Savira -- Making Compliance Easy

Real Estate Privacy Risk Scorecard 2026

A 10-minute self-assessment for Australian real estate agencies.

The OAIC launched its first privacy compliance sweep targeting real estate agencies in January 2026. Since 1 July 2026, agencies providing designated services under the AML/CTF Act have also been reporting entities, which removes the small business exemption under the Privacy Act. Penalties for serious or repeated breaches reach $50 million, and a statutory tort for serious invasions of privacy is in force. This scorecard covers governance, open homes, applications, your website and marketing, and security.

0 of 30 answeredScore: 0/60

Governance and accountability

Questions 1 to 6 of 30

1A senior staff member is formally responsible for privacy compliance.
2Privacy risk is reported to owners, directors or partners at least annually.
3There is a documented privacy management plan.
4Staff receive privacy training at least once every 12 months.
5Privacy obligations are included in onboarding for new employees.
6There is a documented data breach response procedure aligned to the Notifiable Data Breaches scheme.

This assessment provides general information only and does not constitute legal advice.

Ready to connect?

Start collecting compliant consent through your website in minutes. No developers required.