Privacy Act 2026 — by industry
Privacy Policy for Real Estate Agencies: The 2026 Australian Compliance Guide
What an Australian real estate agency's privacy policy needs in 2026 under the Privacy Act 1988 — including AML Tranche 2's KYC collection from 1 July 2026 and the 10 December 2026 automated decision-making disclosure. Plain English, source-checked.
Real estate agencies handle a lot of personal information — buyers, sellers, tenants, landlords, and now, from 1 July 2026, AML/KYC identity and beneficial-ownership details. In 2026 that puts a compliant privacy policy squarely on your to-do list. Here is what an agency's policy needs.
Why this lands on agencies specifically
Two things converge in 2026. First, AML/CTF Tranche 2 makes real estate professionals reporting entities from 1 July 2026 — and the moment you collect KYC, the Privacy Act applies to that information regardless of turnover. See AML Tranche 2 and the Privacy Act. Second, the OAIC's early-2026 compliance sweep explicitly reviewed real estate agents among the sectors collecting personal information in person. (Sources: AUSTRAC; OAIC sweep.)
What your policy must cover (APP 1)
- What you collect: identity documents, contact details, financial details, KYC
and beneficial-ownership information, tenancy application data.
- Why: sales/leasing, legal obligations, and AML/CTF customer due diligence.
- Who you disclose to: landlords, agents, tenancy databases, AUSTRAC where
required, and any overseas recipients.
- Access, correction and complaints, with the path to the OAIC.
- Security and retention — only keep what you need; the OAIC has flagged excessive
retention as a priority.
The general step-by-step is in how to write a privacy policy that complies in 2026.
The KYC collection notice
Because you collect identity and beneficial-ownership data for AML, you need an APP 5 collection notice at that point — one that works as both a privacy and an AML document. Build it into your onboarding.
Tenant screening = automated decision-making?
If you use software to score or filter tenancy applications in a way that significantly affects applicants, the 10 December 2026 ADM disclosure obligation likely applies — your privacy policy must disclose the kinds of information used and decisions made. See the ADM guide.
Don't forget the breach clock
Agencies hold sensitive identity data — a prime breach target. The Notifiable Data Breaches scheme requires you to assess a suspected eligible breach within 30 days. See the data-breach response plan.
Run the free checker, then use the free checklist's self-audit to pressure-test your policy.
General information only, not legal or compliance advice. Current to June 2026; confirm your obligations at oaic.gov.au and austrac.gov.au or with a qualified adviser. Last verified: 8 June 2026.
Run the free ML/TF risk assessment →