The 2026 privacy & AML obligations map for Australian real-estate agencies
In 2026 an Australian real-estate agency answers to two regimes: the Privacy Act 1988 (Cth) with its 13 Australian Privacy Principles, which governs every scrap of personal information you hold, and, for agencies providing property-sale services, the AML/CTF Act, under which they have been reporting entities since 31 March 2026 and have carried the obligations since 1 July 2026. This page maps each obligation to what you actually have to do.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
The obligations at a glance
The Privacy Act rows bind an agency the Act covers, and not every agency is: you may genuinely be exempt, and "Who's actually caught?" below sets out the tests.
| Obligation | What it means for your agency | Where it comes from | Who it applies to |
|---|---|---|---|
| Open & transparent management | Have a clear, current, compliant privacy policy | APP 1 | Every agency |
| Collect only what you need | Don't gather personal information beyond what's reasonably necessary | APP 3 | Every agency |
| Give a collection notice | Tell people what you're collecting and why, at the point of collection | APP 5 | Every agency |
| Use & disclose lawfully | Only use information for the purpose collected, or a permitted one | APP 6 | Every agency |
| Cross-border disclosure | Take care before sending personal information overseas | APP 8 | Every agency |
| Secure it, then let it go | Protect information, and destroy or de-identify it once you no longer need it and no Australian law requires you to keep it | APP 11.1, 11.2 | Every agency the Privacy Act covers |
| Access requests | Let individuals see the personal information you hold about them | APP 12 | Every agency |
| Correction | Fix personal information that's wrong when asked | APP 13 | Every agency |
| Notify eligible breaches | Give the Commissioner a statement, then notify the individuals concerned or those at risk; publish it if neither is practicable | Part IIIC, ss 26WK, 26WL | Every agency the Privacy Act covers |
| Enrol with AUSTRAC | Enrol as a reporting entity. 29 July 2026 if you provided a designated service at any time before 1 July 2026, a date fixed outright by Sch 3 Pt 4 item 12 rather than counted from anything. A later starter instead gets the ordinary s 51B(1) window from their own first service | AML/CTF Act 2006 s 51B(1) | Sales agencies |
| Customer due diligence (KYC) | Verify the identity of the customers you deal with | AML/CTF Act 2006 | Sales agencies |
| Report suspicious matters | Lodge suspicious matter reports to AUSTRAC | AML/CTF Act 2006 | Sales agencies |
| Keep records for 7 years | Retain AML/CTF records for at least seven years | AML/CTF Act 2006 | Sales agencies |
| Maintain an AML/CTF program | Have a documented program to identify and manage risk | AML/CTF Act 2006 | Sales agencies |
What are the Privacy Act duties for every agency?
The Privacy Act 1988 (Cth) and its 13 Australian Privacy Principles (APPs) govern how you handle personal information: buyer, seller, tenant and landlord details alike. The APPs that do the heavy lifting for an agency are:
- APP 1: open & transparent management. Manage personal information openly and keep a clear, current, compliant privacy policy that says what you collect, why, and how people can complain or get access. The OAIC assesses policies against APP 1.4.
- APP 3: collect only what's necessary. Only collect personal information that is reasonably necessary for your functions. Resist gathering "nice to have" data.
- APP 5: collection notice. At (or before) the point of collection, tell the person what you're collecting, why, and who you might share it with.
- APP 6: use & disclosure. Use and disclose personal information only for the purpose you collected it, or a directly related purpose the person would reasonably expect.
- APP 11: security and destruction. Take reasonable steps to protect the information from misuse, interference, loss and unauthorised access, and destroy or de-identify it once you no longer need it, unless an Australian law requires you to keep it, as AML/CTF record-keeping does.
- APP 12: access. Give individuals access to the personal information you hold about them when they ask.
- APP 13: correction. Correct personal information that is inaccurate, out of date or incomplete on request.
Two 2025–26 developments raise the stakes. The statutory tort for serious invasions of privacy commenced on 10 June 2025, so individuals can sue directly and, under Schedule 2 clause 7(2), without proving they lost a cent. Carelessness alone is not enough: clause 7(1)(c) requires the invasion to be intentional or reckless and clause 7(1)(d) requires it to be serious. And the OAIC ran a 2026 privacy compliance sweep in which rental and property was the first of six named sectors, assessing privacy policies against APP 1.4. A policy that breaches APP 1.3 or 1.4 is a contravention of s 13K(1), which the Commissioner can pursue by infringement notice without going to court (s 80UB), or a court can penalise at up to 200 penalty units for an individual and 1,000 for a body corporate, which is $72,800 and $364,000 at the penalty unit value of $364 in force from 1 July 2026. If an eligible data breach occurs, the Notifiable Data Breaches scheme requires a statement to the Commissioner and then notice to the individuals the information relates to, or those at risk, or publication if neither is practicable. See the OAIC sweep release.
What AML/CTF duties apply to sales agencies from 1 July 2026?
On 31 March 2026, real-estate agencies that provide property-sale services became reporting entities under the AML/CTF Act 2006, the "Tranche 2" reforms. If you sell property, five duties now sit alongside your privacy obligations:
- Enrol with AUSTRAC: if your agency provided a designated service at any time before 1 July 2026, your date was 29 July 2026, fixed by Schedule 3 Part 4 item 12 of the amending Act rather than counted from your own start date. If your first designated service comes later, s 51B(1) gives you 28 days from it, and s 186A sets the infringement notice for late enrolment at 60 penalty units for a body corporate. Is your agency on the Reporting Entities Roll?
- Customer due diligence (CDD / KYC): verify who your customers are before you act for them.
- Suspicious matter reports (SMRs): report suspicious matters to AUSTRAC.
- Record-keeping: s 111 runs seven years from the end of the business relationship; s 108 runs seven years from the day a customer gave you a document for a service you went on to provide.
- AML/CTF program: maintain a documented program to identify, mitigate and manage your money-laundering and terrorism-financing risk.
For the detail of which activities count, see the AUSTRAC real-estate designated services page.
Who's actually caught?
Three points decide how much of the above lands on you:
- The small-business turnover threshold. Turnover of A$3 million or less for the previous financial year generally makes you a small business (s 6D(1)), so you may genuinely be exempt. But it runs one way: s 6D(4)(a) excludes a business that has had turnover over A$3 million for any financial year ended since it started, so one year over the line is permanent.
- Sales vs rentals under AML/CTF. Table 5 in s 6(5A) covers brokering the sale, purchase or transfer of real estate, and selling or transferring it. Leasing is in neither item, so an agency that only manages rentals is generally not captured by AML/CTF, though it is still subject to the Privacy Act for the tenant and landlord data it handles.
- Reporting-entity status pulls you in. Here's the catch for sales agencies: Privacy Act s 6E(1A) applies the Act to a small business operator that is a reporting entity "as if the small business operator were an organisation", in relation to its activities connected with the AML/CTF Act. The trigger is that status, which attached on 31 March 2026, not your turnover: see the small-business exemption page.
In short: if you sell, both regimes apply, and s 6E(1A) applies the Privacy Act to your AML/CTF-related activities even if you're under A$3 million. If you only manage rentals, AML/CTF is generally out and the Privacy Act question turns on s 6D.
How do you get ready?
- Confirm which regimes apply to you (sales, rentals, or both) and whether the turnover exemption realistically covers you once you provide a designated service.
- If you sell property, check you are enrolled with AUSTRAC and that your CDD, SMR, record-keeping and AML/CTF program are actually running. The 29 July 2026 date has passed; under s 51B(2B) the duty to apply continues until you do.
- Review your privacy policy against APP 1.4 and check your collection notices, security, retention/destruction, and access/correction processes are actually in place, not just written down.
- Run a plain-English self-audit across the areas agencies actually get caught on so you can see where you stand before a regulator or a claimant does.
Common questions
Which laws apply to a real estate agency in 2026?
In 2026 an Australian real-estate agency answers to two regimes: the Privacy Act 1988 (Cth) with its 13 Australian Privacy Principles, which governs every scrap of personal information you hold, and, for agencies providing property-sale services, the AML/CTF Act, under which they have been reporting entities since 31 March 2026 and have carried the obligations since 1 July 2026.
Do the AML obligations apply to property managers?
Agencies providing property-sale services are captured. Pure property managers who only manage rentals are generally not captured by AML/CTF, but they are still subject to the Privacy Act for the tenant and landlord data they handle.
Can the $3 million turnover exemption still protect a sales agency?
Not necessarily. Privacy Act s 6E(1A) treats a small business operator that is a reporting entity as an organisation in relation to its activities connected with the AML/CTF Act. The trigger is that status, which attached on 31 March 2026, not your turnover and not the data you collect.
What are the core Privacy Act duties for an agency?
Keep a clear, current privacy policy (APP 1), collect only what's reasonably necessary (APP 3), give a collection notice at the point of collection (APP 5), use and disclose only for the purpose collected (APP 6), secure the data and destroy it when no longer needed (APP 11), and handle access and correction requests (APP 12–13).