Does the Privacy Act apply to real estate agents in Australia?
Yes, for many agencies, and increasingly so. Businesses with annual turnover of A$3 million or less have generally been exempt under the Privacy Act 1988 (Cth) "small business exemption." But several exceptions can override that, and since 1 July 2026, agencies providing property-sale services have been drawn in for part of their operations as the AML/CTF reforms commenced, regardless of turnover.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Want to check your own agency rather than read the general position? The Am I Covered? check walks you through the four questions that decide it, in about two minutes.
Most agents have heard the shorthand: under A$3 million turnover, you're exempt. It was never quite that simple, and from 1 July 2026 it's less true again. Here's who's actually caught, and why turnover is only the starting point.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
What is the small-business exemption?
Under section 6D of the Privacy Act 1988 (Cth), a business whose annual turnover for the previous financial year was A$3 million or less is generally exempt from the Act and the Australian Privacy Principles (APPs). Many small agencies have relied on this, but the exemption is not automatic, and it falls away in several common situations.
When does the small-business exemption NOT apply?
Your agency may be covered by the Privacy Act, even under $3m turnover, if it:
| Trigger | What it means for an agency |
|---|---|
| Has ever been over $3m | s 6D(4)(a): not a small business operator if it has had a turnover over $3m for any financial year that has already ended. Dropping back under does not restore it |
| Is an AML/CTF reporting entity | From 1 July 2026, agencies providing designated (sales) services are caught for their AML/KYC data (see below) |
| "Trades in" personal information | Discloses personal information for a benefit, or collects it for a benefit: fact-specific; not automatic |
| Provides services under a Commonwealth contract | Reaches subcontractors too, "whether or not a party to the contract" (s 6D(4)(e)); Commonwealth only, not State or Territory |
| Is related to a larger covered business | s 6D(9) + Corporations Act s 50: a holding company, a subsidiary, or a subsidiary of the same holding company. Two companies that merely share an individual owner are not related |
| Opts in voluntarily | Some agencies choose to comply to win trust |
Whether an ordinary agency "trades in" personal information (for example, via a tenancy database) is fact-specific. Sections 6D(7) and 6D(8) each carry two carve-outs: the disclosure or collection is not caught if the individual consented, or if it was required or authorised by or under legislation. "Authorised" is materially wider than "required": State tenancy legislation that authorises a database listing sits inside the carve-out.
How does the 1 July 2026 AML change affect real-estate agents?
From 1 July 2026, real-estate agencies providing designated services around property transactions (buying and selling) become reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act (as the Tranche-2 reforms commence). Whether a particular agency is caught depends on the specific designated services it provides.
Here's the privacy link, and it's narrower than the headlines suggest: under section 6E(1A) of the Privacy Act, a small reporting entity is treated as an organisation only in relation to the activities it carries on for the purposes of, or in connection with, its AML/CTF obligations, even below the $3m threshold. That is wider than a photocopied licence: section 28(2) customer due diligence reaches beneficial owners, politically-exposed-person and sanctions screening, and the nature and purpose of the relationship, and section 111(3) requires seven years of records of your risk analysis about a named customer.
It does not pull the rest of your agency into the Act. "Real estate" is defined to exclude a leasehold of 30 years or less, so ordinary residential and commercial leasing is not a designated service at all. Rent rolls and general marketing stay outside this trigger.
Note: this is separate from the proposed reform that would remove the small-business exemption entirely; that is not law as at 2026.
Does the exemption protect you from everything?
No. The statutory tort of serious invasion of privacy, in Schedule 2 of the Privacy Act, gives an individual a cause of action against "another person." It is not limited to entities covered by the Australian Privacy Principles, and Schedule 2 directs that the rest of the Act be disregarded in construing it. Being exempt from the APPs is not the same as being beyond reach. The tort does have a real limit, though: the invasion must have been intentional or reckless, so carelessness or an honest mistake is not enough to found a claim.
So, is your agency caught?
You're more likely to be covered if you: handle property sales (since 1 July 2026), turn over more than $3m, are part of a larger group, or disclose client data in ways that count as "trading." Even if you're technically exempt, your CRM, cloud tools or supplier contracts may already commit you to Privacy Act-style obligations.
The fastest way to see where your agency actually stands, across the obligations that apply to you, is the free 2-minute Privacy Readiness self-audit.
Start the free 2-minute self-audit →
This is general information, not legal advice, and does not assess the AML/CTF Act, Spam Act, Do-Not-Call Register or state tenancy laws. Sources: Office of the Australian Information Commissioner (oaic.gov.au); Privacy Act 1988 (Cth).