Privacy compliance for Australian buyers agents: you broker purchases, so from 1 July 2026 the Privacy Act applies to you.
A buyers agent who finds, identifies or negotiates a property purchase for a client provides an AML/CTF "designated service", which makes you an AUSTRAC reporting entity from 1 July 2026. The moment that happens, Privacy Act s 6E(1A) switches the Privacy Act on for the client-identity data you collect for those checks, even if your practice turns over less than A$3 million. Your AML tool does the identity checks. It does not give you the privacy documents the same change now expects. This page is about that overlooked half.
General information , document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.
The cleanest fit of any profession: you have no rental side to shelter behind
A mixed sales-and-rentals agency is only partly caught, because property management and residential leasing are not designated services. A buyers agent has no such shelter. Finding or identifying a property to buy, and negotiating the purchase, is the core of the work, so close to all of what you do is the caught activity. Read: are buyers agents caught by AML Tranche 2?
The obligation attaches at the front of the relationship: you start providing the designated service when the client signs the agreement to find or identify a property, before any property is found. Enrolment with AUSTRAC is due around 29 July 2026 for firms already operating on 1 July 2026 (confirm your firm's exact date with AUSTRAC).
How the Privacy Act switches on: s 6E(1A)
Most boutique buyers agents turn over under A$3 million and have relied on the small-business exemption (s 6D), which meant the Australian Privacy Principles did not apply. Becoming an AUSTRAC reporting entity changes that. Via Privacy Act s 6E(1A), the personal information you handle for your AML/CTF activities, the identity, verification, source-of-funds and beneficial-ownership data you collect for customer due diligence, comes under the Privacy Act regardless of turnover. Read: does the Privacy Act apply to buyers agents under $3 million?
Scope, stated honestly: s 6E(1A) catches the AML/KYC customer-due-diligence data. It does not pull your general buyer CRM, your newsletter list, your property alerts or your web enquiries under the Privacy Act. The rest of your practice stays under the small-business exemption unless a separate trigger applies. Do not overclaim that your whole business is now covered.
Why a buyers agent's data is unusually sensitive
Unlike a selling agency, you hold few files but each one is deep. To act for a buyer you gather, and actively assess, a concentrated set of high-sensitivity financial data:
- Identity and verification documents (VOI) for the buyer.
- Financial-capacity evidence: mortgage pre-approvals, bank and savings statements, proof of deposit and borrowing capacity.
- Source-of-funds and source-of-wealth evidence, where a client is higher-risk under your customer due diligence. (This is data you may hold, not every file.)
- Beneficial-ownership, PEP and sanctions-screening results.
- The buyer brief, which often carries sensitive context (a relocation, a divorce, an inheritance, an SMSF purchase).
Few, deep, often high-net-worth records. A breach of them is very likely to cause serious harm, which is exactly what makes it notifiable under the data-breach scheme. Read: your data-breach response plan · Read: VOI and source-of-funds privacy rules
Advice-only or research-only? It depends
If your service genuinely never finds or identifies a specific property and never negotiates, only advises, you may fall outside the brokering definition. But a buyers agency retained to acquire a property is doing the caught activity on any reading. This is fact-specific, so confirm your own position rather than assuming either way. Read: advice-only buyers agents and AML
What a buyers agent actually needs
1. A privacy policy (APP 1) written for a buyers agent, not a generic fill-in or a selling-agency template. 2. Collection notices (APP 5), including the AML customer-due-diligence notice at engagement, and cover for information you collect about people from third parties. 3. A data-breach response plan for the NDB scheme, tuned to the concentrated financial-capacity data you hold. 4. A retention and destruction schedule that reconciles the AML record-keeping floor with the Privacy Act's "destroy when no longer needed" principle.
You do not need a rent roll, a tenancy-database notice, a rental-application form or an open-home register. A selling-agency kit is the wrong shape for you. Read: the privacy kit no RE-agency tool covers
The AML doc packs stop at the identity checks. Free generic templates are not written for a buyers agent and do not keep pace as the law changes. Read: AML kit vs privacy kit
What Privaproof is building for buyers agents
A dedicated, buyers-agent-specific privacy document set, written for buy-side broking, and kept current as the law changes. Not an AML bolt-on, not a generic download: the privacy half the AML packs leave out.
- Written for buyers agents: VOI, source of funds, the buyer brief, offshore VAs and cloud tools.
- Practical, plain-English documents you tailor to your practice, with guidance built in.
- Kept current: while your subscription is active, we monitor the law and aim to provide updated versions as it changes, including the 10 December 2026 automated-decision-making rule. This is not a guarantee of compliance, and does not replace your own legal advice.
These are compliance tools and templates you tailor to your own business. They are general information, not legal advice, and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner.
Join the founding list
Be first to know when the Buyers-Agent Kit opens, and get the plain-English updates as the 2026 changes land. No cost, no obligation.
✓ You’re on the founding list. We’ll email you as the changes land.
We never sell your data. See our Privacy Policy.
Keep reading
- Does the Privacy Act apply to buyers agents under $3 million?
- Are buyers agents caught by AML Tranche 2? The designated service explained
- Does becoming an AML reporting entity trigger the Privacy Act?
- The buyers agent privacy policy: what it must cover
- The collection notice you need at engagement
- VOI and source-of-funds: the privacy rules for identity checks
- Data-breach response plan for buyers agents
- How long must a buyers agent keep client records?
- AML kit vs privacy kit: what your AML pack leaves out
- Advice-only or research-only buyers agent: are you caught?
- Standalone and REBAA buyers agents: the kit no RE tool covers
- Buyers agents, offshore VAs and cloud tools: your APP 8 duty
- What does 2026 privacy and AML compliance cost a buyers agent?
General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC. Privaproof's buyers-agent documents are self-authored and are not independently reviewed by a solicitor. The Privacy Act 1988 (Cth) and related guidance change over time, so check you are working from a current version.