This guide explains what has changed, why real estate is under regulatory scrutiny, and what your agency must do now to avoid enforcement action.
Privacy reform is now a real business risk
Penalties up to $50M
Serious or repeated privacy breaches can now attract penalties up to AU$50 million, 30 percent of adjusted turnover, or three times the benefit gained.
Regulatory spotlight
The OAIC has launched a compliance sweep targeting rental and property businesses, focusing on in-person data collection at open homes and inspections.
Over-collection risks
Collecting more information than reasonably necessary, especially identity documents at inspections, is a regulatory red flag.
Your privacy policy is a public document
It is the one part of your compliance anyone can check without asking, including a regulator. Most agency policies are years old and describe a business that no longer exists.
Individuals can sue
The statutory cause of action for serious invasions of privacy has been in force since 10 June 2025. Litigation and class action risk is real and present.
Consent has to be provable
Under APP 7 you need consent or a compliant opt-out for marketing. If asked to demonstrate it, most agencies cannot, because the consent was verbal, implied, or came across in a spreadsheet from a previous system.
Does the Privacy Act apply to your agency?
The Privacy Act 1988 (Cth) includes a small business exemption that generally excludes businesses with an annual turnover of $3 million or less. However, the exemption is narrower than many assume, and relying on it without proper consideration is risky.
The exemption does not apply if your agency is related to a body corporate that is not a small business, has opted in to the Privacy Act (sometimes done as part of a franchise arrangement), or shares tenancy information with third parties such as tenancy databases - which can constitute "trading in personal information" and removes the exemption entirely.
Beyond the legal question, the OAIC's compliance sweep has not limited its focus to businesses above the threshold. Agencies handling sensitive financial, employment and identity information as a matter of routine are squarely in the frame, regardless of size.
For many agencies the question is already settled. Since 1 July 2026, real estate agencies providing designated services under AML/CTF Tranche 2 have been reporting entities, required to enrol with AUSTRAC and meet anti-money laundering obligations. Once you are a reporting entity, the small business exemption under the Privacy Act no longer applies, even if your turnover is below $3 million. Many agencies that previously sat outside the Privacy Act are now inside it.
Paragraph text goes here.
What has changed under the privacy act?
Much stronger enforcement powers
The Privacy and Other Legislation Amendment Act 2024 significantly expanded the powers of the OAIC, including the ability to issue infringement notices for certain breaches, stronger investigation and information gathering powers, and public inquiries into systemic privacy practices.
Significantly higher penalties
Maximum penalties for serious or repeated interferences with privacy have been increased to the greater of AU$50 million, three times the value of the benefit obtained, or 30 percent of adjusted turnover during the breach period.
Individuals can now sue
The statutory cause of action for serious invasions of privacy commenced on 10 June 2025. Individuals can now take legal action where a privacy invasion was intentional or reckless, serious in nature, and where they had a reasonable expectation of privacy.
New Privacy Act coverage for real estate agencies
Since 1 July 2026, real estate agencies providing designated services under the AML/CTF Act have been reporting entities. All reporting entities are subject to the Privacy Act regardless of turnover. The OAIC has published guidance confirming that firms should not retain copies of full identification documents for record-keeping, and that privacy obligations operate alongside, not in place of, other regulatory requirements.
WHY IT MATTERS
Why are real estate agencies in the spotlight?
The OAIC has announced its first privacy compliance sweep targeting multiple sectors, explicitly including rental and property businesses and real estate agents, with a focus on in-person data collection practices.
The risk profile of real estate is obvious. Agencies routinely collect identity documents, financial records and payslips, employment information, rental histories, and sometimes health or hardship information.
Regulators have flagged particular concern about open home sign-in processes, collection of driver licence details or copies without clear necessity, lack of transparency about how information will be used, and over-collection relative to what is reasonably necessary.
This often happens face to face, in pressured environments, where individuals have limited time to understand what they are agreeing to.
WHY IT MATTERS
Real examples of regulatory action
Under the APPs, agencies must only collect personal information that is reasonably necessary, and must tell people why they are collecting it.
Open home sign-ins are the clearest pressure point. Where an agency collects driver licence details or copies without a clear lawful purpose, or provides no collection notice at the point of sign-in, both the over-collection and the lack of transparency can amount to an interference with privacy. The OAIC's compliance sweep has focused specifically on in-person collection practices at inspections, and the fact that a form was signed does not establish that consent was informed.
For many agencies the question is already settled. Since 1 July 2026, real estate agencies providing designated services under AML/CTF Tranche 2 have been reporting entities, required to enrol with AUSTRAC and meet anti-money laundering obligations. Once you are a reporting entity, the small business exemption under the Privacy Act no longer applies, even if your turnover is below $3 million. Many agencies that previously sat outside the Privacy Act are now inside it.
Key obligations under the Australian Privacy Principles
APP 1 – Privacy Policy
Agencies must have a clear, accurate and accessible privacy policy explaining what is collected, why, how it is used and disclosed, and how individuals can access or correct it.
APP 3 and 5 – Collection
Only collect information that is reasonably necessary, and notify individuals at or before collection. Open homes and inspections are the obvious risk point. Appraisal request forms, rental alert sign-ups and anything else that collects a name on your site carry the same obligation.
APP 6 – Use and Disclosure
Information must generally only be used for the purpose for which it was collected. Public online responses using client data can breach this principle.
APP 7 – Direct Marketing
Personal information cannot be used for marketing without consent or a compliant opt-out mechanism. The OAIC can issue infringement notices for certain direct marketing breaches.
APP 8 - Cross-border disclosure
Your CRM, listings portal, email tool and inspection app are often overseas or built on overseas infrastructure. Sending personal information to them is a disclosure, and you remain accountable for what happens to it.
APP 11 – Security
Agencies must take reasonable steps to protect information from misuse, interference, loss and unauthorised access.
What real estate agencies should do now
Privacy compliance requires a structured approach across three timeframes. Immediate actions address critical gaps, medium-term work builds governance capability, and strategic initiatives position your agency for ongoing reform.
If your agency provides designated services and has not enrolled with AUSTRAC, do that now. Enrolment closed on 29 July 2026, and AUSTRAC has begun issuing notices to businesses that appear to be providing designated services without enrolling. Enrolment is free and completed through AUSTRAC Online Services.
Immediate (0-3 months)
Fix critical privacy gaps now
Medium term (3-12 months)
Build governance and processes
Strategic (12-18 months)
Embed long-term privacy strategy
Immediate: 0 to 3 months
- Draft or update your privacy policy so it reflects how your agency actually collects, uses and stores personal information, including through the website and CRM.
- Check what your website collects and what tracking runs on it, including on the listings pages, and make sure nothing fires before consent is given.
- Review open home and inspection sign-in forms. Remove anything not reasonably necessary and add a clear collection notice.
- Confirm every marketing list has documented consent and a working unsubscribe, consistent with the Spam Act 2003.
- Stop including tenant or applicant details in public responses to online reviews or on social media.
- Implement basic security hygiene, including multi-factor authentication and removing dormant CRM accounts.
Medium term: 3 to 12 months
- Appoint a privacy lead.
- Document a privacy management plan.
- Conduct data mapping across your applications, portals and CRM.
- Define retention periods for tenancy applications and identity documents.
- Review vendor contracts.
- Deliver annual privacy training with real estate-specific scenarios.
Strategic: 12 to 18 months
- Conduct privacy impact assessments for higher-risk initiatives, particularly AI-assisted tenant screening tools.
- Integrate privacy risk into board reporting and risk registers.
- Review insurance coverage.
- Consider privacy capability as a genuine differentiator.
Practical checklist
Use this as an accountability tool. Assign an owner in your team to each item and track progress against it.
What businesses like yours ask
What Savira does
Savira helps Australian real estate agencies handle the parts of privacy compliance that are ongoing rather than one-off. Generate and maintain a privacy policy that reflects what your agency actually does, collect and record consent through your website, and keep an auditable record of who agreed to what and when, so you can answer a tenant, a vendor or a regulator without digging through inboxes.
Whether you are a single office or a franchise network, Savira gives you the compliance foundations without needing a consultant or a developer.
Make compliance the default
Most privacy problems in real estate are not decisions anyone made. They are things that were set up once and never revisited. Getting the policy, the consent and the records right at the process level means every new listing, campaign and application starts from the same baseline.
This guide was last updated 29 August 2026 to reflect the commencement of AML/CTF Tranche 2 on 1 July 2026, updated OAIC privacy guidance for reporting entities, and the latest compliance sweep announcements. Australian privacy law continues to evolve. Register to stay across regulatory changes affecting real estate agencies.

