Skip to content

Privacy & data terms explained: for Australian real-estate agents

A plain-English glossary for agents, principals and property managers, not lawyers.

This page explains the privacy, data and AML terms that keep turning up in the OAIC's 2026 real-estate focus, the Tranche 2 AML reforms, and the rental-application rulings. It's written for time-poor agents who need to know what a word actually means for their forms, their CRM and their front desk, not a legal treatise.

This is general information, not legal advice. Rules change and every agency's situation differs. Each entry names the section of the Act, the rule or the determination it comes from, so the wording can be checked at source, and anything an agency plans to act on is worth confirming with a qualified lawyer. If you'd rather just find out where you stand, start with our free Privacy Readiness audit.

See also: Does the Privacy Act apply to real-estate agents? · Privacy Act compliance for real-estate agencies


Layer 1: Core terms

The six terms the rest of this page keeps coming back to. If you only learn six, learn these.

Sensitive information

A higher-protection category of personal information, and the s 6(1) list is closed: health information, genetic information that is not otherwise health information, biometric information that is to be used for automated biometric verification or identification, biometric templates, and information or an opinion about a person's racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual orientation or practices, or criminal record. Off that list it is not sensitive information, however damaging its loss: a driver's licence, passport, visa or country of birth is ordinary personal information. Disability is covered only as health information, which the Act defines as including information about an illness, disability or injury. Information is sensitive where it clearly indicates a listed matter, not where it merely hints at one. Collection generally needs the person's consent and must be reasonably necessary. Related: reasonably necessary, government-related identifier. Source: Privacy Act 1988 (Cth) s 6(1) and s 6FA; APP 3.3; OAIC APP Guidelines Ch B & Ch 3

Small business exemption

A business is a small business if its annual turnover for the previous financial year was $3,000,000 or less, and a small business operator is generally exempt from the Australian Privacy Principles. Being under the threshold does not settle it: the exceptions in s 6D(4) apply whatever the turnover. A business is not a small business operator if it discloses personal information about another individual for a benefit, service or advantage (unless the individual consented, or the disclosure was required or authorised by legislation), if it gives a benefit, service or advantage to be allowed to collect personal information about another individual from someone else, or if it is a contracted service provider for a Commonwealth contract. Operating a residential tenancy database is separately prescribed whatever the turnover, but that binds the database operators, not the agencies that search or contribute to one, and only for acts and practices connected with collecting for, maintaining, or using or disclosing from that database. A database must both store personal information about an individual's occupation of residential premises as a tenant and be accessible by someone other than its operator, so an agency's internal list of the tenancies it manages is not one. Where an agency provides a real-estate designated service, s 6E(1A) applies the Privacy Act whatever its turnover, but only to the activities carried on for the purposes of, or in connection with, activities relating to the AML/CTF Act; see AML/CTF Tranche 2. The Government has agreed in principle to repeal the small-business exemption, but that repeal is not legislated and has no confirmed date. Fuller answer: Does the Privacy Act apply to real-estate agents?. Source: Privacy Act 1988 (Cth) ss 6D, 6DA, 6E(1A), 6E(2); Privacy Regulations 2025 (Cth) ss 5, 7(1)-(2); Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth) Sch 3 Pt 4 items 11 and 12; OAIC small business guidance

Collection notice

The short statement you give a person when you collect their personal information. Where the Privacy Act applies to you, APP 5 requires reasonable steps to notify them, at or before collection or as soon as practicable after: who you are, what you're collecting and why, who you usually disclose it to, whether a law requires the collection (and which law), the main consequences if they don't provide it, and that your privacy policy covers access, correction and complaints. Say if the information is likely to go to overseas recipients, and name the countries where it is practicable to do so. It is a separate obligation from your privacy policy (APP 1.3), not a replacement: the notice goes at the point of collection, including on rental application forms, appraisal request forms and open-home sign-in sheets; the policy is the standing document you publish. More: Do agents need a collection notice? Source: Privacy Act 1988 (Cth) Sch 1, APP 5.1-5.2 and APP 1.3-1.5; OAIC APP Guidelines Ch 5

Permission that is genuinely valid. The Privacy Act defines consent only as "express consent or implied consent" (s 6(1)), so it can be implied by conduct. The OAIC treats four elements as necessary: adequately informed, voluntary, current and specific, and within the person's capacity to understand and communicate. A pre-ticked box or a buried "tick to agree to everything" clause generally won't count. Consent, or an APP 3.4 exception such as a collection required by law, is what permits collecting sensitive information, which must still be reasonably necessary for the agency's functions (APP 3.3). It is also one route to a secondary purpose under APP 6.2. Direct marketing is handled separately under APP 7 and does not always need consent (APP 7.2); for marketing email and SMS the Spam Act 2003 applies instead (APP 7.8). Source: Privacy Act 1988 (Cth) s 6(1); OAIC APP Guidelines Ch B paras B.38, B.43, B.48-B.49; APP 3.3-3.4; APP 6.1(a), 6.2(a); APP 7.2, 7.8

AML/CTF Tranche 2

The reform that pulls real-estate agents, developers and conveyancers into Australia's anti-money-laundering net. Key dates: brokering the sale, purchase or transfer of real estate became a designated service on 31 March 2026, when Tables 5 and 6 commenced and agencies providing those services became reporting entities. The AML/CTF obligations applied from 1 July 2026, and for a business already providing a designated service the enrolment deadline was 29 July 2026, set by Sch 3 Pt 4 item 12 of the amending Act. Those obligations bring customer due diligence, identity verification, reporting and 7-year record-keeping. Leases of 30 years or less sit outside the Act's definition of real estate, so the reform reaches the sales side: ordinary leasing and property management are not designated services. More ID data means more Privacy Act exposure, so collection, storage and destruction all matter more. Full detail: AML/CTF Tranche 2 for real-estate agents. Related: customer due diligence, 100 points of ID. Source: AML/CTF Act 2006 (Cth) s 5 (definitions) and s 6 (tables 5 and 6, designated services); Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth) Sch 3 Pt 4 items 11 and 12; AUSTRAC, 'Real estate designated services'

Data breach response plan

A documented procedure for containing and assessing a breach and reporting an eligible data breach within the timeframes the Act sets: who does what, and how to notify the OAIC and affected people. The OAIC says such a plan, focused on reducing a breach's impact, can be one of the reasonable steps an entity takes under APP 11.1 to protect the personal information it holds. Related: notifiable data breach and serious harm. Source: Privacy Act 1988 (Cth) Sch 1, APP 11.1, and Part IIIC (NDB scheme); OAIC, Data breach preparation and response, Part 2 (updated February 2025)


Layer 2: How it's actually asked

The same questions, in the words agents and tenants actually type.

Does a real estate agency need a privacy policy?

If your agency is covered by the Privacy Act (see small business exemption), APP 1.3 requires a clearly expressed, up-to-date privacy policy on how you manage personal information, APP 1.4 sets its minimum contents, and APP 1.5 requires reasonable steps to make it available free of charge. It must describe the agency's actual handling, including appraisals, rentals, sales and marketing, and it is what the 2026 OAIC sweep assessed against APP 1.4. It is separate from the shorter collection notice on your forms (both, together). Source: Privacy Act 1988 (Cth) Sch 1, APP 1.3-1.5; OAIC APP Guidelines Ch 1; OAIC media release "Privacy compliance sweep to put privacy policies under the spotlight", 9 December 2025

Do agents need a collection notice on rental application forms?

Only if the agency is an APP entity (see small business exemption). Where the Act applies, APP 5.1 requires such steps (if any) as are reasonable in the circumstances, at or before collection or, if that is not practicable, as soon as practicable afterwards, to notify the person of the APP 5.2 matters that are reasonable in the circumstances. Those matters are set out at APP 5.2(a) to (j) and under collection notice. In Commissioner initiated investigation into 7-Eleven Stores Pty Ltd (Privacy) [2021] AICmr 50 the Commissioner said at [121] that a privacy policy is not generally a way of giving notice under APP 5, and at [122] that notice should have been given at the point of collection, before capture. Source: Privacy Act 1988 (Cth) Sch 1, APP 5.1 and 5.2 (Compilation No. 104, compilation date 4 June 2026, C2026C00227); OAIC APP Guidelines Ch 5; Commissioner initiated investigation into 7-Eleven Stores Pty Ltd (Privacy) [2021] AICmr 50 at [121] and [122]

Is my agency exempt from the Privacy Act under $3 million turnover?

It depends, and turnover is only the first test. An agency providing a sales-side designated service (brokering the sale or purchase of real estate) is a reporting entity under the AML/CTF Act, and s 6E(1A) then applies the Privacy Act whatever its turnover, but only to the AML/CTF activities described under small business exemption. There is no group aggregation rule: s 6D(9) does not add related companies' turnover together, but asks whether a body corporate the agency is related to is, on its own figures, not a small business operator, and if so the agency is taken not to be one either. Relatedness is decided under the Corporations Act 2001, so companies that merely share an owner are not related bodies corporate. Even under $3,000,000, the exceptions in s 6D(4) can apply on their own. Get advice if any trigger is close. Source: Privacy Act 1988 (Cth) ss 6D(4), 6D(7)-(8), 6D(9), 6DA, 6E(1A); Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth) Sch 3 Pt 4 items 11 and 12; Corporations Act 2001 (Cth) s 50

What counts as sensitive information on a rental application?

The categories are listed under sensitive information; the ones that surface on a rental form are health information, racial or ethnic origin, religious beliefs or affiliations, and criminal record. Disability isn't a separate category but is captured as health information, and information is sensitive only where it clearly indicates a listed matter, not where it hints at one. Citizenship and visa details are not sensitive information as such, but in IRE Pty Ltd (Privacy) [2026] AICmr 24 the Commissioner found at [94] that the platform could carry out its functions without collecting citizenship status and visa expiry. Under APP 3.3, an APP entity must not collect it unless the individual consents and the information is reasonably necessary for one or more of the entity's functions or activities, or an APP 3.4 exception applies. On a rental form, a doctor's letter supporting an assistance animal is health information, and an open-ended "any other information" box can draw in sensitive information the agency has no need for. Source: Privacy Act 1988 s 6(1), s 6FA; APP 3.3, APP 3.4; OAIC APP Guidelines Ch B (B.77, B.142) and Ch 3; Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 at [94]

Can a rental agent ask about my health, disability or religion?

Generally no: these are sensitive information, and disability counts as health information (s 6FA). Collecting them needs consent and reasonable necessity for an agency function, or an APP 3.4 exception such as a collection required or authorised by an Australian law (APP 3.3); a covered agency must also take reasonable steps to state its collection purposes (APP 5.1, 5.2(d)). A small business operator under s 6D sits outside the APPs unless a trigger applies. Anti-discrimination law is a separate regime and binds agents whatever their turnover: refusing an application for accommodation on the ground of disability, or requesting information relating to a disability in connection with such an act, is unlawful, subject to the exceptions in those sections (Disability Discrimination Act 1992 (Cth) ss 25(1)(a), 30). Whether religion is protected in renting depends on the applicable state or territory law. Source: Privacy Act 1988 (Cth) ss 6(1), 6FA, 6D; Sch 1 APP 3.3, 3.4, 5.1, 5.2(d); Disability Discrimination Act 1992 (Cth) ss 25, 30; OAIC APP Guidelines Ch 3

The 100 points of ID question

No Australian tenancy law requires a renter to provide 100 points of ID. The 100-point framework was a banking rule under the Financial Transaction Reports Act 1988, repealed with its regulations on 7 January 2025. Queensland caps requests at 2 documents verifying a prospective tenant’s identity. In Victoria, applications to enter a residential rental agreement made on or after 31 March 2026 must use prescribed Form 3A, whose item 7 allows a rental provider or agent to request "no more than two identity documents" from a set list (social and specialised housing aside). Where the Privacy Act applies, collecting more identity documents than are reasonably necessary is over-collection under APP 3.2, and copies no longer needed attract the APP 11.2 destroy-or-de-identify duty. Related: driver’s licence & Medicare. Source: Financial Transaction Reports Regulations 2019 (Cth) s 9(2), repealed 7 January 2025 with the Financial Transaction Reports Act 1988 by the AML/CTF Amendment Act 2024; Residential Tenancies and Rooming Accommodation Act 2008 (Qld) ss 57B, 57C(1)(b)(i); Residential Tenancies Act 1997 (Vic) s 30AC and Residential Tenancies Regulations 2021 (Vic) reg 14A and Sch 1 Form 3A item 7 (inserted by SR 123/2025); Privacy Act 1988 (Cth) Sch 1, APP 3.2 and APP 11.2

Can an agent ask for my driver's licence or Medicare number?

An agency covered by the Privacy Act can ask to see a government related identifier (a driver's licence, Medicare card, passport or Centrelink CRN) and use it where reasonably necessary to verify identity, but generally must not adopt the number as its own customer reference. Whether it may collect a copy is a separate question under APP 3.2: if the identifier could not lawfully be used or disclosed under APP 9.2, collecting it is not reasonably necessary. Copies that are no longer needed attract the APP 11.2 destruction or de-identification duty. Source: Privacy Act 1988 (Cth) Sch 1, APP 9.1 and APP 9.2(a), APP 3.2 and APP 11.2; OAIC APP Guidelines Ch 9 paras 9.13, 9.15, 9.16, 9.26

Tenant application data: what agents collect

A rental application can gather identity documents, income and employment evidence, rental history, references and bank statements: personal information, and sometimes sensitive information. Under APP 3.2 an agency covered by the Privacy Act may collect personal information only where it is reasonably necessary for one or more of its functions or activities, here assessing the application; sensitive information faces the stricter APP 3.3 test. In IRE [2026] AICmr 24 at [95] the Commissioner found the 2Apply platform could have performed its functions while collecting a lesser amount of identification and proof-of-income documents. No determination deals with bank statements by name, and that determination is under review, but it is the clearest signal on where the over-collection line sits. Source: Privacy Act 1988 (Cth) Sch 1, APP 3.2 and APP 3.3; OAIC APP Guidelines Ch 3; OAIC, "Tenancy" privacy-rights guidance; Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 at [95]

Over-collection (APP 3)

Collecting more personal information than is reasonably necessary for one or more of an agency's functions or activities, which contravenes APP 3.2 and binds an agency that is an APP entity. "Reasonably necessary" is an objective test: whether a properly informed reasonable person would agree the collection is necessary; merely helpful, desirable or convenient is not enough. The OAIC's rental examples, at APP Guidelines Ch 3 para 3.28, are gender, citizenship status and visa expiry; emergency contact and vehicle details from every applicant when only the successful one needs them; and identification documents, or details inside them, where less would establish identity at application stage. They come from Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24, decided against a rental technology platform rather than an agency, and the OAIC records the determination is under review in the Administrative Review Tribunal. Related: tenant application data. Source: Privacy Act 1988 (Cth) Sch 1, APP 3.2 (and APP 3.3 for sensitive information); OAIC APP Guidelines Ch 3 paras 3.25 to 3.28; Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24

How long can an agent keep an unsuccessful applicant's data?

There's no single number in the Privacy Act. APP 11.2 requires such steps as are reasonable in the circumstances to destroy or de-identify personal information once it is no longer needed for any purpose for which it may be used or disclosed under the APPs, and no Australian law, or court or tribunal order, requires it to be retained. The trigger is the purpose ending, not a date: for an unsuccessful applicant's file, that is once the property is let and any dispute window has closed. The laws that reach a leasing file set destruction deadlines rather than minimum retention: in Queensland, an unsuccessful applicant's information must be destroyed within 3 months (Residential Tenancies and Rooming Accommodation Act 2008 (Qld) s 457E(1)(c)). AML/CTF customer due diligence records sit on the sales side, because leases of 30 years or less are not a designated service. Destruction means the information can no longer be retrieved, and reasonable steps reach every copy held, including archives and back-ups; where electronic information cannot be irretrievably destroyed, the OAIC accepts putting it beyond use instead, on the conditions at paras 11.51-11.52. Moving a file to an archive folder is neither. Related: de-identification, AML/CTF Tranche 2. Source: Privacy Act 1988 (Cth) Sch 1, APP 11.2; OAIC APP Guidelines ch 11 paras 11.39, 11.49, 11.51-11.52; Residential Tenancies and Rooming Accommodation Act 2008 (Qld) s 457E(1)(c); AML/CTF Act 2006 (Cth)

Do agents have to do AML checks from 2026?

Only on the sales side. Brokering the sale, purchase or transfer of real estate became a designated service under AML/CTF Tranche 2 on 31 March 2026, when Tables 5 and 6 commenced, and the agency became an AUSTRAC reporting entity that day. Leases of 30 years or less sit outside the Act's definition of real estate, so ordinary leasing and property management are not designated services. The obligations started on 1 July 2026, and a business already providing a designated service had to be enrolled with AUSTRAC by 29 July 2026, the date fixed by Sch 3 Pt 4 item 12 of the amending Act. What the checks involve is set out under customer due diligence; the verification data is personal information, and s 6E(1A) applies the Privacy Act to those AML-related activities rather than the whole business even under the turnover threshold, so collect only what the AML/CTF rules require (data minimisation). Source: AML/CTF Act 2006 (Cth) ss 28(2), 51B; AML/CTF Rules 2025 ss 6-21, 6-23; AML/CTF Amendment Act 2024 (Cth) Sch 3 Pt 4 items 11 and 12; Privacy Act 1988 (Cth) s 6E(1A)

Do I have to give my name and number at an open home?

Nothing in the Privacy Act requires a visitor to complete a sign-in sheet, and where the agency is covered by the Act, APP 3.2 limits collection to what is reasonably necessary for its functions or activities. If contact details are collected, APP 5.1 requires reasonable steps to make the person aware of the collection notice matters at or before collection, and reusing them for marketing is governed by APP 7. Where practicable and lawful, people may be able to deal with an agent anonymously or by pseudonym (APP 2). Source: Privacy Act 1988 (Cth) Sch 1, APP 2, APP 3.2, APP 5.1 and APP 7; OAIC APP Guidelines Ch 2, 3, 5 & 7

Can I email past appraisal contacts about new listings?

For an emailed campaign the Spam Act does the work. APP 7.1 bars using personal information for direct marketing. APP 7.2 allows it for non-sensitive details collected from the person, where they would reasonably expect the use, are given a simple opt-out and have not opted out; otherwise APP 7.3 requires their consent (or that obtaining consent is impracticable) plus an opt-out statement in every message. For email and SMS the regimes do not stack: APP 6.7 hands direct marketing to APP 7, APP 7.8 disapplies APP 7 to the extent the Spam Act 2003 applies, so the message needs consent (s 16), accurate sender details (s 17) and a working unsubscribe (s 18). APP 7 still governs the data, including the APP 7.6 right to be told the source. An appraisal enquiry or an open-home sign-in is not by itself consent. Source: Privacy Act 1988 (Cth) Sch 1, APP 6.7, APP 7.1, APP 7.2, APP 7.3, APP 7.6 and APP 7.8; Spam Act 2003 (Cth) ss 16, 17, 18; OAIC APP Guidelines Ch 7

Can I reuse tenant data for a different purpose?

If you're an APP entity, APP 6 permits use or disclosure for the purpose of collection (the primary purpose, such as assessing a rental application), including disclosure to a third party for that purpose (passing the application to the landlord). A different purpose needs an APP 6 exception: the person consents (APP 6.1(a)), or the person would reasonably expect it and the new purpose is related to the primary purpose, and directly related if the information is sensitive (APP 6.2(a)). APP 6.2 also covers use or disclosure required or authorised by an Australian law or a court or tribunal order, and a small number of other permitted situations. Direct marketing to your tenant list is not an APP 6 question: APP 6.7 takes direct marketing by an organisation out of APP 6 and into APP 7. Source: Privacy Act 1988 (Cth) Sch 1, APP 6.1(a), 6.2(a), 6.2(b), 6.7 and APP 7 (Compilation No. 104, 4 June 2026); OAIC APP Guidelines Ch 6

How do tenant blacklists like TICA work?

Tenancy databases, TICA and NTD among them, record former tenants on narrow grounds: the tenancy must have ended, only a person named as a tenant on the agreement can be listed, and only where a breach left them owing more than the bond or a tribunal ordered the agreement terminated. Falling behind during a tenancy is not on its own a ground. The listing rules sit in each state and territory's residential-tenancy Act, and the Privacy Act sits alongside them: a database operator is treated as an organisation for its database acts and practices. Before listing, the person must be given a copy of the proposed listing (or other reasonable steps to disclose it) and time to object: at least 14 days in NSW (s 213(1)) and SA (s 99G(1)), 28 days in the NT (s 129(1)(b)). A listing must relate to the breach and be accurate, complete and unambiguous (NSW s 212(d); SA s 99F(1)(d)(ii)), and a lister who learns it is inaccurate, incomplete, ambiguous or out of date has 7 days to tell the operator (NSW s 214; SA s 99H), a duty Victoria puts on the rental provider, not the agent (s 439G(1)). A written request for a copy must be answered within 14 days (NSW s 216; Qld s 459C), free in NSW (s 216(3)), and in Qld for a fee that must not be excessive and must not apply to lodging the request (s 459C(3)). Related: access & correction (APP 12/13). Source: Residential Tenancies Act 2010 (NSW) ss 211-218; Residential Tenancies Act 1995 (SA) ss 99D-99K; Residential Tenancies and Rooming Accommodation Act 2008 (Qld) ss 459-459D (current as at 17 August 2026); Residential Tenancies Act 1999 (NT) ss 128-129; Residential Tenancies Act 1997 (Vic) s 439G; Privacy Act 1988 (Cth) s 6E(2); Privacy Regulations 2025 (Cth) s 7(1)-(2)

Can a tenant see the data I hold on them?

Yes, if your agency is an APP entity. APP 12.1 requires access, on request, to the personal information the agency holds about a person; APP 12.3 lets an organisation withhold on ten narrow grounds, and only to the extent a ground actually applies. APP 13.1 requires such steps (if any) as are reasonable in the circumstances to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading, having regard to a purpose for which it is held, whether or not the person asks. In the Privacy Act "agency" means a Commonwealth agency, so the hard 30-day deadline in APP 12.4(a)(i) does not bind a private real-estate business: it is an "organisation", and responds within a reasonable period (APP 12.4(a)(ii), and APP 13.5(a)(ii) for corrections). That is not a longer deadline: the OAIC's guidance is that a reasonable period should not exceed 30 calendar days. Responding means giving access or notifying a refusal, so an acknowledgement does not stop the clock. Related: personal information. Source: Privacy Act 1988 (Cth) Sch 1, APP 12.1, 12.3, 12.4(a)(i)-(ii), 13.1 and 13.5(a)(ii), Compilation No. 104 (4 June 2026); OAIC APP Guidelines ch 12 para 12.67 and ch 13 para 13.63

What actually counts as personal information?

Any information or opinion about an identified individual, or someone reasonably identifiable (names, contact details, tenancy history, payslips, references, photos and signatures), whether true or not, and whether it is recorded in a material form or not. A CRM record that identifies a tenant, buyer or vendor is personal information. Where the Privacy Act covers an agency, the APPs govern how it is collected, stored, used and disposed of. Coverage turns on the small business exemption and on the triggers that override it, the AML/CTF one included. The higher-protection subset is sensitive information. Source: Privacy Act 1988 (Cth) ss 6(1), 6C(1), 6D, 15; OAIC 'What is personal information?' guidance

What happens if my agency has a data breach?

The Notifiable Data Breaches scheme reaches APP entities: the agency if the small business exemption does not apply, and an AML-covered agency for personal information handled in connection with its designated services. On loss, or unauthorised access or disclosure, s 26WH requires an assessment of whether there are reasonable grounds to believe there has been an "eligible data breach": one a reasonable person would conclude is likely to result in serious harm. "Serious harm" is not defined in the Act; the OAIC's guidance is that it may include serious physical, psychological, emotional, financial or reputational harm. The s 26WG factors are applied to the circumstances, among them the kind of information (c), its sensitivity (d) and who could obtain it (g); no category is automatically serious. Then ss 26WK and 26WL require a statement to the OAIC and notification of the individuals at risk, both as soon as practicable. Remedial action taken so that serious harm is no longer likely means the breach is taken never to have been eligible (s 26WF). Related: data breach response plan. Source: Privacy Act 1988 (Cth) ss 26WE, 26WF, 26WG, 26WH, 26WK, 26WL; OAIC, Data breach preparation and response, Part 4: Notifiable Data Breach (NDB) scheme (updated February 2025)

How long do I have to report a data breach?

Once an agency covered by the Privacy Act is aware of reasonable grounds to suspect an eligible data breach, s 26WH(2) requires a reasonable and expeditious assessment, with all reasonable steps to complete it within 30 days. The clock starts at that awareness, not at the incident. If it gives reasonable grounds to believe there has been an eligible data breach, the agency gives the OAIC a statement as soon as practicable (s 26WK) and notifies the individuals at risk (s 26WL). The 30 days is an outer limit on the assessment, not a deadline to report. In Datateks Pty Ltd (Privacy) [2023] AICmr 97 at [98] the Commissioner held that preparing the statement "should have taken no more than a day or two". Source: Privacy Act 1988 (Cth) ss 26WH(2), 26WK(2), 26WL; Datateks Pty Ltd (Privacy) [2023] AICmr 97 at [98]; OAIC notifiable data breaches guidance

Can I be personally fined for a privacy breach at my agency?

A civil penalty order under s 13G is made against the entity whose act or practice was the interference, which for an incorporated agency is the company. An individual can still be reached two ways. A sole trader who is an APP entity is the entity itself: under s 6C(1)(a) an individual is an "organisation", and so an APP entity, unless they are a small business operator. And under s 92 of the Regulatory Powers (Standard Provisions) Act 2014 (Cth), applied to the Privacy Act's civil penalty provisions by s 80U, a person who aids, abets, counsels or procures a contravention, or is knowingly concerned in one, is taken to have contravened it themselves. Section 13G applies to a serious interference with privacy. The maximum is A$2.5 million for a person other than a body corporate (s 13G(2)), and for a body corporate the greatest of A$50 million, three times the benefit attributable to the conduct, or, where the court cannot determine that benefit, 30% of adjusted turnover during the breach turnover period (s 13G(3)); figures as at Compilation No. 104, 4 June 2026. The Privacy and Other Legislation Amendment Act 2024 (Cth) removed the earlier "or repeated" limb, so repetition is now only a matter a court may have regard to under s 13G(1B)(f). Section 13H covers an interference without the seriousness element, and under s 13J a court not satisfied the interference was serious may make a s 13H order instead. More: penalties for a privacy breach. Source: Privacy Act 1988 (Cth) ss 13G, 13H, 13J, 80U and s 6C(1)(a), Compilation No. 104 (4 June 2026); Regulatory Powers (Standard Provisions) Act 2014 (Cth) s 92, Compilation No. 4 (20 March 2024)

Can a tenant sue a real estate agent for invasion of privacy?

Only in narrow circumstances. The statutory tort for serious invasions of privacy (Privacy Act Schedule 2, inserted by the Privacy and Other Legislation Amendment Act 2024) commenced on 10 June 2025. It gives a direct court claim, separate from the OAIC complaints process, but only where all five conditions in clause 7(1) are met: the defendant intruded on the person's seclusion or misused information relating to them (the only two forms the invasion can take); a person in that position would have had a reasonable expectation of privacy; the invasion was intentional or reckless; it was serious; and the public interest in the person's privacy outweighed any countervailing public interest. Carelessness is not enough, so an application form misdirected by mistake would not ground a claim. Confirm the precise scope and any defences with a lawyer. Related: penalties. Source: Privacy Act 1988 (Cth) Sch 2 cl 7(1) (cause of action); Privacy and Other Legislation Amendment Act 2024 (Cth) s 2 table item 8 (commencement, 10 June 2025)

What happens if my CRM stores tenant data overseas?

If your agency is an APP entity, APP 8.1 requires steps reasonable in the circumstances, before disclosing personal information to an overseas recipient (a person outside Australia who is not the entity or the individual), to ensure that recipient does not breach the APPs other than APP 1. Hosting on an overseas server is not automatically a disclosure: use or disclosure turns on effective control, and the OAIC treats outsourcing to an overseas provider as a disclosure in most circumstances. Where it is a disclosure, s 16C can treat the recipient's act as your agency's own, but only if all three of its conditions are met: APP 8.1 applies and no APP 8.2 exception is relied on, the APPs do not already apply to the recipient, and the act would breach an APP other than APP 1. Check a vendor's data residency before data is loaded. Your privacy policy must say whether you are likely to disclose personal information overseas (APP 1.4(f)) and, if so, the likely countries, where it is practicable to specify them (APP 1.4(g)). Related: third-party processors. Source: Privacy Act 1988 (Cth) Sch 1, APP 8.1 and APP 8.2, APP 1.4(f)-(g); s 16C(1)-(2); OAIC APP Guidelines Ch 8 paras 8.10, 8.12, 8.14, 8.60-8.63

Am I liable if my property management software gets hacked?

The duty cannot be outsourced. APP 11.1 applies to an APP entity that holds personal information, and "holds" means possession or control of the record (s 6(1)): an entity that outsources storage but keeps the right to deal with the information still holds it (OAIC APP Guidelines para 11.6). The reasonable-steps duty therefore stays with the agency, and covers third party providers, cloud computing included, and data breaches (para 11.9); see breach response plan. If the provider is breached, the agency's own assessment duty under s 26WH still runs; and where the same incident is an eligible data breach of both entities, once one has notified under ss 26WK and 26WL those sections no longer apply to the other (s 26WM), so settle in the contract who notifies. The only judicial consideration of APP 11.1(b) held the obligation to be "not capable of being discharged simply by delegating it to another entity and doing nothing more" (Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224 at paragraph 52(b)). Related: cross-border disclosure (APP 8). Source: Privacy Act 1988 (Cth) Sch 1 APP 11.1; s 6(1) "holds"; ss 26WH, 26WK, 26WL, 26WM; OAIC APP Guidelines Ch 11 paras 11.6, 11.9; [2025] FCA 1224 at paragraph 52(b)

Are rental apps like 2Apply privacy compliant?

Using RentTech does not transfer the agency's duties. Where the agency is an APP entity, APP 3.2 still limits what is collected through the platform, APP 11.1 covers how it is secured, APP 11.2 destroying or de-identifying it once it is no longer needed, and APP 5.1 a collection notice at or before collection, or as soon as practicable after. In Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 (1 April 2026) the operator of the 2Apply platform, not any agency, was found to have collected applicant information that was not reasonably necessary; at [94] the Commissioner listed ten categories it could have done without, including gender, details of dependants, bankruptcy and retirement status, previous living history and visa expiry. The OAIC's APP Guidelines note that this position is not settled, because the determination is under review in the Administrative Review Tribunal. From 10 December 2026, APP 1.7 to 1.9 require an APP entity's privacy policy to set out the kinds of personal information used in a computer program that makes, or does something substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests, and which decisions it makes alone or only assists. Related: over-collection. Source: Privacy Act 1988 (Cth) Sch 1, APP 3.2, APP 5.1, APP 11.1, APP 11.2; Commissioner Initiated Investigation into IRE Pty Ltd (Privacy) [2026] AICmr 24 at [94]; OAIC APP Guidelines Ch 3 (review status); APP 1.7 to 1.9, inserted by the Privacy and Other Legislation Amendment Act 2024 (Cth) items 87 to 89, commencing 10 December 2026

What is the OAIC 2026 privacy sweep?

From the first week of January 2026 the OAIC swept the privacy policies of approximately 60 entities across six sectors that may collect personal information in person. Rental and property is one, and the Privacy Commissioner's announcement named real estate agents. It assessed those policies against APP 1.4; in May 2026 the Australian Information Commissioner said it had found instances of non-compliance in a significant proportion of the 60. A policy that does not meet APP 1.3 or APP 1.4 is a contravention named in s 13K: the OAIC can give a compliance notice (s 80UC) or an infringement notice (s 80UB), and a court can order up to 200 penalty units (s 13K(4)). Source: OAIC media release, "Privacy compliance sweep to put privacy policies under the spotlight", 9 December 2025; Australian Information Commissioner, IAPP Sydney KnowledgeNet keynote, 20 May 2026; Privacy Act 1988 (Cth) ss 13K, 40(2), 80UB, 80UC


Quick reference: the rest of the jargon

APP entity

An agency or organisation bound by the Australian Privacy Principles (for a private real-estate business, the limb is "organisation"). Under s 6C(1) an organisation does not include a small business operator (s 6D(1)), so the small business exemption is the starting point and holds the s 6D(4) triggers that displace it. Turnover of more than $3,000,000 for a financial year ending after the relevant date makes a business an APP entity under s 6D(4)(a), and that does not reverse if turnover later falls. A small business operator can also opt in under s 6EA. Separately, s 6E(1A) reaches a small business operator's AML/CTF activities, not the whole business. Which side of those lines a particular agency sits on is a question for its own adviser. Source: Privacy Act 1988 (Cth) Compilation No. 104 (4 June 2026) ss 6(1), 6C(1), 6D(1), 6D(4)(a), 6E(1A), 6EA, 15; OAIC APP Guidelines Ch B

Australian Privacy Principles (APPs)

The 13 principles in Schedule 1 of the Privacy Act 1988, covering the whole information lifecycle: transparency (APP 1, 5), collection limits (APP 3), use and disclosure (APP 6, 7), cross-border (APP 8), security and destruction (APP 11), and access and correction (APP 12, 13). They're the checklist your compliance is measured against. Source: Privacy Act 1988 Schedule 1; OAIC APP quick reference

OAIC

The Office of the Australian Information Commissioner: the federal privacy regulator that handles complaints, investigates breaches, runs compliance sweeps and can seek penalties. Its 2024-25 Annual Report identifies health, finance and Australian Government agencies as the most-complained-about sectors; real estate isn't among the top-complaint sectors, but the OAIC's 2026 sweep put the industry under specific scrutiny. Source: OAIC Annual Report 2024-25; Australian Information Commissioner Act 2010

Privacy policy (APP 1)

Your standing, published document (usually on your website, free of charge) describing how you manage personal information across appraisals, rentals, sales and marketing. Different from the collection notice, which is given at the point of collection. Source: Privacy Act 1988 (Cth) Sch 1, APP 1.3-1.5; OAIC APP Guidelines Ch 1

Customer due diligence (CDD)

The AML/CTF Tranche 2 obligation on a reporting entity to establish, on reasonable grounds, the identity of its customer (and of anyone acting on the customer's behalf, or on whose behalf the service is received) and the nature and purpose of the transaction, before it commences a designated service; s 29 allows initial CDD to be delayed in limited circumstances. It covers beneficial owners where the customer is not an individual, and screening those people for politically exposed person status or targeted financial sanctions, which is standard initial CDD rather than a higher-risk extra. Source of wealth and source of funds are established under enhanced customer due diligence, where relevant to that customer's ML/TF risk. Real-estate designated services are sales-side, and where the agency would otherwise be a small business operator, s 6E(1A) of the Privacy Act reaches its AML/CTF activities rather than the rest of the business. Source: AML/CTF Act 2006 (Cth) ss 28, 29, 32; AML/CTF Rules 2025 ss 6-21, 6-32(4); Privacy Act 1988 (Cth) s 6E(1A); AUSTRAC customer due diligence guidance

De-identification

Information is de-identified when it is no longer about an identifiable individual, or one who is reasonably identifiable. APP 11.2 accepts de-identification as an alternative to destruction: once the information is no longer needed, and no Australian law or court or tribunal order requires it to be kept, the duty is reasonable steps to destroy it or ensure it is de-identified. Removing a name alone does not settle it: the test is whether the person is still reasonably identifiable from what remains, such as the address, application details or references. Source: Privacy Act 1988 (Cth) s 6(1) and Sch 1, APP 11.2, Compilation No. 104 (4 June 2026)


Not sure which of these apply to you? The free Privacy Readiness audit maps your forms, CRM and retention against the APPs in a few minutes. For the bigger picture, start with Privacy Act compliance for real-estate agencies.