier to do lawfully than it looks. The clean basis is the client's consent under APP 6.1(a): you offer the introduction, they say yes, you pass the details. The non-compliant version is the automatic overnight feed, where every enquiry is copied to the broker because the systems are joined.
The part usually left out matters more than the rule. A referral model does not automatically cost a smaller business its small-business exemption. Section 6D treats an operator that discloses personal information for a benefit, service or advantage as trading in personal information, which removes the exemption. But s 6D(7) and (8) carve out disclosures made with the individual's consent, and those required or authorised by legislation. A consented referral sits inside that carve-out. So the model above is both the privacy-compliant version and the one that protects your exemption. An unconsented automatic feed is what puts it at risk.
Being paid for the referral is precisely what engages the s 6D analysis, which is why the consent carve-out matters so much here.
Sources: Privacy Act 1988 (Cth), ss 6D, 6D(7) and 6D(8), and APP 5, APP 6.1(a) and APP 8 (Schedule 1) · OAIC APP Guidelines chapters 5 and 6 · OAIC APP guidelines
When are we required or authorised by law to hand over tenant information?
More often than a cautious office rule assumes, and this is worth knowing precisely, because being wrong conservatively still has a cost.
- Someone is at risk. s 16A(1) Item 1, reached through APP 6.2(c), applies where you reasonably believe the use or disclosure is necessary to lessen or prevent a serious threat to the life, health or safety of any individual or to public health or safety, and it is unreasonable or impracticable to obtain consent. Note what is not required: the threat does not have to be imminent. That word was removed from the law in 2014, so a threat likely to occur at an uncertain time can still be serious.
⚠️ This exception fails in two directions, and the second one is worse. Holding back in a genuine welfare check applies a test that no longer exists. But the dominant failure in real-estate practice is disclosing a person's new location to someone presenting as concerned, typically an ex-partner or a family member. Item 1 requires a belief that this disclosure, to this recipient, is necessary to lessen the threat. That almost never supports giving a private individual a forwarding address. It supports contacting police or the person at risk. If someone is worried about a former tenant, take their details and contact the police yourself.
- You suspect fraud against your own business. s 16A(1) Item 2 covers a reasonable suspicion of unlawful activity, or misconduct of a serious nature, relating to your functions or activities, where you reasonably believe the use or disclosure is necessary in order for you to take appropriate action in relation to the matter. Forged payslips and application fraud sit here.
- You are pursuing or defending a claim. s 16A(1) Item 4 covers use or disclosure reasonably necessary to establish, exercise or defend a legal or equitable claim. The OAIC reads this narrowly: there must be a real possibility of legal proceedings, not merely a dispute. Routine arrears reporting to the landlord does not need Item 4 at all, because it is within the primary purpose. Do not treat Item 4 as a general licence to pass information to debt collectors or insurers.
- Police and enforcement bodies. APP 6.2(e) permits disclosure where you reasonably believe it is reasonably necessary for one or more enforcement related activities conducted by, or on behalf of, an enforcement body. Three things are commonly missed. "Enforcement related activity" and "enforcement body" are defined terms in s 6(1), so not everything police ask for qualifies. The belief must have a reasonable basis, not merely be genuine or subjective, and you must be able to justify it. And the exception permits, it never compels: nothing in the Privacy Act obliges you to hand anything over under 6.2(e).
So verify the request, then disclose the minimum. A dated, signed written request from the enforcement body gives you a reasonable basis. An unverified phone call does not. Call back on the organisation's published number before disclosing anything, for the same reason this page gives twice above: the caller category most likely to be impersonated is the official-sounding one. Disclose only what is reasonably necessary, not the file.
Where you disclose in reliance on APP 6.2(e), APP 6.5 requires you to make a written note of the use or disclosure. That is mandatory, not best practice.
Sources: Privacy Act 1988 (Cth), s 6(1) (definitions of "enforcement body" and "enforcement related activity"), s 16A(1) Items 1, 2 and 4, and APP 6.2(b), 6.2(c), 6.2(e) and APP 6.5 (Schedule 1) · OAIC APP Guidelines chapters 6 (paragraphs 6.59, 6.60 and 6.64) and C · OAIC APP guidelines
An agent has joined us with their old buyer database. Can we use it?
Treat it as a serious risk, and treat the information as unsolicited. "Solicits" means you requested it. Merely receiving a list an incoming agent brought with them is not a request, and the OAIC's guidance is that where it is unclear you should err on the side of caution and treat information as unsolicited.
That matters, because APP 4 then sets a faster and non-discretionary clock than the one people reach for:
- APP 4.1: decide within a reasonable period whether you could have collected the information under APP 3.
- APP 4.3: if you could not have, destroy or de-identify it as soon as practicable, where lawful and reasonable. That is not the same as APP 11.2's "once you no longer need it", which the holder effectively controls.
- APP 4.4: if you could have collected it under APP 3, then APPs 5 to 13 apply as though you had, which switches on an APP 5 notification duty to every person on that list. Keeping the list is not the cheap option.
Had you actually asked for the list, it would be solicited collection, and the cleanest breach is APP 3.6: collect personal information about an individual only from that individual, unless it is unreasonable or impracticable to do so.
The practical answer for a principal is to decline the list, say so in writing at onboarding, and make it an express term of employment, which also protects you when the same agent leaves you later.
⚠️ Do not email or SMS the list at all, including one message at a time. The Spam Act has no bulk threshold: a single unsolicited commercial electronic message is enough. So "email them individually to invite them to opt in" is not a safe workaround, it is the same contravention retail. A permission request is itself a commercial electronic message.
⚠️ Phone contact is not a free pass either. A call offering your services is a telemarketing call, which engages the Do Not Call Register Act. If you are going to call at all, the numbers need to be washed against the Register or covered by consent.
Consent given to the former business will not usually extend to yours, though under the Spam Act it can depend on how that consent was framed.
Sources: Privacy Act 1988 (Cth), APP 3.6, APP 4.1, APP 4.3, APP 4.4 and APP 5 (Schedule 1); Spam Act 2003 (Cth); Do Not Call Register Act 2006 (Cth) · OAIC APP Guidelines chapter 4, paragraphs 4.6, 4.7 and 4.9 · ACMA spam rules · OAIC APP guidelines
→ The free 2-minute audit covers the data a real-estate business holds without a clear basis, which is usually where this shows up.