Privacy Act guide · general information, not legal advice

Privacy policy for conveyancers (2026)

Acting for a client in a property transaction is a designated service under the AML/CTF Act, so the Privacy Act applies to the information you collect for AML/CTF purposes, whatever your turnover. This guide sets out what your privacy policy must contain, where customer due diligence fits, and what changes on 10 December 2026.

Last checked 25 September 2026 against the Privacy Act 1988 compilation C2026C00227, the Privacy and Other Legislation Amendment Act 2024 (C2024A00128), the AML/CTF Act 2006 compilation C2026C00274 and the OAIC guidance for reporting entities updated 28 August 2026

APP 1.4 the law, read in the authorised textOAIC guidance the regulator's published guidance, which is not law

Does the Privacy Act apply to your practice?

A business with annual turnover of $3,000,000 or less is generally a small business operator and outside the Privacy Act, unless one of the cases in s 6D(4) applies.1 s 6D(1) s 6D(4) A practice above that threshold is generally covered for all its handling of personal information.

A small practice that provides a Table 6 designated service is covered for that part of its work. If a small business operator is a reporting entity under the AML/CTF Act, the Privacy Act applies to its activities for the purposes of, or in connection with, the AML/CTF Act, Regulations or Rules as if it were an organisation.2 s 6E(1A) AML/CTF obligations applied from 1 July 2026 to the professional services in AML/CTF Act s 6 Table 6.3 AML/CTF Act s 6 Item 1 covers assisting a person to plan or carry out a transaction to sell, buy or otherwise transfer real estate, or acting for them in it, in the course of a business. Receiving, holding or managing a client's money as part of that transaction can also be a designated service (item 3), subject to the exclusions in AML/CTF Act s 6(5C).

If the Privacy Act applies to you only because of s 6E(1A), the OAIC says your policy need only describe your AML/CTF handling.4 OAIC

What the policy must contain

APP 1.3 requires a clearly expressed and up-to-date privacy policy about how you manage personal information, and APP 1.4 lists what it must contain. APP 1.5 requires you to make it available free of charge and in an appropriate form, usually on your website.5 APP 1.3 APP 1.4

APP 1.4 contents, with the AML/CTF handling a conveyancer describes
APP 1.4 requires What to write about AML/CTF handling
(a) The kinds of personal information you collect and hold Know-your-customer details: names, dates of birth, addresses, identity document details and verification results; details of beneficial owners and people acting for a client; politically exposed person and sanctions screening results
(b) How you collect and hold it From the client, from people acting for the client, from any verification or screening service or agent you use, and from another firm whose procedure you rely on; where the records are kept
(c) The purposes Customer due diligence, ongoing monitoring, reporting to AUSTRAC and record-keeping under the AML/CTF Act and Rules
(d) Access and correction How to ask, and who to ask
(e) Complaints How to complain about a breach of the APPs, and how you will deal with the complaint
(f) and (g) Overseas disclosure Whether a provider, such as a cloud system or verification service, is likely to receive the information overseas, and the countries, if it is practicable to name them

Sources for the table: Privacy Act Schedule 1, APP 1.4,5 and the OAIC's guidance for reporting entities.4 OAIC

Before any overseas disclosure, APP 8.1 requires reasonable steps to ensure the recipient does not breach the APPs.5 APP 8.1

Where customer due diligence data fits

Before providing a designated service, you must establish on reasonable grounds the customer's identity; the identity of anyone on whose behalf the customer receives the service, and of anyone acting for the customer; for a customer that is not an individual, its beneficial owners; whether any of them is a politically exposed person or designated for targeted financial sanctions; and the nature and purpose of the business relationship or occasional transaction.3 AML/CTF Act s 28 For Table 6 item 1, your customer is the person you act for.3

Where a client is a company or trust, you collect information about its owners and controllers through the client. APP 5.2(b) requires reasonable steps to tell a person when you collect about them from someone else, and the circumstances.5 APP 5.2 The OAIC's guidance accepts that collecting directly from beneficial owners may be unreasonable or impracticable.4 OAIC

Three further points from the OAIC's guidance:4 OAIC

  • When a sale falls through. In the OAIC's example, a multi-disciplinary law firm collects know-your-customer information at onboarding because the engagement may involve selling a client's house. That collection is permitted even if no sale happens, and the records must still be kept. Doing customer due diligence on all customers at onboarding "merely because this is helpful, desirable or convenient" is unlikely to meet the reasonably necessary test in APP 3.2.
  • Sensitive information. Screening for politically exposed persons can collect sensitive information, such as whether a person belongs to a political association. APP 3.4(a) allows that without consent where the AML/CTF Act or Rules require or authorise it.
  • No ID copies needed. The AML/CTF Act does not require scanned copies or photocopies of identity documents. Keep the details and the verification outcome, and destroy or de-identify copies once no longer needed. APP 11.2

Customer due diligence records are kept for 7 years from the end of the business relationship or the completion of the occasional transaction.3 AML/CTF Act s 111

The collection notice

The policy is general. APP 5.1 separately requires reasonable steps, at or before collection, to notify the APP 5.2 matters, including who you are, the purposes, the main consequences of not providing the information, your usual disclosures and any overseas recipients.5 APP 5.1 Where the law requires the collection, one of those matters is that fact and the name of the law (APP 5.2(c)): here, the AML/CTF Act or Rules. For a conveyancer, the main consequence is usually that you cannot start providing the designated service until customer due diligence is done.3

The OAIC says you need not give notice content that would tip off a client.4 OAIC Disclosing that a suspicious matter report has been or must be made, where that could prejudice an investigation, is an offence.3 AML/CTF Act s 123

From 10 December 2026: automated decisions

APP 1.7 to 1.9 commence on 10 December 2026, the day after the 24-month period that began with Royal Assent on 10 December 2024.6 POLA Act s 2 If a computer program makes, or does a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect a person's rights or interests, using personal information about them, the policy must describe the kinds of personal information used and the kinds of decisions.6 POLA Act Sch 1 item 88 Check whether any electronic verification or screening service you use decides, or all but decides, whether you can act for a client. See automated decision-making disclosure.

Breaches and penalties

If you are aware of reasonable grounds to suspect an eligible data breach, you must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days of becoming aware.7 s 26WH(2) See the data breach response plan.

A missing policy, or one without the APP 1.4 contents, is a matter under s 13K: a civil penalty of up to 200 penalty units ($72,800) for a person other than a body corporate and 1,000 penalty units ($364,000) for a body corporate, at $364 a unit for conduct on or after 1 July 2026, or an infringement notice.7 s 13K See Privacy Act penalties 2026.

Start here

Read AML tranche 2 and the Privacy Act for the full KYC picture. For your AML/CTF program, see AML/CTF for conveyancers. More in the Privacy Act section. Every source we use: sources.

AMLCompliant is published by Wani Meridian Pty Ltd, an independent private business. We are not affiliated with, or endorsed by, the Office of the Australian Information Commissioner, AUSTRAC, the Attorney-General's Department or any other government body. This guide is general information, not legal advice.

Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.

Sources

Law is quoted from the authorised text on the Federal Register of Legislation, opened 25 September 2026. OAIC pages are guidance, not law. They open in a new window, and linking to them does not mean the OAIC endorses this page.

  1. Privacy Act 1988 ss 6C(1), 6D(1) and 6D(4), compilation No. 104 (C2026C00227), compilation date 4 June 2026. legislation.gov.au/C2004A03712/latest/text

  2. Privacy Act 1988 s 6E(1A).

  3. Anti-Money Laundering and Counter-Terrorism Financing Act 2006, compilation C2026C00274: AML/CTF Act s 6 Table 6 (items 1 and 3), AML/CTF Act s 6(5C), AML/CTF Act s 28, AML/CTF Act s 111(2) and AML/CTF Act s 123. Commencement: AML/CTF Amendment Act 2024 (C2024A00110), Schedule 3, item 11. legislation.gov.au/C2006A00169/latest/text

  4. OAIC, "Privacy guidance for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act", updated 28 August 2026, including its Example 1 (a multi-disciplinary law firm onboarding a client who may sell a house). Guidance, not law. oaic.gov.au

  5. Privacy Act 1988, Schedule 1 (Australian Privacy Principles), APP 1.3 to 1.5, 3.2, 3.4, 5.1, 5.2, 8.1 and 11.2.

  6. Privacy and Other Legislation Amendment Act 2024 (C2024A00128), s 2 table items 1 and 7; Schedule 1, Part 15, items 87 to 89. legislation.gov.au/C2024A00128/latest/text

  7. Privacy Act 1988 ss 13K, 26WH(2) and 80UB; Regulatory Powers Act s 82(5)(a); Crimes Act s 4AA and the Crimes (Amount of a Penalty Unit) Instrument 2026 (F2026N00424).

Questions

Do we need a separate AML collection notice?

In practice, yes. The privacy policy describes your handling in general; a collection notice is given at or before the time you collect (APP 5.1). The OAIC says reporting entities must have a privacy policy and collection notices that explain how they handle personal information for their AML/CTF obligations, and it publishes a free template collection notice for reporting entities. If you use our AML/CTF kit, the conveyancer edition includes a drafted collection notice for customer due diligence that refers to the OAIC's guidance.

What if an agent or another firm verifies identity for us?

The AML/CTF Act lets you use an agent to collect and verify know-your-customer information; the principles of agency apply and you remain liable (AML/CTF Act s 37). You can also rely on another person's procedure under a written agreement or arrangement, or in other circumstances, if the conditions are met (AML/CTF Act ss 37A and 38; Rules 6-29 to 6-31). For privacy, your policy should say that you receive information from those third parties, and your notice should cover it. If a provider is overseas, APP 8.1 applies. The OAIC suggests keeping detailed records of what each third-party provider holds for you and for how long.

What must APP 1 contain?

APP 1.4 lists seven items: the kinds of personal information you collect and hold; how you collect and hold it; the purposes for which you collect, hold, use and disclose it; how a person can access it and seek its correction; how a person can complain about a breach of the APPs and how you will deal with the complaint; whether you are likely to disclose it to overseas recipients; and, if so, the countries where they are likely to be, if it is practicable to name them.

How long do we keep KYC records?

Customer due diligence records are kept for 7 years from the end of the business relationship or the completion of the occasional transaction (AML/CTF Act s 111). The OAIC's guidance says the AML/CTF Act does not require copies of identity documents: keep the details you need and the outcome of verification, and take reasonable steps to destroy or de-identify copies once no longer needed.