Skip to content

Does becoming an AML reporting entity trigger the Privacy Act for buyers agents?

Yes, for one specific part of what you do. When brokering property purchases makes you an AUSTRAC reporting entity from 31 March 2026, Privacy Act s 6E(1A) applies the Privacy Act, with the prescribed modifications if any, "in relation to the activities carried on by the small business operator for the purposes of, or in connection with, activities relating to" the AML/CTF Act, its regulations and the AML/CTF Rules, as if you were an organisation. The scope is set by the activity, not by a single data set, so it covers the personal information you handle in carrying those activities on, whatever your turnover. It does not make your whole buyers-agent practice an APP entity across every record you hold.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.

The trigger is two steps, and the second one is the one people miss

A buyers agency whose annual turnover for the previous financial year was A$3,000,000 or less is a small business under section 6D(1) of the Privacy Act 1988 (Cth), and a small business operator sits outside the Australian Privacy Principles (APPs) unless something else brings it in. Turnover is not the only test. Under s 6D(4)(a) to (f) you are not a small business operator if you have had a financial year end with turnover above A$3,000,000, provide a health service and hold health information, disclose personal information for a benefit, service or advantage, provide a benefit, service or advantage to collect it, are a contracted service provider for a Commonwealth contract, or are a credit reporting body. s 6D(4)(a) is one way: it turns on a financial year that has ended, so a later fall in turnover does not put you back inside the exemption. Two things now happen in sequence.

Step one: you become a reporting entity. Brokering the sale, purchase or transfer of real estate on behalf of a buyer in the course of carrying on a business is a designated service under the AML/CTF Act (Table 5 item 1, AML/CTF Act s 6(5A)), and Table 5 commenced on 31 March 2026, so you have been an AUSTRAC reporting entity since that date. A firm already providing a designated service at any time before 1 July 2026 had to be enrolled with AUSTRAC by 29 July 2026, a date fixed outright by Sch 3 Pt 4 item 12 of the amending Act rather than counted from the day it started. Read: are buyers agents caught by AML Tranche 2?

Step two: s 6E(1A) follows automatically. This is the step the AML material tends not to mention. Once something done in the course of your business makes you a reporting entity, Privacy Act s 6E(1A) applies the Act to you, with the prescribed modifications if any, in relation to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act, its regulations and the AML/CTF Rules, as if you were an organisation. The reach is defined by what you are doing, not by your size, so it holds regardless of turnover. You do not have to opt in under s 6EA, register separately, or cross the A$3,000,000 line. Becoming a reporting entity is the switch.

What s 6E(1A) actually switches on

s 6E(1A) is scoped by activity, not by a named data set. The Act applies in relation to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act, its regulations and the AML/CTF Rules, so it reaches the personal information you handle in doing those things. Customer due diligence is the largest part of that in a buyers agency, but the same words also pick up the personal information in your AML/CTF risk assessment, your ongoing monitoring, your reporting to AUSTRAC and your AML/CTF record keeping. The usual examples:

Within those activities the Act applies to you as if you were an organisation, subject to any modifications prescribed under s 6E(1A), so the APPs govern that handling: collect only what is reasonably necessary (APP 3), give the client the collection notice (APP 5), take reasonable steps to protect the information (APP 11.1), and do not use or disclose it for an unrelated secondary purpose such as marketing (APP 6). Read: VOI and source-of-funds privacy rules

What it leaves alone

This is where honest scope matters, because it is easy to overstate. s 6E(1A) does not put your whole business under the Privacy Act.

So the accurate answer is not "the whole Privacy Act now applies to you." It is "the Privacy Act applies to you in relation to your AML/CTF activities, and the personal information you handle in carrying them on has to be handled to the APP standard." The line is drawn by the activity rather than by a list of file types, so the same record can be inside for one purpose and outside for another. A general removal of the small-business exemption has been proposed as a future reform, but it is not yet law, so treat blanket "exemption removed" claims with caution.

Why the turnover threshold stops mattering for these activities

The small-business exemption is about size. s 6E(1A) is about activity. Once providing a designated service makes you a reporting entity, the exemption that shelters the rest of your firm no longer reaches the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act. A sole-operator buyers agent turning over A$200,000 and a large agency are in the same position for those activities: both are treated as organisations for them. Size changes nothing here. Read: does the Privacy Act apply to buyers agents under $3 million?

The enforcement point is structural, so state it structurally. An act or practice that breaches an APP in relation to personal information about an individual is an interference with the privacy of that individual, and an individual can complain to the Information Commissioner. A determination under s 52(1) contains no penalty limb: it can declare the conduct an interference, require steps to be taken, and award compensation to the complainant. A civil penalty is a separate track, because s 13G(1) is a civil penalty provision and s 80U makes the Commissioner an authorised applicant to the Federal Court or the Federal Circuit and Family Court for a penalty order. AML/CTF penalties are separate again, sit with AUSTRAC, and Privaproof does not assess them.

This is the half your AML pack skips

Your AML tool or doc-pack does the identity checks and the AUSTRAC-facing program. It does not produce the privacy-side documents the APPs call for once s 6E(1A) reaches you: the APP 1 privacy policy, the APP 5 collection notice at engagement, and a retention schedule that reconciles the seven-year AML/CTF record-keeping requirement in Part 10 of the AML/CTF Act with APP 11.2, which requires reasonable steps to destroy or de-identify personal information the entity no longer needs and is not required by an Australian law or a court or tribunal order to retain. A written breach-response plan is not itself an APP, but Part IIIC puts the duty on you: under s 26WH(2) the entity must carry out a reasonable and expeditious assessment of a suspected eligible data breach and take all reasonable steps to complete it within 30 days. That gap is the privacy half, and it was opened by the same change that made you a reporting entity. Read: AML kit vs privacy kit, what your AML pack leaves out

What if you are advice-only?

AUSTRAC describes a broker as "a person who acts as an intermediary or agent for another person for consideration", and says a common indicator is that "your services include negotiating on behalf of the person you represent or seeking to find a person for the person you represent to transact with, in return for a payment of a commission". If your service genuinely never seeks to find a party or a specific property for a client and never negotiates on their behalf, only advises, you may sit outside that description, in which case step one never fires and s 6E(1A) never reaches you. A buyers agency retained to find and negotiate an acquisition for a fee answers both of AUSTRAC's indicators. This is fact-specific, so confirm your own position with AUSTRAC rather than assuming either way. Read: advice-only or research-only buyers agent, are you caught?

Common questions

Do I have to register with the OAIC once I am a reporting entity?

No. There is no separate privacy registration. s 6E(1A) applies by operation of law the moment your AML/CTF reporting-entity status begins. Your job is to handle the customer-due-diligence data to the APP standard, not to sign up anywhere for it.

Does s 6E(1A) put my whole business under the Privacy Act?

No. s 6E(1A) applies the Act in relation to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act, so the reach is set by the activity and covers the personal information you handle in it. In a buyers agency that is mainly customer due diligence, risk assessment, ongoing monitoring, AUSTRAC reporting and AML record keeping. Your newsletter list, property alerts and CRM handling that has nothing to do with those activities stay outside that route unless a separate trigger applies.

I turn over well under $3 million. Does the exemption still protect me?

Not for your AML/CTF activities. The s 6D small-business exemption is about size; s 6E(1A) is about activity. Once providing a designated service makes you a reporting entity, the exemption no longer reaches what you do for the purposes of, or in connection with, activities relating to the AML/CTF Act, whatever your turnover. Turnover is also not the only route out of the exemption: s 6D(4)(b) to (f) set out the others, and s 6EA lets a small business operator opt in.

Is this the same as being "fully APP-compliant"?

For the activities s 6E(1A) covers, the Act applies to you as if you were an organisation, with any prescribed modifications, so the APPs govern the personal information you handle in carrying them on. It does not make your whole practice an APP entity across every record you hold. The obligation is real, and it is scoped by activity rather than by turnover or by a fixed list of documents.

When does this start?

Two different dates, and they are often run together. You became a reporting entity on 31 March 2026, when table 5 commenced and brokering the purchase of real estate became a designated service. The four deferred obligation Parts (AML/CTF programs, customer due diligence, reporting and record keeping) started on 1 July 2026, and a firm already providing a designated service at any time before that date had to be enrolled with AUSTRAC by 29 July 2026, a date the amending Act fixes outright rather than one you count from your own start date. s 6E(1A) follows your reporting-entity status, so the Privacy Act reached your AML/CTF activities from the earlier date, not the later one. Confirm your own enrolment position with AUSTRAC.


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC. The Privacy Act 1988 (Cth) and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.

Keep reading