The privacy and AML compliance calendar for Australian real-estate agencies (2025–2026)
Four dated changes matter for agencies: the statutory tort for serious invasions of privacy (from 10 June 2025); AML/CTF Tranche 2 reporting-entity status for property-sale services (from 1 July 2026), with AUSTRAC enrolment due around 29 July 2026; and APP 1.7 automated decision-making transparency (from 10 December 2026). The thread: the moment you collect identity data for AML, the Privacy Act reaches it, even under the $3 million turnover threshold.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
The calendar at a glance
| Date | What changes | Applies to | What it means for you |
|---|---|---|---|
| 10 June 2025 | Statutory tort for serious invasions of privacy commenced | Every agency (individuals can sue directly) | A serious, intentional or reckless invasion of privacy can now be sued on directly; a person does not have to prove financial loss |
| 1 July 2026 | AML/CTF Tranche 2: property-sale services become AUSTRAC reporting entities | Sales agencies and buyers' agents providing designated services | Enrol with AUSTRAC, run customer due diligence, keep records for seven years, report to AUSTRAC |
| ~29 July 2026 | AUSTRAC enrolment deadline (enrolment opened 31 March 2026) | Agencies caught by Tranche 2 | Enrol by this date, or within 28 days of first providing a designated service |
| 10 December 2026 | APP 1.7 automated decision-making transparency | Agencies using automated tenancy screening or application scoring | Your privacy policy must disclose qualifying automated decision-making |
10 June 2025: can you now be sued directly for invasion of privacy?
The Privacy and Other Legislation Amendment Act 2024 created a new statutory tort, sitting as Schedule 2 to the Privacy Act, that commenced on 10 June 2025. It lets an individual sue where there has been a serious invasion of their privacy (intrusion on seclusion, or misuse of their information), they had a reasonable expectation of privacy, the invasion was intentional or reckless, and the public interest in their privacy outweighs any countervailing interest. Notably, they do not have to prove they suffered loss. For an agency, this raises the stakes on how you handle tenant, buyer and vendor information day to day.
1 July 2026: does AML/CTF Tranche 2 pull property-sale agencies in?
From 1 July 2026, agencies providing designated real-estate services (brokering the sale, purchase or transfer of real estate) became reporting entities under the AML/CTF regime. That brings eight core obligations: AUSTRAC enrolment, a risk assessment, an AML/CTF program, customer due diligence, sanctions screening, suspicious-matter reporting, seven-year record keeping, and staff training. The quieter consequence is the privacy one: see the thread below.
~29 July 2026: when is the AUSTRAC enrolment deadline?
Enrolment opened on 31 March 2026. Agencies that started providing designated services on 1 July 2026 generally must be enrolled by around 29 July 2026 (within 28 days). If you begin later, the 28-day clock runs from your first designated service. For the full checklist, see AML/CTF for real estate agents: your 2026 action checklist.
10 December 2026: what is the APP 1.7 automated decision-making rule?
From 10 December 2026, a new APP 1.7 requires your privacy policy to disclose automated decision-making, where a computer program uses personal information to make, or substantially and directly support, a decision that could reasonably be expected to significantly affect a person's rights or interests. In real estate the most likely trigger is automated tenancy screening or application scoring. It is a transparency rule, not a ban, and whether a given tool qualifies is fact-specific. See the full explainer.
What's the common thread through all these changes?
Three of these four changes touch the Privacy Act, and Tranche 2 quietly drags more agencies into it. The moment you collect identity documents for AML customer due diligence, the Privacy Act reaches that information, even for agencies turning over under $3 million a year that previously relied on the small-business exemption. So the AML deadline and the privacy obligations are not two separate projects; they are one. A current privacy policy, a proper collection notice and a data-breach plan are the baseline, and they need to keep pace with each of the dates above.
This is exactly why a one-off template ages badly. A policy written for 1 July 2026 is not written for 10 December 2026. A privacy Kit that is kept current carries each change as it lands, so you are working from the current version rather than a file that slowly falls behind.
Common questions
Which of these dates actually apply to my agency?
The statutory tort (10 June 2025) applies to everyone. AML/CTF Tranche 2 (1 July 2026) applies to agencies providing designated property-sale services, which is most sales agencies. The APP 1.7 automated decision-making rule (10 December 2026) applies only if you use software that makes, or substantially supports, decisions that significantly affect people, such as automated tenancy screening.
Do I have to act on AML and privacy separately?
No. They overlap. Becoming an AUSTRAC reporting entity means the identity data you collect for AML falls under the Privacy Act, so your privacy documents need to cover it. Treat them as one compliance picture.
Does the $3 million small-business exemption still protect me?
Not for the information caught above. Once you collect personal information as a reporting entity, the Privacy Act reaches it regardless of turnover. See does the Privacy Act apply to real estate agents?
What is the single most useful thing to have in place?
A current, real-estate-specific set of core documents: a privacy policy, an APP 5 collection notice and a data-breach response plan, kept current as each of these dates lands.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: OAIC: statutory tort for serious invasions of privacy; MinterEllison: statutory tort comes into force (10 June 2025); AUSTRAC: real estate professionals; OAIC: automated decision-making and privacy.