The buyers agent privacy policy: what it must cover in 2026
A buyers agent's privacy policy must meet APP 1 for the client-identity data that Privacy Act s 6E(1A) brings under the Australian Privacy Principles once you are an AUSTRAC reporting entity. It should set out what identity, source-of-funds and financial-capacity information you collect, why, how you hold and secure it, how someone can access, correct or complain about it, and whether any of it is handled overseas.
By Jon Oates, Founder of Privaproof · Last updated
General information , document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.
Why you need a compliant privacy policy now
From 1 July 2026, a buyers agent who brokers, finds or identifies a property purchase for a client provides an AML/CTF designated service, which makes you an AUSTRAC reporting entity (enrolment due around 29 July 2026 for firms already operating on 1 July 2026; confirm your exact date with AUSTRAC). Brokering the purchase of real estate is the caught activity (Table 5 item 1, AML/CTF Act s 6(5A)).
The moment you become a reporting entity, Privacy Act s 6E(1A) switches the Australian Privacy Principles on for the AML/KYC customer-due-diligence data you collect, regardless of the A$3 million small-business exemption. APP 1 then requires you to have a clearly expressed and up-to-date privacy policy about how you manage that personal information, and to make it available free of charge, usually on your website. A generic or a selling-agency policy will not be written for the data you actually hold. Read: does becoming an AML reporting entity trigger the Privacy Act?
Scope first: what the policy is actually about
This is where honesty matters, because it is easy to overstate. The s 6E(1A) route pulls in the AML/KYC/CDD identity data, the information you collect and verify to satisfy customer due diligence. It does not pull your general buyer CRM, your newsletter list, your property alerts or your web enquiries under the Privacy Act by itself. The rest of your practice stays under the small-business exemption unless a separate trigger applies.
So your privacy policy is not a claim that "our whole business is now under the Privacy Act". It is an accurate account of how you handle the client-identity and due-diligence data the law now reaches. Many buyers agents choose to write a single, honest policy that covers all of their personal-information handling anyway, which is good practice, but the legal obligation bites on the CDD data.
What APP 1 requires the policy to contain
APP 1.4 sets out what a privacy policy must cover. For a buyers agent, that means spelling out, in plain English:
- The kinds of personal information you collect and hold. For you, that is identity and verification documents, and the due-diligence data described below.
- How you collect it and where you hold it. For example, direct from the buyer, from third parties such as a verification provider, and stored in your CRM or document system.
- The purposes you collect, hold, use and disclose it for, including satisfying your AML/CTF customer due diligence.
- How an individual can access their information and seek correction of it.
- How an individual can complain about a privacy breach, and how you will deal with the complaint.
- Whether you are likely to disclose personal information overseas, and if so, the countries where recipients are likely to be located.
The buyers-agent specifics a template misses
A generic privacy-policy generator does not know what a buyers agent holds. Yours should be written for the concentrated, high-sensitivity data at the centre of buy-side broking:
- Identity and verification (VOI) data for the buyer, collected to meet your customer due diligence.
- Financial-capacity evidence such as mortgage pre-approvals, bank and savings statements, proof of deposit and borrowing capacity.
- Source-of-funds and source-of-wealth evidence, where a client is higher-risk under your due diligence. Frame this as data you may hold, not data on every file. Read: VOI and source-of-funds privacy rules
- Beneficial-ownership, PEP and sanctions-screening results.
- Third-party-collected data. Where you obtain information about a person from someone other than that person, your policy and your collection notices should reflect it. Read: the collection notice you need at engagement
Overseas handling. If you use an offshore virtual assistant or an overseas-hosted cloud tool to process client identity or financial data, your policy has to disclose that overseas handling and the likely countries, and APP 8 sits behind it. This is a common gap in buyers-agent operations. Read: offshore VAs, cloud tools and your APP 8 duty
The 10 December 2026 addition: automated decision-making
From 10 December 2026, a new transparency rule (APP 1.7) requires certain privacy policies to include information about automated decision-making. This is a fact-specific trigger, not a universal one. It bites where you use a computer program to make, or to substantially help make, a decision that could significantly affect an individual's rights or interests. For a buyers agent, the likely candidates are automated identity, PEP or sanctions screening where the result meaningfully affects whether you can act for someone. If that describes any part of your process, your privacy policy will need to say so from that date. A policy written this year should be built to take that update, which is exactly the kind of change a kept-current document set carries for you.
Retention, breaches and the rest of the set
A privacy policy is one document in a connected set. It works alongside your collection notices (APP 5), your data-breach response plan for the Notifiable Data Breaches scheme, and a retention and destruction schedule that reconciles the AML record-keeping floor with the Privacy Act's "destroy when no longer needed" principle (APP 11.2). Getting the policy right but leaving those out still leaves the obligation half-met. Read: your data-breach response plan and how long must a buyers agent keep client records?
Penalties for privacy breaches are ceilings, not certainties, and most matters resolve without a fine. The point of a compliant, buyers-agent-specific policy is not fear of a maximum penalty. It is that it is the document a client, an auditor or the regulator looks at first, and it should describe what you actually do.
Common questions
Can I just use a free online privacy policy generator?
You can, but it will be written for a generic business, not a buyers agent, so it will not describe the identity, source-of-funds and financial-capacity data you actually hold, or your overseas handling. A policy that does not match your real information handling is worse than useless if a complaint is ever made. Use one written for buy-side broking, and keep it current as the law changes.
Does my privacy policy have to cover my whole business or just the AML data?
The legal obligation via s 6E(1A) bites on the AML/KYC customer-due-diligence data. It does not, by itself, pull your general CRM, newsletter or property-alert lists under the Privacy Act. Many buyers agents still choose to write one honest policy covering all their personal-information handling, which is good practice, but do not claim your whole business is now regulated when the trigger is narrower than that.
I only give buyers advice and never find or negotiate. Do I still need one?
It depends on what you actually do, and it is fact-specific. Brokering the purchase of a specific property for a fee is the caught activity, and a buyers agency retained to acquire property is doing it. A genuinely advice-only or research-only service that never finds property and never negotiates for a commission may fall outside brokering, but confirm your own position rather than assuming either way. Read: advice-only or research-only buyers agent, are you caught?
When does the automated-decision-making requirement start?
From 10 December 2026, and only where you use automated decision-making that could significantly affect an individual, such as automated sanctions or PEP screening that determines whether you can act for a client. If that is part of your process, your privacy policy will need to describe it from that date. Build the policy now so it can take the update.
Where this sits
A compliant privacy policy is the first document a reporting-entity buyers agent needs, but it is one part of the privacy half the AML doc packs leave out. Read the cornerstone: privacy compliance for Australian buyers agents, and what an AML pack leaves out.
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC. Privaproof's buyers-agent documents are self-authored and are not independently reviewed by a solicitor. The Privacy Act 1988 (Cth) and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.