What is data protection?

Claudia AinsleyWritten byClaudia Ainsley
Reviewed byMatt Leeburn
Updated 26 Aug 2026

Data protection is the legal duty of brokers and lenders to handle customers' personal information under the Privacy Act and the Australian Privacy Principles, from collection to secure destruction.

Also known as: privacy compliance, personal information handling, data security for brokers

Key points

  • The Privacy Act 1988 and its Australian Privacy Principles (APPs) apply to brokers, licensees and lenders holding payslips, bank statements, tax returns and ID.
  • Collect only what the lending purpose needs, tell customers why, and use or share it only for that purpose or one directly related.
  • Protect it from misuse, loss and unauthorised access with encryption, access controls and secure file transfer, and destroy it when no longer needed.
  • Customers can ask to see their information, and a breach likely to cause serious harm must be reported to the OAIC and those affected.
  • KYC checks are why ID is collected and credit reporting is why data may go to credit bureaus; customers should be told both.

What information brokers and lenders hold

Obligations under the Privacy Act

Practical controls and common mistakes

Notifiable data breaches and the OAIC

Example

Not to be confused with

Privacy Act
the Privacy Act is the law; data protection is the day-to-day practice of complying with it
OAIC
the OAIC is the regulator that enforces privacy law, not the obligation itself
Know your customer (KYC)
KYC is why you collect identity documents; data protection governs how you store, share and destroy them

Frequently asked questions

What does the Privacy Act require brokers to do with customer data?

Collect personal information only for the lending purpose and tell customers why, use and disclose it only for that purpose or a directly related one such as a referral to a lender, keep it secure against loss and unauthorised access, destroy it when it is no longer needed, give customers access on request and maintain a written privacy policy.

Is emailing a payslip a privacy breach?

Sending payslips, bank statements or ID as unencrypted email attachments is a serious risk. If the email reaches the wrong person or the recipient's account is compromised, you have likely breached the security principle and may have a notifiable data breach on your hands. Use encrypted email, password-protected transfer or a secure portal instead, and tell your compliance officer if it happens.

How long should a broker keep customer documents?

Only as long as they are needed for the lending purpose and any legal retention requirement, such as the periods that apply to tax and financial records, then destroy them securely. Write the periods into a retention schedule, check whether your professional indemnity insurer expects anything longer, and do not keep documents indefinitely just in case.

Do I need a privacy policy as a broker?

Yes. The first Australian Privacy Principle requires a clearly expressed, up-to-date privacy policy. It should say what personal information you collect, why, how you use it, who you disclose it to such as lenders, aggregators and credit reporting bodies, how customers can access or correct it, how you protect it and how to complain. Keep it short and readable.

What do I do if customer data is breached?

Contain it first: stop the ongoing exposure. Then assess whether unauthorised access or disclosure is likely to cause serious harm, documenting your reasoning. If it is, notify the OAIC and the affected customers as soon as practicable, explaining what happened, what data was involved, the likely impact and what they can do, such as monitoring their credit. Keep a record of every step.

Go deeper

Sources

This article is general information only and is not financial advice.