Privacy compliance for Australian strata and owners-corporation managers: you hold a whole community's data, whether or not the Privacy Act binds you.
A strata management office concentrates the most sensitive information of an entire residential community in one place: the owners roll, tenants' and residents' details, levy arrears and debt-recovery files, by-law-breach and dispute records, committee correspondence, and CCTV footage. Whether the federal Privacy Act binds your business depends on your turnover and structure, and many smaller managers genuinely fall outside it. But state strata law and state surveillance law apply either way, and the data is just as sensitive regardless. This page is about handling that data responsibly, honestly, and without pretending you face a deadline you do not.
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
Are you even covered by the Privacy Act? The honest answer
We will not tell you that you are "caught" by a new law, because for strata that is often not true. There is no anti-money-laundering trigger for strata management and no 1 July 2026 deadline. Here is the honest position:
- The owners corporation itself is almost always a small business (turnover A$3 million or less) and usually falls within the small-business exemption (s 6D), so the Australian Privacy Principles largely do not bind it.
- Your managing-agent business is covered by the Privacy Act if either its turnover exceeds A$3 million or it is a related body corporate of a larger covered group. This is why many branded and national strata managers are already covered, even where an individual office assumes it is exempt.
- If you are a smaller independent manager under A$3 million and not part of a larger group, you may genuinely be exempt from the APPs across your business. We will say so rather than sell you coverage you do not have. Read: does the Privacy Act apply to strata managers?
But three things bind you regardless of turnover: your state strata legislation, your management agreement with the owners corporation, and your state surveillance-devices law. And a data breach harms residents whether or not a statute compelled you to prevent it. That is why this matters even if the Privacy Act does not reach you.
Why strata data is uniquely exposed
You hold, in one small office, a concentrated and unusually sensitive pool of a whole building's personal information: the owners and strata roll (names, lots, contact details), tenant and occupier details that often arrive without the person ever contacting you, levy arrears and debt-recovery files, by-law-breach and dispute records in a high-conflict context, committee and proxy records naming individuals, contractor details, and CCTV footage and access logs. Strata offices have already been hit by ransomware. A breach here exposes people who never chose to deal with you. Read: a data-breach response plan for strata managers
The two issues no generic template handles
1. The owners roll: state law makes you disclose it, and the Privacy Act may make you protect it. State strata law compels a manager to keep the roll and make it available for inspection, so privacy is not a lawful excuse to refuse a proper request. Yet a manager who is covered by the Privacy Act still owes APP 6 (use or disclose it only for authorised purposes) and APP 11 (keep it secure) over that same roll. Both are true at once, and getting the line right is the hardest question in strata privacy. Most templates handle one side and ignore the other. Read: can a strata manager give out an owner's details? · Read: who can access the strata roll?
2. CCTV and surveillance on common property. Cameras, video intercoms, boom-gate plate readers and audio recording on common property are governed by your state's surveillance-devices and listening-devices laws, which apply independently of the Privacy Act and bind you even if you are inside the small-business exemption. They govern where cameras may point (not into private lots), whether audio may be recorded at all (usually far more strictly than video), what signage is required, and who may view footage. Read: CCTV and surveillance privacy laws for strata
What a covered strata manager actually needs
1. A privacy policy written for a strata management business, not a generic website template. 2. Collection notices for the real collection points, including the handover of an existing scheme (where you inherit data about people who never dealt with you) and tenants collected via the owner. 3. A CCTV and surveillance policy with a resident notice and signage guidance, scoped to your state. 4. A strata-roll disclosure and access procedure that reconciles the statutory duty to disclose with the duty to protect. 5. A data-breach response plan and a retention and destruction schedule (including how long to keep an ex-owner's or former tenant's records).
Generic generators do not cover the roll, CCTV, state surveillance law, or the handling of people who never chose to deal with you. A real-estate or conveyancer kit is the wrong shape (no AML, no rentals, a different data pool).
What Privaproof is building for strata managers
A dedicated, strata-specific privacy document set, written for owners-corporation and body-corporate management, and kept current as the law changes.
- Written for strata: the roll, tenants and occupiers, arrears and debt recovery, CCTV, committee records.
- Scoped for New South Wales, Victoria and Queensland at launch, with clear prompts to confirm your own state's requirements. (We would rather cover three states properly than imply we maintain all eight.)
- Practical, plain-English documents you tailor to your business, with guidance built in.
- Kept current: while your subscription is active, we monitor the law and aim to provide updated versions as it changes. This is not a guarantee of compliance, and does not replace your own legal advice.
These are compliance tools and templates you tailor to your own business. They are general information, not legal advice, and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner.
Join the founding list
Be first to know when the Strata Kit opens, and get the plain-English updates as the rules move. No cost, no obligation.
✓ You’re on the founding list. We’ll email you as the changes land.
We never sell your data. See our Privacy Policy.
Keep reading
- Does the Privacy Act apply to strata managers?
- Owners corporations and the $3 million small-business exemption
- Strata manager vs owners corporation: who is actually covered?
- CCTV and surveillance on strata common property
- Strata CCTV rules by state: NSW, Victoria, Queensland
- Can a strata manager give out an owner's details?
- Who can access the strata roll, and what does it contain?
- Is the Privacy Act a shield against strata record access?
- Levy arrears, debt recovery and privacy in strata
- A data-breach response plan for strata managers
- How long must a strata manager keep owner records?
- What a strata manager's privacy policy actually needs
- Facial recognition, ANPR and smart surveillance in strata buildings
General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. Whether the Privacy Act 1988 (Cth) applies to your business depends on your turnover and structure; state strata legislation and state surveillance-devices law apply separately and vary by jurisdiction. Privaproof's strata documents are self-authored and are not independently reviewed by a solicitor. The law changes over time, so check you are working from a current version and confirm your own state's requirements.