AML Tranche 2 for conveyancers: the privacy half nobody mentions
Since 1 July 2026, conveyancers and WA settlement agents who provide designated services are AUSTRAC reporting entities under the AML/CTF Act's Tranche 2 reforms. That brings customer due diligence, record-keeping, reporting and enrolment. The half nobody flags: becoming a reporting entity also switches the Privacy Act on, via s 6E(1A), for the client data you collect for AML.
By Jon Oates, Founder of Privaproof · Last updated
‹ Conveyancer privacy compliance hub
General information, not legal advice. Your obligations depend on your circumstances.
What does Tranche 2 ask of a conveyancer?
The capturing service is a designated service under the AML/CTF Act (inserted by the AML/CTF Amendment Act 2024): assisting a person in the planning or execution of a transaction to sell, buy or otherwise transfer real estate, in the course of a business. Because that description covers core conveyancing, most practising firms are squarely caught. Whether a particular firm is a reporting entity depends on the specific designated services it provides, but for a practising conveyancer, the answer is usually yes.
| Obligation | In plain terms | Source |
|---|---|---|
| AML/CTF program | Have a compliant program (risk assessment plus policies and controls) in place by 1 July 2026 | AUSTRAC |
| Enrolment | Enrol with AUSTRAC within 28 days of first providing a designated service | AUSTRAC |
| Customer due diligence (CDD) | Verify the parties' identity, identify beneficial owners (25% or more), and screen for PEPs and sanctions | AML/CTF Rules 2025 |
| Source of funds / wealth | For higher-risk matters, understand where the settlement money originates | AML/CTF Rules 2025 |
| Record-keeping | Keep AML records for at least 7 years | AUSTRAC |
| Reporting | Report suspicious matters and threshold transactions to AUSTRAC | AUSTRAC |
Note that AML customer due diligence is a separate regime from the identity verification you already do for electronic conveyancing. The ARNECC Model Participation Rules (Version 7), Schedule 8 set a safe-harbour "reasonable steps" identity standard for lodgment. It is not mandatory, and it is not the same obligation as AUSTRAC's CDD. Both exist; both generate a sensitive identity dataset; don't treat one as satisfying the other.
What's the key date for firms already practising?
AUSTRAC enrolment opened on 31 March 2026. The statutory rule is that you must enrol within 28 days of first providing a designated service. For a firm already operating when the regime commenced on 1 July 2026, that 28-day clock runs from 1 July, giving a practical enrolment cut-off of 29 July 2026. A firm that first provides a designated service later has its own 28-day clock from that first service. Because timing turns on your firm's circumstances, confirm your exact deadline directly with AUSTRAC. The privacy obligation is live from the moment you're providing designated services and are a reporting entity, not from the day you get to the paperwork.
Why does privacy come bundled with Tranche 2?
Here is what most AML guidance leaves out. Under section 6D of the Privacy Act, small firms (turnover $3 million or less) are generally exempt from the APPs, and almost every conveyancing practice has relied on that. Becoming a reporting entity does not simply delete that exemption for your whole firm. Instead, section 6E(1A) of the Privacy Act deems a small business operator that is a reporting entity to be an "organisation", an APP entity, but only for the activities it carries on for the purposes of, or in connection with, the AML/CTF Act.
So the personal information you now collect for AML (the identity documents, KYC and beneficial-ownership records, PEP and sanctions results, and source-of-funds evidence) comes under the Privacy Act, even below the $3 million threshold. The rest of the practice's data (say, a general marketing list) isn't swept in by force of s 6E(1A) alone. The coverage is targeted at the AML/CTF-connected data, not the whole firm.
That is the quiet point: the AML customer checks you're rushing to build for AUSTRAC are themselves the exact data the Privacy Act now regulates. You can't do the AML side of Tranche 2 without triggering the privacy side. For most conveyancers this is a first-ever privacy obligation, and it doesn't come in the AML consultant's box. In practice, because the AML data and the transaction data in a file are so intertwined, many firms choose to apply Privacy-Act-standard handling across the whole matter, a sensible practical step, not something the law demands of your non-AML records.
What two more privacy pressures should conveyancers know?
- Statutory tort: since 10 June 2025. Individuals can sue directly for a serious invasion of privacy (intrusion into seclusion or misuse of information), with no OAIC involvement needed. The invasion has to have been intentional or reckless, so carelessness alone is not enough. Conveyancers hold exactly the high-sensitivity identity and financial data that makes such a claim viable.
- Automated decision-making disclosure: conditional, from 10 December 2026. If you use identity-verification (IDV/electronic-VOI) or PEP/sanctions-screening software that makes, or substantially supports, a decision that could significantly affect a person's rights or interests, then from 10 December 2026 the new APP 1.7 will require your privacy policy to disclose that automated decision-making. Whether any given tool crosses that threshold is fact-specific and still being clarified, so treat it as something to check, not an automatic obligation.
What does this mean in practice?
To be compliant you need both halves:
1. The AML side: program, enrolment, CDD, source-of-funds checks and reporting. This is AUSTRAC's domain; AML consultants and platforms cover it, and Privaproof does not assess it. 2. The privacy side: an APP 1 privacy policy, APP 5 collection notices (including a purpose-built notice for the identity and source-of-funds data you collect for verification), and, because the Notifiable Data Breaches scheme requires you to assess and notify eligible breaches, a breach response plan for the concentrated identity and financial dataset you now hold.
The AML vendors tend to treat privacy as an afterthought, and generic templates go stale the moment a rule like the ADM transparency requirement lands on 10 December 2026. If you want the detail on the privacy documents themselves (what an APP 1 policy has to say and why a conveyancer's is different), see the companion guide, Do conveyancers need a privacy policy in 2026?
Common questions
Are conveyancers caught by AML Tranche 2?
Generally yes. The capturing service is a designated service under the AML/CTF Act (assisting to buy, sell or transfer real estate), which is core conveyancing, so most practising firms are reporting entities from 1 July 2026.
What's the privacy half of Tranche 2?
Becoming a reporting entity also brings the personal information you collect for AML (identity, KYC, beneficial ownership, source of funds) under the Privacy Act via s 6E(1A), regardless of turnover. Most AML guidance leaves this out.
When do I have to enrol with AUSTRAC?
Within 28 days of first providing a designated service. For firms already operating on 1 July 2026, the reforms treat 29 July 2026 as the practical cut-off. Confirm your exact date with AUSTRAC.
Does Tranche 2 apply to WA settlement agents?
Yes. The capture is by activity, not job title, so WA settlement agents providing the designated service are caught the same way. See our WA settlement agents guide.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice. It does not assess your AML/CTF obligations, which are administered by AUSTRAC. Privaproof's conveyancer materials are self-authored and are not independently reviewed by a solicitor. Sources: AUSTRAC, professional designated services; AUSTRAC, professional services reform (new industries regulated); OAIC, privacy guidance for reporting entities under the AML/CTF Act; Privacy Act 1988 (Cth) s 6E(1A) and s 6D; OAIC, statutory tort for serious invasions of privacy.