Skip to content

The privacy and AML compliance calendar for Australian real-estate agencies (2025–2026)

Four dated changes matter for agencies: the statutory tort for serious invasions of privacy (since 10 June 2025); AML/CTF Tranche 2, where property-sale services became designated services on 31 March 2026, the deferred obligations applied from 1 July 2026 and enrolment was fixed at 29 July 2026; and APP 1.7 automated decision-making transparency (from 10 December 2026). The thread: once you are a reporting entity, the Privacy Act reaches the activities you carry on in connection with the AML/CTF Act, even under the $3 million turnover threshold.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price, rising to A$649 on 1 Oct 2026

Orientation only, not a compliance assessment. General information and tools, not legal advice.

The calendar at a glance

DateWhat changesApplies toWhat it means for you
10 June 2025Statutory tort for serious invasions of privacy commencedEvery agency (individuals can sue directly)A serious, intentional or reckless invasion of privacy can now be sued on directly; a person does not have to prove financial loss
31 March 2026AML/CTF Tranche 2: property-sale services became designated services, so agencies providing them became reporting entitiesSales agencies and buyers' agents providing designated servicesEnrol with AUSTRAC; the program, customer due diligence, reporting and seven-year record-keeping Parts were deferred and applied from 1 July 2026
29 July 2026AUSTRAC enrolment date for the day-one cohort, fixed by Sch 3 Pt 4 item 12 of the amending Act (enrolment opened 31 March 2026)Agencies already providing designated services before 1 July 2026That date has passed. It was not counted from your own start date. An agency whose first designated service comes later applies to enrol within 28 days of that service (s 51B(1))
10 December 2026APP 1.7 and 1.8 automated decision-making transparencyAgencies using automated tenancy screening or application scoringYour privacy policy must set out the kinds of personal information used and the kinds of decisions made solely by the program or substantially supported by it

10 June 2025: can you now be sued directly for invasion of privacy?

The Privacy and Other Legislation Amendment Act 2024 created a new statutory tort, sitting as Schedule 2 to the Privacy Act, that commenced on 10 June 2025. It lets an individual sue where there has been a serious invasion of their privacy (intrusion on seclusion, or misuse of their information), they had a reasonable expectation of privacy, the invasion was intentional or reckless, and the public interest in their privacy outweighs any countervailing interest. Notably, they do not have to prove they suffered loss. For an agency, this raises the stakes on how you handle tenant, buyer and vendor information day to day.

31 March and 1 July 2026: does AML/CTF Tranche 2 pull property-sale agencies in?

On 31 March 2026, agencies providing designated real-estate services (brokering the sale, purchase or transfer of real estate) became reporting entities under the AML/CTF regime. That brings eight core obligations: AUSTRAC enrolment, a risk assessment, an AML/CTF program, customer due diligence, sanctions screening, suspicious-matter reporting, seven-year record keeping, and staff training. Four of them (program, CDD, reporting, record keeping) applied from 1 July 2026. The quieter consequence is the privacy one: see the thread below.

29 July 2026: when was the AUSTRAC enrolment deadline?

Enrolment opened on 31 March 2026. If your agency was already providing designated services before 1 July 2026, your enrolment date was 29 July 2026, and Sch 3 Pt 4 item 12 of the amending Act fixes that date rather than leaving it to be calculated. ⚠️ Do not reach it by adding 28 days to a commencement date: the designated services commenced on 31 March 2026, so that arithmetic produces late April, which is wrong. If you began later, the ordinary 28-day clock in s 51B(1) runs from your first designated service. The date passing does not remove the s 51B obligation to apply to enrol. For the full checklist, see AML/CTF for real estate agents: your 2026 action checklist.

10 December 2026: what is the APP 1.7 automated decision-making rule?

From 10 December 2026, a new APP 1.7 requires your privacy policy to disclose automated decision-making, where a computer program uses personal information to make, or do a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect a person's rights or interests. APP 1.8 sets the content: the kinds of personal information used, and the kinds of decisions made solely by the program or substantially supported by it. In real estate the likely trigger is automated tenancy screening, and APP 1.9 counts a refusal to decide as a decision. It is a transparency rule, not a ban, and whether a given tool qualifies is fact-specific. See the full explainer.

What's the common thread through all these changes?

Three of these four changes touch the Privacy Act, and Tranche 2 quietly drags more agencies into it. Under s 6E(1A) the small-business exemption falls away for the activities a reporting entity carries on in connection with the AML/CTF Act, whatever its turnover. So the AML work and the privacy obligations are not two projects; they are one. A current privacy policy, a proper collection notice and a data-breach plan are the baseline: in the first court-imposed civil penalty under the Privacy Act, Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224, A$800,000 of the A$5.8 million was for the slow breach assessment and A$800,000 for not notifying.

This is exactly why a one-off template ages badly. A policy written for 1 July 2026 is not written for 10 December 2026. A privacy Kit that is kept current carries each change as it lands, so you are working from the current version rather than a file that slowly falls behind.

Common questions

Which of these dates actually apply to my agency?

The statutory tort (10 June 2025) applies to everyone. AML/CTF Tranche 2 applies if your agency brokers the sale, purchase or transfer of real estate: that status started 31 March 2026 and the deferred obligations 1 July 2026. The APP 1.7 automated decision-making rule (10 December 2026) applies only if you use software that makes, or substantially supports, decisions that significantly affect people, such as automated tenancy screening.

Do I have to act on AML and privacy separately?

No. They overlap. Under s 6E(1A) the Privacy Act applies to the activities you carry on for the purposes of, or in connection with, the AML/CTF Act, so your privacy documents need to cover them. Treat them as one compliance picture.

Does the $3 million small-business exemption still protect me?

Not for the AML side. Under s 6E(1A) the Privacy Act applies to the activities you carry on in connection with the AML/CTF Act, whatever your turnover. And s 6D(4)(a) is a one-way ratchet: once a completed financial year tops $3 million, a later fall does not put you back outside the Act. See does the Privacy Act apply to real estate agents?

What is the single most useful thing to have in place?

A current, real-estate-specific set of core documents: a privacy policy, an APP 5 collection notice and a data-breach response plan, kept current as each of these dates lands. Then ask: does your policy name the identity documents you now collect for AML, and who owns the 30-day breach assessment under s 26WH(2)?


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: OAIC: statutory tort for serious invasions of privacy; Privacy and Other Legislation Amendment Act 2024 (Cth); Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth), Sch 3 Pt 4 item 12; AUSTRAC: real estate professionals; OAIC: automated decision-making and privacy.