AML Tranche 2 for conveyancers: the privacy half nobody mentions
Conveyancers and WA settlement agents who provide a designated service in table 6 of the AML/CTF Act (s 6(5B), professional services) have been AUSTRAC reporting entities since 31 March 2026, and the obligations started on 1 July 2026. That brings customer due diligence, record-keeping, reporting and enrolment. The half nobody flags: becoming a reporting entity also switches the Privacy Act on, via s 6E(1A), for the activities you carry on in connection with the AML/CTF Act.
By Jon Oates, Founder of Privaproof · Last updated
‹ Conveyancer privacy compliance hub
General information, not legal advice. Your obligations depend on your circumstances.
What does Tranche 2 ask of a conveyancer?
The capturing service is item 1 of table 6 (professional services), s 6(5B) of the AML/CTF Act, inserted by the AML/CTF Amendment Act 2024: assisting a person in the planning or execution of a transaction to sell, buy or otherwise transfer real estate, in the course of carrying on a business, where the transfer is not pursuant to, or resulting from, an order of a court or tribunal. That is the conveyancing job itself, and AUSTRAC states the service covers "the typical steps taken in the conveyancing process to transfer real property from one person to another". The court-order limb is a real carve-out, and AUSTRAC confines it to services carried out after the order is made.
| Obligation | In plain terms | Source |
|---|---|---|
| AML/CTF program | Have a compliant program (risk assessment plus policies and controls) in place by 1 July 2026 | AUSTRAC |
| Enrolment | 29 July 2026 if you were already providing a designated service before 1 July 2026 (a fixed statutory date, not a 28-day count); otherwise within 28 days of first providing one | AML/CTF Amendment Act 2024 Sch 3 Pt 4 item 12; s 51B(1) |
| Customer due diligence (CDD) | Verify the parties' identity, identify beneficial owners (25% or more), and screen for PEPs and sanctions | AML/CTF Rules 2025 |
| Source of funds / wealth | For higher-risk matters, understand where the settlement money originates | AML/CTF Rules 2025 |
| Record-keeping | Keep AML records for at least 7 years | AUSTRAC |
| Reporting | Report suspicious matters and threshold transactions to AUSTRAC | AUSTRAC |
Note that AML customer due diligence is a separate regime from the identity verification you already do for electronic conveyancing. The ARNECC Model Participation Rules (Version 7), Schedule 8 set a safe-harbour "reasonable steps" identity standard for lodgment. It is not mandatory, and it is not the same obligation as AUSTRAC's CDD. Both exist; both generate a sensitive identity dataset; don't treat one as satisfying the other.
What's the key date for firms already practising?
AUSTRAC enrolment opened on 31 March 2026, the day table 6 commenced. The general rule in s 51B(1) is that you enrol within 28 days of first providing a designated service, but that clock does not govern firms already in practice: item 12 of Schedule 3 Part 4 to the AML/CTF Amendment Act 2024 replaces it with a fixed date, so anyone who provided a designated service at any time before 1 July 2026 had to be enrolled by 29 July 2026. A firm that first provides one after that date has the ordinary 28-day clock. Because timing turns on your firm's circumstances, confirm your exact deadline directly with AUSTRAC. The privacy obligation is live from the moment you are a reporting entity, not from the day you get to the paperwork.
Why does privacy come bundled with Tranche 2?
Check this before you assume the small-business exemption saves you. Under section 6D of the Privacy Act a small business operator (turnover of $3 million or less) is generally outside the APPs, but s 6D(4)(a) removes that permanently once the business has had a turnover above $3 million for any financial year since 2002, and s 6D(4) has other limbs besides. Becoming a reporting entity does not delete the exemption for your whole firm. Section 6E(1A) deems a small business operator that is a reporting entity to be an "organisation", an APP entity, but only in relation to the activities it carries on for the purposes of, or in connection with, activities relating to the AML/CTF Act.
So the AML work itself, collecting identity documents, building KYC and beneficial-ownership records, running PEP and sanctions checks, holding source-of-funds evidence and everything you then do with those records, is carried on as an APP entity, even below the $3 million threshold. The rest of the practice (say, a general marketing list) is not swept in by force of s 6E(1A) alone. Note what the subsection actually catches: the activities connected with the AML/CTF Act, not a single folder of data.
That is the quiet point: the AML checks you built for AUSTRAC are themselves the activity the Privacy Act now regulates. You cannot do the AML side of Tranche 2 without triggering the privacy side. Does your practice already have an APP 1 privacy policy and an APP 5 collection notice covering the identity data, or would this be the first privacy obligation it has ever had? Because the AML records and the transaction records sit in one file, the cleaner path is usually to apply Privacy-Act-standard handling across the whole matter, a practical choice rather than something the law demands of your non-AML records.
What two more privacy pressures should conveyancers know?
- Statutory tort: since 10 June 2025. Individuals can sue directly for a serious invasion of privacy (intrusion into seclusion or misuse of information), with no OAIC involvement needed. Schedule 2 clause 7(1) sets five cumulative conditions, and clause 7(1)(c) is the limit: the invasion has to have been intentional or reckless, so carelessness alone is not enough. It is actionable without proof of damage (clause 7(2)), and conveyancers hold the records such a claim would be about.
- Automated decision-making disclosure: conditional, from 10 December 2026. If you use identity-verification (IDV/electronic-VOI) or PEP/sanctions-screening software that makes, or substantially supports, a decision that could significantly affect a person's rights or interests, then from 10 December 2026 the new APP 1.7 will require your privacy policy to disclose that automated decision-making. Whether any given tool crosses that threshold is fact-specific and still being clarified, so treat it as something to check, not an automatic obligation.
What does this mean in practice?
To be compliant you need both halves:
- The AML side: program, enrolment, CDD, source-of-funds checks and reporting. This is AUSTRAC's domain; AML consultants and platforms cover it, and Privaproof does not assess it.
- The privacy side: an APP 1 privacy policy, APP 5 collection notices (including a purpose-built notice for the identity and source-of-funds data you collect for verification), and, because s 26WH(2) puts the duty on the entity to assess a suspected eligible breach and take all reasonable steps to finish within 30 days, a breach response plan for that dataset. The only court-imposed civil penalty under the Privacy Act so far, A$5.8m in Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224, included A$800,000 for the slow assessment.
Open the AML pack you were sold and check it for four things: an APP 1 privacy policy, an APP 5 collection notice for the identity and source-of-funds data, a retention and destruction rule for it under APP 11.2, and a step that assesses a suspected breach against s 26WH. If all four are there, you do not need us. If they are not, a static document set will also miss the APP 1.7 disclosure duty when it commences on 10 December 2026. For what an APP 1 policy has to say and why a conveyancer's is different, see the companion guide, Do conveyancers need a privacy policy in 2026?
Common questions
Are conveyancers caught by AML Tranche 2?
Generally yes. Item 1 of table 6 (professional services, s 6(5B)) covers assisting a person to buy, sell or transfer real estate in the course of a business, which is core conveyancing, so a firm providing it has been a reporting entity since 31 March 2026. Transfers made under a court or tribunal order sit outside item 1.
What's the privacy half of Tranche 2?
Becoming a reporting entity means s 6E(1A) applies the Privacy Act to you as if you were an organisation, in relation to the activities you carry on for the purposes of, or in connection with, the AML/CTF Act. That reaches the identity, KYC, beneficial-ownership and source-of-funds work, regardless of turnover.
When do I have to enrol with AUSTRAC?
Section 51B(1) says within 28 days of first providing a designated service. For anyone providing one before 1 July 2026 that clock was replaced by a fixed statutory date, 29 July 2026, by Schedule 3 Part 4 item 12 of the AML/CTF Amendment Act 2024. Confirm your exact date with AUSTRAC.
Does Tranche 2 apply to WA settlement agents?
Yes. The capture is by activity, not job title, so WA settlement agents providing the designated service are caught the same way. See our WA settlement agents guide.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice. It does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: AUSTRAC, professional designated services; AUSTRAC, professional services reform (new industries regulated); OAIC, privacy guidance for reporting entities under the AML/CTF Act; Privacy Act 1988 (Cth) s 6E(1A) and s 6D; OAIC, statutory tort for serious invasions of privacy.