Interactive Brokers Australia
Banking & Finance
Not addressed in any section. Product context (regulated brokerage, adults-only by AFSL requirement) reduces relevance, but the policy contains no statement to that effect either. Overall: Significant gaps.
10 dimensions · 0 claims · assessed 8 June 2026 · methodology
Score Breakdown
Transparency
Significant gaps
4.67/104.67/10
Transparency
Significant gaps
Transparency & Clarity
5/10Numbered sections, dated version header, and a contact path exist, but the policy has no table of contents, no plain-language commitment, and no introductory summary of commitments. Most materially, the policy is distributed only as a PDF inside the IBKR onboarding flow — APP 1.4 expects the policy to be freely available, and §12 of the policy itself promises website publication that does not match observed distribution.
No specific findings.
Purpose Limitation & Use
5/10Purposes stated: legal/regulatory compliance (AML/CTF, Corporations Act, FATCA), eligibility determination, identity verification, service improvement, and unauthorised-activity monitoring. Silent on marketing use — neither asserted nor disclaimed. No explicit purpose-limitation commitment beyond the stated purposes.
No specific findings.
Policy Maintenance & Accountability
3/10Document carries a version code ('3311') and date (13 November 2025). §12 reserves right to revise 'from time to time for any reason' and to upload to the website. No review cadence, no changelog, no commitment to notify users of changes. A 'Complaints Officer' exists; no Privacy Officer is named.
No specific findings.
Data Protection
Room for improvement
5.22/105.22/10
Data Protection
Room for improvement
Data Collection Disclosure
7/10Strong itemisation: names, addresses, DOB, email, phone, TFN, passport, driver's licence, marital and employment status, annual income, net worth, trading history, investment objectives, deposit/transfer information. Sources also disclosed (directly from client, public registers, government databases, information aggregators). Sensitive-information handling not explicitly flagged (TFN handled implicitly), and automated-collection detail limited to a brief cookies mention.
No specific findings.
Third-Party Sharing & Disclosure
6/10Categories of recipients enumerated clearly — IB Group affiliates, other financial institutions and sub-custodians, external consulting/legal/audit firms, regulators and government bodies in Australia and abroad, professional verification firms, and courts. No specific third parties named. No clause stating recipients are contractually bound to equivalent privacy obligations.
No specific findings.
Data Security
3/10Only the breach-notification commitment is disclosed (§8, aligned with the NDB scheme). No mention of encryption (in transit or at rest), no access controls or authentication practices, no security certifications or standards, no staff training, no audit cadence. Notably thin for a broker holding TFNs, passport numbers, and trading history.
No specific findings.
Cross-Border Data Flows
2/10Acknowledges overseas storage in §2 — 'inside and outside of Australia in places where we maintain electronic storage facilities.' Does not name any country or region, does not describe safeguards, SCCs, BCRs, or any contractual mechanism. For a US-headquartered group operating globally, this is the thinnest possible APP 8 disclosure.
No specific findings.
Your Rights
Major deficiencies
3.2/103.2/10
Your Rights
Major deficiencies
Consumer Rights & Control
6/10Access right disclosed (§11). Implicit correction obligation via the client agreement. OAIC complaint pathway disclosed with full contact details. Response timeframe of 30 days stated, with 1 business day acknowledgment for complaints. No deletion right addressed at all (which AML/CTF retention does not excuse mentioning). No marketing opt-out — consistent with the silence on marketing in purpose limitation.
No specific findings.
Automated Decision-Making
2/10Mentions electronic matching of identity against government records, with a manual-verification fallback if electronic checks fail — providing a partial human-review path. No disclosure of AI or machine-learning use, no breakdown of decision types, no logic transparency, no opt-out. Not aligned with the December 2026 Privacy Act ADM-transparency reforms.
No specific findings.
Children's Data
0/10Not addressed in any section. Product context (regulated brokerage, adults-only by AFSL requirement) reduces relevance, but the policy contains no statement to that effect either.
No specific findings.
Sector Comparison
Banking & Finance comparison
How this score was produced
- Scanned
- 8 June 2026
- Policy source
- Live site
This scan predates provenance recording — model and engine details were not captured.