← All articles
australian migration agent whatsapp 2026 privacy act 1988 apps oaic notifiable data breaches By BossBot Editorial Team · · Updated · 9 min read min read
Drafted with AI assistance under founder-led editorial direction. How our editorial team works.

Australian migration agents 2026: OMARA Code, Privacy Act 1988 + APPs

A british passport sitting on top of a white table
Photo: Ethan Wilkinson · Unsplash

Registered Australian migration agents 2026 face Privacy Act 1988 + APPs + OAIC + OMARA Code of Conduct + Migration Act 1958 + ATO GST 10% + PayID rules before choosing WhatsApp.

In this article Hide ▲
  1. Privacy Act 1988, APPs, and the Notifiable Data Breaches scheme: what the OAIC expects from a migration practice
  2. OMARA, the Registered Migration Agents Code of Conduct, and confidentiality obligations
  3. Migration Act 1958 Section 276 and the fee-for-immigration-assistance monopoly
  4. GST 10%, ATO invoicing rules and the export-services concession
  5. PayID, Osko, NPP and the Australian payment collection landscape for a professional services firm
  6. Document security, biometric data, and the specific privacy sensitivities of migration files
  7. Five hard questions to ask the vendor before signing an annual migration-practice contract

Privacy Act 1988, APPs, and the Notifiable Data Breaches scheme: what the OAIC expects from a migration practice

The Australian Privacy Act 1988 (Cth) is the foundational federal statute governing the handling of personal information by Australian government agencies and by private sector organisations meeting the small business exemption threshold or specified sector exceptions. Most professional service firms — including registered migration agent practices — either exceed the small business turnover threshold (AUD 3 million annual turnover) or fall within specified sectors that lose the exemption regardless of size (health service providers, credit reporting bodies, entities that trade personal information). The practical reality is that virtually every migration agent practice of any meaningful scale is subject to the Privacy Act and the 13 Australian Privacy Principles (APPs). The Office of the Australian Information Commissioner (OAIC) is the independent statutory regulator, empowered to investigate complaints, conduct own-motion inquiries, issue determinations, and refer matters to the Federal Court for civil penalty proceedings. Since 2018 the Notifiable Data Breaches (NDB) scheme requires entities subject to the Privacy Act to notify the OAIC and affected individuals of eligible data breaches — those likely to result in serious harm — as soon as practicable and within a defined period. Migration client data is materially sensitive: passport copies, visa histories, criminal record disclosures, medical certificates for health waivers, family relationship documents, financial records for skilled and business visa streams, biometric identifiers. A migration practice suffering a data breach exposing client passport scans or health information faces immediate OAIC notification obligations, individual notification obligations, and reputational exposure that can end the practice. The Privacy Act Review 2022 (the Government's response published in 2023 and progressive legislative reform through 2024-2026) will materially strengthen the regime: a direct right of action for individuals to seek remedy in court, a statutory tort of serious invasions of privacy, alignment with GDPR-style provisions on children's data, deletion rights, and consent standards. A WhatsApp automation platform choice made in 2026 must accommodate the current regime and adapt to reforms as they land during the currency of a multi-year contract. The APPs relevant to WhatsApp practice include: APP 1 (open and transparent management of personal information — publish a privacy policy), APP 3 (collection of solicited personal information — only collect what is reasonably necessary; sensitive information requires consent or specific legal basis), APP 5 (notification of collection — inform the individual at or before collection about who collects, purpose, disclosures), APP 6 (use or disclosure — only for the primary purpose disclosed or a related secondary purpose the individual would reasonably expect), APP 8 (cross-border disclosure — the Australian entity remains accountable for overseas recipient handling unless exceptions apply), APP 11 (security of personal information — reasonable steps to protect from misuse, interference, loss, unauthorised access), APP 12 (access — individual's right to access personal information about them held by the entity), APP 13 (correction — right to have inaccurate personal information corrected).

OMARA, the Registered Migration Agents Code of Conduct, and confidentiality obligations

The Office of the Migration Agents Registration Authority (OMARA) is the regulatory body responsible for registered migration agents (RMAs), located within the Department of Home Affairs. It was formed through a transitional restructure that unified the earlier Migration Agents Registration Authority (MARA) functions under direct government supervision. The Registered Migration Agents Code of Conduct is a legislative instrument prescribed under the Migration Act 1958 that binds every RMA — breach of the Code can trigger disciplinary action including caution, suspension, cancellation of registration, and referral for prosecution in aggravated cases. Provisions materially relevant to WhatsApp practice include: (a) act in the lawful interests of the client (Clause 2.1) — genuine advocacy, not misleading advice, no false representations to the Department; (b) client confidentiality (Clause 2.7 and related) — protect confidential information disclosed by clients in the course of the engagement, apply reasonable security to protect stored information; (c) client agreement in writing (Clause 5) — before providing services, sign a written agreement setting out the fees, scope, refund policy, complaint process; (d) fee disclosure (Clauses 5, 6, 7) — provide upfront and updated fee estimates, itemise fees on final invoicing, refund unearned fees promptly; (e) file management (Clause 8) — maintain organised client files, provide copies on request, retain files for the retention period specified (typically seven years post-completion); (f) prompt attention (Clause 2.3) — respond to client communications within a reasonable time; (g) do not disparage the Department, tribunals, or the Migration Review process (Clause 2.11) — professional conduct in advocacy; (h) no false statements to the Department (Clause 2.15) — never submit fabricated documents, misrepresent facts, or coach a client to deceive. WhatsApp communications with a client are within the ambit of client file management and confidentiality — messages, images (particularly of documents), and voice notes must be treated with the same confidentiality as email correspondence and paper files. Using a personal WhatsApp account for client communication (rather than a Business account or Business Platform integrated with practice management) blurs boundaries and creates evidence hygiene issues. Using WhatsApp features that expose message content to non-agents (unencrypted device backup, iCloud sync, family-shared devices) risks confidentiality breach. Group chats that include multiple unrelated clients ("a batch WhatsApp group for prospective students") violate confidentiality by exposing each client's contact information and status to the others. Compliant practice uses one-to-one direct messages, integrated with practice management, with retention aligned to Code-mandated file retention periods.

🎯 For small-business owners
Weekly notes on what's actually working for small businesses.
WhatsApp scripts, SaaS-tool comparisons, real revenue tactics — honest, no fluff.

Migration Act 1958 Section 276 and the fee-for-immigration-assistance monopoly

Section 276 of the Migration Act 1958 (Cth) restricts the provision of immigration assistance for a fee to persons who are: (a) registered migration agents (RMAs) under Part 3 of the Migration Act; or (b) Australian legal practitioners with an unrestricted practising certificate. This is a hard prohibition: anyone else who provides immigration assistance for a fee commits a criminal offence, regardless of qualifications held overseas or in other Australian professions. Immigration assistance is broadly defined and includes advising on visa options, preparing visa applications, preparing submissions on character or health grounds, representing clients before the Department of Home Affairs or the Administrative Appeals Tribunal / Administrative Review Tribunal. The practical implication for WhatsApp is that only a registered migration agent or a legal practitioner can lawfully use WhatsApp to advise clients on visa strategy for a fee. A recent migrant who has successfully obtained their own visa and now wants to help friends navigate the system for a small fee is committing an offence. A student consultant based overseas advising Australian visa applicants for a fee via WhatsApp — even if never physically in Australia — is committing an offence and can be pursued by Australian authorities including cancellation of the client's visa on the basis of engagement of unregistered assistance. This has implications for how a legitimate RMA structures WhatsApp communications: any unlicensed staff (paralegals, admin, sales) can undertake administrative and clerical tasks (scheduling, document collection, invoicing) but must not provide substantive advice. A WhatsApp bot flow that appears to give visa advice must be architected such that any substantive legal advice is delivered under the supervision and responsibility of the registered agent — the bot answers process questions ("what documents do I need"), routes substantive questions to the human agent ("you should book a consultation to discuss your character issue"), and does not generate advice content that could be construed as unauthorised advice.

GST 10%, ATO invoicing rules and the export-services concession

The Australian Taxation Office (ATO) administers the Goods and Services Tax (GST) at a standard rate of 10% on most supplies of goods and services in Australia. Migration services provided to a client physically present in Australia are typically GST-taxable at 10%. Migration services provided to a client outside Australia (offshore client applying for a visa to come to Australia) may qualify as GST-free exports under Section 38-190 of the A New Tax System (Goods and Services Tax) Act 1999, provided the specific conditions are met — the services must be provided to a non-resident who is outside Australia at the time of supply and the services must not be effectively used or enjoyed in Australia at that time. The interpretation of these conditions has been the subject of ATO rulings and litigation; a migration practice serving both onshore and offshore clients typically needs professional accounting advice on the GST treatment of specific engagements. GST-registered businesses (those with annual turnover exceeding AUD 75,000 or opting to register voluntarily) must charge GST on taxable supplies, lodge Business Activity Statements (BAS) monthly or quarterly depending on turnover, and issue tax invoices meeting ATO requirements: the words "tax invoice", the seller's identity and Australian Business Number (ABN), the date, a description of the items, the GST amount payable (either separately or as a note that the total includes GST), and the buyer's identity or ABN for invoices AUD 1,000 or more. Migration invoices must also reflect any trust money handling if the practice is a dual-registered lawyer subject to Legal Profession Uniform Law trust account rules — client money held pending disbursement (Department of Home Affairs application fees, disbursements to translation services) must be held in a trust account with strict record-keeping. A WhatsApp automation platform that integrates with Xero, MYOB, or migration-specific practice management systems to generate tax-invoice-compliant documents automatically upon payment confirmation delivers material efficiency. Trying to issue "informal receipts" via WhatsApp does not substitute for a formal ATO-compliant tax invoice for a GST-taxable supply.

PayID, Osko, NPP and the Australian payment collection landscape for a professional services firm

Australia's payment infrastructure has been substantially modernised through the New Payments Platform (NPP), launched in 2018, which enables near-instant payment settlement 24/7. PayID is the addressing service overlay on NPP: a bank customer registers their mobile phone number, email address, or ABN with their bank as their PayID, and payments can be sent to that PayID from any participating bank account. Osko is the specific NPP scheme brand for consumer-facing instant payments. For a migration practice, PayID means a client can pay a fee by initiating a transfer to the practice's PayID from their own bank app, and the funds arrive in seconds with a message reference. This is materially faster than the older direct entry (DE) batch processing that took overnight, and cheaper than card acceptance (no card surcharge, no merchant fee beyond the bank's basic transaction fee). The alternative payment options include: (a) BPAY (biller code and reference) for clients who prefer the older phone-banking or online-banking bill payment interface; (b) Stripe Australia, Square Australia, Tyro, or Zeller for card acceptance (credit and debit cards, tap-to-pay), typically at 1.5-2.5% per transaction; (c) direct debit for scheduled fee instalments under a client agreement; (d) international remittance for offshore clients — Wise, Convera (formerly Western Union Business Solutions), OFX, Airwallex offer competitive currency conversion and receiving mechanisms compared to traditional SWIFT wires. A WhatsApp automation platform integrated with PayID and Stripe Australia can generate a payment request from within the conversation flow: the bot sends a message with the practice's PayID and reference, or a Stripe Checkout link if the client prefers card, and the practice receives automated confirmation upon settlement. For offshore clients, sending a Wise payment request or a multi-currency invoice link allows the client to pay in their local currency at competitive rates, with the practice receiving Australian dollars net of Wise's small conversion fee — often cheaper than SWIFT for the client and faster than international bank transfer. Cash payments for migration services are technically legal but expose the practice to money-laundering scrutiny under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), particularly for sizeable payments; migration practices increasingly refuse cash for anything above modest thresholds and route everything through auditable digital channels.

Document security, biometric data, and the specific privacy sensitivities of migration files

Migration client files typically contain: passport bio-data pages (including passport number, date and place of birth, photograph), visa histories, character disclosures (police clearance certificates from every country of residence for extended periods), health information (medical certificates for permanent visas or high-risk visas, HIV/hepatitis testing results for specified visa classes, mental health disclosures where the client discloses relevant history), biometric identifiers (fingerprints, iris scans in some processes), family relationship evidence (birth certificates, marriage certificates, statutory declarations), financial records (bank statements, tax returns, employer letters, business financial statements for skilled and business visa applications). Under the Privacy Act 1988, health information and biometric information are sensitive information (APP 3.3), requiring explicit consent for collection except where specific legal basis applies. Migration client consent to collect these categories is normally embedded in the client agreement, but the WhatsApp channel introduces specific security considerations. Passport scans sent via WhatsApp are held on Meta infrastructure (the message itself is end-to-end encrypted between sender and recipient devices, but WhatsApp Business Platform routes through Meta's cloud with different encryption model than the consumer app; the vendor's DPO should confirm the specific handling). Backup of WhatsApp messages to iCloud, Google Drive, or the vendor's cloud with different encryption than device-level may reduce the security of the sensitive document. Group chats that include family members ("a family group with the primary applicant and their partner and their sponsor parent") mean that each participant sees the documents shared — a partner's police clearance visible to the sponsor parent may reveal information the partner would not have chosen to share. A compliant practice: (i) uses one-to-one direct messages for sensitive document exchange, not group chats; (ii) instructs clients to remove sensitive documents from their own device after successful upload to the practice's secure system; (iii) prefers a separate encrypted document exchange platform (LEAP Portal, Actionstep Client Portal, encrypted email with S/MIME, encrypted PDF with passphrase shared separately) for the most sensitive documents; (iv) trains staff never to forward client documents from WhatsApp to personal email or messaging accounts; (v) implements a clear document lifecycle — collection, use for the migration application, retention per Code of Conduct minimum, secure deletion after retention period. A WhatsApp automation platform serving migration practices should offer message search, automated file categorisation, and secure archival that supports these requirements — treating WhatsApp as a transient conversation channel with permanent storage in the practice management system is the safer architecture.

Five hard questions to ask the vendor before signing an annual migration-practice contract

Before a registered migration agent or the principal of an Australian migration practice signs an annual subscription with a WhatsApp automation platform, five written questions should be put to the sales representative with a demand for documented replies (dated emails with attachments, contract extracts, feature screen captures): (1) does the consent capture workflow comply with the Australian Privacy Act 1988 and the APPs including APP 3.3 for sensitive information consent, in English, with timestamped logging, one-click revocation, and exportable consent register defensible in an OAIC investigation or an OMARA disciplinary complaint? (2) does the contractual Data Processing Addendum explicitly cover the Privacy Act 1988 and APPs (particularly APP 8 on cross-border disclosure — the Australian entity remains accountable for overseas recipient handling unless narrow exceptions apply), specify data hosting location (Australian hosting through AWS Sydney or Azure Australia East is a strong compliance signal for migration data), and provide breach notification aligned with the NDB scheme? (3) does the platform natively support PayID, Osko, BPAY, EFTPOS/Stripe Australia/Square Australia for card payments, plus international remittance mechanisms (Wise, Convera, OFX) for offshore clients paying visa fees from their home country — or does it force manual sharing of bank account details and BSB? (4) does the invoicing integrate with Xero, MYOB, Reckon, QuickBooks Australia or migration-specific practice management systems (LEAP, LawMaster, Actionstep, Migration Manager, Vsimm, MigrationCloud) generating tax-invoice-compliant documents automatically, with correct GST 10% treatment and the export-services concession where applicable? (5) is the pricing invoiced in Australian dollars (AUD) with GST 10% and ATO-compliant tax invoice issued by an Australian-registered entity, allowing the practice to claim input tax credit, or in USD with imported services and reverse-charge complications? If replies are evasive or negative on multiple points, the vendor has not adequately matured for the regulated Australian professional services market despite a potentially attractive product demonstration. A migration practice paying AUD 100 to AUD 2,000 per month for automation expects both operational function and regulatory alignment with the OAIC, OMARA, ATO, and NPP infrastructure that clients now expect.

Sources

Data + numbers referenced in this article are sourced from these public documents:

  1. Privacy Act Review Report 2022 (Attorney-General's Department)
  2. ATO — Tax invoice requirements
  3. NPP Australia — New Payments Platform
  4. PayID information (NPP Australia)
  5. WhatsApp Business Platform (Meta for Developers)

Frequently Asked Questions

The small business exemption under the Privacy Act 1988 applies to businesses with annual turnover below AUD 3 million, but the exemption is lost if the business (a) provides health services and holds health information (migration practices frequently do — medical certificates, HIV testing results for specified visas, mental health disclosures); (b) trades in personal information; (c) is a Commonwealth contractor; (d) is a credit provider or credit reporting body; (e) opts in to the Privacy Act coverage. A migration practice that handles even a small volume of health information (which is unavoidable in practice for permanent residence and specific temporary visa streams) technically loses the small business exemption for that data. Combined with the Privacy Act Review 2022 reforms progressively removing the small business exemption entirely, the safer posture for any migration practice — regardless of current turnover — is to design its operations for full Privacy Act compliance from the outset. OMARA Code of Conduct confidentiality obligations apply independently regardless of the Privacy Act status, so the substantive standards are similar in either case.
Not indefinitely, and not without appropriate security. APP 11 requires reasonable steps to protect personal information from unauthorised access, use, disclosure, and misuse; APP 4.3 requires destruction or de-identification of personal information no longer required for a purpose. OMARA Code of Conduct Clause 8 specifies file retention obligations (typically minimum seven years post-completion of the matter, longer for specific matters). Practical implication: WhatsApp chat history is not an appropriate long-term storage for sensitive documents. Best practice is: (a) receive the document via WhatsApp, save it immediately to the encrypted practice management system with appropriate access controls; (b) delete or archive the WhatsApp copy within a defined workflow window (some practices delete after client file is opened; others keep for the duration of the active matter and delete on file closure); (c) retain the master copy in the practice management system for the OMARA-required retention period; (d) securely destroy after the retention period. WhatsApp Business Platform archives via the vendor's cloud add another layer to consider — the DPA with the vendor should include commitments on data deletion aligned with the practice's retention policy. Client agreements should mention the document handling flow so clients understand and consent.
Yes, WhatsApp messages are admissible as electronic evidence subject to authentication and chain-of-custody considerations. The Evidence Act (Cth) and state equivalents govern admissibility; WhatsApp messages can be produced via export from the app (WhatsApp offers export as text or with media, and forensic tools can produce more detailed extractions). For the RMA using WhatsApp with clients, the practical implications are: (a) WhatsApp exchanges between agent and client can be produced by either party in the review — messages that appear to make representations to the Department, or that establish the timeline of instructions, are potentially relevant; (b) messages between agent and client that are candid discussions of case strategy may be subject to legal professional privilege only where the RMA is also a legal practitioner and the communication is for the purpose of legal advice — RMAs who are not lawyers do not have privilege in the same way and their communications may be discoverable; (c) messages that record fabrication of documents, coaching of applicants to deceive, or advice to withhold material facts from the Department are potentially incriminating and can trigger criminal and Code of Conduct consequences. The safer practice: professional and factual communication, no candid strategy discussions on WhatsApp that would be embarrassing if seen by a Tribunal member, retention of the WhatsApp record as part of the file, and separate confidential communication channels (in-person meetings, phone calls without recording) for strategic discussions where the RMA is not a lawyer with privilege coverage.
Under Section 38-190 of the A New Tax System (Goods and Services Tax) Act 1999, a supply is GST-free where it is a supply of a right or option to acquire something else that would be GST-free, or where it is a supply of a service to a non-resident who is not in Australia when the service is performed, and the service is not effectively used or enjoyed in Australia at that time. For migration services, the ATO's practical interpretation (subject to specific rulings) is that services provided to an offshore visa applicant preparing their application from outside Australia can be GST-free, but services provided to an onshore visa applicant, or services provided to a family member in Australia paying on behalf of an offshore applicant, may be taxable. The specific application depends on where the client physically is at the time of supply, who is paying, and where the service is effectively enjoyed. This is a technical area — every migration practice serving mixed onshore/offshore clientele should obtain professional accounting advice on the GST treatment. Documentation of the client's location at time of engagement, and of the payment source, is important. An invoice that incorrectly treats an onshore service as GST-free risks ATO reassessment; an invoice that incorrectly treats an offshore service as GST-taxable overcharges the client and may need refund. A WhatsApp platform integrated with practice management should be configured to prompt for onshore/offshore status at intake so the correct invoicing template flows through automatically.
Several progressive reforms are expected to take effect during 2024-2026. The most consequential for migration practice include: (a) removal of the small business exemption (progressively) — will bring all migration practices regardless of turnover under full Privacy Act coverage, aligning with the OMARA Code obligations; (b) direct right of action for individuals — currently individuals must complain to the OAIC which then decides whether to investigate; the reform will allow individuals to bring actions directly in the Federal Court for privacy breaches, materially increasing exposure; (c) statutory tort of serious invasions of privacy — creating a new cause of action in tort for serious privacy breaches, opening the door to damages claims; (d) tightening of consent standards toward GDPR-style specific, informed, unambiguous consent — will require reviewing existing client agreement and privacy policy language; (e) new obligations around children's data (relevant for migration matters involving minor children); (f) new mandatory data breach reporting timeframes potentially tightened from current "reasonable practicable time" to a defined period; (g) new right to erasure aligned with GDPR (with exceptions). A migration practice signing a multi-year WhatsApp platform contract in 2026 should choose a vendor with demonstrated capacity to adapt product features to these reforms as they land — a platform vendor with an EU/GDPR compliance track record is generally better positioned than one focused solely on lower-regulation markets.
What a conversation looks like
🤖
BossBot AI
● Online
Hi! I came across your business and wanted to find out more
Hi there! Happy to help 😊 What would you like to know? I can help with bookings, pricing, availability, or any questions you have.
Great — do you have any appointments available this week?
Yes! I have availability Tuesday and Thursday this week. What time of day works best for you?
Thursday afternoon if possible
Thursday afternoon is available ✅ I'll get that booked for you. Can I take your name to confirm?
How did this land for you?
Tap what fits. Anonymous, one per browser.
✨ Recorded. Thanks for the vote.
📧 Small business owner? Weekly notes on what actually works. Free.