Is your intake form causing you to breach privacy laws?


Key takeaways

  • “Online Choice Architecture” is now a live compliance test. Confirmshaming, biased framing and bundled consent in a form’s design can make a collection unfair, independent of whether any single field is arguably necessary.
  • The same test applies to job applications, course enrolments and loyalty sign-ups – any form that frames an optional field as something that “helps us serve you better” carries the same risk.
  • Use the five fairness factors as a checklist; awareness, reasonable expectation, choice distortion, potential harm, and vulnerability.
  • The determination is under review at the Administrative Review Tribunal, but the OAIC’s reasoning is already in its updated APP 3 guidance.

Have you considered that the design of your intake form may be unfair, leading to an unlawful collection of personal information? That’s the question at the centre of Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24. The Privacy Commissioner’s determination against InspectRealEstate’s 2Apply rental platform in April.

The Commissioner didn’t find a data leak or a mishandled disclosure She found two breaches instead. APP 3.2, for collecting personal information that wasn’t reasonably necessary. And APP 3.5, for gathering it by unfair means.

The standard APP 3 test is well known. Don’t collect personal information unless it’s reasonably necessary, and only by lawful and fair means. Most privacy teams run that test once, on paper, when a form is being built, then move on to the next launch.

Here, the Commissioner examined the wording of the 2Apply form. It told applicants that providing information would “help speed up your application,” and that withholding it might “affect whether you are considered as a suitable tenant”. Neither statement was necessarily false. But she found their cumulative effect was to pressure applicants into handing over more than the platform needed. Notably, the Commissioner analysed the design and structure of the 2Apply platform, and how it presented information to applicants. She termed this its “Online Choice Architecture,” and found it displayed three harmful practices:

  • Confirmshaming – emotive language that makes withholding information feel like the wrong choice
  • Biased framing – presenting choices in a way that emphasises their supposed benefits or downsides
  • Bundled consent – folding unrelated purposes (in 2Apply’s case, direct marketing) into a single consent request, so the only way to opt out was to withdraw the application entirely

The Australian Privacy Principles have required collection to be “reasonably necessary” and by “fair means” for three decades. What’s new is where the Commissioner now looks for evidence that a collection wasn’t fair. In this case, that included a power imbalance she found built into the rental market itself. An applicant can’t choose which platform a landlord requires, and doesn’t feel able to say no.

The same test reaches a standard job application form. The OAIC’s own updated guidance on APP 3 gives a clear example. An employer asks an applicant to disclose a prior work-related injury when it had no bearing on the role advertised. That alone would ground a straightforward “not reasonably necessary” finding under APP 3.2, with no choice-architecture analysis required. 2Apply shows the harder version of the same question. Even when a field might arguably relate to the purpose, the way the form pressures a disclosure matters. It can independently make the collection unfair. A course enrolment form can run the same risk. Consider one that frames an optional field as something that will “help us serve you better,” with no visible way to skip it. That framing alone runs the risk of being unfair under APP 3.5.

Ask a general-purpose AI tool whether a sign-up form complies with the Privacy Act. It will give a competent answer on the numbered principles: collection, use, disclosure: the standard checklist. What it won’t reliably surface is that “fair” now has a design dimension the Commissioner is actively testing. Online Choice Architecture isn’t in the statute. It’s a live interpretive move inside a specific 2026 determination. The OAIC developed it further in the its own 13 May 2026 update to the APP 3 guidelines. It’s the kind of thing that only shows up if someone is tracking determinations as they land, not just reading the Act.

That’s the gap Practical Law is built to close.

Practical Law’s lawyer writers track OAIC determinations in real time and keep Practical Law’s exclusive Australian Privacy Principles Practice Note up-to-date. They’ve already folded in the 2Apply analysis alongside the May guidance. With reference to the determination linked via Westlaw Australia, the Practice Note names the five factors the Commissioner now treats as relevant to fairness:

  • whether the individual was aware of the collection,
  • whether they’d reasonably expect it,
  • whether the form’s design distorted their choice
  • what harm the information exposes them to, and
  • whether they were in a vulnerable position.

It won’t redesign your form. Instead it gives your team the current test to check it against. That’s a source you can point to if anyone asks how you got there. If you’re working in marketing law or privacy compliance, then you know the corporate and reputational risks that come with operating on out-of-date legal guidance (or web-scraped AI answers). Using Practical Law’s Deep Research capability ensures you are basing your judgment on correct law, so you’re right when it matters.

Expand the scope of your form review to align with the updated APP guidelines, and ask pointed questions about your Online Consent Architecture, such as:

  1. Confirmshaming check – read every “helps us” or “may affect your application” line out loud. Does it manufacture guilt for saying no?
  2. Biased framing check – for every optional field, is the upside stated while the cost of providing information left out?
  3. Bundled consent check – can an applicant complete the transaction while declining any purpose (marketing, data sharing) that isn’t the core service?

Asking these questions can be the difference between using a form that was fine two years ago and one that’s fine now.

Explore Practical Law’s Data Privacy & Cybersecurity guidance with Deep Research

Discover now

Subscribe toLegal Insight

Discover best practice and keep up-to-date with insights on the latest industry trends.

Subscribe