The Times Australia
The Times Australia
.

Renting a home in Australia means handing over too much sensitive info. It’s a national security risk

  • Written by Moataz ElQadi, Adjunct Researcher, Faculty of Information Technology, Monash University

Our personal information[1] is more valuable than ever. The most recent government cyber threat report warns that foreign state actors have an[2] “enduring interest” in obtaining sensitive and personally identifiable information about Australians.

In recent weeks, Prime Minister Anthony Albanese noted[3] “there is a cyber attack in Australia roughly every six minutes. This is a regular issue.”

In some situations, it can be difficult to protect our info even when we’re aware of the risks. Notably, in Australia many rental providers and their agents collect, store and disclose excessive personal information on potential tenants. Sometimes, they collect more info than what’s needed to get a government security clearance.

With about one-third[4] of Australian households being renters, the handling of renters’ data is a major concern for Australia’s information security.

So what information are real estate agents collecting, and how can we mitigate the risks?

Steep competition for rentals

For several years now, Australia has faced a rental crisis[5]. Low vacancy rates[6] – below 1% in some capital cities – not only drive up rental prices[7], but can result in “bidding wars” over rentals[8].

With renters competing for housing, rental providers are empowered to command larger rent increases[9]. They also require potential tenants to provide extensive personal information.

For tenants, sharing – or oversharing – of personal information in the hope of securing a home might seem acceptable.

However, the collection and handling of this information raises serious security concerns. If Australians’ sensitive personal data falls into the hands of cyber criminals, or foreign agents, this has security implications for the entire nation.

What info are renters asked for?

Potential tenants need to provide information to the satisfaction of the real estate agent and their client, the rental provider. This information is increasingly collected online via rental application websites where the form questions are controlled by real estate agents[10].

The websites themselves are subject to the Australian Privacy Act 1988[11], but the data is handed over to real estate agents and owners.

The rental application websites seem to recognise that this information is extensive: one rental application website started selling[12] a privacy service where they vouch for the applicant instead of sharing their information with the real estate agents.

In some cases, the requested data matches or even exceeds the requirements for a government security clearance[13]. The Australian Government Security Vetting Agency (AGSVA) has a clear public privacy statement[14]. It explains how data is collected and handled and used only for the assessment of a security clearance. Rental providers don’t necessarily follow the same stringent rules.

Information collected by some rental application forms may include five or more years of address history. Others request five or more years of employment history. In addition, financial information such as payslips and bank statements are also required.

Other sensitive – and irrelevant – information includes vehicle registration numbers and pet names.

Potential tenants are also usually asked to attach personal identification documents including passports, driver licences and Medicare cards. They may be asked to list up to two personal and one business references.

Screenshot of a rental application form requesting employment history.
A rental agent may require five years of employment history. Author provided

If any of this information falls into the wrong hands, it easily exposes the person to social engineering[15], personalised scams[16] or identity and account theft.

Who can access the info?

The names of family members and pet names are a common – albeit unsafe – choice of password. The rental application forms collect both. In Australia, research by Telstra and YouGov found[17] that 20% of Australians used pets’ names as passwords, and 17% used their birth dates.

Pet names may be required on rental applications. This can give away some people’s passwords. Author provided

If a rental provider, or their agent, shares applicant information with others, it can be a security breach. This makes the storage, handling and sharing of this information by private rental providers a major concern.

Rental agency agreements commonly state that personal information can be disclosed to “any person who maintains any record, listing or database of defaults by tenants.”[18] This policy, which a tenant has to accept, is already loose.

More importantly, after the information is sent to the owner of the rental property, there is no visibility as to who that is, or what they do with the information.

Example of a privacy agreement on a rental application form. Author provided

Too much info to rent a home

Having to share extensive personal information is more than an inconvenience for renters – it’s a serious security concern. The government should put explicit limits on personal information requested by rental providers.

One technological solution to this problem could be “access tokens” provided by banks. People in Australia are protected by the Consumer Data Right[19]. This allows consumers to authorise a data holder, such as a bank, to share data with an accredited recipient.

Australian banks are held to strict information security requirements[20]. They already handle highly sensitive data, such as client identity, income sources and other financial information.

If real estate agents require proof of this info to vet potential rental applicants, they could request it through an authorisation token with the applicant’s bank. This way, proof of identity and financial status could be shared without having to disclose actual sensitive personal information, limiting the cyber security risk.

In the meantime, rental providers and their agents should request the least possible amount of personal information – it’s the responsible thing to do.

References

  1. ^ personal information (www.oaic.gov.au)
  2. ^ foreign state actors have an (www.cyber.gov.au)
  3. ^ noted (www.abc.net.au)
  4. ^ one-third (www.aihw.gov.au)
  5. ^ faced a rental crisis (www.abc.net.au)
  6. ^ vacancy rates (propertyupdate.com.au)
  7. ^ drive up rental prices (www.abs.gov.au)
  8. ^ in “bidding wars” over rentals (www.abc.net.au)
  9. ^ larger rent increases (www.abs.gov.au)
  10. ^ controlled by real estate agents (help.2apply.com.au)
  11. ^ subject to the Australian Privacy Act 1988 (www.oaic.gov.au)
  12. ^ started selling (www.smh.com.au)
  13. ^ government security clearance (www.agsva.gov.au)
  14. ^ privacy statement (www.agsva.gov.au)
  15. ^ social engineering (www.cyber.gov.au)
  16. ^ personalised scams (www.scamwatch.gov.au)
  17. ^ Telstra and YouGov found (www.telstra.com.au)
  18. ^ “any person who maintains any record, listing or database of defaults by tenants.” (www.google.com)
  19. ^ Consumer Data Right (www.accc.gov.au)
  20. ^ strict information security requirements (www.apra.gov.au)

Read more https://theconversation.com/renting-a-home-in-australia-means-handing-over-too-much-sensitive-info-its-a-national-security-risk-254293

Jim Chalmers wants roundtable to ‘crack open’ the challenge of slow housing approvals

The Reserve Bank’s rate cut this week will help relieve many mortgage holders, but it wasn’t all positive news...

Times Magazine

DIY Is In: How Aussie Parents Are Redefining Birthday Parties

When planning his daughter’s birthday, Rich opted for a DIY approach, inspired by her love for drawing maps and giving clues. Their weekend tradition of hiding treats at home sparked the idea, and with a pirate ship playground already chosen as t...

When Touchscreens Turn Temperamental: What to Do Before You Panic

When your touchscreen starts acting up, ignoring taps, registering phantom touches, or freezing entirely, it can feel like your entire setup is falling apart. Before you rush to replace the device, it’s worth taking a deep breath and exploring what c...

Why Social Media Marketing Matters for Businesses in Australia

Today social media is a big part of daily life. All over Australia people use Facebook, Instagram, TikTok , LinkedIn and Twitter to stay connected, share updates and find new ideas. For businesses this means a great chance to reach new customers and...

Building an AI-First Culture in Your Company

AI isn't just something to think about anymore - it's becoming part of how we live and work, whether we like it or not. At the office, it definitely helps us move faster. But here's the thing: just using tools like ChatGPT or plugging AI into your wo...

Data Management Isn't Just About Tech—Here’s Why It’s a Human Problem Too

Photo by Kevin Kuby Manuel O. Diaz Jr.We live in a world drowning in data. Every click, swipe, medical scan, and financial transaction generates information, so much that managing it all has become one of the biggest challenges of our digital age. Bu...

Headless CMS in Digital Twins and 3D Product Experiences

Image by freepik As the metaverse becomes more advanced and accessible, it's clear that multiple sectors will use digital twins and 3D product experiences to visualize, connect, and streamline efforts better. A digital twin is a virtual replica of ...

The Times Features

How to Choose a Cosmetic Clinic That Aligns With Your Aesthetic Goals

Clinics that align with your goals prioritise subtlety, safety, and client input Strong results come from experience, not trends or treatment bundles A proper consultation fe...

7 Non-Invasive Options That Can Subtly Enhance Your Features

Non-invasive treatments can refresh your appearance with minimal downtime Options range from anti-wrinkle treatments to advanced skin therapies Many results appear gradually ...

What is creatine? What does the science say about its claims to build muscle and boost brain health?

If you’ve walked down the wellness aisle at your local supermarket recently, or scrolled the latest wellness trends on social media, you’ve likely heard about creatine. Creati...

Whole House Water Filters: Essential or Optional for Australian Homes?

Access to clean, safe water is something most Australians take for granted—but the reality can be more complex. Our country’s unique climate, frequent droughts, and occasional ...

How Businesses Turn Data into Actionable Insights

In today's digital landscape, businesses are drowning in data yet thirsting for meaningful direction. The challenge isn't collecting information—it's knowing how to turn data i...

Why Mobile Allied Therapy Services Are Essential in Post-Hospital Recovery

Mobile allied health services matter more than ever under recent NDIA travel funding cuts. A quiet but critical shift is unfolding in Australia’s healthcare landscape. Mobile all...