Skip to content

The buyers agent privacy policy: what it must cover in 2026

Once you are an AUSTRAC reporting entity, Privacy Act s 6E(1A) applies the Act to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act, so your privacy policy must meet APP 1 for the personal information you handle in carrying on those activities. It should set out what identity, source-of-funds and financial-capacity information you collect, why, how you hold and secure it, how someone can access, correct or complain about it, and whether any of it is handled overseas.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.

Why you need a compliant privacy policy now

From 31 March 2026, a buyers agent who brokers the purchase of real estate on behalf of a buyer in the course of carrying on a business provides an AML/CTF designated service, which makes you an AUSTRAC reporting entity. Brokering is the caught activity, in those words (Table 5 item 1, AML/CTF Act s 6(5A)); finding or researching property without brokering the purchase is not named in the item. For anyone providing a table 5 designated service at any time before 1 July 2026, enrolment is due by 29 July 2026, a date the transitional provision fixes outright (Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024, Sch 3 Pt 4 item 12) rather than one you calculate from the usual 28-day rule in s 51B(1). Confirm your own position with AUSTRAC.

The moment you become a reporting entity, Privacy Act s 6E(1A) applies the Act to you as if you were an organisation, regardless of the A$3 million small-business exemption, but only in relation to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act and the AML/CTF Rules. Within that scope you are an APP entity, so APP 1.3 requires a clearly expressed and up-to-date privacy policy about how you manage personal information, and APP 1.5 requires you to take reasonable steps to make it available free of charge, which the Act's own note says usually means on your website. A generic or a selling-agency policy will not be written for the information you actually hold. Read: does becoming an AML reporting entity trigger the Privacy Act?

Scope first: what the policy is actually about

This is where honesty matters, because it is easy to overstate. The s 6E(1A) route is scoped to activities, not to a category of data: it applies the Act to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act, which in practice means your customer due diligence, the identity and source-of-funds material you collect and verify for it, and the record-keeping and reporting that go with it. It does not, by itself, pull your general buyer CRM, your newsletter list, your property alerts or your web enquiries under the Privacy Act. Whether the rest of your practice is exempt is a separate question, and the small-business exemption has more exits than the turnover one: s 6D(4) takes you out of it on any of six grounds, including an annual turnover above A$3 million in a financial year that has ended (s 6D(4)(a), which does not reverse if turnover later falls), disclosing personal information about someone for a benefit, and providing a benefit to collect personal information about someone from a third party (s 6D(4)(c) and (d), subject to the consent and legislation carve-outs in s 6D(7) and (8)). Check your own position rather than assuming the exemption still holds.

So your privacy policy is not a claim that "our whole business is now under the Privacy Act". It is an accurate account of how you handle the personal information involved in the AML-connected activities the law now reaches. Writing a single policy that covers all of your personal-information handling is one way to do it, and it saves your team policing a line internally, but the s 6E(1A) obligation is scoped to those activities.

What APP 1 requires the policy to contain

APP 1.4 sets out the minimum a privacy policy must contain, without limiting the general requirement in APP 1.3. For a buyers agent, that means spelling out, in plain English:

The buyers-agent specifics a template misses

A generic privacy-policy generator does not know what a buyers agent holds. Yours should be written for the concentrated identity and financial information at the centre of buy-side broking. Most of it is not "sensitive information" as the Privacy Act defines that term in s 6(1), with one exception worth knowing: if your VOI tool does automated biometric face matching, the biometric information it uses is sensitive information, and APP 3 sets a higher bar for collecting it. What your policy has to describe is:

Overseas handling. If you use an offshore virtual assistant or an overseas-hosted cloud tool to process client identity or financial data, APP 1.4(f) and (g) require your policy to state whether you are likely to disclose personal information to overseas recipients and, where it is practicable to specify them, the countries those recipients are likely to be in. APP 8 sits behind it and applies before you disclose. Read: offshore VAs, cloud tools and your APP 8 duty

The 10 December 2026 addition: automated decision-making

From 10 December 2026, a new transparency rule (APP 1.7, inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth), Part 15) requires certain privacy policies to include information about automated decision-making. This is a fact-specific trigger, not a universal one. It applies where you have arranged for a computer program to make, or to do a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests, and personal information about that individual is used in the operation of the program. Beneficial effects count as well as adverse ones, and a part-automated process where a human makes the final call is still within it. For a buyers agent, the likely candidates are automated identity, PEP or sanctions screening where the result meaningfully affects whether you can act for someone. If that describes any part of your process, APP 1.8 sets out what the policy must then say: the kinds of personal information used, the kinds of decisions made solely by the program, and the kinds of decisions the program substantially and directly contributes to. A policy written this year should be built to take that update, which is exactly the kind of change a kept-current document set carries for you.

Retention, breaches and the rest of the set

A privacy policy is one document in a connected set. It works alongside your collection notices (APP 5), your data-breach response plan for the Notifiable Data Breaches scheme, and a retention and destruction schedule that sequences the AML record-keeping floor and the Privacy Act's "destroy when no longer needed" principle. APP 11.2 does the sequencing for you: the destruction duty does not apply while an Australian law requires you to retain the record (APP 11.2(d)), so the schedule dates destruction from the end of that period. Getting the policy right but leaving those out still leaves the obligation half-met. Read: your data-breach response plan and how long must a buyers agent keep client records?

Penalties for privacy breaches are ceilings, not certainties. An OAIC determination under s 52(1) contains no penalty limb at all, and a civil penalty requires the Commissioner to obtain a court order (ss 13G and 80U). The point of a compliant, buyers-agent-specific policy is not fear of a maximum penalty. It is that it is the document a client, an auditor or the regulator looks at first, and it should describe what you actually do.

Common questions

Can I just use a free online privacy policy generator?

You can, but it will be written for a generic business, not a buyers agent, so it will not describe the identity, source-of-funds and financial-capacity data you actually hold, or your overseas handling. A policy that does not match your real information handling is worse than useless if a complaint is ever made. Use one written for buy-side broking, and keep it current as the law changes.

Does my privacy policy have to cover my whole business or just the AML data?

The obligation via s 6E(1A) is scoped to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act, which covers your customer due diligence and the identity and source-of-funds information you handle for it. It does not, by itself, pull your general CRM, newsletter or property-alert lists under the Privacy Act. You can still write one policy covering all your personal-information handling, which saves maintaining two, but do not claim your whole business is now regulated when the trigger is narrower than that.

I only give buyers advice and never find or negotiate. Do I still need one?

It depends on what you actually do, and it is fact-specific. Brokering the purchase of a specific property for a fee is the caught activity, and a buyers agency retained to acquire property is doing it. A genuinely advice-only or research-only service that never finds property and never negotiates for a commission may fall outside brokering, but confirm your own position rather than assuming either way. Read: advice-only or research-only buyers agent, are you caught?

When does the automated-decision-making requirement start?

From 10 December 2026, and only where you have arranged for a computer program to make, or to substantially and directly contribute to, a decision that could reasonably be expected to significantly affect an individual's rights or interests, using personal information about that individual. Automated sanctions or PEP screening that determines whether you can act for a client is the likely example for a buyers agent. If that is part of your process, APP 1.7 and 1.8 require your privacy policy to describe it from that date. Build the policy now so it can take the update.

Where this sits

A compliant privacy policy is the first document a reporting-entity buyers agent needs, and it sits on the privacy side of the line: an AML pack is built for the AUSTRAC-facing program, customer due diligence and reporting, which is a different set of documents from the ones the Privacy Act asks for. Read the cornerstone: privacy compliance for Australian buyers agents, and what an AML pack leaves out.


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC. The Privacy Act 1988 (Cth) and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.