Walk into almost any open home and you will be asked for the same thing: your name, phone number and perhaps your email address. You write them down, walk through the property and probably never think about that sign-in sheet again.
But where do those details go next?
They may be entered into an agency's CRM, added to a contact database and used to communicate with you long after the open home is over. For years, this has been a routine part of real estate. In 2026, however, it has caught the attention of Australia's privacy regulator.
In January, the Office of the Australian Information Commissioner (OAIC) launched its first privacy compliance sweep, reviewing the privacy policies of businesses that collect personal information face-to-face. One of the regulator's own examples was particularly familiar to real estate: agents asking for phone numbers at open homes.
And that is only one part of a much broader shift. New anti-money laundering requirements, ongoing privacy reforms and changes across the Tasman are placing greater attention on how businesses collect, use and manage personal information.
For real estate agencies, this raises a bigger question than compliance alone. A database containing tens of thousands of contacts may look like one of the agency's greatest assets. But how valuable is that database if the agency cannot confidently explain where those contacts came from, what they were told when their information was collected, or whether they still want to hear from them?
In 2026, the question is no longer simply how big your database is. It is how well you know the people in it, and how well their information is being managed.
What the privacy regulator actually looked at
The January compliance sweep was not about stopping agents from collecting personal information. It was about whether businesses were transparent about what happened to that information afterwards.
For its first privacy compliance sweep, the OAIC reviewed approximately 60 businesses across six sectors where personal information is commonly collected face-to-face, including rental and property businesses.
Under Australian Privacy Principle 1.4, businesses covered by the Privacy Act must explain what personal information they collect, why they collect it, how it may be used or disclosed, and how individuals can access or correct it.
For real estate agencies, this puts an everyday practice under the spotlight. When someone provides their phone number at an open home, do they know how it will be used? Does the agency's privacy policy reflect what actually happens? And if that person ends up in a marketing database, can the agency explain how they got there?
The OAIC said businesses with non-compliant privacy policies may face compliance or infringement notices, with penalties of up to $66,000.
The message for agencies is clear: collecting customer information is only the beginning. How that information is used and managed matters too.
What changed on 1 July
Privacy was not the only regulatory change to reach real estate in 2026. From 1 July, the industry's obligations expanded under Australia's anti-money laundering and counter-terrorism financing reforms, known as AML/CTF Tranche 2.
The reforms brought real estate professionals into the AML/CTF regime, requiring agencies to take additional steps to identify and verify customers and manage information collected for these purposes. The aim is to make it harder for criminals to use property transactions to hide or move illicit money.
But for agencies, there is an important privacy consequence too. Many smaller businesses have traditionally relied on the Privacy Act's small business exemption. Under the Tranche 2 reforms, even businesses that would otherwise qualify for that exemption can become subject to Privacy Act requirements for personal information handled as part of their AML/CTF obligations.
This does not mean every contact in an agency's CRM suddenly falls under the Privacy Act. It does mean agencies are operating in an environment where the information they collect is subject to greater scrutiny and responsibility.
For principals, the takeaway is simple: knowing what information the agency holds, why it was collected and how it is being managed is becoming increasingly important.
Why privacy rules are only getting stricter
The changes that arrived in 2026 are part of a much broader shift in how Australia approaches privacy.
Most small businesses with an annual turnover of $3 million or less are still generally exempt from the Privacy Act, unless a specific exception applies. However, the future of that exemption is uncertain. The OAIC has recommended its removal, arguing that the risks associated with personal information no longer depend on the size of the business holding it.
Importantly, the small business exemption has not been removed across the board. Broader changes to the exemption remain part of the ongoing privacy reform discussion, so agencies should be careful not to treat proposed reforms as existing law.
What has changed is the direction of travel. The January compliance sweep, the July AML/CTF changes and Australia's wider privacy reform agenda all point towards greater accountability for how businesses collect and manage personal information.
For agencies, waiting until every proposed reform becomes law may miss the bigger picture. The safer question is whether the way customer information is being managed today would stand up to the privacy expectations of tomorrow.
What is New Zealand doing?
Australia is not the only country tightening the rules around personal information. On 1 May 2026, New Zealand introduced Information Privacy Principle 3A (IPP 3A), which specifically addresses information collected indirectly.
Indirect collection happens when a business receives someone's personal information from another source rather than directly from that person. Under the new rule, businesses generally need to take reasonable steps to notify the individual that their information has been collected, why it was collected and who may receive it, unless an exception applies.
For real estate, this could be relevant when contact information comes through sources such as referrals, other agents or branches, rather than directly from the individual.
For agencies operating across Australia and New Zealand, this is already another privacy requirement to manage. For Australian agencies, it also provides a useful example of the broader shift towards greater transparency around how businesses build and manage their databases.
What this means for your marketing database
For years, the size of a real estate database has been treated as a measure of its value. More contacts meant more potential buyers, sellers and opportunities.
But a database of 40,000 contacts is only valuable if the agency understands who those people are, where their details came from and whether they can appropriately be contacted.
That starts with provenance. If someone entered the database through an open home, website enquiry, referral or another source, the agency should be able to identify that journey. This becomes particularly important when personal information is used for direct marketing, as individuals may have the right to ask where their information came from.
Consent also needs to be treated as more than a box that was ticked years ago. For commercial emails and messages, agencies need to ensure they have the appropriate consent to contact recipients and maintain records of how that consent was obtained. What someone was told when they provided their details matters too. Giving a phone number to attend an open home does not automatically mean a person expects every possible form of future marketing.
The same principle applies at the other end of the relationship. When someone unsubscribes, that preference needs to be reflected across the agency's marketing processes. Australian spam rules require commercial electronic messages to provide a simple way to unsubscribe and generally require requests to be actioned within five working days.
This is where database hygiene becomes more than a marketing exercise. Outdated details, unclear sources, inactive contacts and inconsistent unsubscribe records can make a large database less useful and harder to manage.
A smaller database of people who are genuinely engaged and whose information is properly managed can ultimately be more valuable than a much larger list of contacts an agency knows very little about. Cleaner data means teams can spend more time communicating with people who actually want to hear from them, while building greater confidence in the information behind every campaign.
The goal should not simply be to grow the database. It should be to build one the agency can trust.
The audit a principal can run this quarter
The regulatory landscape may be complicated, but reviewing your database does not have to be. A good place to start is with a simple audit of what your agency holds, where it came from and how it is being used.
Know where your contacts came from
Review the different ways people enter your database, from open homes and website enquiries to referrals and imported lists. Make sure the source of each contact is recorded wherever possible.
Check what people are told when you collect their details
Look at open home forms, website forms and other collection points. Do they clearly explain why information is being collected and how it may be used?
Review your marketing consent records
Make sure the agency can identify how and when consent to receive marketing was obtained where required, rather than assuming every contact can be marketed to indefinitely.
Check your unsubscribe process
Test what happens when someone opts out. Their preference should be recorded and respected across the agency's marketing activity.
Clean up outdated and inactive contacts
Identify duplicate, inaccurate and long-term inactive records. A larger database is not necessarily a better one if much of the information is outdated or unusable.
Compare policy with practice
Your privacy policy should reflect what actually happens inside the agency. Check that the way staff collect and handle information matches what customers are being told.
Make database health an ongoing process
Do not treat this as a one-off clean-up. Regular reviews of consent, contact sources, engagement and data quality can help keep the database useful and trustworthy over time.
The result should not simply be a smaller database. It should be a database the agency understands and can confidently use.
A better database is a safe database
The privacy changes of 2026 should not just be viewed as another compliance burden. They are an opportunity for agencies to take a closer look at one of their most valuable assets.
A clean, trusted database is the starting point. The next challenge, particularly for enterprise agencies managing tens of thousands of contacts, is knowing what to do with it.
This is where iRealty goes beyond simply helping agencies maintain their database. Our patented technology can analyse engagement across large databases, identifying the behavioural signals that indicate which contacts may be moving closer to a property decision. Rather than treating thousands of contacts as one static list, agencies can better understand who is engaging, what they are interested in and when it may be time for an agent to make contact.
And identifying those opportunities is only part of the equation. iRealty helps agencies consistently nurture the wider database with relevant communication, keeping relationships warm until the timing is right. Built specifically for real estate and designed to scale from individual agents to multi-office brands, the platform gives larger agencies a way to manage database communication without losing relevance as their contact lists grow.
The goal is not to have the biggest database. It is to have one you can trust, understand and put to work.
Build a database you can trust
Talk to the iRealty team about how engagement signals across your database can surface the contacts closest to a property decision.
Book a Strategy CallSources
- OAIC: Privacy compliance sweep to put privacy policies under the spotlight
- Real Estate Business: OAIC privacy compliance reform, practical implications for real estate agencies
- National Law Review: Australia's privacy regulator begins 2026 with its first compliance sweep
- HWL Ebsworth: Small businesses, big change. Privacy obligations under Tranche 2 of the AML/CTF reforms
- Coleman Greig: AML/CTF reforms for real estate in Australia under Tranche 2
- NZ Ministry of Justice: New privacy information principle
- Bell Gully: Preparing for IPP 3A, new requirements effective 1 May 2026
- Property Noise NZ: New Zealand's new privacy laws are changing prospecting
- DLA Piper Data Protection: Australia, electronic marketing