Skip to content

Privacy Act compliance for Australian real-estate agencies: the 2026 guide

Australian real-estate agencies handle large volumes of personal information (tenant, landlord, buyer and vendor data), and the privacy rules are tightening in 2026. Whether the Privacy Act 1988 (Cth) applies to your agency depends on its size and activities, but the direction is clear: more agencies are being drawn in, penalties have risen, and individuals have gained new rights. This guide covers what applies, what changed, and how to check where you stand.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price

Orientation only, not a compliance assessment. General information and tools, not legal advice.

Does it apply to your agency?

Businesses turning over A$3m or less have generally been exempt under s 6D, but that exemption is not automatic, and from 1 July 2026 agencies providing property-sale services are drawn in for part of their operations as the AML/CTF reforms commence. (See: Does the Privacy Act apply to real estate agents?)

The Australian Privacy Principles that matter most for agencies

APPWhat it means for an agency
APP 1Have a current, compliant privacy policy (with the content required by APP 1.4)
APP 3 / 5Collect only what you need; give a collection notice explaining what and why
APP 6 / APP 7Use and disclose only for the purpose collected (or with consent). Direct marketing is carved out of APP 6 by APP 6.7 and governed by APP 7: give a simple opt-out and honour it
APP 8Stay accountable if data goes overseas (e.g. a US-hosted CRM)
APP 11Keep personal information secure; destroy or de-identify it when no longer needed
APP 12 / 13Handle access and correction requests
NDB schemeAssess and notify eligible data breaches

This table is the subset that does the most work in an agency. All thirteen apply, and each one has a plain-English meaning in a real-estate context: see the 13 Australian Privacy Principles, and what each one means for an agency.

What changed for real-estate privacy in 2025–26?

How does a real-estate agency comply with the Privacy Act?

Compliance comes down to a handful of practical steps: a compliant privacy policy, clear collection notices, collecting only what you need, securing the data, a breach-response plan, a process for access/correction requests, knowing whether your data goes overseas, and destroying it when it's no longer needed. (See: Privacy Act checklist for property managers.)

The fastest way to see where your agency stands is the free 2-minute Privacy Readiness self-audit.

Common questions

Which Australian Privacy Principles matter most for an agency?

The heavy lifters are: a compliant privacy policy (APP 1), collecting only what you need and giving a collection notice (APP 3 / 5), using and disclosing information only for the purpose collected (APP 6), staying accountable for overseas data (APP 8), keeping information secure and destroying it when no longer needed (APP 11), handling access and correction requests (APP 12 / 13), and the Notifiable Data Breaches scheme.

What changed for agencies in 2025–26?

From 1 July 2026, sales agencies became AUSTRAC reporting entities, bringing their customer-ID data under the Privacy Act. Since June 2025, individuals can bring a direct claim for a serious invasion of privacy. And the OAIC has named real estate a regulatory priority.

How does a real estate agency comply with the Privacy Act?

A compliant privacy policy, clear collection notices, collecting only what you need, securing the data, a breach-response plan, a process for access and correction requests, knowing whether your data goes overseas, and destroying it when it's no longer needed.

Is the June 2025 right to sue the same as the Privacy Act's penalties?

No. The direct claim for a serious invasion of privacy is separate from the Privacy Act's own penalties and has a high bar: intentional or reckless conduct.

Start the free 2-minute self-audit →


General information, not legal advice, and does not assess the AML/CTF Act, Spam Act, Do-Not-Call Register or state tenancy laws. Sources: OAIC (oaic.gov.au); Privacy Act 1988 (Cth).