For real estate agencies & property managers
You enrolled with AUSTRAC. The Privacy Act came with it.
Since 1 July 2026, real estate agencies providing designated services are reporting entities under the AML/CTF Act. The Privacy Act small business exemption no longer covers the personal information you collect for those services — regardless of your turnover.
ComplyHub builds your privacy program in four weeks, for a fixed fee, without a law firm's hourly rate.
No obligation. We'll tell you if you don't need us.
Where the law actually stands
Three dates matter. Only one has already passed.
Plenty of people will tell you every small business is about to fall under the Privacy Act. That isn't law yet. Here is what is in force, what is scheduled, and what is still only proposed.
General information, current as at the date of publication — not legal advice. We review this table monthly and date every change.
Why agencies are exposed
You hold more sensitive data than almost any business on your street.
A single tenancy application can contain a driver licence, passport, bank statements, payslips, rental ledger and referee contacts. Multiply that by every applicant who didn't get the property — and whose file is still sitting in your inbox, your CRM and a folder on the shared drive.
Add the 100-point identity checks and beneficial ownership records you now collect for AUSTRAC, and the volume of personal information your agency handles has gone up sharply at exactly the moment it became regulated.
Most agencies we speak to have never mapped where that information lives, have a privacy policy copied from a template that doesn't mention the Australian Privacy Principles, and have no plan for the day a staff member emails the wrong attachment.
What it costs to get this wrong. The OAIC can issue infringement notices of up to $66,000 per contravention for lower-level failures such as not maintaining a compliant privacy policy. Serious or repeated breaches carry substantially higher penalties. Separately, since June 2025, an individual can bring a civil claim against you directly.
What we do
Four ways to work with us.
Start small if you want to see how we work. Start with the foundations if you already know where this is heading.
Privacy health check
$750 + GST, one-off
A half day of our time and a written answer to one question: how exposed are you?
- Review of your current policy, forms and file handling
- Written findings memo against the Australian Privacy Principles
- Prioritised list of what to fix first
- Credited in full against foundations if you proceed within 60 days
Privacy foundations
$4,500 – $7,500 + GST, one-off
A complete privacy program, built and handed over in four weeks.
- Data map of every place personal information lives
- Gap assessment against the 13 Australian Privacy Principles
- Privacy policy and collection notices written for your practice
- Notifiable data breach response plan
- 60-minute staff training session
Most agencies choose this
ComplyHub annual
from $10,500 + GST, per year
Foundations plus twelve months of maintenance, bundled.
- Everything in Privacy foundations
- Quarterly compliance review
- Policies and registers updated as the law changes
- Breach response line — call us first, not your lawyer
- Annual staff training refresher
Ongoing privacy officer
$400 – $800 + GST, per month
Maintenance only, for agencies whose program is already built.
- Quarterly reviews and register upkeep
- Regulatory change monitoring
- Breach response line
- If someone else built your program, we'll assess it first ($1,500)
The four weeks
What actually happens.
Week 1 — Discovery
A 90-minute session with you and whoever runs your trust accounting and property management. We walk through every system you touch and every point where a client hands you something personal.
Week 2 — Data map and gap assessment
We document what you hold, where, who can see it and how long you keep it — then assess it against each of the 13 Australian Privacy Principles and give you a prioritised list of gaps.
Week 3 — Documents
Privacy policy, collection notices for your application forms and website, breach response plan, and a retention schedule. Written for your agency, not filled in from a template.
Week 4 — Handover and training
An hour with your team on what changed and what they need to do differently, plus a written summary you can put in front of your franchisor, your insurer or the OAIC.
Fair questions
What principals usually ask us.
Doesn't my AML/CTF program already cover this?
No. They're separate obligations under separate Acts with separate regulators — AUSTRAC for AML/CTF, the OAIC for privacy. Your AML program tells you to collect and keep identity records. The Privacy Act governs how you must handle, secure, disclose and eventually destroy them. Being enrolled with AUSTRAC is what brought you into scope, not what satisfies it.
We're under $3 million turnover. Aren't we exempt?
Not for AML/CTF-related personal information. That's the specific effect of the 1 July 2026 change — the small business exemption stops applying to the parts of your business providing designated services. The broader removal of the exemption for everything else is still only a proposal.
Why not just use our lawyer?
You can, and for interpreting the legislation you probably should. But most of this work isn't legal advice — it's implementation. Mapping data, writing operational documents, training staff and maintaining registers is practice-management work, and it's slow and expensive at a solicitor's hourly rate. We do the build; where something genuinely requires legal advice, we tell you and refer you.
Are you lawyers?
No. We're privacy and compliance practitioners. We don't provide legal advice, and our engagement letter says so plainly.
Our franchise gave us a compliance pack. Is that enough?
Sometimes it's a good start. Bring it to the call — if it covers you, we'll tell you and you can stop reading. If it's a generic policy that doesn't reflect how your office actually handles files, we'll show you the gaps.
Who you're dealing with
A small Australian firm, and you'll deal with a founder.
ComplyHub is based in Melbourne and works with Australian professional services businesses on Privacy Act obligations. Our work is delivered onshore — your data stays in Australia, and we can tell you exactly which systems it touches.
Between us we hold certifications from the International Association of Privacy Professionals in privacy program management, privacy technology and AI governance, alongside security credentials. That matters less than the fact that you'll speak to the person doing the work.
Find out where your agency stands.
Twenty minutes on the phone. We'll walk through what you collect and where it goes, and tell you plainly whether you have a problem. If you don't, we'll say so.