Savira -- Making Compliance Easy
Be the business people trust

Privacy compliance for Australian real estate agencies

Give customers visibility and control over their data.

Real estate agencies collect more personal information than almost any other small business, at open homes, through applications, and through the listings site and CRM that run in the background. The OAIC's first compliance sweep is targeting rental and property businesses, and penalties for serious breaches reach $50 million.

Making Compliance easy

This guide explains what has changed, why real estate is under regulatory scrutiny, and what your agency must do now to avoid enforcement action.

Key takeaways

Privacy reform is now a real business risk

Penalties up to $50M

Serious or repeated privacy breaches can now attract penalties up to AU$50 million, 30 percent of adjusted turnover, or three times the benefit gained.

Regulatory spotlight

The OAIC has launched a compliance sweep targeting rental and property businesses, focusing on in-person data collection at open homes and inspections.

Over-collection risks

Collecting more information than reasonably necessary, especially identity documents at inspections, is a regulatory red flag.

Your privacy policy is a public document

It is the one part of your compliance anyone can check without asking, including a regulator. Most agency policies are years old and describe a business that no longer exists.

Individuals can sue

The statutory cause of action for serious invasions of privacy has been in force since 10 June 2025. Litigation and class action risk is real and present.

Consent has to be provable

Under APP 7 you need consent or a compliant opt-out for marketing. If asked to demonstrate it, most agencies cannot, because the consent was verbal, implied, or came across in a spreadsheet from a previous system.

Does this apply to you?

Does the Privacy Act apply to your agency?

The Privacy Act 1988 (Cth) includes a small business exemption that generally excludes businesses with an annual turnover of $3 million or less. However, the exemption is narrower than many assume, and relying on it without proper consideration is risky.

The exemption does not apply if your agency is related to a body corporate that is not a small business, has opted in to the Privacy Act (sometimes done as part of a franchise arrangement), or shares tenancy information with third parties such as tenancy databases - which can constitute "trading in personal information" and removes the exemption entirely.

Beyond the legal question, the OAIC's compliance sweep has not limited its focus to businesses above the threshold. Agencies handling sensitive financial, employment and identity information as a matter of routine are squarely in the frame, regardless of size.

For many agencies the question is already settled. Since 1 July 2026, real estate agencies providing designated services under AML/CTF Tranche 2 have been reporting entities, required to enrol with AUSTRAC and meet anti-money laundering obligations. Once you are a reporting entity, the small business exemption under the Privacy Act no longer applies, even if your turnover is below $3 million. Many agencies that previously sat outside the Privacy Act are now inside it.

Paragraph text goes here.

What has changed under the privacy act?

Much stronger enforcement powers

The Privacy and Other Legislation Amendment Act 2024 significantly expanded the powers of the OAIC, including the ability to issue infringement notices for certain breaches, stronger investigation and information gathering powers, and public inquiries into systemic privacy practices.

Significantly higher penalties

Maximum penalties for serious or repeated interferences with privacy have been increased to the greater of AU$50 million, three times the value of the benefit obtained, or 30 percent of adjusted turnover during the breach period.

Individuals can now sue

The statutory cause of action for serious invasions of privacy commenced on 10 June 2025. Individuals can now take legal action where a privacy invasion was intentional or reckless, serious in nature, and where they had a reasonable expectation of privacy.

New Privacy Act coverage for real estate agencies

Since 1 July 2026, real estate agencies providing designated services under the AML/CTF Act have been reporting entities. All reporting entities are subject to the Privacy Act regardless of turnover. The OAIC has published guidance confirming that firms should not retain copies of full identification documents for record-keeping, and that privacy obligations operate alongside, not in place of, other regulatory requirements.

WHY IT MATTERS

Why are real estate agencies in the spotlight?

The OAIC has announced its first privacy compliance sweep targeting multiple sectors, explicitly including rental and property businesses and real estate agents, with a focus on in-person data collection practices.

The risk profile of real estate is obvious. Agencies routinely collect identity documents, financial records and payslips, employment information, rental histories, and sometimes health or hardship information.

Regulators have flagged particular concern about open home sign-in processes, collection of driver licence details or copies without clear necessity, lack of transparency about how information will be used, and over-collection relative to what is reasonably necessary.

This often happens face to face, in pressured environments, where individuals have limited time to understand what they are agreeing to.

WHY IT MATTERS

Real examples of regulatory action

Person reading The Australian newspaper article about Australian privacy compliance on a tablet device

Under the APPs, agencies must only collect personal information that is reasonably necessary, and must tell people why they are collecting it.

Open home sign-ins are the clearest pressure point. Where an agency collects driver licence details or copies without a clear lawful purpose, or provides no collection notice at the point of sign-in, both the over-collection and the lack of transparency can amount to an interference with privacy. The OAIC's compliance sweep has focused specifically on in-person collection practices at inspections, and the fact that a form was signed does not establish that consent was informed.

For many agencies the question is already settled. Since 1 July 2026, real estate agencies providing designated services under AML/CTF Tranche 2 have been reporting entities, required to enrol with AUSTRAC and meet anti-money laundering obligations. Once you are a reporting entity, the small business exemption under the Privacy Act no longer applies, even if your turnover is below $3 million. Many agencies that previously sat outside the Privacy Act are now inside it.

THE APPS

Key obligations under the Australian Privacy Principles

APP 1 – Privacy Policy

APP 1 – Privacy Policy

Agencies must have a clear, accurate and accessible privacy policy explaining what is collected, why, how it is used and disclosed, and how individuals can access or correct it.

APP 3 and 5 – Collection

APP 3 and 5 – Collection

Only collect information that is reasonably necessary, and notify individuals at or before collection. Open homes and inspections are the obvious risk point. Appraisal request forms, rental alert sign-ups and anything else that collects a name on your site carry the same obligation.

APP 6 – Use and Disclosure

APP 6 – Use and Disclosure

Information must generally only be used for the purpose for which it was collected. Public online responses using client data can breach this principle.

APP 7 – Direct Marketing

APP 7 – Direct Marketing

Personal information cannot be used for marketing without consent or a compliant opt-out mechanism. The OAIC can issue infringement notices for certain direct marketing breaches.

APP 8 - Cross-border disclosure

APP 8 - Cross-border disclosure

Your CRM, listings portal, email tool and inspection app are often overseas or built on overseas infrastructure. Sending personal information to them is a disclosure, and you remain accountable for what happens to it.

APP 11 – Security

APP 11 – Security

Agencies must take reasonable steps to protect information from misuse, interference, loss and unauthorised access.

YOUR COMPLIANCE ROADMAP

What real estate agencies should do now

Privacy compliance requires a structured approach across three timeframes. Immediate actions address critical gaps, medium-term work builds governance capability, and strategic initiatives position your agency for ongoing reform.

If your agency provides designated services and has not enrolled with AUSTRAC, do that now. Enrolment closed on 29 July 2026, and AUSTRAC has begun issuing notices to businesses that appear to be providing designated services without enrolling. Enrolment is free and completed through AUSTRAC Online Services.

Immediate (0-3 months)

Fix critical privacy gaps now

Medium term (3-12 months)

Build governance and processes

Strategic (12-18 months)

Embed long-term privacy strategy

Immediate: 0 to 3 months

  • Draft or update your privacy policy so it reflects how your agency actually collects, uses and stores personal information, including through the website and CRM.
  • Check what your website collects and what tracking runs on it, including on the listings pages, and make sure nothing fires before consent is given.
  • Review open home and inspection sign-in forms. Remove anything not reasonably necessary and add a clear collection notice.
  • Confirm every marketing list has documented consent and a working unsubscribe, consistent with the Spam Act 2003.
  • Stop including tenant or applicant details in public responses to online reviews or on social media.
  • Implement basic security hygiene, including multi-factor authentication and removing dormant CRM accounts.

Medium term: 3 to 12 months

  • Appoint a privacy lead.
  • Document a privacy management plan.
  • Conduct data mapping across your applications, portals and CRM.
  • Define retention periods for tenancy applications and identity documents.
  • Review vendor contracts.
  • Deliver annual privacy training with real estate-specific scenarios.

Strategic: 12 to 18 months

  • Conduct privacy impact assessments for higher-risk initiatives, particularly AI-assisted tenant screening tools.
  • Integrate privacy risk into board reporting and risk registers.
  • Review insurance coverage.
  • Consider privacy capability as a genuine differentiator.
Free tool

Practical checklist

Use this as an accountability tool. Assign an owner in your team to each item and track progress against it.

AreaImmediate PriorityNext Phase
Privacy Policy Update and publish; cover website and CRM Schedule annual review; assign a named owner
Website Check what tracking runs; ensure nothing fires before consent Keep consent records auditable and reviewable
Open Homes Remove over-collection; add a collection notice Standardise compliant templates across all offices
Applications Audit what is stored and where Set and enforce retention and deletion periods
MarketingConfirm consent and opt-out on all lists Conduct full CRM governance review
SecurityTighten access controls, remove dormant accountsCommission periodic risk assessments
TrainingInitial all-staff sessionBuild annual refresh into calendar
GovernanceAppoint a privacy leadIntegrate into board reporting cycle
Privacy Policy
Immediate Priority Update and publish; cover website and CRM
Next Phase Schedule annual review; assign a named owner
Website
Immediate Priority Check what tracking runs; ensure nothing fires before consent
Next Phase Keep consent records auditable and reviewable
Open Homes
Immediate Priority Remove over-collection; add a collection notice
Next Phase Standardise compliant templates across all offices
Applications
Immediate Priority Audit what is stored and where
Next Phase Set and enforce retention and deletion periods
Marketing
Immediate PriorityConfirm consent and opt-out on all lists
Next Phase Conduct full CRM governance review
Security
Immediate PriorityTighten access controls, remove dormant accounts
Next PhaseCommission periodic risk assessments
Training
Immediate PriorityInitial all-staff session
Next PhaseBuild annual refresh into calendar
Governance
Immediate PriorityAppoint a privacy lead
Next PhaseIntegrate into board reporting cycle
Common questions

What businesses like yours ask

Only where you can justify it for a lawful purpose, and you have to tell people why. Collecting licence details for general safety or follow-up is difficult to justify, and copying or retaining the document is harder again. Collect a name and contact detail, explain what it is for, and stop there.
Probably not any more. Since 1 July 2026, agencies providing designated services under the AML/CTF Act are reporting entities, and reporting entities lose the small business exemption regardless of turnover.
Often not. The question is whether tracking scripts wait for consent before they run, and whether declining actually stops them. Many banners are decorative, meaning collection has already happened by the time anyone clicks. Open your site in a private window and watch what loads before you touch the banner.
Yes. A policy has to reflect what you actually collect and who you disclose it to, and for most agencies that includes the CRM, the portal, the inspection app and any email tool. Most agency policies describe a business that only collects on paper.
Under APP 12 you generally have to give them access, and under APP 13 correct it if it is wrong. The practical difficulty is usually not the obligation, it is finding everything: the CRM, the inspection app, the marketing list, old application emails. If you cannot answer quickly, that is a sign the data is spread further than you think.

What Savira does

Savira helps Australian real estate agencies handle the parts of privacy compliance that are ongoing rather than one-off. Generate and maintain a privacy policy that reflects what your agency actually does, collect and record consent through your website, and keep an auditable record of who agreed to what and when, so you can answer a tenant, a vendor or a regulator without digging through inboxes.

Whether you are a single office or a franchise network, Savira gives you the compliance foundations without needing a consultant or a developer.

Make compliance the default

Most privacy problems in real estate are not decisions anyone made. They are things that were set up once and never revisited. Getting the policy, the consent and the records right at the process level means every new listing, campaign and application starts from the same baseline.

This guide was last updated 29 August 2026 to reflect the commencement of AML/CTF Tranche 2 on 1 July 2026, updated OAIC privacy guidance for reporting entities, and the latest compliance sweep announcements. Australian privacy law continues to evolve. Register to stay across regulatory changes affecting real estate agencies.