Skip to content

The 2026 privacy & AML obligations map for Australian real-estate agencies

In 2026 an Australian real-estate agency answers to two regimes: the Privacy Act 1988 (Cth) with its 13 Australian Privacy Principles, which governs every scrap of personal information you hold, and, for agencies providing property-sale services, the AML/CTF Act, under which they have been reporting entities since 31 March 2026 and have carried the obligations since 1 July 2026. This page maps each obligation to what you actually have to do.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price, rising to A$649 on 1 Oct 2026

Orientation only, not a compliance assessment. General information and tools, not legal advice.

The obligations at a glance

The Privacy Act rows bind an agency the Act covers, and not every agency is: you may genuinely be exempt, and "Who's actually caught?" below sets out the tests.

ObligationWhat it means for your agencyWhere it comes fromWho it applies to
Open & transparent managementHave a clear, current, compliant privacy policyAPP 1Every agency
Collect only what you needDon't gather personal information beyond what's reasonably necessaryAPP 3Every agency
Give a collection noticeTell people what you're collecting and why, at the point of collectionAPP 5Every agency
Use & disclose lawfullyOnly use information for the purpose collected, or a permitted oneAPP 6Every agency
Cross-border disclosureTake care before sending personal information overseasAPP 8Every agency
Secure it, then let it goProtect information, and destroy or de-identify it once you no longer need it and no Australian law requires you to keep itAPP 11.1, 11.2Every agency the Privacy Act covers
Access requestsLet individuals see the personal information you hold about themAPP 12Every agency
CorrectionFix personal information that's wrong when askedAPP 13Every agency
Notify eligible breachesGive the Commissioner a statement, then notify the individuals concerned or those at risk; publish it if neither is practicablePart IIIC, ss 26WK, 26WLEvery agency the Privacy Act covers
Enrol with AUSTRACEnrol as a reporting entity. 29 July 2026 if you provided a designated service at any time before 1 July 2026, a date fixed outright by Sch 3 Pt 4 item 12 rather than counted from anything. A later starter instead gets the ordinary s 51B(1) window from their own first serviceAML/CTF Act 2006 s 51B(1)Sales agencies
Customer due diligence (KYC)Verify the identity of the customers you deal withAML/CTF Act 2006Sales agencies
Report suspicious mattersLodge suspicious matter reports to AUSTRACAML/CTF Act 2006Sales agencies
Keep records for 7 yearsRetain AML/CTF records for at least seven yearsAML/CTF Act 2006Sales agencies
Maintain an AML/CTF programHave a documented program to identify and manage riskAML/CTF Act 2006Sales agencies

What are the Privacy Act duties for every agency?

The Privacy Act 1988 (Cth) and its 13 Australian Privacy Principles (APPs) govern how you handle personal information: buyer, seller, tenant and landlord details alike. The APPs that do the heavy lifting for an agency are:

Two 2025–26 developments raise the stakes. The statutory tort for serious invasions of privacy commenced on 10 June 2025, so individuals can sue directly and, under Schedule 2 clause 7(2), without proving they lost a cent. Carelessness alone is not enough: clause 7(1)(c) requires the invasion to be intentional or reckless and clause 7(1)(d) requires it to be serious. And the OAIC ran a 2026 privacy compliance sweep in which rental and property was the first of six named sectors, assessing privacy policies against APP 1.4. A policy that breaches APP 1.3 or 1.4 is a contravention of s 13K(1), which the Commissioner can pursue by infringement notice without going to court (s 80UB), or a court can penalise at up to 200 penalty units for an individual and 1,000 for a body corporate, which is $72,800 and $364,000 at the penalty unit value of $364 in force from 1 July 2026. If an eligible data breach occurs, the Notifiable Data Breaches scheme requires a statement to the Commissioner and then notice to the individuals the information relates to, or those at risk, or publication if neither is practicable. See the OAIC sweep release.

What AML/CTF duties apply to sales agencies from 1 July 2026?

On 31 March 2026, real-estate agencies that provide property-sale services became reporting entities under the AML/CTF Act 2006, the "Tranche 2" reforms. If you sell property, five duties now sit alongside your privacy obligations:

For the detail of which activities count, see the AUSTRAC real-estate designated services page.

Who's actually caught?

Three points decide how much of the above lands on you:

In short: if you sell, both regimes apply, and s 6E(1A) applies the Privacy Act to your AML/CTF-related activities even if you're under A$3 million. If you only manage rentals, AML/CTF is generally out and the Privacy Act question turns on s 6D.

How do you get ready?

Common questions

Which laws apply to a real estate agency in 2026?

In 2026 an Australian real-estate agency answers to two regimes: the Privacy Act 1988 (Cth) with its 13 Australian Privacy Principles, which governs every scrap of personal information you hold, and, for agencies providing property-sale services, the AML/CTF Act, under which they have been reporting entities since 31 March 2026 and have carried the obligations since 1 July 2026.

Do the AML obligations apply to property managers?

Agencies providing property-sale services are captured. Pure property managers who only manage rentals are generally not captured by AML/CTF, but they are still subject to the Privacy Act for the tenant and landlord data they handle.

Can the $3 million turnover exemption still protect a sales agency?

Not necessarily. Privacy Act s 6E(1A) treats a small business operator that is a reporting entity as an organisation in relation to its activities connected with the AML/CTF Act. The trigger is that status, which attached on 31 March 2026, not your turnover and not the data you collect.

What are the core Privacy Act duties for an agency?

Keep a clear, current privacy policy (APP 1), collect only what's reasonably necessary (APP 3), give a collection notice at the point of collection (APP 5), use and disclose only for the purpose collected (APP 6), secure the data and destroy it when no longer needed (APP 11), and handle access and correction requests (APP 12–13).