The 2026 privacy & AML obligations map for Australian real-estate agencies
In 2026 an Australian real-estate agency answers to two regimes: the Privacy Act 1988 (Cth) with its 13 Australian Privacy Principles, which governs every scrap of personal information you hold, and (for agencies providing property-sale services from 1 July 2026) the AML/CTF Act. This page maps each obligation to what you actually have to do.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
The obligations at a glance
| Obligation | What it means for your agency | Where it comes from | Who it applies to |
|---|---|---|---|
| Open & transparent management | Have a clear, current, compliant privacy policy | APP 1 | Every agency |
| Collect only what you need | Don't gather personal information beyond what's reasonably necessary | APP 3 | Every agency |
| Give a collection notice | Tell people what you're collecting and why, at the point of collection | APP 5 | Every agency |
| Use & disclose lawfully | Only use information for the purpose collected, or a permitted one | APP 6 | Every agency |
| Cross-border disclosure | Take care before sending personal information overseas | APP 8 | Every agency |
| Secure it, then let it go | Protect information and destroy or de-identify it once no longer needed | APP 11 | Every agency |
| Access requests | Let individuals see the personal information you hold about them | APP 12 | Every agency |
| Correction | Fix personal information that's wrong when asked | APP 13 | Every agency |
| Notify eligible breaches | Report qualifying data breaches to the OAIC and affected people | NDB scheme | Every agency holding personal information |
| Enrol with AUSTRAC | Register as a reporting entity, generally within 28 days | AML/CTF Act 2006 | Sales agencies |
| Customer due diligence (KYC) | Verify the identity of the customers you deal with | AML/CTF Act 2006 | Sales agencies |
| Report suspicious matters | Lodge suspicious matter reports to AUSTRAC | AML/CTF Act 2006 | Sales agencies |
| Keep records for 7 years | Retain AML/CTF records for at least seven years | AML/CTF Act 2006 | Sales agencies |
| Maintain an AML/CTF program | Have a documented program to identify and manage risk | AML/CTF Act 2006 | Sales agencies |
What are the Privacy Act duties for every agency?
The Privacy Act 1988 (Cth) and its 13 Australian Privacy Principles (APPs) govern how you handle personal information: buyer, seller, tenant and landlord details alike. The APPs that do the heavy lifting for an agency are:
- APP 1: open & transparent management. Manage personal information openly and keep a clear, current, compliant privacy policy that says what you collect, why, and how people can complain or get access. The OAIC assesses policies against APP 1.4.
- APP 3: collect only what's necessary. Only collect personal information that is reasonably necessary for your functions. Resist gathering "nice to have" data.
- APP 5: collection notice. At (or before) the point of collection, tell the person what you're collecting, why, and who you might share it with.
- APP 6: use & disclosure. Use and disclose personal information only for the purpose you collected it, or a directly related purpose the person would reasonably expect.
- APP 11: security and destruction. Take reasonable steps to protect the information from misuse, loss and unauthorised access, and destroy or de-identify it once you no longer need it.
- APP 12: access. Give individuals access to the personal information you hold about them when they ask.
- APP 13: correction. Correct personal information that is inaccurate, out of date or incomplete on request.
Two 2025–26 developments raise the stakes. A statutory tort for serious invasions of privacy commenced in June 2025, so individuals can now sue directly where the invasion was intentional or reckless. Carelessness alone is not enough. And the OAIC ran a 2026 privacy compliance sweep, naming rental & property a target sector and assessing privacy policies against APP 1.4; for a non-compliant policy the OAIC can issue an infringement notice directly, without going to court, for a fraction of the court maximum, with higher court penalties (up to $72,800 for an individual or $364,000 for a company) reserved for serious cases. If an eligible data breach occurs, the Notifiable Data Breaches scheme requires you to notify the OAIC and the affected individuals. See the OAIC sweep release.
What AML/CTF duties apply to sales agencies from 1 July 2026?
From 1 July 2026, real-estate agencies that provide property-sale services became reporting entities under the AML/CTF Act 2006, the "Tranche 2" reforms. If you sell property, five duties now sit alongside your privacy obligations:
- Enrol with AUSTRAC: generally within 28 days of first providing a designated service. An agency that started providing services on 1 July 2026 is due to enrol around 29 July 2026. Missing this enrolment cliff is the first and easiest thing to get wrong.
- Customer due diligence (CDD / KYC): verify who your customers are before you act for them.
- Suspicious matter reports (SMRs): report suspicious matters to AUSTRAC.
- Record-keeping: keep the relevant records for at least seven years.
- AML/CTF program: maintain a documented program to identify, mitigate and manage your money-laundering and terrorism-financing risk.
For the detail of which activities count, see the AUSTRAC real-estate designated services page.
Who's actually caught?
Three points decide how much of the above lands on you:
- The small-business turnover threshold. Under the Privacy Act, businesses with annual turnover of A$3 million or less are generally exempt, but exceptions apply, and you should not assume the exemption covers you.
- Sales vs rentals under AML/CTF. Agencies providing property-sale services are captured. Pure property managers who only manage rentals are generally not captured by AML/CTF, but they are still subject to the Privacy Act for the tenant and landlord data they handle.
- Customer-ID data pulls you in. Here's the catch for sales agencies: the customer-identity data you collect to meet AML/CTF obligations can bring Privacy Act obligations regardless of the turnover threshold. Collecting KYC information can be the very thing that removes your small-business exemption.
In short: if you manage rentals, the Privacy Act applies. If you sell, both regimes apply, and the AML side can switch on the full privacy regime even if you're under A$3 million.
How do you get ready?
- Confirm which regimes apply to you (sales, rentals, or both) and whether the turnover exemption realistically covers you once AML/CTF data is in the mix.
- If you sell property, get your AUSTRAC enrolment done and stand up your CDD, SMR, record-keeping and AML/CTF program before the enrolment window closes.
- Review your privacy policy against APP 1.4 and check your collection notices, security, retention/destruction, and access/correction processes are actually in place, not just written down.
- Run a plain-English self-audit across the areas agencies actually get caught on so you can see where you stand before a regulator or a claimant does.
Common questions
Which laws apply to a real estate agency in 2026?
In 2026 an Australian real-estate agency answers to two regimes: the Privacy Act 1988 (Cth) with its 13 Australian Privacy Principles, which governs every scrap of personal information you hold, and (for agencies providing property-sale services from 1 July 2026) the AML/CTF Act.
Do the AML obligations apply to property managers?
Agencies providing property-sale services are captured. Pure property managers who only manage rentals are generally not captured by AML/CTF, but they are still subject to the Privacy Act for the tenant and landlord data they handle.
Can the $3 million turnover exemption still protect a sales agency?
Not necessarily. The customer-identity data you collect to meet AML/CTF obligations can bring Privacy Act obligations regardless of the turnover threshold: collecting KYC information can be the very thing that removes your small-business exemption.
What are the core Privacy Act duties for an agency?
Keep a clear, current privacy policy (APP 1), collect only what's reasonably necessary (APP 3), give a collection notice at the point of collection (APP 5), use and disclose only for the purpose collected (APP 6), secure the data and destroy it when no longer needed (APP 11), and handle access and correction requests (APP 12–13).