Privacy Act guide · general information, not legal advice

Privacy policy for real estate agencies (2026)

An agency that brokers property sales is an AML/CTF reporting entity, so the Privacy Act applies to the information it collects for AML/CTF purposes, whatever its turnover. This guide sets out what your privacy policy must contain, where customer due diligence on vendors and buyers fits, and what changes on 10 December 2026.

Last checked 25 September 2026 against the Privacy Act 1988 compilation C2026C00227, the Privacy and Other Legislation Amendment Act 2024 (C2024A00128), the AML/CTF Act 2006 compilation C2026C00274 and the OAIC guidance for reporting entities updated 28 August 2026

APP 1.4 the law, read in the authorised textOAIC guidance the regulator's published guidance, which is not law

Does the Privacy Act apply to your agency?

A business with annual turnover of $3,000,000 or less is generally a small business operator and outside the Privacy Act, unless one of the cases in s 6D(4) applies.1 s 6D(1) s 6D(4) An agency above that threshold is generally covered for all its handling of personal information, including rentals and open homes.

A small agency that provides a Table 5 designated service is covered for that part of its work. If a small business operator is a reporting entity under the AML/CTF Act, the Privacy Act applies to its activities for the purposes of, or in connection with, the AML/CTF Act, Regulations or Rules as if it were an organisation.2 s 6E(1A) AML/CTF obligations applied from 1 July 2026 to the real estate services in AML/CTF Act s 6 Table 5: brokering the sale, purchase or transfer of real estate for a buyer, seller, transferee or transferor (item 1), and selling real estate in a business where no independent agent brokers the sale (item 2).3 AML/CTF Act s 6

If the Privacy Act applies to you only because of s 6E(1A), the OAIC says your policy need only describe your AML/CTF handling.4 OAIC The rest of your work, such as rentals, is covered only if your agency is covered for another reason.

What the policy must contain

APP 1.3 requires a clearly expressed and up-to-date privacy policy about how you manage personal information, and APP 1.4 lists what it must contain. APP 1.5 requires you to make it available free of charge and in an appropriate form, usually on your website.5 APP 1.3 APP 1.4

APP 1.4 contents, with the AML/CTF handling an agency describes
APP 1.4 requires What to write about AML/CTF handling
(a) The kinds of personal information you collect and hold Know-your-customer details for vendors and buyers: names, dates of birth, addresses, identity document details and verification results; details of beneficial owners and people acting for a vendor or buyer; politically exposed person and sanctions screening results
(b) How you collect and hold it From the vendor, from the buyer, from people acting for them, and from any verification or screening service you use; where the records are kept
(c) The purposes Customer due diligence, ongoing monitoring, reporting to AUSTRAC and record-keeping under the AML/CTF Act and Rules
(d) Access and correction How to ask, and who to ask
(e) Complaints How to complain about a breach of the APPs, and how you will deal with the complaint
(f) and (g) Overseas disclosure Whether a provider, such as a cloud system or verification service, is likely to receive the information overseas, and the countries, if it is practicable to name them

Sources for the table: Privacy Act Schedule 1, APP 1.4,5 and the OAIC's guidance for reporting entities.4 OAIC

Before any overseas disclosure, APP 8.1 requires reasonable steps to ensure the recipient does not breach the APPs.5 APP 8.1

Where customer due diligence data fits

Before providing a designated service, you must establish on reasonable grounds the customer's identity; the identity of anyone on whose behalf the customer receives the service, and of anyone acting for the customer; for a customer that is not an individual, its beneficial owners; whether any of them is a politically exposed person or designated for targeted financial sanctions; and the nature and purpose of the business relationship or occasional transaction.3 AML/CTF Act s 28 For a brokered sale, the customer is both the seller and the buyer (Table 5 item 1).3

So a selling agent collects know-your-customer information from a buyer who is not its client. Tell the buyer, at or before collection, who you are and why you need it (APP 5).5 APP 5.1

Three further points from the OAIC's guidance:4 OAIC

  • Only the vendor and the successful buyer. In the OAIC's auction example, the agent does customer due diligence on the vendor and the successful buyer, not on everyone who inspects or bids. Collecting it from every prospect is unlikely to meet the reasonably necessary test in APP 3.2.
  • Sensitive information. Screening for politically exposed persons can collect sensitive information, such as whether a person belongs to a political association. APP 3.4(a) allows that without consent where the AML/CTF Act or Rules require or authorise it.
  • No ID copies needed. The AML/CTF Act does not require scanned copies or photocopies of identity documents. Keep the details and the verification outcome, and destroy or de-identify copies once no longer needed. APP 11.2

Customer due diligence records are kept for 7 years from the end of the business relationship or the completion of the occasional transaction.3 AML/CTF Act s 111

The collection notice

The policy is general. APP 5.1 separately requires reasonable steps, at or before collection, to notify the APP 5.2 matters, including who you are, the purposes, the main consequences of not providing the information, your usual disclosures and any overseas recipients.5 APP 5.1 Where the law requires the collection, one of those matters is that fact and the name of the law (APP 5.2(c)): here, the AML/CTF Act or Rules.

The OAIC says you need not give notice content that would tip off a customer.4 OAIC Disclosing that a suspicious matter report has been or must be made, where that could prejudice an investigation, is an offence.3 AML/CTF Act s 123

The OAIC is looking at property

The OAIC's first privacy compliance sweep, announced on 9 December 2025 for early 2026, set out to review the privacy policies of about 60 businesses in 6 sectors against APP 1.4. One sector was rental and property: "collection of individuals' personal information during property inspections".8 OAIC The OAIC's regulatory action priorities for 2025–26 name the rental and property sector and "excessive collection and retention of personal information".9 OAIC If your agency is covered for all its work, your policy must describe what you collect at inspections too.

From 10 December 2026: automated decisions

APP 1.7 to 1.9 commence on 10 December 2026, the day after the 24-month period that began with Royal Assent on 10 December 2024.6 POLA Act s 2 If a computer program makes, or does a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect a person's rights or interests, using personal information about them, the policy must describe the kinds of personal information used and the kinds of decisions.6 POLA Act Sch 1 item 88 Check verification and screening tools used for vendors and buyers and, if your rental work is covered, tenant-screening tools. See automated decision-making disclosure.

Breaches and penalties

If you are aware of reasonable grounds to suspect an eligible data breach, you must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days of becoming aware.7 s 26WH(2) See the data breach response plan.

A missing policy, or one without the APP 1.4 contents, is a matter under s 13K: a civil penalty of up to 200 penalty units ($72,800) for a person other than a body corporate and 1,000 penalty units ($364,000) for a body corporate, at $364 a unit for conduct on or after 1 July 2026, or an infringement notice.7 s 13K See Privacy Act penalties 2026.

Start here

Read AML tranche 2 and the Privacy Act for the full KYC picture. For your AML/CTF program, see AML/CTF for real estate. More in the Privacy Act section. Every source we use: sources.

AMLCompliant is published by Wani Meridian Pty Ltd, an independent private business. We are not affiliated with, or endorsed by, the Office of the Australian Information Commissioner, AUSTRAC, the Attorney-General's Department or any other government body. This guide is general information, not legal advice.

Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.

Sources

Law is quoted from the authorised text on the Federal Register of Legislation, opened 25 September 2026. OAIC pages are guidance, not law. They open in a new window, and linking to them does not mean the OAIC endorses this page.

  1. Privacy Act 1988 ss 6C(1), 6D(1) and 6D(4), compilation No. 104 (C2026C00227), compilation date 4 June 2026. legislation.gov.au/C2004A03712/latest/text

  2. Privacy Act 1988 s 6E(1A).

  3. Anti-Money Laundering and Counter-Terrorism Financing Act 2006, compilation C2026C00274: AML/CTF Act s 6 Table 5 (items 1 and 2), AML/CTF Act s 28(2), AML/CTF Act s 111(2) and AML/CTF Act s 123. Commencement: AML/CTF Amendment Act 2024 (C2024A00110), Schedule 3, item 11. legislation.gov.au/C2006A00169/latest/text

  4. OAIC, "Privacy guidance for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act", updated 28 August 2026, including its real estate auction example. Guidance, not law. oaic.gov.au

  5. Privacy Act 1988, Schedule 1 (Australian Privacy Principles), APP 1.3 to 1.5, 3.2, 3.4, 5.1, 5.2, 8.1 and 11.2.

  6. Privacy and Other Legislation Amendment Act 2024 (C2024A00128), s 2 table items 1 and 7; Schedule 1, Part 15, items 87 to 89. legislation.gov.au/C2024A00128/latest/text

  7. Privacy Act 1988 ss 13K, 26WH(2) and 80UB; Regulatory Powers Act s 82(5)(a); Crimes Act s 4AA and the Crimes (Amount of a Penalty Unit) Instrument 2026 (F2026N00424).

  8. OAIC, "Privacy compliance sweep to put privacy policies under the spotlight", media release, 9 December 2025. Guidance, not law. oaic.gov.au

  9. OAIC, "OAIC releases regulatory action priorities for 2025-26". Guidance, not law. oaic.gov.au

Questions

Do we need a separate AML collection notice?

In practice, yes. The privacy policy describes your handling in general; a collection notice is given at or before the time you collect (APP 5.1). The OAIC says reporting entities must have a privacy policy and collection notices that explain how they handle personal information for their AML/CTF obligations, and it publishes a free template collection notice for reporting entities. If you use our AML/CTF kit, the real estate agency edition includes a drafted collection notice for customer due diligence that refers to the OAIC's guidance.

What about tenant-screening software as a possible automated decision?

First check whether the Privacy Act covers your rental work at all. Section 6E(1A) covers only AML/CTF-related handling; rentals are covered if your agency is not a small business operator, for example because its turnover is above $3,000,000. If it is covered, then from 10 December 2026 a program that makes, or does a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect an applicant's rights or interests brings APP 1.7 and 1.8 into play. The Act's examples include decisions affecting rights under a contract and access to a significant service. Describe the kinds of information used and the kinds of decisions in the policy.

What must APP 1 contain?

APP 1.4 lists seven items: the kinds of personal information you collect and hold; how you collect and hold it; the purposes for which you collect, hold, use and disclose it; how a person can access it and seek its correction; how a person can complain about a breach of the APPs and how you will deal with the complaint; whether you are likely to disclose it to overseas recipients; and, if so, the countries where they are likely to be, if it is practicable to name them.

How long do we keep KYC records?

Customer due diligence records are kept for 7 years from the end of the business relationship or the completion of the occasional transaction (AML/CTF Act s 111). The OAIC's guidance says the AML/CTF Act does not require copies of identity documents: keep the details you need and the outcome of verification, and take reasonable steps to destroy or de-identify copies once no longer needed.