Australian Rental Platforms Under Fire for Extensive Data Collection and Security Risks
New research reveals that Australian rental application platforms frequently demand a vast array of personal data from applicants, raising significant alarms regarding privacy, data security, and the potential for breaches. A report from the Australian Housing and Urban Research Institute (AHURI) highlights that some platforms require applicants to answer up to 50 questions, potentially exceeding the information genuinely needed for suitability assessments. This widespread issue has sparked urgent calls for updated regulations and enhanced safeguards to protect renters' sensitive information.
Extensive Data Collection Practices
The AHURI report, co-authored by Dr. Sophia Maalsen from the University of Sydney, indicates that the housing sector's growing reliance on technology has normalized the collection of increasingly private information from renters. This practice extends beyond standard requirements like income verification and references. Some platforms now delve into details such as lifestyle choices, household composition, pet ownership, and smoking habits.
Tenants often report feeling pressured to provide all requested information to enhance their application prospects, contributing to a significant power imbalance.
Concerns are also mounting that these platforms empower real estate agents to filter applications based on specific characteristics, potentially leading to selection biases.
Privacy and Security Risks
The extensive collection of personal data by rental platforms creates profound risks for renters' data security and privacy. The report noted that renters frequently lack clarity regarding where their data is stored, who has access to it, and precisely how it might be used to profile or rank applicants. Data shared through these platforms can be distributed across multiple organizations, potentially increasing vulnerability to breaches.
An individual identified as Michael experienced a severe incident where his digital identity was compromised over two months. His mobile phone number was transferred to an unauthorized individual, leading to access to his passport number, bank, and superannuation accounts. Michael suspected the breach originated from information he had submitted to online rental application platforms.
A separate analysis indicated that millions of leasing documents held by seven rent platforms could be accessible online without authentication. Dr. Maalsen emphasized that while these platforms offer benefits, their security levels can vary widely, and they are not immune to hacking.
Regulatory Landscape and Industry Response
Existing regulations are deemed insufficient by the AHURI report to address the current technological landscape. Notably, some real estate agents and prop tech platforms with an annual turnover under $3 million are exempt from Australia's Privacy Act. There is growing concern that policies and safeguards have failed to keep pace with rapid technological advancements and the integration of artificial intelligence.
In August 2023, the National Cabinet discussed limiting data collection to two pieces of evidence, though no federal rollout has occurred. The New South Wales (NSW) government has, however, introduced The Residential Tenancies Amendment Protection of Personal Information Bill. This bill aims to prevent unnecessary collection of personal information, thereby reducing risks of identity theft and data breaches for tenants, platforms, and agents.
NSW Rental Commissioner Trina Jones highlighted that approximately 187,000 pieces of identification are collected weekly from NSW renters without consistent standards for storage or destruction.
Jacob Caine, president of the Real Estate Institute of Australia (REIA), acknowledged agents' legal obligation to verify tenant identities, which necessitates personal information collection. He stressed the importance for agencies to ensure that online platforms comply with privacy obligations and meet high privacy and security standards. The REIA supports robust regulatory oversight and aims to reduce the collection and storage of sensitive documents through initiatives such as the federal government’s digital ID rental pilot. Caine noted that collecting less data inherently reduces exposure.
However, Caine also pointed out a conflicting demand: new anti-money laundering reforms, effective from July 1, will require the real estate sector to collect more data, compelling agents to maintain additional records, monitor, and report suspicious activity. He described the utilization of digital ID as a forward-looking solution that could enhance privacy, improve efficiency, and provide renters with assurance regarding information security.
Social Housing Context
Digitization in social housing applications can streamline processes and potentially help prioritize vulnerable tenants, accelerating assessments. However, given the highly sensitive nature of data often collected in this sector, such as medical records and police reports, strong governmental data security and privacy frameworks are considered essential. The potential for connecting various government databases through these systems necessitates proactive data security measures.
Calls for Action
Experts and industry representatives are united in their calls for enhanced regulation and clearer standards. Dr. Maalsen, Trina Jones, and Jacob Caine have all advocated for significant improvements. The REIA anticipates an influx of new regulatory technology providers who must demonstrate strong governance, verified cybersecurity credentials, and a clear understanding of privacy obligations due to the inherent risks involved.