Skip to content

Standalone and REBAA buyers agents: the privacy kit no RE-agency tool covers

A sole-operator or boutique buyers agent is reached by the same Privacy Act s 6E(1A) obligation as a large agency once you provide a designated service and become an AUSTRAC reporting entity, which for real-estate services happened on 31 March 2026. Being small changes nothing. What does change is the shape of the paperwork: privacy documents written for a selling or rental agency describe a rent roll, tenancy-database and open-home records a pure buy-side broker never holds, and give less room to the buyer-side identity and financial data you do hold.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.

Small does not mean exempt

A buyers agency with annual turnover of A$3,000,000 or less is a small business under s 6D(1) of the Privacy Act 1988 (Cth), and a small business operator generally sits outside the Australian Privacy Principles. Turnover is not the only gate. Section 6D(4) lists other things that take a business out of the exemption, including holding health information, disclosing personal information for a benefit, and being a contracted service provider for a Commonwealth contract, and s 6D(4)(a) runs one way: once a financial year has ended with turnover above A$3,000,000, a later fall does not restore the exemption. Becoming an AUSTRAC reporting entity is a separate route back in, for one specific part of what you do.

Table 5 item 1 of the AML/CTF Act s 6(5A) makes "brokering the sale, purchase or transfer of real estate on behalf of a buyer, seller, transferee or transferor in the course of carrying on a business" a designated service, and Table 5 commenced on 31 March 2026, so a buyers agency providing that service has been a reporting entity since then, whether it runs a team or works alone from a laptop. The AML/CTF obligations themselves were deferred to 1 July 2026. Once you are a reporting entity, Privacy Act s 6E(1A) applies the Act regardless of turnover "in relation to the activities carried on by the small business operator for the purposes of, or in connection with, activities relating to" the AML/CTF Act, as if you were an organisation. The obligation is not scaled to your size. A single-person agency handling one high-value buyer file is inside the Privacy Act for those activities in the same way a national franchise is. Read: does the Privacy Act apply to buyers agents under $3 million?

Scope, stated honestly: s 6E(1A) is scoped to activities, not to a category of data. Its words are the activities carried on "for the purposes of, or in connection with, activities relating to" the AML/CTF Act, which takes in customer due diligence, ongoing monitoring and reporting, record keeping, and the staff due diligence an AML/CTF program requires. Personal information you handle in the course of those activities is caught, most obviously the identity, verification, source-of-funds and beneficial-ownership material you collect for the checks. Marketing that has no connection with those activities, such as a newsletter list or a property alert, is not brought in by this route, although the same record can sit on both sides of the line if you also use it for an AML-related activity.

Why the RE-agency privacy tools are the wrong shape

Privacy paperwork written for a real-estate agency is shaped around a selling and rental business, because that is the shape of the data most agencies hold. A document set written for that business assumes you hold:

A standalone buyers agent holds none of that. Table 5 of the AML/CTF Act lists two real-estate designated services, brokering a sale, purchase or transfer, and selling or transferring real estate in the course of a business, so property management and residential leasing are not real-estate designated services and an agency with a rentals arm is caught for part of what it does. Its paperwork is written around that mixed footprint. You do no selling and no leasing, so a large part of that document set does not describe your business. Read: are buyers agents caught by AML Tranche 2?

The result is a document set scoped to a business you do not run. The tenancy paperwork is paperwork you will never issue, the collection notice is written for sellers and renters, and the buyer-side identity and financial-capacity data gets whatever room is left. A selling-agency template is not a buyers-agent template with the logo changed. It is a document written for a different business.

The data a buyers agent actually holds is the opposite of an agency's

A selling agency holds a wide, shallow footprint: many enquiries, many open-home visitors, many tenancy records, most of it low-sensitivity. A buyers agent is the mirror image. You hold few files, but each one is deep, because to act for a buyer you gather and actively assess a concentrated set of financial data:

Few files, each of them deep. Where you are an APP entity for those activities, Part IIIC applies: under s 26WE(2) there is an eligible data breach where there is unauthorised access to or disclosure of the information and "a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates", subject to the remedial-action exception in s 26WF. That assessment is yours to make on the facts of the file, and a buyers-agent file puts identity documents next to bank statements and source-of-funds evidence. A document set built for open-home sign-in sheets does not address it. Read: your data-breach response plan and VOI and source-of-funds privacy rules.

REBAA-accredited or not, the obligation is identical

The Real Estate Buyers Agents Association of Australia (REBAA) was established in 2000 and accredits buyers agencies rather than admitting every applicant. Its published eligibility rules require the agency to have been operating as a buyers agency for at least 12 months full time or equivalent, to be a licensed real estate agency in the states and territories it buys in, to hold professional indemnity insurance to a minimum value of A$2,000,000, and not to have properties listed for sale or act as a selling agent, and members undertake to uphold the REBAA Code of Conduct. Accredited members are listed in REBAA's public member directory. Not every buyers agent is accredited, and it is worth being clear that accreditation makes no difference to the privacy obligation.

Accreditation is a professional standard, not a privacy exemption. REBAA's published member benefits run to networking, its code of ethics and best practice, credibility, branding, referrals, legislative representation, a members forum, group discounts, its Buyer's Agents Agreement, a mentoring program and media relations, and do not include a privacy or AML document set, so membership should not be assumed to hand you those documents. Privaproof has no association with REBAA, and nothing here is endorsed or published by it. Equally, being outside REBAA does not put you outside the Privacy Act. The s 6E(1A) route runs through providing a designated service and being a reporting entity, not through which body you belong to. Whether you are a REBAA-accredited agency or a newly licensed sole trader, the same activities are caught.

It also matters where a privacy toolkit is offered only to members of a particular association, or is scoped to conveyancers and law firms. A buyers agent outside that body, or outside that scope, cannot use it. The obligation follows the designated service you provide; the availability of the tooling does not.

What a standalone buyers agent actually needs

A buyers agent, of any size, needs a compact set of documents scoped to a pure buy-side broker:

No rent roll. No tenancy-database notice. No rental-application form. No open-home register. The value is in the fit and in keeping the documents current as the law moves, not in bundling paperwork you will never touch. Read: AML kit vs privacy kit, what your AML pack leaves out.

So, do you need a different kit?

If you are a sole operator or a boutique buyers agent, the documents that describe your business are buy-side documents, not a selling-agency set and not a generic download. The obligation is the same as a large agency's, but the shape of your data and your paperwork is not. A document set written around a rental and property-management footprint spends its length on records you do not hold, and little on the buyer-side financial data you do. Read the cornerstone: privacy compliance for Australian buyers agents.

Common questions

I am a one-person buyers agency. Am I too small for the Privacy Act to matter?

No. The s 6E(1A) route runs through providing an AML designated service and being a reporting entity, which for real-estate services has been the position since 31 March 2026, not through your size or turnover. It applies the Act in relation to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act, so a sole operator handling one high-value buyer file is inside the Privacy Act for that work in the same way a large agency is. Confirm your own AML position with AUSTRAC, as that assessment is separate from the privacy half.

Can I just use a real-estate agency privacy policy or a generic template?

You can, but check the shape of it before you rely on it. A template written for a selling and rental agency describes tenancy and property-management handling you do not do, and it will cover the buyer-side identity, source-of-funds and financial-capacity data only as far as its author had that business in mind. A privacy policy and a collection notice have to describe what you actually collect and why, so a buyers agent needs documents scoped to a pure buy-side broker.

Does REBAA membership give me the privacy documents I need, or change my obligation?

Neither, on REBAA's own published material. REBAA is a professional accreditation body and its published member benefits do not include a privacy or AML document set, so membership should not be assumed to hand you the templates. Privaproof has no association with REBAA and is not endorsed by it. Membership also does not change the obligation: an un-accredited sole trader and a REBAA-accredited agency are reached by the same s 6E(1A) rule for the same AML-related activities.

What data do I actually have to protect?

Personal information you handle in the course of your AML-related activities. Section 6E(1A) is scoped to the activities carried on for the purposes of, or in connection with, activities relating to the AML/CTF Act, which takes in customer due diligence, ongoing monitoring and reporting, record keeping and the staff due diligence your program requires. In practice that is the verification documents, and where a client is higher risk, the source-of-funds and beneficial-ownership evidence, plus financial-capacity material such as pre-approvals and bank statements to the extent you handle it for those checks. A marketing list such as a newsletter or property alerts is not brought in by this route unless you also use that information for an AML-related activity.


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC. The Privacy Act 1988 (Cth) and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.