Privacy Act compliance for Australian real-estate agencies: the 2026 guide
Australian real-estate agencies handle large volumes of personal information (tenant, landlord, buyer and vendor data), and the privacy rules are tightening in 2026. Whether the Privacy Act 1988 (Cth) applies to your agency depends on its size and activities, but the direction is clear: more agencies are being drawn in, penalties have risen, and individuals have gained new rights. This guide covers what applies, what changed, and how to check where you stand.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
Does it apply to your agency?
Businesses turning over A$3m or less have generally been exempt under s 6D, but that exemption is not automatic, and from 1 July 2026 agencies providing property-sale services are drawn in for part of their operations as the AML/CTF reforms commence. (See: Does the Privacy Act apply to real estate agents?)
The Australian Privacy Principles that matter most for agencies
| APP | What it means for an agency |
|---|---|
| APP 1 | Have a current, compliant privacy policy (with the content required by APP 1.4) |
| APP 3 / 5 | Collect only what you need; give a collection notice explaining what and why |
| APP 6 / APP 7 | Use and disclose only for the purpose collected (or with consent). Direct marketing is carved out of APP 6 by APP 6.7 and governed by APP 7: give a simple opt-out and honour it |
| APP 8 | Stay accountable if data goes overseas (e.g. a US-hosted CRM) |
| APP 11 | Keep personal information secure; destroy or de-identify it when no longer needed |
| APP 12 / 13 | Handle access and correction requests |
| NDB scheme | Assess and notify eligible data breaches |
This table is the subset that does the most work in an agency. All thirteen apply, and each one has a plain-English meaning in a real-estate context: see the 13 Australian Privacy Principles, and what each one means for an agency.
What changed for real-estate privacy in 2025–26?
- 1 July 2026, AML/CTF Tranche 2: sales agencies become AUSTRAC reporting entities, bringing their customer-ID data under the Privacy Act via s 6E(1A). (See: What the AML changes mean for agents.)
- June 2025, a new right to sue: individuals can now bring a direct claim for a serious invasion of privacy. This is separate from the Privacy Act's own penalties and has a high bar (intentional or reckless conduct).
- OAIC focus on the sector: real estate is a stated regulatory priority, and a 2026 determination found a rental-application platform collected more than the law allows.
How does a real-estate agency comply with the Privacy Act?
Compliance comes down to a handful of practical steps: a compliant privacy policy, clear collection notices, collecting only what you need, securing the data, a breach-response plan, a process for access/correction requests, knowing whether your data goes overseas, and destroying it when it's no longer needed. (See: Privacy Act checklist for property managers.)
The fastest way to see where your agency stands is the free 2-minute Privacy Readiness self-audit.
Common questions
Which Australian Privacy Principles matter most for an agency?
The heavy lifters are: a compliant privacy policy (APP 1), collecting only what you need and giving a collection notice (APP 3 / 5), using and disclosing information only for the purpose collected (APP 6), staying accountable for overseas data (APP 8), keeping information secure and destroying it when no longer needed (APP 11), handling access and correction requests (APP 12 / 13), and the Notifiable Data Breaches scheme.
What changed for agencies in 2025–26?
From 1 July 2026, sales agencies became AUSTRAC reporting entities, bringing their customer-ID data under the Privacy Act. Since June 2025, individuals can bring a direct claim for a serious invasion of privacy. And the OAIC has named real estate a regulatory priority.
How does a real estate agency comply with the Privacy Act?
A compliant privacy policy, clear collection notices, collecting only what you need, securing the data, a breach-response plan, a process for access and correction requests, knowing whether your data goes overseas, and destroying it when it's no longer needed.
Is the June 2025 right to sue the same as the Privacy Act's penalties?
No. The direct claim for a serious invasion of privacy is separate from the Privacy Act's own penalties and has a high bar: intentional or reckless conduct.
Start the free 2-minute self-audit →
General information, not legal advice, and does not assess the AML/CTF Act, Spam Act, Do-Not-Call Register or state tenancy laws. Sources: OAIC (oaic.gov.au); Privacy Act 1988 (Cth).