Skip to content

The 2026 privacy & AML obligations map for Australian real-estate agencies

In 2026 an Australian real-estate agency answers to two regimes: the Privacy Act 1988 (Cth) with its 13 Australian Privacy Principles, which governs every scrap of personal information you hold, and (for agencies providing property-sale services from 1 July 2026) the AML/CTF Act. This page maps each obligation to what you actually have to do.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price

Orientation only, not a compliance assessment. General information and tools, not legal advice.

The obligations at a glance

ObligationWhat it means for your agencyWhere it comes fromWho it applies to
Open & transparent managementHave a clear, current, compliant privacy policyAPP 1Every agency
Collect only what you needDon't gather personal information beyond what's reasonably necessaryAPP 3Every agency
Give a collection noticeTell people what you're collecting and why, at the point of collectionAPP 5Every agency
Use & disclose lawfullyOnly use information for the purpose collected, or a permitted oneAPP 6Every agency
Cross-border disclosureTake care before sending personal information overseasAPP 8Every agency
Secure it, then let it goProtect information and destroy or de-identify it once no longer neededAPP 11Every agency
Access requestsLet individuals see the personal information you hold about themAPP 12Every agency
CorrectionFix personal information that's wrong when askedAPP 13Every agency
Notify eligible breachesReport qualifying data breaches to the OAIC and affected peopleNDB schemeEvery agency holding personal information
Enrol with AUSTRACRegister as a reporting entity, generally within 28 daysAML/CTF Act 2006Sales agencies
Customer due diligence (KYC)Verify the identity of the customers you deal withAML/CTF Act 2006Sales agencies
Report suspicious mattersLodge suspicious matter reports to AUSTRACAML/CTF Act 2006Sales agencies
Keep records for 7 yearsRetain AML/CTF records for at least seven yearsAML/CTF Act 2006Sales agencies
Maintain an AML/CTF programHave a documented program to identify and manage riskAML/CTF Act 2006Sales agencies

What are the Privacy Act duties for every agency?

The Privacy Act 1988 (Cth) and its 13 Australian Privacy Principles (APPs) govern how you handle personal information: buyer, seller, tenant and landlord details alike. The APPs that do the heavy lifting for an agency are:

Two 2025–26 developments raise the stakes. A statutory tort for serious invasions of privacy commenced in June 2025, so individuals can now sue directly where the invasion was intentional or reckless. Carelessness alone is not enough. And the OAIC ran a 2026 privacy compliance sweep, naming rental & property a target sector and assessing privacy policies against APP 1.4; for a non-compliant policy the OAIC can issue an infringement notice directly, without going to court, for a fraction of the court maximum, with higher court penalties (up to $72,800 for an individual or $364,000 for a company) reserved for serious cases. If an eligible data breach occurs, the Notifiable Data Breaches scheme requires you to notify the OAIC and the affected individuals. See the OAIC sweep release.

What AML/CTF duties apply to sales agencies from 1 July 2026?

From 1 July 2026, real-estate agencies that provide property-sale services became reporting entities under the AML/CTF Act 2006, the "Tranche 2" reforms. If you sell property, five duties now sit alongside your privacy obligations:

For the detail of which activities count, see the AUSTRAC real-estate designated services page.

Who's actually caught?

Three points decide how much of the above lands on you:

In short: if you manage rentals, the Privacy Act applies. If you sell, both regimes apply, and the AML side can switch on the full privacy regime even if you're under A$3 million.

How do you get ready?

Common questions

Which laws apply to a real estate agency in 2026?

In 2026 an Australian real-estate agency answers to two regimes: the Privacy Act 1988 (Cth) with its 13 Australian Privacy Principles, which governs every scrap of personal information you hold, and (for agencies providing property-sale services from 1 July 2026) the AML/CTF Act.

Do the AML obligations apply to property managers?

Agencies providing property-sale services are captured. Pure property managers who only manage rentals are generally not captured by AML/CTF, but they are still subject to the Privacy Act for the tenant and landlord data they handle.

Can the $3 million turnover exemption still protect a sales agency?

Not necessarily. The customer-identity data you collect to meet AML/CTF obligations can bring Privacy Act obligations regardless of the turnover threshold: collecting KYC information can be the very thing that removes your small-business exemption.

What are the core Privacy Act duties for an agency?

Keep a clear, current privacy policy (APP 1), collect only what's reasonably necessary (APP 3), give a collection notice at the point of collection (APP 5), use and disclose only for the purpose collected (APP 6), secure the data and destroy it when no longer needed (APP 11), and handle access and correction requests (APP 12–13).