AML kit vs privacy kit: what your buyers-agent AML pack leaves out
An AML kit does the AUSTRAC job: the AML/CTF program, the customer due diligence checks, the reporting and the enrolment paperwork. The Privacy Act is a separate Act with a separate regulator. Brokering the purchase of real estate for a buyer has been a designated service since 31 March 2026 (Table 5 item 1, AML/CTF Act s 6(5A)), and Privacy Act s 6E(1A) then applies the Privacy Act "in relation to the activities carried on by the small business operator for the purposes of, or in connection with, activities relating to" the AML/CTF Act. Those activities carry their own documents: a privacy policy (APP 1.3), a collection notice (APP 5), a data-breach plan under Part IIIC and a retention schedule that reconciles with APP 11.2. Check what your AML product covers, then check whether those are covered too.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.
One trigger, two sets of documents
If you broker the purchase of real estate on behalf of a buyer, that is a designated service, so from 31 March 2026 you are an AUSTRAC reporting entity (Table 5 item 1, AML/CTF Act s 6(5A)). That single event creates two separate jobs. If your engagement stops short of brokering, for example a search-and-shortlist service where the client negotiates their own purchase, the answer is fact-specific and worth checking against what you actually do.
- The AML job is what the acronym describes: identify your customer, verify who they are, assess money-laundering risk, keep the records, report where you must, and satisfy AUSTRAC. This is AUSTRAC's domain, and an AML pack is built for it.
- The privacy job is what happens to all the personal information you gathered doing the AML job. Privacy Act s 6E(1A) provides that where a small business operator is a reporting entity because of anything done in the course of a small business it carries on, the Act applies "in relation to the activities carried on by the small business operator for the purposes of, or in connection with, activities relating to" the AML/CTF Act, as if the operator were an organisation. It is scoped by activity, not by turnover, so the customer due diligence you run and the identity, verification and source-of-funds information you handle in running it sit inside the Australian Privacy Principles even below the $3,000,000 turnover limb in s 6D(4)(a).
The same collection of a driver licence, a bank statement or a proof-of-deposit satisfies an AML rule and engages the Privacy Act at the same moment. Those are two obligations, under two Acts, overseen by two regulators: AUSTRAC administers the AML/CTF Act, and the OAIC administers the Privacy Act. Whether a given AML product also does the second job is a question to put to its vendor.
What the AML/CTF Act asks of a reporting entity
An AML product is built to serve the obligations the AML/CTF Act places on a reporting entity, and AUSTRAC administers those obligations. They are:
- an AML/CTF program and risk assessment tailored to real-estate broking,
- customer due diligence and identity-verification procedures,
- enrolment with AUSTRAC, and the reporting the Act requires, including suspicious matter reporting,
- record-keeping for the AML seven-year floor,
- sanctions screening, and staff AML/CTF training.
AUSTRAC also publishes free real-estate AML/CTF guidance and starter program material, so there is a free starting point for the AUSTRAC-facing half. Check the scope AUSTRAC states for that material against the size of your own practice.
Where the AML/CTF Act stops and the Privacy Act starts
None of those obligations is a Privacy Act obligation. The AML/CTF Act tells a reporting entity to collect and verify identity information. The Privacy Act separately expects an APP entity to notify the individual of the matters in APP 5.2 at or before the time it collects personal information; to have "a clearly expressed and up-to-date policy ... about the management of personal information by the entity" (APP 1.3); to run the Part IIIC process where there is unauthorised access to, disclosure of, or loss of that information; and to take reasonable steps to destroy or de-identify personal information it no longer needs, unless it is required by or under an Australian law to retain it (APP 11.2). Two Acts, two regulators: AUSTRAC for the first, the OAIC for the second.
That gap is the privacy half, and it is four documents:
- 1. A privacy policy (APP 1.3), written for a buyers agent rather than a selling agency or a generic download, covering the identity, financial-capacity and source-of-funds data you actually hold. Read: the buyers agent privacy policy
- 2. A collection notice (APP 5), given at engagement, that explains the AML customer-due-diligence collection and covers information you collect about people from third parties. Read: the collection notice you need at engagement
- 3. A data-breach response plan for the Notifiable Data Breaches scheme, tuned to the concentrated financial data a buyers agent holds. Read: your data-breach response plan
- 4. A retention and destruction schedule that holds AML records for the mandated period and then disposes of the personal information, reconciling the AML seven-year rule with APP 11.2. Read: how long must a buyers agent keep client records?
Why the gap matters more for a buyers agent
A buyers agent holds few files, but each one is deep: mortgage pre-approvals, bank and savings statements, borrowing capacity, proof of deposit, and, for higher-risk clients under your due diligence, source-of-funds evidence you actively assess. Under s 26WE(2) a breach is an eligible data breach where there is unauthorised access to, or unauthorised disclosure of, the information and a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates, or where the information is lost in circumstances where that access or disclosure is likely to occur. That is an assessment made on the facts of the particular breach, not a conclusion this page can reach for your files. Collecting the data is what the AML/CTF Act asks for; how you hold, secure, disclose and eventually destroy it is what the Privacy Act asks for.
Why not just buy a generic privacy template to fill the gap?
Because a generic policy is not written for a buyers agent and does not keep pace as the law changes. Two dates move the target. A reporting entity already providing a designated service before 1 July 2026 had to be enrolled with AUSTRAC by 29 July 2026, a date fixed by item 12 of Schedule 3 to the amending Act rather than counted from a start date. And the automated-decision-making transparency requirement in APP 1.7 commences 10 December 2026, reaching a privacy policy where a computer program makes, or substantially and directly supports, a decision that could reasonably be expected to significantly affect an individual's rights or interests, which can take in automated identity, politically-exposed-person or sanctions screening. A one-off download bought this month does not update itself. A kept-current, buyers-agent-specific set does.
A note on scope, because it is easy to overstate. Section 6E(1A) applies the Privacy Act "in relation to the activities carried on by the small business operator for the purposes of, or in connection with, activities relating to" the AML/CTF Act, not to your whole practice. Your general buyer CRM, your newsletter list and your property alerts sit outside that route and stay under the small-business exemption unless another limb of s 6D(4) reaches them, such as an annual turnover of more than $3,000,000 for a financial year that has ended (s 6D(4)(a)), which does not reverse if turnover later falls. The privacy half you need is scoped to those AML activities, not a claim that your entire business is now regulated.
So, which do you need?
Both, and they do different work. Your AML arrangements, bought or built on AUSTRAC's free material, serve the AML/CTF Act obligations AUSTRAC administers. The four privacy documents serve the Privacy Act obligations the OAIC administers for the personal information those checks generate. Privaproof builds only that privacy half, buyers-agent-specific and kept current as the law changes. We do not assess or sell the AML side, and we make no claim about what any particular AML product does or does not include. Read the cornerstone: privacy compliance for Australian buyers agents
Common questions
Does my AML pack already cover the Privacy Act?
They are obligations under two separate Acts, so check. An AML product is built for the AML/CTF Act: the program, customer due diligence, reporting and record keeping, all administered by AUSTRAC. The privacy policy (APP 1.3), the collection notice (APP 5), the data-breach plan under Part IIIC and the retention schedule that reconciles with APP 11.2 sit under the Privacy Act and are administered by the OAIC, which s 6E(1A) applies to the activities you carry on for the purposes of, or in connection with, the AML/CTF Act. Ask your AML vendor which of those documents its product supplies, and cover whatever it does not.
If AUSTRAC gives an AML starter kit for free, is the privacy side free too?
No, they are different Acts with different regulators. AUSTRAC's free real-estate material serves the AML/CTF Act, which AUSTRAC administers. The Privacy Act is administered by the OAIC, and the privacy policy (APP 1.3), collection notice (APP 5), data-breach plan (Part IIIC) and retention schedule (APP 11.2) sit under that Act. Check the scope AUSTRAC states for its starter material against your own practice, and cover the privacy half separately.
Can I just download a generic privacy policy to cover it?
You can, but a generic template is not scoped to a buyers agent's identity and source-of-funds data, and it does not update when the law moves, such as the automated-decision-making rule commencing 10 December 2026. A buyers-agent-specific, kept-current set is built for the data you actually hold and stays current as the changes land.
Does the privacy half put my whole CRM under the Privacy Act?
No. Section 6E(1A) applies the Privacy Act in relation to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act, so it reaches the customer due diligence you run and the identity information you handle in running it. It does not reach your general buyer database, newsletter list or property alerts, which stay under the small-business exemption unless another limb of s 6D(4) applies, such as an annual turnover of more than $3,000,000 for a financial year that has ended (s 6D(4)(a)). The privacy documents you need are scoped to those AML activities.
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC. The Privacy Act 1988 (Cth) and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.