Skip to content

Does AML compliance cover your privacy obligations? (real-estate agencies)

No. These are two Acts with two regulators: AUSTRAC administers the AML/CTF Act 2006, the OAIC the Privacy Act 1988, and meeting one does not discharge the other. There is a twist that catches agencies out: agencies brokering the sale or transfer of real estate have been reporting entities since 31 March 2026, with the AML obligations applying from 1 July 2026, and s 6E(1A) of the Privacy Act then applies the Act to the activities you carry on for AML purposes even if you turn over under $3 million. So AML work tends to create privacy obligations, not satisfy them.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price, rising to A$649 on 1 Oct 2026

Orientation only, not a compliance assessment. General information and tools, not legal advice.

The short answer: no, and there's a twist

Meeting your AML obligations does not meet your privacy obligations: nothing in an AUSTRAC enrolment, a CDD procedure or an AML/CTF program answers APP 1.3 (privacy policy), APP 5 (collection notice), APP 11.1 and 11.2 (security, then destruction) or Part IIIC (data breaches). The AML work can quietly expand what the Privacy Act covers for you.

Why can AML increase your privacy obligations?

Many small agencies rely on the small-business exemption (turnover under $3 million), though it is not the only question: s 6D(4)(b) to (f) are separate routes in, and under s 6D(4)(a) one completed financial year above $3 million ends the exemption for good. But once you are a reporting entity, s 6E(1A) applies the Privacy Act "in relation to the activities carried on by the small business operator for the purposes of, or in connection with, activities relating to" the AML/CTF Act, as if you were an organisation.

Scope it precisely, because this is where agencies over- or under-react. The hook is activity-based, not document-based: monitoring and reporting are caught too, not just the licence scan. But the OAIC also states small businesses "are not covered by the Privacy Act in relation to the non-AML/CTF business activities they undertake, unless the small business is covered by the Privacy Act for a different reason", so your open-home sheet is not pulled in by this route.

What do you have to do on the privacy side?

Once those activities are covered, the APP obligations attach to them. Run each one against your own AML pack:

Two obligations, one pile of data

The AML side (AUSTRAC, AML/CTF Act)The privacy side (OAIC, Privacy Act)
Enrol (by 29 July 2026 if you provided a designated service before 1 July 2026), run customer due diligence, verify identitySay how you handle it (APP 1.3); tell people at collection (APP 5)
Report suspicious mattersHold that data securely (APP 11.1)
Keep records for seven yearsDestroy or de-identify what you no longer need, unless a law requires you to keep it (APP 11.2)
Have an AML/CTF programAssess a suspected breach within 30 days, notify where required (Part IIIC)

The same customer file sits in the middle of both. AML tells you to identify the customer and keep records of what you did, not to keep the scan; the Privacy Act governs how you handle and eventually dispose of what you do keep. For the AML side itself, see AML/CTF for real estate agents: your 2026 action checklist; for whether the Privacy Act applies to you at all, see does the Privacy Act apply to real estate agents?.

Common questions

If I am AML-compliant, am I privacy-compliant?

No. They are separate obligations under separate laws with separate regulators. Being enrolled and running AML checks says nothing about whether you have a compliant privacy policy, collection notice, secure handling and a breach plan for the data those checks produce. They are enforced separately too: in the only court-imposed Privacy Act penalty to date, Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224, a listed pathology company was ordered to pay A$5.8 million, A$800,000 of it for failing to assess a suspected breach as s 26WH(2) requires. They are enforced separately too: in the only court-imposed Privacy Act penalty to date, Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224, a listed pathology company was ordered to pay A$5.8 million, A$800,000 of it for failing to assess a suspected breach as s 26WH(2) requires. They are enforced separately too: in the only court-imposed Privacy Act penalty to date, Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224, a listed pathology company was ordered to pay A$5.8 million, A$800,000 of it for failing to assess a suspected breach as s 26WH(2) requires.

I am under $3 million turnover. Doesn't the small-business exemption cover me?

Not for your AML work. Once you are a reporting entity, s 6E(1A) applies the Privacy Act to the activities you carry on for AML/CTF purposes as if you were an organisation, whatever your turnover. The exemption still covers your other activities, unless you are caught for a different reason under s 6D.

What is the single most useful thing to have in place?

A privacy policy (APP 1.3), a collection notice (APP 5), a secure-handling and destruction rule (APP 11.1 and 11.2) and a data-breach plan (Part IIIC), all tuned to the customer due diligence AUSTRAC now requires. That is the privacy half of the same 2026 job.

Who administers each?

AUSTRAC administers the AML/CTF regime; the OAIC administers the Privacy Act and the Australian Privacy Principles. Privaproof helps with the privacy half and does not assess your AML obligations.


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: OAIC: privacy guidance for reporting entities under the AML/CTF Act; OAIC: rights and responsibilities (small business); AUSTRAC: real estate professionals; OAIC: Notifiable Data Breaches scheme.