Skip to content

Privacy & data terms explained: for Australian real-estate agents

A plain-English glossary for agents, principals and property managers, not lawyers.

This page explains the privacy, data and AML terms that keep turning up in the OAIC's 2026 real-estate focus, the Tranche 2 AML reforms, and the rental-application rulings. It's written for time-poor agents who need to know what a word actually means for their forms, their CRM and their front desk, not a legal treatise.

This is general information, not legal advice. Rules change and every agency's situation differs. Sentences flagged with ** state a specific legal obligation, dollar figure or deadline. Confirm these with a qualified lawyer before you rely on them. If you'd rather just find out where you stand, start with our free Privacy Readiness audit.

See also: Does the Privacy Act apply to real-estate agents? · Privacy Act compliance for real-estate agencies


Layer 1: Core terms

The terms that came up in almost every analysis. If you only learn six, learn these.

Sensitive information

A special, higher-protection category of personal information, including health and genetic information, racial or ethnic origin, political opinions or membership of a political association, religious or philosophical beliefs, membership of a professional or trade association or trade union, sexual orientation or practices, criminal record and biometric data. (Disability isn't a separate statutory category: it's protected to the extent it is health information; and the Act protects "political opinions" and "sexual orientation or practices" as distinct categories, not a single "political or sexual orientation".) ** Under the Privacy Act you generally can't collect sensitive information without the person's consent, and only where it's reasonably necessary. Agents most often collect it by accident: through visa status, support-pet medical letters, hardship documents, or an open-ended "any other information" box on a rental application. Related: reasonably necessary, government-related identifier. Source: Privacy Act 1988 s 6(1); APP 3.3; OAIC APP Guidelines Ch B & Ch 3

Small business exemption

Why many agencies assumed the Privacy Act didn't apply to them: businesses with annual turnover of $3 million or less can be exempt. But real estate is a notable exception: an agency can still lose the exemption, for example if it discloses personal information about someone for a benefit without their consent, or holds a Commonwealth contract. (Operating a residential tenancy database is also covered regardless of turnover, but that binds the database operators, such as TICA or NTD, not the agencies that merely use or contribute to one. A database only counts if it can be accessed by someone other than its operator, so an internal list about your own managed tenancies is not one at all.) From 1 July 2026, agencies providing AML/CTF designated services are covered (for the personal information handled in connection with those services) regardless of turnover. The Government has also agreed in principle to repeal the small-business exemption in a future reform, but that repeal is not yet legislated and has no confirmed date. Treat it as a policy commitment, not a scheduled change. Don't assume you're exempt. See Does the Privacy Act apply to real-estate agents? or run the audit. Related: APP entity, AML/CTF Tranche 2. Source: Privacy Act 1988 ss 6D, 6E, 7B; AML/CTF Amendment Act 2024; OAIC small business guidance

Collection notice

A short "at or before collection" statement, required under Australian Privacy Principle (APP) 5, telling a person what you're collecting, why, who you might share it with, and how to access their data or complain. ** It is a legal requirement separate from your privacy policy, and it's what belongs on rental application forms, appraisal request forms and open-home sign-in sheets. Agents constantly confuse the notice (given at the point of collection) with the policy (the standing document on your website). More: Do agents need a collection notice? Source: APP 5; OAIC APP Guidelines Ch 5

Permission that is genuinely valid. Consent under the Privacy Act must be voluntary, informed, current, specific and given by someone with capacity. A pre-ticked box or a buried "tick to agree to everything" clause generally won't count. You need it to collect sensitive information, to use data for a secondary purpose the person wouldn't reasonably expect (like direct marketing), and often before disclosing data to third parties beyond what your collection notice covered. Related: primary vs secondary purpose (APP 6). Source: Privacy Act 1988 s 6(1); OAIC APP Guidelines Ch B

AML/CTF Tranche 2

The reform that pulls real-estate agents, developers and conveyancers into Australia's anti-money-laundering net. ** Key dates: AUSTRAC enrolment opens 31 March 2026, obligations commence 1 July 2026, and enrolment closes 29 July 2026 (the 28-day deadline for businesses providing designated services from day one), bringing customer due diligence, identity verification, reporting and 7-year record-keeping. More ID data means more Privacy Act exposure, so collection, storage and destruction all matter more. Full detail: AML/CTF Tranche 2 for real-estate agents. Related: customer due diligence, 100 points of ID. Source: AML/CTF Act 2006 (as amended by AML/CTF Amendment Act 2024); AUSTRAC Tranche 2 guidance

Data breach response plan

A documented, ready-to-go procedure for containing, assessing and reporting a breach within the required timeframes: who does what, who to call, and how to notify the OAIC and affected people. ** The OAIC treats having and following one as part of the reasonable security steps required under APP 11. Improvising the assessment after a leak is how agencies blow the deadline and worsen the harm. Related: notifiable data breach, serious harm. Source: APP 11.1; Privacy Act 1988 Part IIIC (NDB scheme); OAIC Data breach preparation and response guide


Layer 2: How it's actually asked

The same questions, in the words agents and tenants actually type.

Does a real estate agency need a privacy policy?

** If your agency is covered by the Privacy Act (see small business exemption), APP 1 requires a clearly worded, up-to-date privacy policy that's freely available, usually on your website, covering appraisals, rentals, sales and marketing. It's the first document the OAIC's 2026 sweep checks, and it's different from the shorter collection notice on your forms. Sort both at once: do agents need a privacy policy and collection notice? Source: APP 1.3–1.5; OAIC APP Guidelines Ch 1

Do agents need a collection notice on rental application forms?

** Yes: if you're a covered entity, APP 5 requires you to tell people, at or before collection (or as soon as practicable after), who's collecting their information, why, who it may be shared with, and how to access or complain. In practice that's a short APP 5 statement on the rental application, appraisal form and open-home sign-in. Search results often return US forms instead of APP 5 guidance. Don't copy those. See collection notice. Source: APP 5; OAIC APP Guidelines Ch 5

Is my agency exempt from the Privacy Act under $3 million turnover?

Probably not as safely as you'd hope. ** From 1 July 2026, AML-covered agencies are in, for the personal information handled in connection with their AML designated services, regardless of turnover. The $3 million turnover test also counts your whole corporate group, so many agencies are over it. And even under $3 million, the small business exemption is lost if you disclose personal information about someone for a benefit without their consent, or hold a Commonwealth contract. Treat yourself as an APP entity unless a lawyer confirms otherwise. Full answer: Does the Privacy Act apply to real-estate agents? Source: Privacy Act 1988 s 6D; AML/CTF Amendment Act 2024; OAIC guidance on AML/CTF reforms

What counts as sensitive information on a rental application?

Health, race or ethnicity, religion, sexual orientation, criminal record and biometrics, plus things that reveal them, like visa status (which can reveal racial/ethnic origin) or a support-pet medical letter. Disability isn't a separate category but is captured as health information. ** You generally can't collect sensitive information without consent and a genuine need, so open-ended fields that invite it are a common breach. An agent usually has no reasonable need for health or religion details. Source: Privacy Act 1988 s 6(1); APP 3.3; OAIC APP Guidelines Ch B & Ch 3

Can a rental agent ask about my health, disability or religion?

** Generally no: these are sensitive information (disability counts as health information), which the Privacy Act says can only be collected with your consent and where reasonably necessary, and an agent almost never has a genuine need for them to assess a tenancy. You can question or refuse such requests. (These are also discrimination-adjacent, which is a separate area of law.) Source: APP 3.3; Privacy Act 1988 s 6(1); OAIC APP Guidelines Ch 3

The 100 points of ID question

There's no general legal rule forcing a tenant to hand over 100 points of ID to rent. The 100-point framework comes from anti-money-laundering identity checks (originating in the Financial Transaction Reports Act 1988), not tenancy law. Demanding full ID from every applicant can amount to over-collection under APP 3, and some states cap how many identity documents can be required: in Victoria, from 31 March 2026 a rental provider/agent must use the prescribed standard application form and can require no more than two identity documents. Verify what you need, and don't retain more than necessary. Related: AML/CTF Tranche 2, driver's licence & Medicare. Source: Financial Transaction Reports Act 1988; APP 3.2; Residential Tenancies Act 1997 (Vic) prescribed form (31 Mar 2026)

Can an agent ask for my driver's licence or Medicare number?

** An agent may sight a government-related identifier (licence, Medicare, passport, Centrelink CRN) where reasonably necessary to verify identity, but generally must not adopt it as its own customer reference, and should not store licence scans indefinitely. Hoarding licence images for rejected applicants is a classic over-retention breach under APP 11. Related: sensitive information. Source: APP 9.2; APP 3; APP 11; OAIC APP Guidelines Ch 9

Tenant application data: what agents collect

A rental application typically gathers identity documents, income and employment evidence, rental history, references and sometimes bank statements: a rich pool of personal and occasionally sensitive information. ** Under APP 3 you may only collect what's reasonably necessary to assess the tenancy; demanding full bank statements, excess ID or social-media logins risks breaching the over-collection rule that's central to the OAIC's scrutiny. This dataset is the single biggest privacy risk for property managers. Source: APP 3.2; OAIC APP Guidelines Ch 3

Over-collection (APP 3)

Gathering more personal information than is reasonably necessary for your function. ** Under APP 3 that's a breach, and in rentals the flagged examples are routine bank statements, 100-point ID from every applicant, medical or relationship details, or social-media access when less intrusive proof would do. "Reasonably necessary" is an objective test. This is the buzzword behind much of the sweep coverage. Related: tenant application data, data retention. Source: APP 3.2 (and APP 3.3 for sensitive information); OAIC APP Guidelines Ch 3

How long can an agent keep an unsuccessful applicant's data?

There's no single number in the Privacy Act. APP 11.2 requires you to destroy or de-identify personal information once it's no longer needed for any purpose for which it may be used or disclosed under the APPs (unless a law or court order requires you to keep it), so unsuccessful applicants' ID scans, payslips and references should be securely deleted soon after the property is let, not kept "just in case." Other laws (tax, tenancy, AML) may set minimum retention for specific records, so the practical rule is: keep only what a law requires, then destroy. Secure destruction means putting data beyond use: shredding paper and permanently deleting electronic copies including backups and email attachments, not just moving files to an archive folder. Source: APP 11.2; OAIC APP Guidelines Ch 11

Do agents have to do AML checks from 2026?

** Yes: under AML/CTF Tranche 2, real-estate agents providing designated services must enrol with AUSTRAC and perform customer due diligence (identity verification and, for higher-risk deals, source-of-funds and PEP/sanctions screening) once obligations commence 1 July 2026 (enrolment opened 31 March 2026). The verification data you collect is itself personal information the Privacy Act governs, so balance it against data minimisation. Full detail: AML/CTF Tranche 2 for real-estate agents. Source: AML/CTF Act 2006 (as amended 2024); AUSTRAC enrolment/CDD guidance

Do I have to give my name and number at an open home?

A visitor generally isn't legally compelled to complete a sign-in sheet, and under APP 3 an agent can only collect details that are reasonably necessary. If contact details are collected, you must give a collection notice and not silently reuse them for marketing, a practice the OAIC's 2026 sweep flagged. Where practicable and lawful, people may be able to deal with an agent anonymously or by pseudonym (APP 2). Source: APP 2; APP 3.2; APP 5; OAIC APP Guidelines Ch 2, 3 & 5

Can I email past appraisal contacts about new listings?

Carefully. APP 7 restricts using personal information for direct marketing: you generally need to have collected it for that purpose or have consent, and every message must carry a simple opt-out you honour. Sweeping appraisal enquiries or open-home attendees into a newsletter list without a lawful basis or unsubscribe risks breaching APP 7, and the Spam Act applies on top for email and SMS. Related: primary vs secondary purpose. Source: APP 7; Spam Act 2003; OAIC APP Guidelines Ch 7 (entry not independently verified in this fact-check pass)

Can I reuse tenant data for a different purpose?

** APP 6 lets you use or disclose personal information only for the primary purpose you collected it for (e.g. assessing a rental application) unless a secondary use is one the person would reasonably expect and is related to that primary purpose (directly related for sensitive information), or the person consents. Repurposing a tenant database to market other properties, or sharing it with a third party, generally needs consent or a stated exception. Related: direct marketing. Source: APP 6 (6.1, 6.2(a)); OAIC APP Guidelines Ch 6

How do tenant blacklists like TICA work?

Tenancy databases (TICA, NTD, Barclay MIS) record renters listed for issues like arrears or breaches. These are governed mainly by State/Territory residential-tenancy laws (not the APPs). You generally must give written notice before listing (commonly 14 days to object), list only accurate, complete, current and permitted information, and allow access and correction; wrongful or stale listings are a common complaint source. A tenant can ask whether they're listed and request a copy, usually free once in any 12-month period (further requests attract a fee), with the operator required to respond within set timeframes. The general privacy right of access & correction (APP 12/13) is a related pointer, but the specific tenancy-database rights sit in state RTA law. Related: sensitive information. Source: State/Territory Residential Tenancies Acts (tenancy-database provisions)

Can a tenant see the data I hold on them?

Yes: APP 12 gives individuals a right to access the personal information you hold about them, and APP 13 requires you to correct it if it's inaccurate, out of date or misleading. A private real-estate business (an "organisation") must respond within a reasonable period, which OAIC guidance benchmarks at no more than 30 days, so "within a reasonable time, commonly around 30 days" is the right expectation. Related: personal information. Source: APP 12 & 13; OAIC APP Guidelines Ch 12 & 13

What actually counts as personal information?

Any information or opinion about an identified individual, or someone reasonably identifiable (names, contact details, tenancy history, payslips, references, photos, signatures and increasingly things like IP addresses), whether true or not, and whether recorded or not. ** If your agency holds it, the APPs govern how you collect, store, use and dispose of it. Almost everything in an agent's CRM qualifies. The higher-protection subset is sensitive information. Source: Privacy Act 1988 s 6(1); OAIC 'What is personal information?' guidance

What happens if my agency has a data breach?

If tenant or client personal information is lost or accessed without authorisation, you must assess whether it's an "eligible data breach" likely to cause serious harm, and if so notify the OAIC and affected individuals as soon as practicable under the Notifiable Data Breaches (NDB) scheme. Serious harm can be physical, psychological, financial or reputational. Leaked tenant IDs, bank details, or a vulnerable person's address are exactly the data that pushes a breach over the line. You may also face reputational damage, OAIC investigation and civil penalties if your security was inadequate. Have a data breach response plan ready before it happens. Source: Privacy Act 1988 Part IIIC (NDB); APP 11; OAIC NDB scheme guidance

How long do I have to report a data breach?

** Once you have grounds to suspect an eligible data breach, the Privacy Act requires a reasonable and expeditious assessment within 30 calendar days, then notification to the OAIC and affected people as soon as practicable if serious harm is likely. It's commonly misquoted as "30 days to report". It's actually 30 days maximum to assess, and regulators expect faster action where harm is clear (often notification within a day or two of forming the belief). The clock starts when the suspected breach comes to your attention. Related: data breach response plan. Source: Privacy Act 1988 ss 26WH & 26WL; OAIC Data breach preparation and response Part 4

Can I be personally fined for a privacy breach at my agency?

Usually penalties fall on the entity (the company), but directors, principals and sole traders can be personally exposed: a sole trader is the responsible APP entity, and accessorial liability can reach individuals who aid or abet a contravention. Civil penalties for serious or repeated interference with privacy (s 13G) are very large (for a body corporate, up to the greater of $50m, three times the benefit, or 30% of adjusted turnover), so personal exposure is a real risk worth checking. More: penalties for a privacy breach. Source: Privacy Act 1988 s 13G; s 6 (APP entity)

Can a tenant sue a real estate agent for invasion of privacy?

** Yes: Australia's statutory tort for serious invasions of privacy (Schedule 2 to the Privacy Act, inserted by the Privacy and Other Legislation Amendment Act 2024) commenced on 10 June 2025 and is now in force. It gives individuals a potential direct court claim for serious, intentional or reckless invasions (such as intrusion on seclusion or misuse of information), separate from the OAIC complaints process. For agents, mishandling personal information could, in serious cases, expose the business to a direct claim. Confirm the precise scope and any defences with a lawyer. Related: penalties. Source: Privacy Act 1988 Schedule 2 (statutory tort), commenced 10 June 2025

What happens if my CRM stores tenant data overseas?

** APP 8 makes you take reasonable steps to ensure an overseas recipient handles personal information consistently with the APPs before you disclose it offshore, and under s 16C you can remain accountable for their breach. Many real-estate CRMs, e-sign tools and application platforms host data in the US or overseas, so you should know where your provider stores tenant data and name the relevant countries in your privacy policy. Related: accountability for third-party processors. Source: APP 8.1; Privacy Act 1988 s 16C; APP 1.4(f); OAIC APP Guidelines Ch 8

Am I liable if my property management software gets hacked?

** You can't fully outsource responsibility: as the APP entity that collected the data, you must take steps reasonable in the circumstances to protect it, including vetting your providers' security and keeping a breach response plan. A vendor hack can still trigger your own notification duties and potential penalties if your arrangements were inadequate. Vendor due diligence manages the risk; it doesn't transfer it. Related: cross-border disclosure (APP 8). Source: APP 11.1; OAIC APP Guidelines Ch 11

Are rental apps like 2Apply and Ignite privacy compliant?

Using RentTech doesn't transfer your privacy responsibility. The agency remains accountable under APP 11 for what's collected through the platform, where it's stored and how long it's kept, and must still give applicants a compliant collection notice. Regulators have signalled that excessive collection and retention through these tools carries real privacy risk (any suggestion of a specific OAIC determination against a rental-application platform is not confirmed in this pass; verify or remove before publication). ** From 10 December 2026, privacy policies must also disclose the kinds of personal information used in, and decisions made by, a computer program that substantially helps make decisions that could significantly affect someone's rights or interests, relevant if a platform auto-scores or auto-rejects applicants. Related: over-collection. Source: APP 11; automated-decision-making transparency requirement (POLA Act 2024, commences 10 Dec 2026)

What is the OAIC 2026 privacy sweep?

In early 2026 the OAIC ran its first-ever compliance sweep, reviewing the privacy policies of around 60 organisations across six higher-risk sectors including rental and property, and singling out practices like agents demanding phone numbers at open homes. Non-compliant policies can attract compliance or infringement notices, issued by the OAIC directly for a fraction of what a court could impose, with higher court penalties reserved for serious cases. Expect scrutiny of your collection notices, privacy policy, retention and breach readiness. The OAIC, the Office of the Australian Information Commissioner, is the federal privacy regulator that runs these sweeps, handles complaints, and can investigate on its own initiative. Source: OAIC media release (privacy compliance sweep); APP 1 civil penalty provisions (POLA Act 2024)


Quick reference: the rest of the jargon

APP entity

An agency or organisation bound by the Australian Privacy Principles (for a private real-estate business, the relevant limb is "organisation"). ** Most real-estate businesses are caught (either turnover exceeds the small business threshold, or they trade in personal information / provide a screening service), so the safe assumption is that your agency is one. Source: Privacy Act 1988 s 6(1); OAIC APP Guidelines Ch B

Australian Privacy Principles (APPs)

The 13 principles in Schedule 1 of the Privacy Act 1988, covering the whole information lifecycle: transparency (APP 1, 5), collection limits (APP 3), use and disclosure (APP 6, 7), cross-border (APP 8), security and destruction (APP 11), and access and correction (APP 12, 13). They're the checklist your compliance is measured against. Source: Privacy Act 1988 Schedule 1; OAIC APP quick reference

OAIC

The Office of the Australian Information Commissioner: the federal privacy regulator that handles complaints, investigates breaches, runs compliance sweeps and can seek penalties. Its 2024-25 Annual Report identifies health, finance and Australian Government agencies as the most-complained-about sectors; real estate isn't among the top-complaint sectors, but the OAIC's 2026 sweep put the industry under specific scrutiny. Source: OAIC Annual Report 2024-25; Australian Information Commissioner Act 2010

Privacy policy (APP 1)

Your standing, published document (usually on your website, free of charge) describing how you manage personal information across appraisals, rentals, sales and marketing. Different from the collection notice, which is given at the point of collection. Source: APP 1.3–1.5; OAIC APP Guidelines Ch 1

Customer due diligence (CDD)

** The AML/CTF Tranche 2 obligation to identify and verify who your customer really is before providing a designated service: ID checks, beneficial ownership, and for higher-risk deals source of funds plus sanctions/PEP screening. The verification data is itself personal information the Privacy Act governs. Source: AML/CTF Act 2006 Part 2; AUSTRAC customer due diligence guidance

De-identification

Altering personal information so an individual is no longer identified or reasonably identifiable: an alternative to destruction under APP 11.2. ** Deleting a name is rarely enough if the remaining data (address, application details, references) can still re-identify the person. Source: Privacy Act 1988 s 6(1); APP 11.2; OAIC de-identification guidance


Not sure which of these apply to you? The free Privacy Readiness audit maps your forms, CRM and retention against the APPs in a few minutes. For the bigger picture, start with Privacy Act compliance for real-estate agencies.

*Draft: pending legal review. Every ** claim must be confirmed before publication.*