Privacy Act 2026 — by industry

Privacy Policy for Conveyancers: The 2026 Australian Compliance Guide

What an Australian conveyancing business's privacy policy needs in 2026 under the Privacy Act 1988 — including AML Tranche 2 KYC from 1 July 2026 and the 10 December 2026 automated decision-making disclosure. Plain English, source-checked.

By Daniel Ebiau, AMLCompliant ·

Conveyancers sit at the centre of property transactions — handling identity, financial and settlement information for every party. From 1 July 2026, AML/CTF Tranche 2 adds formal KYC collection, and that brings the Privacy Act 1988 firmly into your practice. Here is what your privacy policy needs.

Why 2026 matters for conveyancers

If you provide a designated service, AML/CTF Tranche 2 makes you a reporting entity from 1 July 2026. Once you are, the Privacy Act applies to the personal information you collect for AML/CTF regardless of turnover. See AML Tranche 2 and the Privacy Act. (Source: AUSTRAC.)

What your policy must cover (APP 1)

  • What you collect: client identity and contact details, KYC and

beneficial-ownership information, financial and settlement details, property data.

  • Why: completing conveyancing, meeting legal obligations, and AML/CTF due

diligence.

  • Who you disclose to: other parties to the transaction, land registries, banks,

AUSTRAC where required, and any overseas recipients.

  • Access, correction and complaints, with the path to the OAIC.
  • Security and retention — keep only what you need.

The general method is in how to write a privacy policy that complies in 2026.

The KYC collection notice

Build an APP 5 collection notice for the identity and beneficial-ownership information you gather for AML — one that works as both a privacy and an AML document, delivered at onboarding.

Automated decision-making

If you use software to make or substantially support decisions that significantly affect people, the 10 December 2026 ADM disclosure obligation may apply. See the ADM guide.

Breach response

Settlement and identity data are high-value breach targets. Build your 30-day assessment process under the Notifiable Data Breaches scheme — see the data-breach response plan.

Run the free checker, then self-audit your policy with the free checklist.

General information only, not legal or compliance advice. Current to June 2026; confirm your obligations at oaic.gov.au and austrac.gov.au or with a qualified adviser. Last verified: 8 June 2026.

Run the free ML/TF risk assessment →

Frequently asked questions

Do conveyancers need a Privacy Act compliant privacy policy in 2026?
If you provide a designated service, AML Tranche 2 makes you a reporting entity from 1 July 2026, and the Privacy Act applies to the KYC personal information you collect regardless of turnover — so yes, APP 1 requires a current privacy policy. Sources — AUSTRAC; OAIC.
What new disclosure applies from December 2026?
From 10 December 2026, if you use software to make or substantially support decisions that significantly affect people, your privacy policy must disclose it. Source — OAIC.
Is this legal advice?
No. General information, current to June 2026. Confirm your obligations with the OAIC, AUSTRAC or a qualified adviser.
conveyancerprivacy policyprivacy act 1988aml tranche 2app 1