Australian Privacy Law-Change Timeline for Real-Estate Agencies (2022 to 2027)
Australian privacy law changed for real-estate agencies at a series of dated points between 2022 and 2026, and one further change is already enacted and commences on 10 December 2026. The maximum civil penalty under s 13G of the Privacy Act 1988 (Cth) rose on 13 December 2022. Further civil penalty provisions commenced on 11 December 2024 (ss 13H, 13J and 13K), and s 13K is the provision for which the Commissioner may give an infringement notice (s 80UB) or a compliance notice (s 80UC). A statutory tort for serious invasions of privacy commenced on 10 June 2025, limited to intentional or reckless conduct. The first civil penalty under the Privacy Act was imposed on 8 October 2025, on conduct that occurred under the maximums in force before 13 December 2022. The OAIC's privacy-policy compliance sweep began in the first week of January 2026, with rental and property the first of the six sectors it listed. Brokering the sale, purchase or transfer of real estate became an AML/CTF designated service on 31 March 2026, with the AML/CTF obligations applying from 1 July 2026. Operators of residential tenancy databases were prescribed as organisations for their database acts and practices on 1 April 2026, and the Commissioner decided Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 on the same day. The Commonwealth penalty unit rose to $364 on 1 July 2026. From 10 December 2026, privacy policies must disclose certain automated decision-making (APP 1.7 to 1.9). Removing the s 6D small-business exemption is still proposed and is not law: the exposure-draft Privacy Amendment (Personal Data Protection) Bill 2026, released 31 August 2026, does not remove it.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. This timeline is a plain-English reference for real-estate professionals in Australia. It summarises, in our own words, changes to the Privacy Act 1988 (Cth) and adjacent laws that touch how agencies collect and handle personal information. It is not a substitute for advice from a qualified Australian lawyer on your specific circumstances. State and territory rules, and industry-specific obligations, may also apply and can vary.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
Every change at a glance
| Date | Change | Instrument or source | Status |
|---|---|---|---|
| 22 Feb 2018 | NDB scheme baseline: assess a suspected eligible data breach within 30 days (s 26WH(2)); remedial-action exception (s 26WF) | Privacy Act 1988 (Cth) Pt IIIC | In force |
| 13 Dec 2022 | s 13G maximum civil penalty for a serious interference by a body corporate: the greatest of A$50m, 3 times the benefit, or 30% of adjusted turnover in the breach turnover period. As enacted in 2022 the trigger was serious or repeated | Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 (Cth) | In force |
| 11 Dec 2024 | Further civil penalty provisions: s 13G narrowed to serious interferences; s 13H (2,000 penalty units, and 10,000 for a body corporate under s 82(5)(a) of the Regulatory Powers (Standard Provisions) Act 2014 (Cth)); s 13K, naming APP 1.3 and APP 1.4 (200 penalty units, likewise 1,000 for a body corporate), being the provision for which infringement notices (s 80UB) and compliance notices (s 80UC) can be given | Privacy and Other Legislation Amendment Act 2024 (Cth) Sch 1 | In force |
| 10 Jun 2025 | Statutory tort for serious invasions of privacy: five cumulative conditions, intentional or reckless, damages capped by Sch 2 cl 11(5); first applied at an interlocutory hearing in Kurraba Group Pty Ltd v Williams [2025] NSWDC 396 | Privacy and Other Legislation Amendment Act 2024 (Cth) Sch 2 | In force |
| 8 Oct 2025 | First civil penalty under the Privacy Act: A$5.8 million, on 2022 conduct under the maximums then in force | AIC v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224 | Decided |
| Jan 2026 | Privacy-policy compliance sweep of approximately 60 entities across 6 sectors, assessed against APP 1.4; rental and property was the first sector listed | OAIC media release, 9 December 2025 | Regulator activity, not law |
| 31 Mar 2026 | Brokering the sale, purchase or transfer of real estate becomes a designated service (table 5); agencies become reporting entities; Privacy Act s 6E(1A) engages | AML/CTF Amendment Act 2024 (Cth) Sch 3 Pt 1 | In force |
| 1 Apr 2026 | Operators of residential tenancy databases treated as organisations | Privacy Regulations 2025 (Cth) s 7(1) to (2) | In force |
| 1 Apr 2026 | Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24: the 2Apply / InspectRealEstate platform, APP 3.2 and APP 3.5 | Determination of the Australian Information Commissioner | Decided; recorded by the OAIC as under review in the Administrative Review Tribunal (APP Guidelines Ch 3, updated 13 May 2026) |
| 1 Jul 2026 | AML/CTF obligations begin: programs, customer due diligence, reporting, record-keeping. Enrolment date fixed at 29 Jul 2026 for services provided before 1 Jul | AML/CTF Amendment Act 2024 (Cth) Sch 3 Pt 4 items 11 and 12 | In force |
| 1 Jul 2026 | Penalty unit rises to $364 (was $330 from 7 Nov 2024; next indexation day 1 Jul 2029) | Crimes Act 1914 (Cth) s 4AA and the notifiable instrument made under it | In force |
| 10 Dec 2026 | Privacy policies must disclose certain automated decision-making (APP 1.7 to 1.9) | Privacy and Other Legislation Amendment Act 2024 (Cth) Sch 1 Pt 15 | Enacted, commences 10 Dec 2026 |
| Proposed | Abolish the s 6D small-business exemption; wider reform. The exposure-draft Privacy Amendment (Personal Data Protection) Bill 2026 does not abolish it | Attorney-General's Department exposure draft, released 31 Aug 2026, submissions closing 18 Sep 2026 | Proposed, not law |
Baseline: the Notifiable Data Breach (NDB) scheme
In force since 22 February 2018. Part IIIC, Privacy Act 1988 (Cth), inserted by the Privacy Amendment (Notifiable Data Breaches) Act 2017 (Cth).
The NDB scheme is the standing backdrop to everything below, and its trigger is narrower than "a breach". It applies where an entity is aware of reasonable grounds to suspect there may have been an eligible data breach, which is the serious-harm species: under s 26WE(2), unauthorised access or disclosure where "a reasonable person would conclude that the access or disclosure would be likely to result in serious harm", or a loss where that is likely to follow. Where that suspicion arises, s 26WH(2) requires the entity to:
"(a) carry out a reasonable and expeditious assessment of whether there are reasonable grounds to believe that the relevant circumstances amount to an eligible data breach of the entity; and (b) take all reasonable steps to ensure that the assessment is completed within 30 days after the entity becomes aware as mentioned in paragraph (1)(a)."
Where the entity then has reasonable grounds to believe there has been an eligible data breach, it must prepare a statement under s 26WK and notify under s 26WL. Note the remedial-action exception in s 26WF: where action is taken before serious harm results, such that a reasonable person would conclude serious harm is no longer likely, the breach "is taken never to have been" an eligible data breach.
What it means: The duty is triggered by reasonable grounds to suspect an eligible data breach, not by any loss or exposure, and the assessment window in s 26WH(2)(b) is 30 days from the entity becoming aware. Containment matters for a statutory reason: under s 26WF, action that removes the likelihood of serious harm removes the eligible-data-breach characterisation.
2022
13 December 2022: the maximum civil penalty under s 13G rose
Instrument: Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 (Cth), amending s 13G of the Privacy Act 1988 (Cth). Commenced 13 December 2022.
For a body corporate, s 13G(3) sets the maximum at "the greatest of the following": "$50,000,000"; where the court can determine the value of the benefit the body corporate and any related body corporate obtained and that is reasonably attributable to the conduct, "3 times the value of that benefit"; or where the court cannot determine that value, "30% of the adjusted turnover of the body corporate during the breach turnover period for the contravention" (Privacy Act 1988 (Cth), Compilation 104, compilation date 4 June 2026). "Breach turnover period" is defined in s 13G(7). For a person other than a body corporate, s 13G(2) sets the maximum at $2,500,000.
As enacted in 2022 the trigger was serious or repeated interferences. The Privacy and Other Legislation Amendment Act 2024 (Cth) narrowed it. In Compilation 104, s 13G(1) reads: "An entity contravenes this subsection if: (a) the entity does an act, or engages in a practice, that is an interference with the privacy of an individual; and (b) the interference with privacy is serious." Repetition survives only as one of the matters a court may have regard to under s 13G(1B)(f).
What it means: These figures are a statutory ceiling for the most serious cases, not a going rate, and they do not mean a breach produces a $50m bill. A court sets the amount, and only on an application the Commissioner brings under s 80U; under s 82(3) of the Regulatory Powers (Standard Provisions) Act 2014 (Cth) the court may order "such pecuniary penalty for the contravention as the court determines to be appropriate", taking into account the matters in s 82(6). Section 13J applies only inside proceedings for a contravention of s 13G: where the court is satisfied there was an interference but is not satisfied it was serious, it "may make a pecuniary penalty order against the entity for contravening section 13H, instead of section 13G". Which maximum applies to particular conduct is fixed by when that conduct occurred, so conduct before 13 December 2022 is governed by the earlier maxima.
2024
11 December 2024: a tiered civil penalty regime, and infringement notices for privacy-policy failures
Instrument: Privacy and Other Legislation Amendment Act 2024 (Cth), inserting ss 13H, 13J and 13K into the Privacy Act 1988 (Cth). Royal Assent was 10 December 2024 and these provisions commenced the day after. The legislation history in Privacy Act 1988 (Cth) Compilation 104 records the block as "sch 1 (items 1-44, 49-67, 72, 73, 82-86): 11 Dec 2024 (s 2(1) items 2, 5, 6)". The Royal Assent date is not the commencement date.
s 13H(1) covers an act or practice that is an interference with the privacy of an individual, without the seriousness element, and s 13H(3) provides that the penalty "must not exceed 2,000 penalty units". Paragraph 82(5)(a) of the Regulatory Powers (Standard Provisions) Act 2014 (Cth) sets a body corporate's maximum at five times the penalty specified for the provision, which takes s 13H to 10,000 penalty units and s 13K to 1,000. Section 13G is drafted differently: s 13G(4) provides that s 13G(3) "applies despite paragraph 82(5)(a) of the Regulatory Powers Act", because s 13G(3) states its own body-corporate maximum. s 13J applies only inside proceedings for a contravention of s 13G: where the court is satisfied of the interference but not of its seriousness, it "may make a pecuniary penalty order against the entity for contravening section 13H, instead of section 13G". s 13K(1)(b) lists the administrative principles whose breach can attract an infringement or compliance notice, and the first two it names are "Australian Privacy Principle 1.3 (requirement to have APP privacy policy)" and "Australian Privacy Principle 1.4 (contents of APP privacy policy)"; s 13K(4) caps that penalty at 200 penalty units.
The notice powers sit outside s 13K. s 80UB(1)(a) makes "subsections 13K(1) and (2)" subject to an infringement notice under Part 5 of the Regulatory Powers (Standard Provisions) Act 2014 (Cth), and s 80UB(2)(a) makes the Commissioner an "infringement officer" for that purpose, so that route involves no court. s 80UC(1) allows the Commissioner to give a compliance notice where the Commissioner "reasonably believes that the entity has contravened subsection 13K(1) or (2)". Under s 103(1) of the Regulatory Powers Act an infringement officer who "believes on reasonable grounds" that a person has contravened the provision "may give" the notice, and s 103(2) requires it within 12 months of the alleged contravention. The amount that may be stated in a notice is set by s 104 of that Act and is a fraction of the maximum a court could impose, so the court maximum and the notice amount are different figures.
The three provisions overlap rather than form a ladder. The note to s 13K(1) reads: "Conduct that contravenes this section may also contravene section 13G or 13H." Section 84(2) of the Regulatory Powers Act provides that "the person is not liable to more than one pecuniary penalty under this Part in relation to the same conduct".
These are statutory maximums, not automatic penalties, infringement-notice amounts or standard fines. The applicable enforcement pathway and amount depend on the relevant provision, the conduct and the circumstances.
What it means: The 2022 ceiling is not the whole penalty picture. The 2024 tiers are expressed in penalty units, so their dollar value moves with the Crimes Act 1914 (Cth) s 4AA indexation rather than staying fixed, and the failures s 13K names include having a privacy policy at all and what that policy contains.
2025
10 June 2025: statutory tort for serious invasions of privacy commences
Instrument: Schedule 2 of the Privacy and Other Legislation Amendment Act 2024 (Cth). Commencement is set by s 2 table item 8: "A single day to be fixed by Proclamation. However, if the provisions do not commence within the period of 6 months beginning on the day this Act receives the Royal Assent, they commence on the day after the end of that period." Royal Assent was 10 December 2024. The legislation history in Privacy Act 1988 (Cth) Compilation 104 (compilation date 4 June 2026) records the commencement of that Schedule as "sch 2: 10 June 2025 (s 2(1) item 8)", which is the date that fallback produces.
The conditions are cumulative. Schedule 2 cl 7(1) provides:
"An individual (the plaintiff) has a cause of action in tort against another person (the defendant) if: (a) the defendant invaded the plaintiff's privacy by doing one or both of the following: (i) intruding upon the plaintiff's seclusion; (ii) misusing information that relates to the plaintiff; and (b) a person in the position of the plaintiff would have had a reasonable expectation of privacy in all of the circumstances; and (c) the invasion of privacy was intentional or reckless; and (d) the invasion of privacy was serious; and (e) the public interest in the plaintiff's privacy outweighed any countervailing public interest."
Negligence is excluded by cl 7(1)(c). Cutting the other way, cl 7(2) provides that "the invasion of privacy is actionable without proof of damage". Damages are capped by cl 11(5): the sum of "any damages awarded for non-economic loss" and "any exemplary or punitive damages" "must not exceed the greater of" "$478,550" and "the maximum amount of damages for non-economic loss that may be awarded in defamation proceedings under an Australian law" (Compilation 104, compilation date 4 June 2026). The court must not award aggravated damages (cl 11(2)) and may award exemplary or punitive damages only in exceptional circumstances (cl 11(4)).
What it means: An individual can bring a court claim separately from any regulator action, but every condition in cl 7(1) has to be met, including a reasonable expectation of privacy and an invasion that was both intentional or reckless and serious. Carelessness alone is not enough. The first published decision applying the tort was an interlocutory one: in Kurraba Group Pty Ltd v Williams [2025] NSWDC 396 (7 October 2025), brought by a property developer over material published about it online, the District Court of New South Wales found a serious question to be tried on the statutory tort and granted injunctions. A serious question to be tried is a lower threshold than proving the cause of action at a final hearing.
8 October 2025: the first civil penalty under the Privacy Act
Citation: Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224 (Federal Court). The OAIC media release published 9 October 2025 records that "The Federal Court yesterday ordered" the penalties, which fixes the orders at 8 October 2025.
The Court imposed a A$5.8 million civil penalty on a listed pathology company over a 2022 breach affecting about 223,000 people: A$4.2 million for failing to take reasonable steps to protect the information (APP 11.1), A$800,000 for failing to carry out a reasonable and expeditious assessment of a suspected eligible data breach, and A$800,000 for failing to prepare and give the Commissioner an eligible-data-breach statement.
"APP 11.1(b) has not been the subject of any previous judicial consideration." · [2025] FCA 1224 at [48]
The conduct occurred in 2022, before the higher maximum-penalty regime commenced on 13 December 2022. The OAIC release records that "The penalties were imposed under the penalty regime which was in force at the time of the contraventions", and that the regime that came into force on 13 December 2022 "allows the Court to impose much higher penalties for serious interferences with privacy". So the maximums the Court analysed are the historic ones, not the s 13G maximums in the 13 December 2022 entry above.
What it means: This is the first civil penalty a court has imposed under the Privacy Act, and it is the only figure on this page a court has actually ordered. The two notification failures were penalised separately from the failure to protect the data, which is why the NDB assessment duty above is not a formality.
2026
January 2026: the OAIC's privacy-policy compliance sweep
Source: OAIC media release, "Privacy compliance sweep to put privacy policies under the spotlight", published 9 December 2025, oaic.gov.au.
The OAIC announced that the sweep "will begin in the first week of January" and that "Entities' privacy policies will be assessed to ensure they meet the requirements of Australian Privacy Principle (APP) 1.4, which sets out what a privacy policy must include". It said the OAIC "will review the privacy policies of approximately 60 entities from the following 6 sectors that may collect information in-person". Rental and property was the first of the six sectors the OAIC listed, described as the "collection of individuals' personal information during property inspections". Privacy Commissioner Carly Kind was quoted in the release: "When confronted with in-person requests for their personal information from retailers, licenced venues, car hire companies or real estate agents, consumers often don't have access to all the information they might need to make an informed decision." In the Commissioner's IAPP Sydney keynote of 20 May 2026, published by the OAIC, she reported the outcome: "Our Privacy Sweep of sixty entities earlier this year found instances of non-compliance in a significant proportion."
What it means: The sweep assessed privacy policies against APP 1.4. In-person collection is how the OAIC chose the six sectors, not what it assessed, so the sweep is not a finding about open-home collection practices. The "significant proportion" result is reported across all sixty entities in six sectors and the split by sector is not published, so it cannot be attributed to real estate. The release also said entities found to have non-compliant privacy policies may face compliance and infringement notices and penalties. The sweep was a review of privacy policies against APP 1.4. It was not a published finding that any particular agency breached APP 1.4. Since 11 December 2024 there are three distinct steps behind that enforcement route: APP 1.4 is the substantive obligation about what a privacy policy must contain; s 13K(1)(b)(ii) makes a breach of it a contravention of a civil penalty provision; and s 80UB(1)(a) then makes subsections 13K(1) and (2), not the APP itself, subject to an infringement notice under Part 5 of the Regulatory Powers Act, with the Commissioner an infringement officer under s 80UB(2)(a). s 80UC(1) allows a compliance notice.
31 March 2026: brokering real-estate sales becomes an AML/CTF designated service
Instrument: Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth) ("Tranche 2"), Schedule 3 Part 1, which inserts table 5, "Real estate services", into s 6 of the AML/CTF Act. Item 2 of the s 2 commencement table sets Schedules 1, 2 and 3 to commence on 31 March 2026.
Table 5 item 1 is "brokering the sale, purchase or transfer of real estate on behalf of a buyer, seller, transferee or transferor in the course of carrying on a business". Agencies providing that service became reporting entities on 31 March 2026.
The obligations were deferred separately. Schedule 3 Part 4 item 11(1) provides that Part 1A (AML/CTF programs), Part 2 (customer due diligence), Part 3 (reporting obligations) and Divisions 2 to 6 of Part 10 (record keeping) "do not apply, until 1 July 2026, to a reporting entity" providing a service covered by table 5 or 6, while item 11(2) provides that "the remaining provisions" of the Act "apply, on and after the commencement of this item". Item 12 fixes enrolment on the AUSTRAC Reporting Entities Roll for anyone providing the service before 1 July 2026: it applies s 51B(1) "as if the reference ... to 28 days after the day on which the person commences to provide the designated service were a reference to 29 July 2026". That date is statutory. It is not 28 days after anything, and deriving it that way produces the wrong answer.
Ordinary leasing work sits outside the table 5 services because of the definition, not because of a separate trigger. The s 6 definition of "real estate" excludes, at paragraph (f), "a leasehold interest under a lease for a term (excluding options for further terms) of 30 years or less", which covers ordinary residential tenancies and any commercial lease of 30 years or less. Note the parenthetical: option terms are not added to the term. Whether any other designated service reaches a particular property-management arrangement is a separate question decided under that item's own words.
The Privacy Act bridge is s 6E(1A), which provides that if a small business operator is a reporting entity because of anything done in the course of a small business it carries on, the Privacy Act applies "in relation to the activities carried on ... for the purposes of, or in connection with, activities relating to" the AML/CTF Act and its regulations and rules, "as if the small business operator were an organisation". Because the trigger in s 6E(1A) is being a reporting entity, it engaged with status on 31 March 2026, not with the obligations on 1 July.
What it means: An agency brokering sales has been a reporting entity since 31 March 2026, and the AML/CTF programs, customer due diligence, reporting and record-keeping obligations apply from 1 July 2026. The s 6E(1A) scoping is activity-based, not a list of documents: it reaches the activities carried on for the purposes of, or in connection with, activities relating to the AML/CTF Act, which is wider than the copied identification document alone. It does not sweep the whole business in, and it does not reach general property-management files or the client database. s 6E(1A) applies to a small business operator, so it is not the relevant provision for an agency already outside the s 6D exemption. An agency that does both sales and property management is a reporting entity for its sales work.
1 April 2026: operators of residential tenancy databases lose the small-business exemption
Instrument: Privacy Regulations 2025 (Cth) (F2025L01377, registered 14 November 2025), s 7(1) to (2), made for s 6E(2) of the Privacy Act 1988 (Cth). The instrument commenced 1 April 2026.
s 7(1) reads: "For the purposes of subsection 6E(2) of the Act, a small business operator that operates a residential tenancy database is prescribed." s 7(2) prescribes the acts and practices caught: collecting personal information for the purpose of establishing or maintaining a residential tenancy database, maintaining personal information on such a database, and using or disclosing personal information stored on one.
What it means: The trigger is operating a residential tenancy database, which is what the prescribed operators do. s 7(2) opens by confining the prescribed acts and practices to "a small business operator of the kind mentioned in subsection (1) of this section", and it limits what is caught even for an operator to collecting for, maintaining, and using or disclosing from that database, rather than the operator's whole business. Section 5 of the same instrument defines a residential tenancy database with two cumulative limbs: it "stores personal information in relation to an individual's occupation of residential premises as a tenant", and it "can be accessed by a person other than the operator of the database or a person acting for the operator". A list nobody outside the agency can reach does not meet the second limb. An agency that searches, screens against or lists on someone else's database is not caught by s 7(1). A separate and genuinely fact-specific question can arise under s 6D(4)(c), which is subject to the carve-outs in s 6D(7).
1 April 2026: the OAIC decision on the 2Apply / InspectRealEstate tenancy-application platform
Instrument or citation: Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 (1 April 2026), a determination of the Australian Information Commissioner. The respondent is IRE Pty Ltd, the platform operator, not an individual agency. At [36] the determination records that the Commissioner commenced the investigation on 18 March 2025 "under s 40(2) of the Privacy Act", the power to investigate on the Commissioner's own initiative rather than on an individual's complaint, and defines the relevant period as running from March 2020, the general release of 2Apply, to that date. The declarations were made under s 52(1A), the limb that applies to an act or practice investigated under s 40(2).
Status note. The OAIC's Australian Privacy Principles Guidelines, Chapter 3, updated 13 May 2026, records that this determination "is under review in the Administrative Review Tribunal", and says the guidance "will be updated should the outcome of the review change this finding". The OAIC has nonetheless written the determination's positions into its guidelines. Section 96(1)(c) of the Privacy Act makes a decision to make a determination reviewable by the Tribunal. What follows describes the determination as published on 1 April 2026.
The Commissioner found the platform collected personal information that was not reasonably necessary, contrary to APP 3.2, listing the fields at [94]:
"gender; details of dependants, specifically names and ages; student status; bankruptcy status; retirement status; details of previous living history; current or intended ownership of their principal place of residence or investment property; current applications for other properties; bond and rent assistance application status; and citizenship status and visa expiry" · [2026] AICmr 24 at [94]
A separate finding was made under APP 3.5, and it was about the way the form asked rather than the field list: at [97] the determination distinguishes the two, and the APP 3.5 finding rests on the platform's Online Choice Architecture and on unfair, rather than unlawful, means. The determination "also considers, for the first time, an entity's Online Choice Architecture in an assessment of whether the collection was fair" ([2026] AICmr 24 at [7]). The outcome was declarations and remedial orders, including ceasing to collect the listed fields within 60 days and an independent review at IRE's own expense, not a penalty.
What it means: This is the most detailed published statement the Commissioner has made on collection through a rental-application platform, and the categories listed at [94] were ordinary ones. The OAIC's own APP 3 guidance, updated 13 May 2026, describes that position as not settled while the Administrative Review Tribunal review is on foot. No finding was made against any agency. APP 3.2 binds the APP entity that does the collecting, and the determination decided that question about the platform only: at [53] the Commissioner found the respondent had "operational involvement in the development and maintenance of the default list of questions" and engaged "in the collection of personal information in its own right", so it was "not merely collecting personal information on behalf of real estate agents". At [6] the Commissioner said operators of RentTech and other online platforms "may bear their own obligations under the Privacy Act", and at [10] encouraged "RentTech providers and real estate agents to turn their minds to the privacy of tenancy applicants". Whether the Privacy Act reaches a particular agency at all is a separate question under s 6D.
1 July 2026: Commonwealth penalty unit rises to $364
Instrument: Crimes Act 1914 (Cth) s 4AA (penalty-unit value), as indexed. The value is $364 for offences and contraventions committed on or after 1 July 2026. The previous value was $330 (7 November 2024 to 30 June 2026), and the next indexation day is 1 July 2029.
The penalty unit is the figure a Commonwealth penalty expressed in units is calculated from, including the Privacy Act 1988 (Cth) s 13H and s 13K tiers described above.
What it means: Penalties expressed in penalty units rise in dollar terms at each indexation without any change to the underlying duty. The unit value that applies is the one in force when the contravention was committed, not today's.
10 December 2026: privacy policies must disclose certain automated decision-making
Instrument: Privacy and Other Legislation Amendment Act 2024 (Cth) Schedule 1 Part 15, inserting APP 1.7 to 1.9. Commencement is set by s 2 table item 7: "The day after the end of the period of 24 months beginning on the day this Act receives the Royal Assent." Royal Assent was 10 December 2024. The legislation history in Privacy Act 1988 (Cth) Compilation 104 records the commencement of Schedule 1 items 87 to 89 as "sch 1 (items 87-89): 10 Dec 2026 (s 2(1) item 7)". Item 7 fixes the day by that formula and, unlike item 8 which governs Schedule 2, it has no proclamation limb.
APP 1.7 requires an APP privacy policy to contain the information covered by APP 1.8 where three cumulative conditions are met: the entity "has arranged for a computer program to make, or do a thing that is substantially and directly related to making, a decision"; the decision "could reasonably be expected to significantly affect the rights or interests of an individual"; and "personal information about the individual is used in the operation of the computer program to make the decision or do the thing". APP 1.8 then sets out what the policy must say: the kinds of personal information used, the kinds of decisions made solely by such programs, and the kinds of decisions where such a program does a substantially and directly related thing.
Status: enacted, commencing 10 December 2026. It is not current law before that date.
What it means: This is the one enacted change still ahead inside the period this timeline covers, so it belongs in the timeline rather than in the horizon section below. It is a privacy-policy content duty, and it applies only where all three APP 1.7 conditions are met.
Proposed or on the horizon (NOT LAW)
The item below is a proposed reform or announced direction only. It is not in force and must not be relied on as current law. Timelines and detail may change. This label does not apply to APP 1.7 to 1.9 above, which are enacted with a fixed commencement date.
2026 to 2027 (proposed): abolishing the s 6D small-business exemption and wider Privacy Act reform
Status: Proposed, not law. Part of the Australian Government's ongoing Privacy Act review response, following the Privacy and Other Legislation Amendment Act 2024 (Cth) "first tranche". The Attorney-General's Department released an exposure draft of the second tranche, the Privacy Amendment (Personal Data Protection) Bill 2026, on 31 August 2026, with submissions closing 18 September 2026. That draft does not repeal s 6D or remove the small-business exemption. It does propose to rewrite the exceptions: its Schedule 2 Part 1 amends s 6D(4) and repeals and substitutes paragraphs 6D(4)(c) and (d) and subsection 6D(8), replacing the disclosure-for-a-benefit limb with one about trading personal information. It is an exposure draft out for consultation, not a Bill before Parliament, and its commencement table is blank.
The current position: under s 6D(1) a business is a small business at a test time "if its annual turnover for the previous financial year is $3,000,000 or less", so the test looks at the previous financial year. Turnover is not the only test. s 6D(4) lists exceptions, and s 6D(4)(a) is one-way: an operator is not a small business operator if it "carries on a business that has had an annual turnover of more than $3,000,000 for a financial year that has ended" after the later of the start of the business and the commencement of the section. In Property Lovers Pty Ltd (Privacy) [2024] AICmr 249 the Commissioner held a business to the APPs under s 6D(4)(c), which covers disclosing personal information about another person for a benefit, despite accepting it turned over under $3 million. Whether a particular agency's disclosures engage that limb depends on its own arrangements.
What it means (if it becomes law): A business relying on the s 6D exemption today would be covered to the extent the enacted provisions covered it, and the Act's obligations would follow that coverage: a compliant privacy policy, APP-standard handling of personal information, and the NDB scheme. Nothing here is settled. The scope of any amending Bill, its transitional provisions and its commencement date are what would decide it.
Sources and how to check them
Legislation is cited via the Federal Register of Legislation (legislation.gov.au) or AustLII, and regulator material via the OAIC (oaic.gov.au). Section numbers and quoted text are taken from the compilations named below.
- Privacy Act 1988 (Cth), Compilation 104 (compilation date 4 June 2026), including Part IIIC (NDB), ss 6D, 6E, 13G, 13H, 13J, 13K and Schedule 2: legislation.gov.au.
- Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 (Cth): legislation.gov.au.
- Privacy and Other Legislation Amendment Act 2024 (Cth), s 2 commencement table, Schedule 1 Part 15 (APP 1.7 to 1.9) and Schedule 2 (statutory tort): legislation.gov.au.
- Privacy Regulations 2025 (Cth), F2025L01377, s 7: legislation.gov.au.
- Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24: oaic.gov.au and AustLII.
- Australian Information Commissioner v Australian Clinical Labs Limited (No 2) [2025] FCA 1224: AustLII, and the OAIC media release on the penalty.
- Property Lovers Pty Ltd (Privacy) [2024] AICmr 249: oaic.gov.au and AustLII.
- OAIC media release, "Privacy compliance sweep to put privacy policies under the spotlight", 9 December 2025, and the Commissioner's IAPP Sydney keynote, 20 May 2026: oaic.gov.au.
- Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth), s 2 commencement table and Schedule 3 Parts 1 and 4, and the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) s 6: legislation.gov.au, with AUSTRAC guidance at austrac.gov.au.
- Crimes Act 1914 (Cth) s 4AA (the indexation mechanism), C1914A00012, and the notifiable instrument made under it publishing the indexed amount: legislation.gov.au.
- Regulatory Powers (Standard Provisions) Act 2014 (Cth), C2014A00093, ss 82, 84, 103 and 104: legislation.gov.au.
- OAIC, Australian Privacy Principles Guidelines, Chapter 3 (APP 3), updated 13 May 2026, for the Administrative Review Tribunal status of [2026] AICmr 24 and the full field list: oaic.gov.au.
- OAIC media release on the Australian Clinical Labs penalties, published 9 October 2025: oaic.gov.au.
This page summarises publicly available legal information in original wording, quoting primary sources where a figure or a test depends on the exact words. It does not reproduce third-party commentary.
General information, not legal advice.