# Verify more, store less: real estate's new trust stack

Real estate agencies do not need to choose between reliable identity checks and better privacy.
The stronger direction for PropTech and RegTech is to verify what is necessary, keep only justified
evidence and make human responsibility clear.

For agents, that can mean fewer identity documents moving through inboxes, downloads and shared
folders. For principals, it can mean a more defensible answer to four questions: what did we
collect, why did we need it, who reviewed it and what did we retain?

This article is general information. It does not determine which obligations apply to a particular
business or matter and is not legal, privacy or compliance advice.

## The 2026 shift: prove what matters, copy less

The privacy and AML/CTF reforms now meet inside the same client workflow.

The Office of the Australian Information Commissioner (OAIC) says real estate professionals newly
brought into the AML/CTF regime also come within the Privacy Act from 1 July 2026. Its updated
guidance says reporting entities should collect only personal information that is reasonably
necessary for their AML/CTF obligations and broader organisational functions.

The guidance also says businesses should not retain copies of full identity documents for AML/CTF
record-keeping purposes after the reforms, unless another law requires it. That does not mean
keeping no evidence. It means designing the record around what the agency must be able to
demonstrate, rather than treating every passport or driver licence copy as the default record.

A useful internal question is therefore not simply, “Did we see an ID?” It is:

> What result, reference, decision and supporting evidence does our program require us to keep,
> and when should information we no longer need be deleted?

The answer belongs in the agency's approved policies and privacy practices. Frontline staff should
not have to invent it one client at a time.

## Why the RentTech and Digital ID developments matter

Privacy is not only a policy-document issue. The design of the collection process matters too.

In April 2026, the Privacy Commissioner found that the 2Apply rental technology platform collected
some personal information excessively and by unfair means. The determination concerned IRE and
2Apply. It was not a finding against every platform or agency, but the OAIC said other RentTech
providers should consider the findings and adapt their practices where needed.

Two months later, the Australian Government published results from a rental application pilot that
used Digital ID instead of asking applicants to scan and share multiple identity documents. It
also tested Consumer Data Right information as an alternative to sharing payslips and bank
statements for rental affordability. The government reported pilot estimates of approximately AUD
150 saved per rental listing and up to 70 hours per month for participating real estate
businesses.

Those figures are pilot estimates, not a promise of the result for every agency. More importantly,
the contexts must stay separate: **The rental pilot is not an AML/CTF rule, and it does not change an agency's sales-side AML/CTF obligations.** An agency must still apply the customer due diligence
process required by the law and its own program when it provides a designated service.

The pilot is useful as a design signal. It shows what can become possible when a workflow proves a
needed fact without passing the largest possible bundle of raw documents between people and
systems.

## Useful automation still needs visible human control

RegTech is increasingly being used to organise information, identify gaps and move work to the
right person. The Australian Communications and Media Authority describes RegTech as a tool that
can support efficient decision-making across sectors, while emphasising that it does not replace
human oversight.

That boundary is especially important when AI is involved. ASIC reported in May 2026 that AI is
becoming embedded in everyday financial operations. At the same time, the OAIC's 2026 community
survey found very low trust in AI companies and reported that 68% of respondents would be more
likely to use digital services requiring personal information if they knew their data was handled
fairly and responsibly.

For a real estate agency, the practical rule is simple: **technology can prepare the evidence; people remain responsible for the decision.**

Technology can assist with:

- presenting approved collection questions consistently;
- recording that a verification step occurred and linking the supporting evidence;
- identifying incomplete fields, mismatches or tasks that need attention;
- routing an exception to the right agent, principal or compliance officer;
- keeping time-stamped actions and review notes together; and
- reminding the team when a review, follow-up or deletion action is due.

People still need to:

- decide what the agency's program requires for the customer and designated service;
- interpret identity mismatches and other facts in context;
- apply the agency's risk assessment and customer due diligence policies;
- decide whether more information, enhanced due diligence or escalation is needed;
- resolve screening results and approve exceptions; and
- decide whether a reporting obligation may apply.

A neat automated result is not a substitute for professional judgement, especially when the input
is incomplete or the circumstances do not fit the normal workflow.

## What agents can do now

Frontline agents make the trust stack real. The most useful habits are straightforward:

1. **Use the approved collection path.** Avoid moving client identity material into personal
   inboxes, local downloads or unapproved apps just because it feels faster.
2. **Explain the purpose.** Tell the client why the information is being requested and direct them
   to the agency's collection notice. Do not improvise a broader reason for collecting it.
3. **Collect the defined information.** More data is not automatically better evidence. Follow the
   agency's program and privacy process instead of adding “just in case” fields or copies.
4. **Check for mismatches.** Notice differences in names, ownership information, contact details or
   the person giving instructions. Record the observable fact rather than labelling the client.
5. **Treat remote friction carefully.** AUSTRAC identifies attempts to avoid KYC, documents that
   appear altered, unusual insistence on online-only verification and unexplained intermediaries as
   possible real-estate risk indicators. **A red flag is a prompt to investigate, not proof of wrongdoing.**
6. **Escalate instead of improvising.** Use the agency's defined path when the normal process does
   not fit. The agent's job can be to spot and record the issue; they do not have to make every
   compliance decision alone.
7. **Finish the record.** Capture what was checked, what exception arose, who reviewed it and the
   next action. Follow the agency's retention and deletion rules rather than keeping an extra copy.

For more detail on the difference between entity verification and the agency's CDD decision, read
[How AMLHive uses KYB to support CDD decisions](/Compliance/compliance-blog/kyb-entity-cdd-routing).

## What principals can do now

Principals and AML/CTF compliance officers own the design around the agent's work. A practical
review can start with seven actions:

1. **Map each field to a purpose.** For every identity or financial field, record the operational,
   AML/CTF or other legal reason for collecting it.
2. **Define acceptable evidence.** State when the process needs a verified result, a reference, a
   document detail or a document copy. Record any separate legal basis for retaining a full copy.
3. **Set access deliberately.** Limit who can view sensitive information and make access visible
   in the audit trail.
4. **Set retention and deletion rules.** Cover successful matters, abandoned enquiries, duplicate
   uploads, expired links and exceptions. Make the action operational rather than leaving it as a
   sentence in the privacy policy.
5. **Give staff an exception path.** Define who reviews an identity mismatch, an inaccessible
   standard document, a remote customer or an unusual ownership structure.
6. **Train with real workflow examples.** Show staff what to collect, where to put it, what not to
   copy and when to escalate.
7. **Review the evidence trail.** Sample completed and abandoned matters. Look for unnecessary
   copies, access that is too broad, missing rationales and unresolved exceptions.

AUSTRAC's [real-estate risk-indicators article](/Compliance/compliance-blog/real-estate-amlctf-risk-indicators)
provides a useful structure for staff escalation without turning indicators into automatic
conclusions.

## Seven questions to ask a PropTech or RegTech vendor

A product demonstration should answer operational questions, not only show a fast happy path:

1. **What information does the product collect, and why is each field needed?**
2. **Does it retain full identity documents, or can it retain an appropriate verification result,
   reference and decision record instead?**
3. **Where is the information stored and processed, which service providers can receive it, and
   can the vendor support the agency's disclosure obligations?**
4. **Which users can see sensitive information, and does the product keep a usable access and
   decision history?**
5. **Where is human approval required, especially for risk ratings, screening matches, exceptions
   and reporting decisions?**
6. **How can the agency apply retention, deletion, correction and export requirements without
   relying on a support ticket for every record?**
7. **What happens when verification is unavailable, data conflicts, an AI extraction is wrong or
   an integration fails?**

The best answer is not always “we automate everything.” It is a clear description of the input,
the result, the person responsible, the evidence retained and the failure path.

## Where AMLHive fits

AMLHive helps Australian real estate agencies organise customer due diligence, screening,
assigned actions, escalation and evidence around their documented AML/CTF program. Its guided
workflow and audit support can reduce scattered administration while keeping review and approval
visible.

AMLHive does not provide legal advice or determine the legal outcome for a customer. It does not automatically lodge reports with AUSTRAC. **The agency retains its AML/CTF decisions and legal responsibility.**
The product does not currently claim an integration with the Australian Government Digital ID
System or Consumer Data Right; those developments are discussed here as property-industry signals.

Explore AMLHive's current [product capabilities](/product) and [security approach](/security), or
start a **14-day free trial** to see how a structured workflow can support your team.

## Sources

- [OAIC - Updated AML/CTF privacy guidance](https://www.oaic.gov.au/news/media-centre/know-your-privacy-obligations-under-the-anti-money-laundering-counter-terrorism-financing-amlctf-act-updated-oaic-guidance) (published 27 February 2026; accessed 16 July 2026)
- [OAIC - RentTech platforms must stop unfair and excessive personal information collection](https://www.oaic.gov.au/news/media-centre/renttech-platforms-must-stop-unfair-and-excessive-personal-information-collection%2C-says-privacy-commissioner) (published 22 April 2026; accessed 16 July 2026)
- [Australian Government Digital ID System - Digital ID renters' pilot](https://www.digitalidsystem.gov.au/news/digital-id-renters-pilot-reducing-the-excessive-collection-of-renters-personal-information) (published 26 June 2026; accessed 16 July 2026)
- [ACMA - Research on emerging technologies](https://www.acma.gov.au/acma-research-emerging-technologies) (updated 21 April 2026; accessed 16 July 2026)
- [ASIC - Innovation in financial technology and RegTech](https://www.asic.gov.au/about-asic/news-centre/find-a-media-release/2026-releases/26-102mr-australia-well-placed-to-unlock-opportunities-from-innovation-in-the-financial-system/) (published 21 May 2026; accessed 16 July 2026)
- [OAIC - Australian Community Attitudes to Privacy Survey release](https://www.oaic.gov.au/news/media-centre/australians-more-concerned-about-privacy-as-trust-in-ai-languishes%2C-survey-finds) (published 28 May 2026; accessed 16 July 2026)
- [AUSTRAC - Risk insights and indicators for the real-estate sector](https://www.austrac.gov.au/industry-and-business/education-and-resources/publications-and-resources/risk-insights-and-indicators-suspicious-activity-real-estate-sector) (accessed 16 July 2026)

This article is general information only and is not legal, financial, privacy or compliance
advice. Check current AUSTRAC and OAIC guidance and obtain independent advice for your agency's
circumstances.
