In this article

Kooky
Builder of Shaka, the payment router that pays every agent their commission on closing date.
About Kooky and Shaka →A rental application holds a payslip, a driver licence number and a rental history. A contract file holds a buyer's identity documents. When a staff member pastes any of that into an AI tool to draft a letter or summarise a file, the question is no longer only whether the tool is useful. It is whether the agency was allowed to put the information there, and what it now owes the person the information is about.
In Australia the answer sits in one federal statute, the Privacy Act 1988, and in the 13 Australian Privacy Principles (APPs) it contains. The regulator is the Office of the Australian Information Commissioner (OAIC), which published its guidance on privacy and the use of commercially available AI products on 21 October 2024 and updated it on 17 January 2025. This guide sets out what that guidance says, which agencies the Act reaches, how the position changed for real estate on 1 July 2026, and what the Notifiable Data Breaches scheme requires when something goes wrong. It describes the general rules as the OAIC states them; how they apply to one agency depends on its turnover, its activities and the tool in question.
Office of the Australian Information Commissioner: small business page, APP quick reference and data breach guide, as read on 10 October 2026.
Who the regulator's AI guidance is written for
The OAIC addresses its guidance to organisations that deploy AI systems. It defines a deployer as anyone who supplies or uses an AI system to provide a product or service, and it says this includes internal use. An agency that buys a subscription to an assistant for its property managers is therefore a deployer in the OAIC's sense, even if no customer ever sees the tool. The guidance covers chatbots, content generators and productivity assistants, and also freely available tools such as public chatbots.
Related readWhat UAE data protection law asks of a Dubai brokerage using AI toolsThe guidance is not itself law. The OAIC says it is intended to assist organisations to comply with their privacy obligations, that it should be read with the Privacy Act and the APP Guidelines, and that it does not cover every privacy issue. The points it labels "best practice" are recommendations; the binding rules are the Act and the APPs.
Its first takeaway frames everything else: privacy obligations apply both to the personal information entered into an AI system and to any output of the system that contains personal information. Both ends of the exchange are regulated.
Which agencies the Privacy Act covers
The Privacy Act does not apply to every business. The OAIC's small business page says a small business is one with an annual turnover of A$3 million or less, and that such a business is generally outside the Act. The OAIC's checklist puts the test as whether turnover was above A$3,000,000 in any financial year since 2002, so a single year over the line matters.
Turnover for this purpose includes all income from all sources, according to the same page. It does not include assets held, capital gains or the proceeds of capital sales. A business that has not operated for a full financial year projects its full-year turnover from its income to date.
The exemption has a list of exceptions. The OAIC says the Act covers a business, whatever its turnover, if it is among other things a health service provider, a business trading in personal information, a contractor providing services under a Commonwealth contract, an operator of a residential tenancy database, a credit reporting body, a reporting entity for the purposes of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, a business related to one the Act covers, or a business that has opted in to be covered. The OAIC's data breach guide gives the section numbers: small business operators are dealt with in sections 6C and 6D, and opting in is done under section 6EA.
Related readHow the Dubai Land Department uses artificial intelligence, by serviceThree of those exceptions touch real estate. The first is the tenancy database. The OAIC defines a residential tenancy database as one that stores personal information about individuals occupying residential premises as tenants, and its tenancy page says the Act covers any organisation running such a database regardless of turnover. That page separates running a database from using one: agents may use these databases and supply information to them, which is a different thing from operating one. The second is trading in personal information. The third, the reporting entity exception, is the one that changed in 2026.
One rule applies outside the turnover test altogether. The OAIC's tenancy page says tax file numbers carry strict handling rules that apply to all real estate agents, whether or not the Privacy Act covers them.
What changed for real estate on 1 July 2026
The OAIC's privacy guidance for reporting entities under the anti-money laundering law, published on 27 February 2026 and updated on 28 August 2026, records that real estate professionals became reporting entities on 1 July 2026. They did so alongside dealers in precious stones and metals, lawyers, conveyancers, accountants and trust and company service providers, in what the guidance calls Tranche 2.
That status brings a small agency inside the Privacy Act, but only in part. The guidance says reporting entities, including small businesses, must comply with the Act when handling personal information for anti-money laundering purposes. It adds that a small business is not covered for its other activities unless another reason applies, and that where information is collected for both an anti-money laundering purpose and another purpose, the Act applies to that information.
Related readNew South Wales rental ads and renter data: the 2026 Act explainedThe two OAIC pages do not read identically on this point. The small business page lists a reporting entity as covered, without qualification. The reporting entity guidance, which is the later and more detailed of the two, limits the coverage to anti-money laundering handling. This guide follows the detailed guidance and names the difference.
The OAIC illustrates the rule with a case study of its own. Real Houses Australia, a fictional agency with a turnover of A$1.1 million, is a small business under the Privacy Act. The guidance concludes that it must comply with the Act for the personal information it handles for customer due diligence and personnel due diligence, but not for its other activities. A second example concerns auctions: the agent completes customer due diligence only on the vendor and the successful buyer, not on every bidder.
| Agency | Annual turnover | Privacy Act coverage |
|---|---|---|
| First agency | A$4.2 million | Above A$3 million: the Act applies to the organisation. |
| Second agency | A$1.1 million | Small business and reporting entity: covered for due diligence information. |
| Third agency | A$2.0 million | Small business that operates a residential tenancy database: covered regardless of turnover. |
Illustrative figures. The second row uses the turnover of the OAIC's own Real Houses Australia case study. No other exception is assumed to apply.
The practical consequence for AI use follows from the second row. A vendor's or buyer's identity details collected for due diligence are covered information, since 1 July 2026, in any agency that is a reporting entity, whatever its turnover. A tenant's application file in a small agency is treated differently: on the OAIC's guidance it falls outside the Act unless one of the other exceptions applies, or unless the same information was also collected for an anti-money laundering purpose. The pages read for this guide do not say how far the Act reaches into the other activities of a small business that operates a tenancy database, and that depends on the case.
Related readSingapore agency AI tools: what ERA and PropNex have announcedWhat an agency may hold about tenants and buyers
Before any AI tool enters the picture, APP 3 limits what a covered agency may collect. The OAIC's tenancy page says agents may collect only personal information that is reasonably necessary for one of their functions or activities. They cannot collect extra information because it is convenient or might be useful later. Sensitive information generally requires the person's consent.
The same page lists what a person should be told before collection: why the information is needed, what happens if it is not provided, who it is usually disclosed to, and the rights to access it and to complain.
Government identifiers have their own principle, APP 9. An agent may collect an identifier such as a Medicare or driver licence number if that is reasonably necessary, the OAIC says, but generally must not adopt, use or disclose it. When copying identity documents, agents should blank out personal information that is not needed, and generally blank out the identifier when using or disclosing the document.
Disclosure is generally limited to the reason the information was collected. For a tenancy application, the OAIC says that may include a residential tenancy database operator, the landlord, a previous agent giving a reference and nominated referees. An AI developer is not on that list.
For due diligence records, the reporting entity guidance adds a rule that reduces what sits in an agency's files. From 1 July 2026 for Tranche 2 businesses, the anti-money laundering law does not require keeping scanned or photocopied identity documents, and the OAIC says only the necessary details should be recorded. Fewer copies held means fewer copies that can reach a tool or leak from one.
Related readSingapore property agents and AI: what the data and advert rules askTyping personal information into an AI tool
APP 6 governs what happens next. The OAIC's guidance says personal information may be used or disclosed only for the primary purpose for which it was collected, unless the person consents or would reasonably expect the secondary use and that use is related to the primary purpose. For sensitive information the secondary use must be directly related.
Whether entering information into a tool is a use or a disclosure depends on control. The guidance treats it as a use if the information stays within the organisation's effective control, and as a disclosure if it is released from that control. Entering personal information into a publicly available chatbot may amount to a disclosure to the chatbot's owners, the OAIC says, and a disclosure needs a basis under APP 6.
The guidance works through an example from another industry that transfers easily. Staff at an insurer entered a customer's health information into a public chatbot to assess a claim. The OAIC treats that as a disclosure and says the primary purpose should be read narrowly. It adds that reasonable expectations may be hard to show if customers were not specifically told, given public concern about chatbots.
The reasonable expectations test is objective. It asks what a reasonable, properly informed person would expect, and it is assessed primarily at the time of collection. Setting out the secondary use expressly in the collection notice and the privacy policy may support it. Where the agency cannot clearly show the use is within reasonable expectations, the guidance says to seek consent, to offer a meaningful and informed opt-out, or both. Consent must be informed, current and specific, and the OAIC states that it cannot be implied merely because a person was notified. The guidance adds that only the minimum information needed should be used, and that APP 8, the cross-border principle, applies when personal information is entered into AI chatbots.
Related readUS mortgage AI denials: what the adverse action notice must sayThe regulator recommends keeping personal information out of public chatbots
The fifth takeaway of the OAIC guidance is a recommendation, not a statutory ban: do not enter personal information, and particularly sensitive information, into publicly available AI chatbots. Where a business sets such a control, the guidance says it must be backed by robust training and auditing.
What the tool writes back is a collection
The less obvious half of the guidance concerns output. The OAIC says personal information that an AI system generates or infers is a collection under APP 3. Collection, as it reads the term, covers information created by reference to other information the organisation holds.
It follows that the output must meet the same tests as any other collection. It must be reasonably necessary for the agency's functions or activities and obtained by lawful and fair means. Where it is sensitive information, consent is generally required. Information that is not needed must be destroyed or de-identified.
Truth is not required for information to be personal information. The guidance says inferred, incorrect or artificially generated information about an identified or reasonably identifiable individual is personal information, and names hallucinations and deepfakes. If a tool asked to summarise a tenancy file produces a statement about the tenant that is wrong, the agency holds personal information about that tenant and must handle it under the APPs.
Accuracy and a human who can overturn the output
APP 10, as the guidance describes it, requires reasonable steps to ensure that personal information is accurate, up to date and complete.
Generative AI is probabilistic, the guidance says, and can produce outputs that look confident and are wrong. Its measures include testing the product for the intended purpose, verifying the quality of what goes in, training staff on the system's design and limitations, and ongoing monitoring that it operates as intended. Outputs should not be recorded as fact, and a record should indicate that the output is probabilistic.
Related readUSA: eXp lets agents connect their own AI assistants to its dataHuman oversight carries the most weight. The OAIC says a human user should be responsible for verifying the accuracy of personal information obtained through AI and should be able to overturn decisions. It singles out decisions with a legal or similarly significant effect as likely to be high privacy risk, and says that if a system's behaviour cannot be clearly explained, it may not be appropriate for such decisions. The guidance does not discuss tenant selection by name; its own examples include an insurance claim and recruitment.
In the regulator's reading, a wrong sentence about a real tenant is still personal information, and the agency that generated it has collected it.
The two checklists for choosing and using a product
The guidance ends with two checklists of five questions each. The first is for selecting a product, the second for using one.
| Question | Selecting a product | Using a product |
|---|---|---|
| First | Is the system appropriate and reliable for the intended use? | Is personal information being used or disclosed? |
| Second | Can the training data be identified? | Is personal information being collected, generated or inferred? |
| Third | What are the potential security risks? | Have reasonable steps been taken to ensure accuracy? |
| Fourth | What is the intended operating environment? | Are transparency and accountability measures in place? |
| Fifth | Will inputs be accessible to the developer? | What ongoing assurance processes are needed? |
The selection questions turn on what an agency can find out before it signs: whether the product has been tested for the intended use, whether the developer can access inputs or train on them, and whether such features can be disabled. "AI products should not be used simply because they are available," the OAIC writes.
Security falls under APP 11, which the guidance describes as an obligation to take reasonable steps to protect the personal information an organisation holds. The guidance says to check for known security incidents and to consider where the system runs. It describes on-premises or local deployment as more privacy-preserving than cloud hosting, which raises questions of server location and offshore disclosure.
The reporting entity guidance gives a parallel list for any outside provider that handles due diligence information: contract terms covering the handling of personal information, due diligence such as requesting the provider's privacy policy and checking for past security incidents, periodic reviews, and confirmation of deletion when the contract ends.
Related readUS fake review rule: what the FTC bans for real estate agentsThe privacy policy, the notice and a date in December
A covered agency must have a privacy policy, the subject of APP 1. The OAIC's tenancy page says an agent covered by the Act must have one available and on its website. The AI guidance asks that the policy include statements about AI use, and that APP 5 notices cover AI-related purposes, AI-generated personal information and disclosures to AI developers. A public-facing chatbot should be identified as AI. In its guidance for reporting entities, the OAIC recommends responding to privacy complaints within 30 days.
A new statutory requirement is scheduled to start on 10 December 2026. On 30 September 2026 the OAIC released a fact sheet, a flowchart and updated APP 1 Guidelines on APP 1.7 to 1.9, which were introduced by the Privacy and Other Legislation Amendment Act 2024. According to that release, the obligation applies where an APP entity has arranged for a computer program to make a decision, or to carry out a step substantially and directly connected to one, where personal information is used in the program's operation and the decision could reasonably be expected to significantly affect the rights or interests of an individual.
Where it applies, APP 1.8 requires the privacy policy to state three things: the kinds of personal information used in operating such programs, the kinds of decisions made solely by them, and the kinds of decisions where a substantially and directly connected step is carried out by them. The release gives no examples, so whether a particular scoring or screening tool in an agency meets the test is a question for the case.
Related readUS housing algorithms: what HUD said on AI and what still appliesWhen a data breach must be notified
The Notifiable Data Breaches scheme was set up by the Privacy Amendment (Notifiable Data Breaches) Act 2017. Under it, the OAIC says, any organisation or agency the Privacy Act covers must notify affected individuals and the OAIC when a data breach is likely to result in serious harm. Breaches that occurred before 22 February 2018 are not eligible.
A data breach happens when personal information an organisation holds is lost or subjected to unauthorised access or disclosure. The OAIC's examples are a lost or stolen device, a hacked database and personal information mistakenly given to the wrong person. An eligible data breach needs three things together: the unauthorised access, disclosure or loss; a likelihood of serious harm to one or more individuals; and a failure to prevent that harm through remedial action. Under section 26WF, if remedial action means serious harm is no longer likely, the breach is not an eligible one.
The Act does not define serious harm. The OAIC's data breach guide says it can include serious physical, psychological, emotional, financial or reputational harm, and that "likely" means more probable than not, judged from the viewpoint of a reasonable person in the entity's position.
The clock starts with suspicion. Under section 26WH, an entity with reasonable grounds to suspect an eligible data breach must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 calendar days. The OAIC suggests three stages.
- InitiateDecide whether an assessment is needed and who will carry it out.
- InvestigateGather information on what was affected, who may have had access and the likely impact.
- EvaluateDecide whether the incident is an eligible data breach.
A worked example shows the timing. Assume a covered agency forms a reasonable suspicion on 1 September 2026 that a staff member disclosed a buyer's identity details without authority. Thirty calendar days later is 1 October 2026, weekends included, and that is the date by which all reasonable steps to finish the assessment should have been taken.
Related readUS real estate AI this week: an MLS assistant, new data, title rulesIf the breach is an eligible one, section 26WK requires a statement to the Commissioner as soon as practicable, given through the OAIC's online Notifiable Data Breach form. It must contain the entity's identity and contact details, a description of the breach, the kinds of information involved and the steps the entity recommends individuals take. Section 26WL then gives three ways of telling individuals: notify everyone whose information was involved, notify only those at risk of serious harm, or, if neither is practicable, publish the statement on the entity's website and take reasonable steps to publicise it.
Two provisions matter where an outside tool is involved. Where information is jointly held, one entity's assessment satisfies the others under section 26WJ and one may notify for all under section 26WM. An entity that disclosed personal information overseas under APP 8.1 is treated as still holding it, under section 26WC. For reporting entities there is one more layer: section 26WP excludes notification to the extent it would conflict with a secrecy provision such as the tipping-off prohibition in section 123 of the anti-money laundering law, and the OAIC notes that it may still be notified when individuals cannot be.
For a small agency, the scheme's reach follows its coverage. On the OAIC's reporting entity guidance, an agency under the turnover threshold is within the scheme for the due diligence information it handles. Tax file number information is covered for every recipient under section 26WE.
What the regulator can do
A failure to meet the scheme's requirements, including the duty to assess, is an interference with privacy under section 13 of the Privacy Act, according to the OAIC's data breach guide. The guide lists the Commissioner's powers: accepting an enforceable undertaking under section 33E, making a determination under section 52, seeking an injunction under section 98, and applying to a court for a civil penalty order under section 80W, which extends to a serious or repeated interference with privacy under section 13G. The pages read for this guide do not state the penalty amounts.
The Commissioner can also direct an entity to notify under section 26WR. The guide states the OAIC's preference for working with entities to encourage compliance before taking enforcement action. Individuals have their own route: the OAIC's tenancy page tells a person to complain to the agent first and then to the OAIC if unhappy with the response.