Skip to content

Standalone and REBAA buyers agents: the privacy kit no RE-agency tool covers

A sole-operator or boutique buyers agent is caught by the same Privacy Act s 6E(1A) obligation as a large agency once you become an AUSTRAC reporting entity from 1 July 2026. Being small changes nothing. What does change is that almost every off-the-shelf privacy tool is built for a selling or rental agency, so it carries a rent roll, tenancy-database and open-home paperwork you will never use, and skips the buy-side data you actually hold.

By Jon Oates, Founder of Privaproof · Last updated

General information , document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.

Small does not mean exempt

Most buyers agents in Australia are sole operators or small boutiques turning over well under A$3 million, and many have relied on the small-business exemption in s 6D of the Privacy Act 1988 (Cth). Becoming an AUSTRAC reporting entity removes that shelter for one specific slice of your data.

Brokering the purchase of real estate for a buyer-client is a designated service under the AML/CTF Act s 6 (Table 5 item 1, AML/CTF Act s 6(5A)), so from 1 July 2026 you are a reporting entity, whether you run a team or work alone from a laptop. Once that happens, Privacy Act s 6E(1A) applies the Australian Privacy Principles to the client-identity data you collect for those checks, regardless of turnover. The obligation is not scaled to your size. A single-person agency handling one high-value buyer file is inside the Privacy Act for that identity data in the same way a national franchise is. Read: does the Privacy Act apply to buyers agents under $3 million?

Scope, stated honestly: s 6E(1A) reaches the AML/KYC customer-due-diligence data, the identity, verification, source-of-funds and beneficial-ownership information you collect for the checks. It does not pull your buyer CRM, your newsletter list or your property alerts under the Privacy Act. Small or large, the caught data is the same narrow set.

Why the RE-agency privacy tools are the wrong shape

The privacy products already on the market, from generic generators to the sector kits built for real-estate agencies, are shaped around a selling and rental business. That is where the volume is, so that is what they cover. A typical real-estate privacy kit assumes you hold:

A standalone buyers agent holds none of that. Property management and residential leasing are not designated services, so an agency with a rentals arm is only partly caught, and its kit is written around that mixed footprint. You do no selling and no leasing, so most of that document set is dead weight. Read: are buyers agents caught by AML Tranche 2?

The result is a kit that is over-scoped and mispriced for you. You pay for tenancy paperwork you will never issue, you get a collection notice written for sellers and renters, and the documents you genuinely need, the ones covering the buyer-side identity and financial-capacity data, are thin or missing. A selling-agency template is not a buyers-agent template with the logo changed. It is the wrong document for a different business.

The data a buyers agent actually holds is the opposite of an agency's

A selling agency holds a wide, shallow footprint: many enquiries, many open-home visitors, many tenancy records, most of it low-sensitivity. A buyers agent is the mirror image. You hold few files, but each one is deep, because to act for a buyer you gather and actively assess a concentrated set of financial data:

Few, deep, often high-net-worth records. A breach of a handful of them is very likely to cause serious harm, which is what makes it notifiable under the data-breach scheme. A privacy kit built for open-home sign-in sheets does not address this. Read: your data-breach response plan and VOI and source-of-funds privacy rules.

REBAA-accredited or not, the obligation is identical

Roughly 140 buyers agents are accredited members of the Real Estate Buyers Agents Association of Australia (REBAA), out of an estimated one thousand or so operating nationally , so most buyers agents are un-accredited boutiques and sole operators. It is worth being clear that this makes no difference to the privacy obligation.

Accreditation is a professional standard, not a privacy exemption or a privacy toolkit. REBAA does not sell a member privacy or AML product, so membership does not hand you the documents. Equally, being outside REBAA does not put you outside the Privacy Act. The s 6E(1A) obligation attaches because you provide a designated service and become a reporting entity, not because of which body you belong to. Whether you are a REBAA-accredited firm or a newly licensed sole trader, the same identity data is caught and the same privacy documents are expected.

This also matters for the association-gated products entering the market. A privacy toolkit offered only to members of a particular association, or scoped to conveyancers and law firms, is not something a standalone buyers agent outside that body can buy. The obligation is universal; some of the tooling is not.

What a standalone buyers agent actually needs

A buyers agent, of any size, needs a compact set of documents scoped to a pure buy-side broker:

1. A privacy policy (APP 1) written for buyers-agent work, not a selling-agency or generic fill-in. 2. Collection notices (APP 5), including the AML customer-due-diligence notice given at engagement, and cover for information you collect about people from third parties. 3. A data-breach response plan for the NDB scheme, tuned to the concentrated financial-capacity data you hold. 4. A retention and destruction schedule that reconciles the AML record-keeping floor with the Privacy Act principle of destroying personal information once it is no longer needed. Read: how long must a buyers agent keep client records?

No rent roll. No tenancy-database notice. No rental-application form. No open-home register. The value is in the fit and in keeping the documents current as the law moves, not in bundling paperwork you will never touch. Read: AML kit vs privacy kit, what your AML pack leaves out.

So, do you need a different kit?

If you are a sole operator or a boutique buyers agent, yes, you need documents built for a buy-side broker, not a selling agency, and not a generic download. The obligation is the same as a large firm's, but the shape of your data and your paperwork is not. A kit written around a rental and property-management footprint is over-scoped, mispriced and silent on the buyer-side financial data that is the real risk in your business. Read the cornerstone: privacy compliance for Australian buyers agents.

Common questions

I am a one-person buyers agency. Am I too small for the Privacy Act to matter?

No. The s 6E(1A) obligation attaches because you provide an AML designated service and become a reporting entity from 1 July 2026, not because of your size or turnover. A sole operator handling one high-value buyer file is inside the Privacy Act for that client-identity data in the same way a large agency is. Confirm your own AML position with AUSTRAC, as that assessment is separate from the privacy half.

Can I just use a real-estate agency privacy policy or a generic template?

You can, but it will be the wrong shape. Agency and generic templates are built around selling, rentals and open homes, so they carry tenancy and property-management paperwork you do not use and skip the buyer-side identity, source-of-funds and financial-capacity data you do hold. A buyers agent needs documents scoped to a pure buy-side broker.

Does REBAA membership give me the privacy documents I need, or change my obligation?

Neither. REBAA is a professional accreditation body and does not sell a member privacy or AML product, so membership does not hand you the templates. It also does not change the obligation: an un-accredited sole trader and a REBAA-accredited firm are caught by the same s 6E(1A) rule for the same identity data.

What data do I actually have to protect?

The AML/KYC customer-due-diligence data you collect for the identity checks: verification documents, and where a client is higher-risk, source-of-funds and beneficial-ownership evidence, plus the financial-capacity material like pre-approvals and bank statements you handle to act for the buyer. Your general CRM, newsletter and property-alert lists are not pulled in by the s 6E(1A) route.


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Privaproof's buyers-agent documents are self-authored and are not independently reviewed by a solicitor. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC. The Privacy Act 1988 (Cth) and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.