Data protection is the legal duty of brokers and lenders to handle customers' personal information under the Privacy Act and the Australian Privacy Principles, from collection to secure destruction.
Also known as: privacy compliance, personal information handling, data security for brokers
Key points
- The Privacy Act 1988 and its Australian Privacy Principles (APPs) apply to brokers, licensees and lenders holding payslips, bank statements, tax returns and ID.
- Collect only what the lending purpose needs, tell customers why, and use or share it only for that purpose or one directly related.
- Protect it from misuse, loss and unauthorised access with encryption, access controls and secure file transfer, and destroy it when no longer needed.
- Customers can ask to see their information, and a breach likely to cause serious harm must be reported to the OAIC and those affected.
- KYC checks are why ID is collected and credit reporting is why data may go to credit bureaus; customers should be told both.
What information brokers and lenders hold
A single finance application carries a lot of personal information: name, date of birth, address, email and phone; bank account details, payslips, tax returns, liabilities and credit history; employer, role and tenure; and copies of driver licences, passports and utility bills. Some of it is sensitive in the legal sense, and all of it is valuable to a fraudster.
That is why the Privacy Act treats the lending process as high-stakes. Loss or unauthorised access can lead to identity fraud and financial loss for the customer, regulatory action against the business, and reputational damage that ends referral relationships. Every broker, credit licensee and lender that collects this material is responsible for it from the moment it arrives until it is securely destroyed.
Obligations under the Privacy Act
The Australian Privacy Principles set the rules. Collection: gather information only for a lawful lending purpose, tell customers what you collect and why, and collect no more than you need. Use and disclosure: use it only for the lending purpose or something directly related, such as passing it to a lender, an aggregator or a valuer, and use it for direct marketing only within the limits of APP 7, which generally means the customer would reasonably expect it and can opt out easily.
Security: protect it from misuse, interference, loss and unauthorised access or disclosure, meaning encryption, secure storage, access controls and careful handling. Retention and destruction: keep it only as long as needed, then destroy or de-identify it securely rather than holding payslips indefinitely. Access: give customers their information on request. And publish a clear privacy policy explaining all of this.
Practical controls and common mistakes
The failures are predictable. Payslips and bank statements sent as plain email attachments. Customer files sitting on a personal laptop, phone or USB stick without encryption. No retention schedule, so documents pile up for years. Vague consent, so customers do not realise their information goes to lenders and credit bureaus. Every staff member able to open every file, often through a single shared login.
The fixes are just as concrete. Send documents through password-protected transfer, secure cloud folders with access controls or encrypted email, with expiry dates where possible. Encrypt local drives and backups and use a password manager. Give each person their own login, restrict access by role and log who opens sensitive documents. Write down how long you keep each document type and actually run the destruction, using secure deletion or shredding. Put a privacy collection notice in your engagement letter and get consent before sharing outside the lending process.
Notifiable data breaches and the OAIC
If personal information is accessed or disclosed without authorisation and that is likely to result in serious harm, it is an eligible data breach and you must notify the OAIC and the affected people as soon as practicable. The sequence is: contain the breach and stop further exposure, assess whether it is eligible and document the reasoning, notify with a description of what happened, what data was involved, the likely impact and what customers can do, then keep a record of the decision.
The Office of the Australian Information Commissioner investigates complaints and notified breaches, can order remedial action, apologies or compensation, and can seek civil penalties in court for serious breaches. Slow or inadequate notification makes all of that worse. Good records of your privacy decisions are your best protection if the OAIC asks questions.
Example
A broker's assistant emails a customer's payslips and bank statements to a lender as plain attachments and mistypes the address, so the email lands with a stranger. That is a likely breach of the security principle. The broker contains it by asking the recipient to delete the email and confirm in writing, assesses whether the exposure is likely to cause serious harm (bank details and identity documents usually are), notifies the customer and the OAIC, and records the reasoning and every step taken. From then on, documents go through the lender's secure portal or a password-protected link, never as open attachments.
Not to be confused with
- Privacy Act
- the Privacy Act is the law; data protection is the day-to-day practice of complying with it
- OAIC
- the OAIC is the regulator that enforces privacy law, not the obligation itself
- Know your customer (KYC)
- KYC is why you collect identity documents; data protection governs how you store, share and destroy them
Frequently asked questions
What does the Privacy Act require brokers to do with customer data?
Collect personal information only for the lending purpose and tell customers why, use and disclose it only for that purpose or a directly related one such as a referral to a lender, keep it secure against loss and unauthorised access, destroy it when it is no longer needed, give customers access on request and maintain a written privacy policy.
Is emailing a payslip a privacy breach?
Sending payslips, bank statements or ID as unencrypted email attachments is a serious risk. If the email reaches the wrong person or the recipient's account is compromised, you have likely breached the security principle and may have a notifiable data breach on your hands. Use encrypted email, password-protected transfer or a secure portal instead, and tell your compliance officer if it happens.
How long should a broker keep customer documents?
Only as long as they are needed for the lending purpose and any legal retention requirement, such as the periods that apply to tax and financial records, then destroy them securely. Write the periods into a retention schedule, check whether your professional indemnity insurer expects anything longer, and do not keep documents indefinitely just in case.
Do I need a privacy policy as a broker?
Yes. The first Australian Privacy Principle requires a clearly expressed, up-to-date privacy policy. It should say what personal information you collect, why, how you use it, who you disclose it to such as lenders, aggregators and credit reporting bodies, how customers can access or correct it, how you protect it and how to complain. Keep it short and readable.
What do I do if customer data is breached?
Contain it first: stop the ongoing exposure. Then assess whether unauthorised access or disclosure is likely to cause serious harm, documenting your reasoning. If it is, notify the OAIC and the affected customers as soon as practicable, explaining what happened, what data was involved, the likely impact and what they can do, such as monitoring their credit. Keep a record of every step.
Related terms
Privacy Act
The Privacy Act 1988 is the Australian law that sets out how government agencies and many organisations must collect, use, disclose and correct personal information, including credit reporting data.
Read definitionOAIC
The OAIC is the Office of the Australian Information Commissioner, Australia's independent privacy regulator, which enforces the Privacy Act, the Australian Privacy Principles and the Notifiable Data Breaches scheme.
Read definitionKnow your customer (KYC)
Know your customer (KYC) is the process a reporting entity uses to identify and verify a customer, understand their business and assess the money laundering and terrorism financing risk.
Read definitionComprehensive credit reporting (CCR)
Comprehensive credit reporting (CCR) is the system under which lenders share positive credit information, such as repayment history and credit limits, as well as defaults, on your credit file.
Read definitionFraud
Fraud is deliberate deception or misrepresentation intended to secure an unfair or unlawful gain or cause loss, such as false documents on a loan application.
Read definitionAustralian credit licence (ACL)
An Australian credit licence (ACL) is the authorisation from ASIC that a business needs to provide consumer credit or credit assistance under the National Consumer Credit Protection Act.
Read definitionGo deeper
Sources
This article is general information only and is not financial advice.