For buyer's agents & property developers

Most buyer's agents don't know Tranche 2 reached them at all.

It did. Since 1 July 2026, brokering the purchase or sale of real property is a designated service under the AML/CTF Act — which makes buyer's agents and developers selling their own stock reporting entities, alongside the sales agencies they deal with.

The Privacy Act small business exemption no longer covers the personal information you handle in that work, regardless of turnover. If this is the first you're hearing of it, you're in the majority.

No obligation. We'll tell you if you don't need us.

Where the law actually stands

Three dates matter. Only one has already passed.

Plenty of people will tell you every small business is about to fall under the Privacy Act. That isn't law yet. Here is what is in force, what is scheduled, and what is still only proposed.

Date
What changed
Status
10 Jun 2025
Statutory tort for serious invasions of privacy Individuals can sue directly. Applies regardless of your turnover.
In force
01 Jul 2026
AML/CTF Tranche 2 — buyer's agents and developers captured Brokering the sale or purchase of real property is a designated service. Small teams and sole operators are captured on the same day as large agencies — there is no size threshold.
In force
10 Dec 2026
Automated decision-making disclosure obligations If you use software to screen buyers, applicants or purchasers, your privacy policy must disclose it.
Scheduled
Not set
Removal of the $3m small business exemption entirely Government supports it in principle. No Bill passed, no commencement date. Treat any specific date you're quoted as commentary.
Proposed

General information, current as at the date of publication — not legal advice. We review this table monthly and date every change.

Why small operators are more exposed, not less

No compliance manager, no IT department, and the same obligations.

A buyer's agent holds a client's full borrowing capacity, pre-approval letters, bank statements, identity documents, family circumstances and often the reason they're moving. Developers hold the same for every purchaser, plus deposit records and beneficial ownership details for the entities buying off the plan.

It usually lives in a personal-plan CRM, a phone, a Dropbox folder and a mailbox that has never had multi-factor authentication turned on. A two-person operation has exactly the same obligations as a hundred-agent franchise and none of the infrastructure.

The good news is that a small operation is far quicker to fix. There are fewer systems to map, fewer people to train, and no committee to convince. Four weeks is a comfortable timeline, not a stretch.

What it costs to get this wrong. The OAIC can issue infringement notices of up to $66,000 per contravention for lower-level failures such as not maintaining a compliant privacy policy. Serious or repeated breaches carry substantially higher penalties. Separately, since June 2025, an individual can bring a civil claim against you directly.

What we do

Four ways to work with us.

Start small if you want to see how we work. Start with the foundations if you already know where this is heading.

Privacy health check

$750 + GST, one-off

A half day of our time and a written answer to one question: how exposed are you?

  • Review of your current policy, forms and file handling
  • Written findings memo against the Australian Privacy Principles
  • Prioritised list of what to fix first
  • Credited in full against foundations if you proceed within 60 days

Privacy foundations

$4,500 – $7,500 + GST, one-off

A complete privacy program, built and handed over in four weeks.

  • Data map of every place personal information lives
  • Gap assessment against the 13 Australian Privacy Principles
  • Privacy policy and collection notices written for your practice
  • Notifiable data breach response plan
  • 60-minute staff training session

Most operators choose this

ComplyHub annual

from $10,500 + GST, per year

Foundations plus twelve months of maintenance, bundled.

  • Everything in Privacy foundations
  • Quarterly compliance review
  • Policies and registers updated as the law changes
  • Breach response line — call us first, not your lawyer
  • Annual staff training refresher

Ongoing privacy officer

$400 – $800 + GST, per month

Maintenance only, for operators whose program is already built.

  • Quarterly reviews and register upkeep
  • Regulatory change monitoring
  • Breach response line
  • If someone else built your program, we'll assess it first ($1,500)

The four weeks

What actually happens.

Week 1 — Discovery

Ninety minutes with you — and if it's a two-person business, that's the whole discovery. We list every place a client's information touches, including the phone and the personal email account.

Week 2 — Data map and gap assessment

A written data map and an assessment against the 13 Australian Privacy Principles, sized for how you actually work rather than for a corporate structure you don't have.

Week 3 — Documents

Privacy policy, collection notice for your client agreement and enquiry form, breach response plan and a retention schedule. Short, plain, and usable by someone working out of a car.

Week 4 — Handover and training

An hour on what changes day to day, plus a written summary you can send to a client, a licensing body or a developer you're doing business with.

Fair questions

Fair questions.

I didn't think Tranche 2 applied to me at all.

That's the most common reaction we get, and it's why this page exists. The obligation attaches to the service, not the size or title of the business. If you broker the purchase or sale of real property for someone else, or sell property you've developed, you're providing a designated service. Bring your client agreement to the call and we'll tell you exactly where you sit.

I'm a sole operator with no staff.

You're still a reporting entity, and the Privacy Act applies to the personal information you handle in that work. The upside is that your program is genuinely small — fewer systems, no training rollout, and a much shorter build. We price accordingly.

Isn't the sales agent handling all of this?

They have their own obligations, and they're not yours. You collect information directly from your client that the sales agency never sees — borrowing capacity, personal circumstances, the brief itself. That's yours to account for.

We're under $3 million turnover.

The exemption no longer applies to personal information handled for AML/CTF purposes. There is no turnover floor on that. The broader removal of the $3m exemption is still only proposed.

Are you lawyers?

No. We're privacy and compliance practitioners and this is implementation work. Anything that's genuinely legal advice, we refer out and say so in writing.

Who you're dealing with

A small Australian firm, and you'll deal with a founder.

ComplyHub is based in Melbourne and works with Australian professional services businesses on Privacy Act obligations. Our work is delivered onshore — your data stays in Australia, and we can tell you exactly which systems it touches.

Between us we hold certifications from the International Association of Privacy Professionals in privacy program management, privacy technology and AI governance, alongside security credentials. That matters less than the fact that you'll speak to the person doing the work.

More about us and our credentials →

Find out whether this actually reached you.

Twenty minutes on the phone. Describe what you do and we'll tell you plainly whether you're providing a designated service. If you aren't, that's a short call and it costs you nothing.