The Times Australia
Google AI
The Times Australia
.

Renting a home in Australia means handing over too much sensitive info. It’s a national security risk

  • Written by Moataz ElQadi, Adjunct Researcher, Faculty of Information Technology, Monash University

Our personal information[1] is more valuable than ever. The most recent government cyber threat report warns that foreign state actors have an[2] “enduring interest” in obtaining sensitive and personally identifiable information about Australians.

In recent weeks, Prime Minister Anthony Albanese noted[3] “there is a cyber attack in Australia roughly every six minutes. This is a regular issue.”

In some situations, it can be difficult to protect our info even when we’re aware of the risks. Notably, in Australia many rental providers and their agents collect, store and disclose excessive personal information on potential tenants. Sometimes, they collect more info than what’s needed to get a government security clearance.

With about one-third[4] of Australian households being renters, the handling of renters’ data is a major concern for Australia’s information security.

So what information are real estate agents collecting, and how can we mitigate the risks?

Steep competition for rentals

For several years now, Australia has faced a rental crisis[5]. Low vacancy rates[6] – below 1% in some capital cities – not only drive up rental prices[7], but can result in “bidding wars” over rentals[8].

With renters competing for housing, rental providers are empowered to command larger rent increases[9]. They also require potential tenants to provide extensive personal information.

For tenants, sharing – or oversharing – of personal information in the hope of securing a home might seem acceptable.

However, the collection and handling of this information raises serious security concerns. If Australians’ sensitive personal data falls into the hands of cyber criminals, or foreign agents, this has security implications for the entire nation.

What info are renters asked for?

Potential tenants need to provide information to the satisfaction of the real estate agent and their client, the rental provider. This information is increasingly collected online via rental application websites where the form questions are controlled by real estate agents[10].

The websites themselves are subject to the Australian Privacy Act 1988[11], but the data is handed over to real estate agents and owners.

The rental application websites seem to recognise that this information is extensive: one rental application website started selling[12] a privacy service where they vouch for the applicant instead of sharing their information with the real estate agents.

In some cases, the requested data matches or even exceeds the requirements for a government security clearance[13]. The Australian Government Security Vetting Agency (AGSVA) has a clear public privacy statement[14]. It explains how data is collected and handled and used only for the assessment of a security clearance. Rental providers don’t necessarily follow the same stringent rules.

Information collected by some rental application forms may include five or more years of address history. Others request five or more years of employment history. In addition, financial information such as payslips and bank statements are also required.

Other sensitive – and irrelevant – information includes vehicle registration numbers and pet names.

Potential tenants are also usually asked to attach personal identification documents including passports, driver licences and Medicare cards. They may be asked to list up to two personal and one business references.

Screenshot of a rental application form requesting employment history.
A rental agent may require five years of employment history. Author provided

If any of this information falls into the wrong hands, it easily exposes the person to social engineering[15], personalised scams[16] or identity and account theft.

Who can access the info?

The names of family members and pet names are a common – albeit unsafe – choice of password. The rental application forms collect both. In Australia, research by Telstra and YouGov found[17] that 20% of Australians used pets’ names as passwords, and 17% used their birth dates.

Pet names may be required on rental applications. This can give away some people’s passwords. Author provided

If a rental provider, or their agent, shares applicant information with others, it can be a security breach. This makes the storage, handling and sharing of this information by private rental providers a major concern.

Rental agency agreements commonly state that personal information can be disclosed to “any person who maintains any record, listing or database of defaults by tenants.”[18] This policy, which a tenant has to accept, is already loose.

More importantly, after the information is sent to the owner of the rental property, there is no visibility as to who that is, or what they do with the information.

Example of a privacy agreement on a rental application form. Author provided

Too much info to rent a home

Having to share extensive personal information is more than an inconvenience for renters – it’s a serious security concern. The government should put explicit limits on personal information requested by rental providers.

One technological solution to this problem could be “access tokens” provided by banks. People in Australia are protected by the Consumer Data Right[19]. This allows consumers to authorise a data holder, such as a bank, to share data with an accredited recipient.

Australian banks are held to strict information security requirements[20]. They already handle highly sensitive data, such as client identity, income sources and other financial information.

If real estate agents require proof of this info to vet potential rental applicants, they could request it through an authorisation token with the applicant’s bank. This way, proof of identity and financial status could be shared without having to disclose actual sensitive personal information, limiting the cyber security risk.

In the meantime, rental providers and their agents should request the least possible amount of personal information – it’s the responsible thing to do.

References

  1. ^ personal information (www.oaic.gov.au)
  2. ^ foreign state actors have an (www.cyber.gov.au)
  3. ^ noted (www.abc.net.au)
  4. ^ one-third (www.aihw.gov.au)
  5. ^ faced a rental crisis (www.abc.net.au)
  6. ^ vacancy rates (propertyupdate.com.au)
  7. ^ drive up rental prices (www.abs.gov.au)
  8. ^ in “bidding wars” over rentals (www.abc.net.au)
  9. ^ larger rent increases (www.abs.gov.au)
  10. ^ controlled by real estate agents (help.2apply.com.au)
  11. ^ subject to the Australian Privacy Act 1988 (www.oaic.gov.au)
  12. ^ started selling (www.smh.com.au)
  13. ^ government security clearance (www.agsva.gov.au)
  14. ^ privacy statement (www.agsva.gov.au)
  15. ^ social engineering (www.cyber.gov.au)
  16. ^ personalised scams (www.scamwatch.gov.au)
  17. ^ Telstra and YouGov found (www.telstra.com.au)
  18. ^ “any person who maintains any record, listing or database of defaults by tenants.” (www.google.com)
  19. ^ Consumer Data Right (www.accc.gov.au)
  20. ^ strict information security requirements (www.apra.gov.au)

Read more https://theconversation.com/renting-a-home-in-australia-means-handing-over-too-much-sensitive-info-its-a-national-security-risk-254293

Subcategories

Australia was once a world leader in innovation. A new report shows the system is now ‘broken’

Australia’s research and innovation system is “broken” and needs “bold reform”, according to a major new indep...

Times Magazine

Efficient Water Carts for Dust Control

Managing dust effectively is a critical challenge across numerous industries in Australia. From sp...

How new rules could stop AI scrapers destroying the internet

Australians are among the most anxious in the world[1] about artificial intelligence (AI). This...

Why Car Enthusiasts Are Turning to Container Shipping for Interstate Moves

Moving across the country requires careful planning and plenty of patience. The scale of domestic ...

What to know if you’re considering an EV

Soaring petrol prices are once again making many Australians think seriously[1] about switching ...

Epson launches ELPCS01 mobile projector cart

Designed for the EB-810E[1] projector and provides easy setup for portable displays in flexible ...

Governance Models for Headless CMS in Large Organizations

Where headless CMS is adopted by large enterprises, governance is the single most crucial factor d...

The Times Features

Taste Port Douglas 10-year celebration

Serving up more than 40 events across four days, the anniversary edition  promises a vibrant cel...

Is dark chocolate healthier than milk chocolate? 2 dietitians explain

Easter chocolate is all over supermarket shelves. Some people reach straight for milk chocolat...

Compulsory super is higher than ever at 12%. But cutting it would hurt low-paid workers most

A central element of Australia’s superannuation system is the superannuation guarantee[1] (SG). ...

Grants open for port communities across the Hunter and Northern Rivers regions

Local organisations doing important work across the Hunter and Northern Rivers regions are being...

AI Is Already Here. The Question Is Whether Your Business Is Built for It

We sat down with Nirlep Adhikari — CTO at LoanOptions.ai and Founder of Mount Mindforce — to cut...

Cleared to Land — and Cleared to Die: How a Runway Failure Killed Two Pilots in Seconds

A modern passenger jet, operating under full clearance, descending onto a controlled runway at o...

Leader of The Nationals Matt Canavan - press conference

CANBERRA PARLIAMENT HOUSE PRESS CONFERENCE WITH SHADOW WATER MINISTER MICHAEL McCORMACK; MURRAY-DA...

The Power Of An Uncomfortable Love

How challenging relationships can help us grow. Never have we lived in a time where relationshi...

US country favourite Larry Fleet joins 2026 Gympie Music Muster

Tennessee singer-songwriter Larry Fleet will bring his band to the Gympie Music Muster on Friday...