Privacy Act 2026 — by industry
Privacy Policy for Conveyancers: The 2026 Australian Compliance Guide
What an Australian conveyancing business's privacy policy needs in 2026 under the Privacy Act 1988 — including AML Tranche 2 KYC from 1 July 2026 and the 10 December 2026 automated decision-making disclosure. Plain English, source-checked.
Conveyancers sit at the centre of property transactions — handling identity, financial and settlement information for every party. From 1 July 2026, AML/CTF Tranche 2 adds formal KYC collection, and that brings the Privacy Act 1988 firmly into your practice. Here is what your privacy policy needs.
Why 2026 matters for conveyancers
If you provide a designated service, AML/CTF Tranche 2 makes you a reporting entity from 1 July 2026. Once you are, the Privacy Act applies to the personal information you collect for AML/CTF regardless of turnover. See AML Tranche 2 and the Privacy Act. (Source: AUSTRAC.)
What your policy must cover (APP 1)
- What you collect: client identity and contact details, KYC and
beneficial-ownership information, financial and settlement details, property data.
- Why: completing conveyancing, meeting legal obligations, and AML/CTF due
diligence.
- Who you disclose to: other parties to the transaction, land registries, banks,
AUSTRAC where required, and any overseas recipients.
- Access, correction and complaints, with the path to the OAIC.
- Security and retention — keep only what you need.
The general method is in how to write a privacy policy that complies in 2026.
The KYC collection notice
Build an APP 5 collection notice for the identity and beneficial-ownership information you gather for AML — one that works as both a privacy and an AML document, delivered at onboarding.
Automated decision-making
If you use software to make or substantially support decisions that significantly affect people, the 10 December 2026 ADM disclosure obligation may apply. See the ADM guide.
Breach response
Settlement and identity data are high-value breach targets. Build your 30-day assessment process under the Notifiable Data Breaches scheme — see the data-breach response plan.
Run the free checker, then self-audit your policy with the free checklist.
General information only, not legal or compliance advice. Current to June 2026; confirm your obligations at oaic.gov.au and austrac.gov.au or with a qualified adviser. Last verified: 8 June 2026.
Run the free ML/TF risk assessment →