Can a tenant or client sue a real estate agency for a privacy breach?
Yes, since 10 June 2025, and directly, with no regulator involved. But the bar is higher than the headlines suggest. Schedule 2 clause 7(1) of the Privacy Act sets five conditions and every one of them has to be met, including that the invasion was intentional or reckless. Carelessness alone does not ground it, so the tenancy application that went to the wrong email through simple human error is not what this tort was built for. What it does reach is deliberate misuse, and it is actionable without proof of damage.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
The interesting part, and the part almost nobody covers, is that the first Australian court to apply this tort was asked to do so by a property business, not against one.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
The five conditions, and all five must be met
Schedule 2 clause 7(1) is cumulative. A claim that satisfies four of these fails.
- An invasion of privacy actually occurred, by intruding on someone's seclusion or by misusing information that relates to them.
- A reasonable expectation of privacy existed, judged from the position of the person complaining, in all the circumstances.
- The invasion was intentional or reckless. This is the limb that decides most agency scenarios, and it is covered on its own below.
- The invasion was serious. Not every breach of an expectation qualifies.
- The public interest in that person's privacy outweighed any countervailing public interest.
Clause 7(2) then adds the sharp edge: the invasion is actionable without proof of damage. Someone does not have to show they lost money. That is a genuine change from the position most agency principals still carry in their heads.
The limb that decides it: intentional or reckless
Clause 7(1)(c) is where most feared scenarios stop, and it is worth being precise because getting this wrong in either direction is expensive.
An email sent to the wrong recipient, a rental file left in a meeting room, a database misconfigured by a supplier: these are the incidents agencies actually have, and they are ordinarily carelessness. Careless conduct does not satisfy clause 7(1)(c). Recklessness means proceeding while aware of a substantial risk and unjustifiably taking it, which is a different thing from not having thought about it at all.
So the honest position is that this tort is not the reason to fix your privacy documents. Your exposure from a careless leak runs through the Australian Privacy Principles, the notifiable data breach scheme and the OAIC, and none of those require intent. See what are the penalties for a privacy breach for a real estate agency?
Where the tort does reach an agency is the deliberate act: looking up a former tenant's new address out of curiosity or to pass on, publishing someone's details to punish them, using a tenancy database to settle a score. Those are intentional, and staff do them.
What the first published decision actually decided
In Kurraba Group Pty Ltd & Anor v Williams [2025] NSWDC 396, decided on 7 October 2025, Gibson DCJ granted an urgent interlocutory injunction, the first published Australian decision to apply the statutory tort.
Read it for what it is. The court found a serious question to be tried, which is the interlocutory test, and expressly did not settle the tort's parameters. Nothing has yet been established at a final hearing, by this decision or any other. Anyone telling you the tort is now "tested" is overstating a preliminary ruling.
And note who was on which side. The plaintiffs were a property development business and its chief executive, seeking to restrain a critic. The first use of this tort by an Australian court was as a sword wielded by a property company, not a shield raised against one. That is worth knowing for two reasons: it means the case is not evidence that an agency can be sued over a data breach, and it means the tort is also available to you and to your vendors when someone deliberately misuses your information.
What actually protects an agency here
Nothing about this tort changes the practical work, which is the same work the Privacy Act already asks for.
- Access control is the real defence. The tort turns on deliberate acts, and deliberate acts are usually committed by someone with a login. Who at your agency can pull up a former tenant's file, and would you know if they had?
- A collection notice sets the expectation. Clause 7(1)(b) asks what a person in the applicant's position would reasonably expect. A clear APP 5 notice at the point of collection shapes that expectation in your favour rather than against you.
- Say what happens to data at the end. An expectation of privacy is strongest over information someone thought was finished with. A stated retention and destruction practice is the answer to that.
- Train for the deliberate case, not the clumsy one. Most privacy training covers accidents. The conduct this tort reaches is a person choosing to look, so the instruction that matters is that curiosity about a file you have no reason to open is itself the breach.
Common questions
Does a tenant need to prove they lost money to sue?
No. Schedule 2 clause 7(2) makes the invasion actionable without proof of damage. They still have to satisfy every limb of clause 7(1), including that the invasion was serious and that it was intentional or reckless.
If a staff member leaks a tenancy file by accident, are we exposed to this tort?
Ordinarily not, because clause 7(1)(c) requires the invasion to have been intentional or reckless and simple carelessness is neither. That does not leave you in the clear: an accidental leak is still capable of being an interference with privacy under the Australian Privacy Principles and may be a notifiable data breach, and neither of those requires intent.
Has any Australian court actually awarded damages under the privacy tort?
Not in any published decision as at 9 September 2026. Kurraba Group Pty Ltd & Anor v Williams [2025] NSWDC 396 granted interlocutory relief on 7 October 2025 after finding a serious question to be tried, and the court expressly left the tort's parameters for another day. Treat anyone describing the tort as settled with caution.
Can our agency use this tort ourselves?
Yes, on the same conditions. The first published application was brought by a property development company seeking to restrain publications about it, so the tort runs in both directions. Whether it fits a given situation is a question for your own lawyer.
Does the small-business exemption protect us from being sued under the tort?
No, and this is the point most often missed. The A$3 million small-business exemption in s 6D governs whether the Australian Privacy Principles bind your business. The statutory tort in Schedule 2 is a cause of action between individuals and does not depend on the defendant being an APP entity. See does the Privacy Act apply to real estate agents?
Where our own documents sit on this
The fourteen documents in the Privaproof real-estate Kit are reviewed by Matthew Hodgkinson, an Australian practising solicitor (Papillon Lawyers). He is also the practitioner the College of Law went to when the tort commenced, for its explainer on the five elements a plaintiff has to prove (College of Law, 12 August 2025). We cite that as a source, in the same way we cite the OAIC: the College of Law has no association with Privaproof and endorses nothing here.
Sources: Privacy Act 1988 (Cth), Schedule 2 clause 7(1) and 7(2) · Privacy and Other Legislation Amendment Act 2024 (Cth), Schedule 2 (commenced 10 June 2025) · Kurraba Group Pty Ltd & Anor v Williams [2025] NSWDC 396 (procedural posture only) · College of Law on the new tort