Skip to content

AML/CTF for real estate agents: your 2026 action checklist (and the privacy trap)

Real-estate agencies brokering the sale, purchase or transfer of real estate have been reporting entities under the AML/CTF Act since 31 March 2026, the AML obligations started on 1 July 2026, and the AUSTRAC enrolment deadline for agencies already providing the service was 29 July 2026. The known checklist: enrol, verify identity, report, keep records. The quieter trap: once you are a reporting entity, s 6E(1A) of the Privacy Act applies that Act to the activities you carry on for your AML/CTF obligations as if you were an organisation, even if you turn over under $3 million.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price, rising to A$649 on 1 Oct 2026

Orientation only, not a compliance assessment. General information and tools, not legal advice.

Which dates matter for AML/CTF?

If those dates apply to your agency, the checklist below is the "what do I actually do" version.

What's on the AML/CTF action checklist?

That is the AUSTRAC half of the job. Customer due diligence and seven-year record keeping quietly create a second obligation, and AUSTRAC is not the regulator that administers it.

What's the AML privacy trap?

Every CDD check you run produces a stack of customer identity documents: driver licences, passports, proof of address. And here's the catch:

So Tranche 2 is as much a privacy problem as an AUSTRAC one, and it did not end at the enrolment deadline. The three questions that matter:

None of this is hard, and the OAIC has published where it stands: destroy or de-identify copies of full identification documents "once they are no longer needed", and if you kept one because it was "merely helpful, convenient or desirable, you will not be able to establish reasonable necessity". That is the half of Tranche 2 that doesn't come with an AUSTRAC reminder.

What are the three privacy documents you need?

For most agencies the privacy step comes down to a few practical documents, kept current:

These are templates you tailor to your agency: general information and tools, not legal advice.

Common questions

When do real estate agents have to enrol with AUSTRAC?

If your agency was already providing designated services when the obligations commenced on 1 July 2026, your enrolment date was 29 July 2026, fixed by Schedule 3 Part 4 item 12 of the amending Act rather than counted from when you began. Do not derive it by adding 28 days to your own start date, which gives the wrong answer now that the designated services commenced on 31 March 2026. If you first provide a designated service after the transition, the ordinary rule in s 51B(1) applies and you enrol within 28 days of that first service. Confirm your exact date with AUSTRAC.

What's on the AML/CTF action checklist for a real estate agency?

Work out whether you're caught, enrol with AUSTRAC within the window, have an AML/CTF program, do customer due diligence (verify the identity of the people you deal with), report suspicious matters to AUSTRAC, and keep records for seven years.

What's the "privacy trap" in AML Tranche 2?

Becoming a reporting entity switches on s 6E(1A) of the Privacy Act, which applies that Act to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act, as if you were an organisation. That is wider than the ID scan, since the OAIC treats a collection made for an AML purpose as well as an ordinary agency purpose as caught in full, and narrower than your whole business: the small-business exemption still holds for handling unrelated to your AML/CTF obligations.

What privacy documents does an agency need for its AML data?

A privacy policy (APP 1) that reflects the AML identity data you now hold, collection notices (APP 5) at the points you collect ID, and a data-breach response plan plus a retention and destruction schedule so the ID doesn't sit around forever or leak.

Find your privacy gaps in about two minutes

Privaproof is an Australian privacy-compliance product for real-estate agencies. The free self-audit maps your agency against the Australian Privacy Principles (including the AML activities now in scope) and shows the gaps to fix first. The Kit then gives you the collection notices, privacy policy and breach plan to close them, all fourteen reviewed by Matthew Hodgkinson, an Australian practising solicitor (Papillon Lawyers), and kept current as the rules change.

Start the free 2-minute self-audit →


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: AUSTRAC: real estate professionals; OAIC: Australian Privacy Principles; AML/CTF Act 2006 (Cth); Privacy Act 1988 (Cth).