Skip to content
TopStreet
For agentsFor agenciesPricingWhy TopStreetBook a callNot sure where to start?

How can an Australian real estate agency use AI without breaching privacy law?

Updated 1 October 2026 · 4 min read

The short answer

Start by working out how the Privacy Act 1988 applies to your agency, then follow the OAIC's guidance on AI: keep personal information out of publicly available AI tools, and use only tools you have checked, for the purpose the information was collected for. Put a human check on anything an AI produces about a person, and update your privacy policy to say how you use AI. Write it down as a one-page policy your agents can follow on a busy Saturday.

The Broker Brain method

This answer applies 3 methods from the guide, led by one.

Use technology and AI to grow your business

Keep one trustworthy working record

Use the CRM for confirmed identifiers, permission, needs, source dates and next actions.

  1. 1Record the person or property using authoritative identifiers.
  2. 2Capture only the information needed for the work.
  3. 3Deduplicate and correct stale records.
  4. 4Give data quality and the next action a named owner.

Hold when: Do not upload customer records to a public host without permission and a suitable data boundary. Do not let chat history become a second CRM.

Read it in Broker Brain →
Use technology and AI to grow your business

Test with a human checkpoint

Use permitted data, verify the output and keep every external action behind an accountable person.

Read it in Broker Brain →
Use technology and AI to grow your business

Start with the repeated problem

Measure the task before selecting a tool, then choose the smallest intervention that could help.

Read it in Broker Brain →

First, how does the Privacy Act apply to you?

The Privacy Act 1988 and its Australian Privacy Principles (APPs) apply to organisations with an annual turnover above $3 million. Smaller businesses can still be covered, for example if they trade in personal information, operate a residential tenancy database or have opted in.

From 1 July 2026, real estate businesses that provide designated services have obligations under the AML/CTF Act, and the OAIC says small businesses that are reporting entities must comply with the Privacy Act for their AML/CTF activities. So even a small agency now has some work under the Act. And whatever the law requires, your vendors, landlords and buyers expect their details to be handled to that standard. This is general information, not legal advice; check your position with a lawyer.

The rules that matter most when AI touches client data

The OAIC's guidance on commercially available AI products names the principles that do most of the work. In plain terms, for an agency:

  1. 01Public tools: as best practice, the OAIC says do not enter personal information, and particularly sensitive information, into publicly available generative AI tools. That rules out client names, numbers, budgets and ID documents in agents' personal ChatGPT or Claude accounts.
  2. 02Purpose (APP 6): use personal information in an AI tool only for the purpose it was collected for, unless the person has consented or would reasonably expect the other use. A buyer's enquiry details were collected to help them buy, not to train a vendor's model.
  3. 03Collection (APP 3): if an AI tool infers or generates information about a person, the OAIC treats that as collecting it, so it must be reasonably necessary and collected lawfully and fairly.
  4. 04Accuracy (APP 10): take reasonable steps to make sure personal information is accurate, which with AI means a person checks what it produced before it is used.
  5. 05Overseas and security (APPs 8 and 11): know whether the tool sends data overseas and how it is protected from misuse and loss.
  6. 06Openness (APPs 1 and 5): keep your privacy policy current, say how you use AI, and make sure any AI chat tool on your website is clearly identified as AI.

Check a tool before agents use it on client work

The guide's ‘Keep one trustworthy working record’ method sets the boundary: do not upload customer records to a public host without permission and a suitable data boundary, and do not let chat history become a second CRM. The OAIC asks for due diligence before adopting an AI product. For an agency, that is a short set of questions with written answers.

  1. 01Where is client data stored and processed, and is any of it sent overseas?
  2. 02Is our data used to train the vendor's models, and can we switch that off in writing?
  3. 03Who at the vendor can see our data, and what happens to it if we leave?
  4. 04Has the tool been tested for the job we want it for, and does it show its sources so we can check it?
  5. 05Can we see which agent used it, on what, and approve client-facing work before it goes out?

Automated decisions: the change due in December 2026

From 10 December 2026, organisations covered by the Privacy Act that use personal information in automated decision-making with the potential to affect a person's rights or interests must say so in their privacy policy: the kinds of personal information used and the kinds of decisions made. The OAIC has consulted on guidance for this.

Ranking which past clients to call is unlikely to be that kind of decision. A tool that scores or screens rental applications could be. List where AI shapes a decision about a person, and decide with your lawyer which ones your policy must describe.

A one-page AI policy your agents will follow

The guide's ‘Test with a human checkpoint’ method keeps every external action behind an accountable person. Put that in writing in words an agent can apply between inspections, and roll it out by testing it on real jobs, not by sending a memo.

  1. 01The approved tools, by name, and what each may be used for.
  2. 02What never goes into an unapproved tool: names, phone numbers, emails, addresses tied to a person, ID, financial details, and anything about health or background.
  3. 03Who checks what: every figure against its source, and every message, listing or report read by the agent who owns it before a client sees it.
  4. 04Nothing is sent, published or decided by a tool on its own.
  5. 05What to do if something goes wrong: who to tell, the same day, and how the agency will respond.
  6. 06A review date, and the principal who owns the policy.

What gets in the way

Letting agents use personal AI accounts for client work because nobody has said not to.

Write down the approved tools and what never goes into anything else, then give agents an approved tool that does the job, so the workaround stops being the easy option.

Assuming a new CRM or platform will make the team careful with data.

Tools follow the policy, not the other way round. Write the rules, choose tools that let you see and approve the work, and check how agents actually use them.

Banning AI entirely because it might get client details wrong.

Agents use it anyway, out of sight. Approve a tool, keep a person checking every output, and record who used it on what.

Sending the AI policy as an email and assuming it is followed.

Train each agent on three real jobs in the approved tool, and check in a week later on what they are using and for what.

Questions agents ask next

Does the Privacy Act apply to a small real estate agency?

Organisations with an annual turnover above $3 million are covered, and smaller ones can be for other reasons. From 1 July 2026, agencies that are AML/CTF reporting entities must comply with the Privacy Act for their AML/CTF activities. Check your position with a lawyer; this is general information, not legal advice.

Can my agents put client details into ChatGPT?

The OAIC recommends not entering personal information, especially sensitive information, into publicly available generative AI tools. Use a tool your agency has checked and approved for client data, and keep identifying details out of personal accounts.

Do we need to tell clients we use AI?

If you are covered by the Privacy Act, your privacy policy must be current and the OAIC expects it to cover how you use AI. Any AI chat tool on your website should be clearly identified as AI. Saying so plainly also builds trust.

What should an agency AI policy include?

The approved tools and what each is for, what never goes into an unapproved tool, who checks each output, that nothing is sent or decided by a tool alone, what to do when something goes wrong, and a review date with an owner.

Is AI-generated information about a client personal information?

It can be. The OAIC treats information an AI tool infers or generates about an identifiable person as collected, so the usual rules on necessity, accuracy and use apply.

Sources · checked 2026-10-01

Get your team set up in a week.

TopStreet sets up one AI workspace in your agency's name in a week, loaded with your listings, voice and client-data rules, with approvals and a record of what went where. Client work waits for the agent who owns it to approve, and each agent is trained on three real jobs in it. Book a set-up call and see it on one of your listings first.