ADS.finance

Privacy and Consent in Broker Lead Capture

ADS Team

Author

September 24, 2026

3 days ago

20

views

Share:

In short: A broker capturing an enquiry is collecting personal information and, once credit is involved, credit-related information governed by Part IIIA of the Privacy Act. You need a collection notice at the point of capture, a privacy policy, express consent before you access a credit report, and a retention and destruction practice. A tick box saying "I agree" is not, by itself, any of those things.

Key takeaways

  • Tell people what you collect and why AT the point of collection, not only in a linked policy.
  • Accessing a credit report requires the consumer's express, informed consent.
  • Credit reporting information carries stricter rules than ordinary personal information.
  • Data you no longer need must be destroyed or de-identified.

What must a lead capture form tell someone?

Australian Privacy Principle 5 requires you to notify a person, at or before the time you collect their information, of specified matters. In practice that is a short collection notice sitting with the form, not buried behind a link.

  • Who you are and how to contact you.
  • Why you are collecting the information and what you will do with it.
  • Who you are likely to disclose it to - lenders, your aggregator, credit reporting bodies.
  • That your privacy policy explains access, correction and complaints.
  • Whether the information will go overseas, and where.

The last one catches brokers using offshore processing or overseas-hosted software. If your CRM or a virtual assistant sits outside Australia, that is a disclosure you need to make.

Where do credit reporting rules apply?

Part IIIA of the Privacy Act and the Privacy (Credit Reporting) Code impose a stricter regime on credit-related information than the general APPs. The moment you move from "what is your name" to "let us check your credit file", the rules change.

ActivityWhat is required
Capturing name and contact detailsAPP 5 collection notice, privacy policy
Collecting income and liabilitiesAs above, plus reasonable necessity for the purpose
Accessing a credit reportExpress, informed consent from the consumer
Disclosing to lenders on the panelConsent and disclosure in the collection notice
Using the data for marketingSeparate basis - credit reporting information has tight limits
Keeping data after the file closesRetain only while needed, then destroy or de-identify

The marketing row is the one brokers most often get wrong. Information obtained for a credit assessment is not automatically available to feed a marketing database.

What about data breaches and retention?

The Notifiable Data Breaches scheme requires you to assess a suspected eligible breach and, if serious harm is likely, notify affected individuals and the OAIC. A broker file is a dense concentration of identity documents, income evidence and bank statements - precisely the material that causes serious harm when it leaks.

Two practical consequences. First, retention: the longer you hold documents you no longer need, the larger the breach you can suffer. Set a schedule that reflects your record-keeping obligations under the NCCP framework and destroy or de-identify beyond it. Second, access: shared drives full of client identity documents with no access control are the most common weak point in a small brokerage.

Privacy law changes periodically and your obligations depend on your specific setup. Confirm your practices with your licensee and, for anything unusual, get your own advice.

Frequently asked questions

Do I need consent to check a client's credit report?

Yes. Accessing consumer credit reporting information requires the individual's express and informed consent, obtained before the access. A general privacy acknowledgement on a web form is not sufficient for this purpose.

Can I use enquiry data for marketing?

Ordinary contact details collected with a clear notice can generally support related marketing with an unsubscribe, subject to the Spam Act. Credit reporting information is far more restricted and should not be used to build marketing segments.

How long should a broker keep client files?

Long enough to satisfy record-keeping obligations under the credit legislation and your licensee's policy, and no longer than you have a need for it. Set an explicit schedule rather than defaulting to keeping everything forever.

What happens if a broker suffers a data breach?

Assess promptly whether it is an eligible data breach likely to result in serious harm. If it is, you must notify affected individuals and the OAIC under the Notifiable Data Breaches scheme, and tell your licensee immediately.

Related reading

Sources

  • Australian Privacy Principles guidelines — OAIC
  • Privacy (Credit Reporting) Code — OAIC
  • Notifiable Data Breaches scheme — OAIC

Information current as at 2 September 2026.

General advice warning: This article contains general information only. It does not take into account your objectives, financial situation or needs, and it is not personal credit or financial advice. Consider whether it is appropriate for you and seek advice from a licensed credit representative before acting.

Any interest rate shown is an example only and is not an offer of credit. Where a rate is quoted, the applicable comparison rate is available from the relevant lender and should be considered alongside it.

Need Financial Assistance?

Connect with our network of trusted finance providers to find the right loan solution for your needs.