For finance & mortgage brokers
You've been doing identity checks for years. The privacy obligations are what moved.
Brokers are used to AML/CTF. Verification of identity, source of funds, lender requirements — none of that is new. What's changed sits on the other side of the file: how you're required to handle, secure, disclose and destroy everything you've been collecting.
Three things moved. The statutory tort came into force in June 2025. Automated decision-making disclosure starts 10 December 2026 and lands squarely on the way broking software works. And the AML/CTF reforms have tightened the sector's obligations across the board.
No obligation. We'll tell you if you don't need us.
Where the law actually stands
Three dates matter. Only one has already passed.
Plenty of people will tell you every small business is about to fall under the Privacy Act. That isn't law yet. Here is what is in force, what is scheduled, and what is still only proposed.
General information, current as at the date of publication — not legal advice. We review this table monthly and date every change.
Why brokers are exposed
The most complete financial picture of a household, held in the most systems.
A single application assembles payslips, bank statements, tax returns, credit file data, identity documents, living expenses, dependants, health and employment circumstances, and often a relationship breakdown explained in an email. Then it goes to an aggregator platform, one or more lenders, a CRM, and sometimes a referral partner.
That chain of disclosure is where the work is. Under APP 8 you remain accountable for personal information you disclose to a third party, including where it's processed overseas — and most brokers have never documented who is in their chain, let alone checked where each of them stores data.
Then there's the declined applications. Brokers keep them, because the client might come back in six months. Under APP 11.2 you need a defensible reason to hold personal information you no longer need, and a date on which it goes.
What it costs to get this wrong. The OAIC can issue infringement notices of up to $66,000 per contravention for lower-level failures such as not maintaining a compliant privacy policy. Serious or repeated breaches carry substantially higher penalties. Separately, since June 2025, an individual can bring a civil claim against you directly.
What we do
Four ways to work with us.
Start small if you want to see how we work. Start with the foundations if you already know where this is heading.
Privacy health check
$750 + GST, one-off
A half day of our time and a written answer to one question: how exposed are you?
- Review of your current policy, forms and file handling
- Written findings memo against the Australian Privacy Principles
- Prioritised list of what to fix first
- Credited in full against foundations if you proceed within 60 days
Privacy foundations
$4,500 – $7,500 + GST, one-off
A complete privacy program, built and handed over in four weeks.
- Data map of every place personal information lives
- Gap assessment against the 13 Australian Privacy Principles
- Privacy policy and collection notices written for your practice
- Notifiable data breach response plan
- 60-minute staff training session
Most brokerages choose this
ComplyHub annual
from $10,500 + GST, per year
Foundations plus twelve months of maintenance, bundled.
- Everything in Privacy foundations
- Quarterly compliance review
- Policies and registers updated as the law changes
- Breach response line — call us first, not your lawyer
- Annual staff training refresher
Ongoing privacy officer
$400 – $800 + GST, per month
Maintenance only, for brokerages whose program is already built.
- Quarterly reviews and register upkeep
- Regulatory change monitoring
- Breach response line
- If someone else built your program, we'll assess it first ($1,500)
The four weeks
What actually happens.
Week 1 — Discovery
Ninety minutes with you and whoever runs your CRM and lodgement process. We map the full disclosure chain — aggregator, lenders, referrers, document collection tools — and confirm your reporting status in writing.
Week 2 — Data map and gap assessment
A documented data map and an assessment against the 13 Australian Privacy Principles, with specific attention to APP 8 cross-border disclosure and the automated decision-making obligations starting in December.
Week 3 — Documents
Privacy policy including the automated decision-making disclosure, collection notice for your fact find and credit guide, breach response plan, and a retention schedule that finally answers what happens to declined applications.
Week 4 — Handover and training
An hour with your team, plus a written summary you can provide to your aggregator, your lender panel or your PI insurer.
Fair questions
What brokers usually ask us.
We've been dealing with AML/CTF for years. What's actually new?
Three things, none of them about collecting identity documents. One: since June 2025 an individual can sue you directly for a serious invasion of privacy — a private right of action, not a regulator complaint. Two: from 10 December 2026 you must disclose automated decision-making in your privacy policy, which is directly relevant to how broking software works. Three: the reforms have tightened obligations across the sector and raised what lenders and aggregators expect you to be able to demonstrate.
Doesn't my aggregator handle compliance?
They handle their own platform and their own obligations. You are a separate entity with your own APP obligations, your own collection notices, your own retention decisions and your own breach response. Their compliance framework is not a defence to a failure in yours. Bring their documentation to the call — we'll read it with you and tell you what it does and doesn't cover.
Are we a reporting entity in our own right?
It depends on the services you provide and how your business is structured, and we won't guess at it on a website. Some brokers are, some sit inside a licensee's arrangements, and some are providing services on behalf of a lender who is. We work it out in week one and put the answer in writing. Note that your privacy obligations don't wait on that answer — the statutory tort and the December disclosure rules apply either way.
What do we do with declined applications?
This is the question we get most. The Privacy Act requires you to destroy or de-identify personal information you no longer need for a permitted purpose. "They might come back" isn't automatically wrong, but it needs to be a documented decision with a retention period attached, not a default. We build you the schedule.
Are you lawyers?
No. We're privacy and compliance practitioners doing implementation work — mapping, documents, training and registers. Anything that's genuinely legal advice we refer out, and our engagement letter says so.
Who you're dealing with
A small Australian firm, and you'll deal with a founder.
ComplyHub is based in Melbourne and works with Australian professional services businesses on Privacy Act obligations. Our work is delivered onshore — your data stays in Australia, and we can tell you exactly which systems it touches.
Between us we hold certifications from the International Association of Privacy Professionals in privacy program management, privacy technology and AI governance, alongside security credentials. That matters less than the fact that you'll speak to the person doing the work.
Twenty minutes, and you'll know where you stand.
Tell us how your brokerage is structured and what systems you use. We'll tell you plainly what applies to you and what doesn't — including the December deadline, which is closer than it looks.