Does the Privacy Act apply to buyers agents under $3 million?
Yes, in part. Once you broker, find or identify property for a buyer-client, you become an AUSTRAC reporting entity from 1 July 2026, and Privacy Act s 6E(1A) then applies the Australian Privacy Principles to the client-identity data you collect for those anti-money-laundering checks, regardless of the A$3 million small-business exemption. It reaches that identity data only, not your whole buyer database.
By Jon Oates, Founder of Privaproof · Last updated
General information , document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.
The small-business exemption is real, but broking punches a hole in it
Under section 6D of the Privacy Act 1988 (Cth), a business turning over A$3 million or less a year is generally a "small business operator", exempt from the Act and the Australian Privacy Principles (APPs). Most boutique and sole-operator buyers agents sit under that threshold, so the common assumption is: under $3m, the Privacy Act does not apply to us.
For a lot of a normal small business, that is broadly right. The hole for a buyers agent is what you do to onboard a client. From 1 July 2026, brokering the purchase of real estate for a buyer is a "designated service" under the AML/CTF Act (Table 5 item 1, AML/CTF Act s 6(5A)), which makes you an AUSTRAC reporting entity. The moment you are a reporting entity, the exemption that shelters the rest of your practice stops reaching the identity data you collect to meet those obligations. Read: are buyers agents caught by AML Tranche 2?
How the Privacy Act switches on: s 6E(1A)
The bridge is Privacy Act s 6E(1A). When a small business becomes a reporting entity under the AML/CTF Act, s 6E(1A) treats it as an organisation for its AML activities, so the personal information it handles for those activities comes under the Privacy Act regardless of turnover. For a buyers agent, that is the customer-due-diligence data: the identity and verification documents, and the source-of-funds, financial-capacity and beneficial-ownership information you collect to satisfy the AML rules.
So the honest answer is not "the whole Privacy Act now applies to you". It is "the Privacy Act now applies to the client-identity data you collect for AML, even under $3 million". Read: does becoming an AML reporting entity trigger the Privacy Act?
What s 6E(1A) does, and does not, pull in
This is where the scope matters, because it is easy to overstate.
- The AML/KYC data is in. Identity and verification documents (VOI), and the source-of-funds, financial-capacity and beneficial-ownership data you gather for customer due diligence, are covered by the APPs via s 6E(1A).
- Your general practice is not. s 6E(1A) does not pull your buyer CRM, your newsletter list, your property alerts or your general web enquiries under the Privacy Act. Those stay under the s 6D small-business exemption unless a separate trigger applies.
- It does not make you a full APP entity for everything. The carve-in is targeted at the AML-related personal information, not blanket Privacy Act coverage of your whole business.
So the accurate line is: the Privacy Act reaches the client-ID data you handle for AML, and you should treat that data accordingly, but it does not swallow your marketing lists or your general buyer records.
Why a buyers agent is close to 100% caught in the first place
A mixed sales-and-rentals agency is only partly caught, because property management and residential leasing are not designated services. A buyers agent has no such shelter. Finding or identifying a property to buy, and negotiating the purchase, is the core of the work, so close to all of what you do is the caught activity, and the s 6E(1A) identity-data obligation follows. That structural fit is why a boutique buyers agent is one of the clearest cases of this trigger. Read: the privacy kit no RE-agency tool covers
The obligation attaches at the front of the relationship. You start providing the designated service when the client signs the agreement to find or identify a property, before any property is actually found, so the identity data comes into scope from engagement.
Advice-only or research-only? It depends
If your service genuinely never finds or identifies a specific property and never negotiates, and takes no brokering commission, you may fall outside the brokering definition, and the s 6E(1A) route may not reach you. But a buyers agency retained to acquire a property is doing the caught activity on any reading. AUSTRAC does not expressly address advice-only buyers agents, so this is fact-specific: confirm your own position rather than assuming either way . Read: advice-only or research-only buyers agent, are you caught?
The data-breach scheme follows the same data
The Notifiable Data Breaches (NDB) scheme runs on the same logic. Because a buyers agent concentrates identity documents, bank and savings statements, borrowing capacity and, for higher-risk clients, source-of-funds evidence on a small number of high-value buyers, a breach of that data is very likely to cause serious harm, which is exactly what makes it notifiable. That is why the privacy half of your obligations is not just a policy document: it is a response plan for the data s 6E(1A) has now brought inside. Read: your data-breach response plan
So, does it apply to you?
If you broker, find, identify or negotiate property purchases for a fee, and almost every practising buyers agent does, then yes, from 1 July 2026 the Privacy Act applies to the client-identity data you collect for AML, under $3 million and regardless of the small-business exemption. The obligation is targeted, not total: it covers the CDD/identity data, not your whole CRM, and it does not make your entire practice a full APP entity. But for the identity, financial-capacity and source-of-funds data at the centre of onboarding a buyer, it is real. Read the cornerstone: privacy compliance for Australian buyers agents
Common questions
Is my buyers agency exempt from the Privacy Act because we turn over less than $3 million?
Not for your AML client-identity data. The s 6D small-business exemption may cover much of your practice, but once you become an AUSTRAC reporting entity from 1 July 2026, Privacy Act s 6E(1A) applies the APPs to the identity and due-diligence data you collect for those checks, regardless of turnover.
Does this put my whole buyer database under the Privacy Act?
No. s 6E(1A) reaches the AML/KYC customer-due-diligence data: identity documents, source-of-funds and financial-capacity evidence, beneficial-ownership information. It does not pull your general buyer CRM, newsletter list or property alerts under the Privacy Act unless a separate trigger applies.
When does the identity data come into scope?
From engagement. You start providing the designated service when the client signs the agreement to find or identify a property, before any property is found, so the identity data you collect to onboard them is in scope from that point.
I only advise and research, I never negotiate. Am I caught?
It depends on the facts. A service that genuinely never finds or identifies a specific property, never negotiates, and takes no brokering commission may fall outside the brokering definition. But a buyers agency retained to acquire a property is doing the caught activity on any reading. Confirm your own position rather than assuming either way.
Is the small-business exemption being removed for buyers agents in 2026?
A general removal of the A$3 million exemption has been proposed as a future reform, but it is not yet law. What is in force is the s 6E(1A) carve-in for AML client-identity data once you are a reporting entity. Treat blanket "exemption removed from 1 July 2026" claims with caution.
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC. Privaproof's buyers-agent documents are self-authored and are not independently reviewed by a solicitor. The Privacy Act 1988 (Cth) and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.