What is a beneficial owner, and what do conveyancers collect about them?
A beneficial owner is an individual who ultimately owns 25% or more of a client that is not an individual, or who controls that client by any means, at any percentage: AML/CTF Act s 5. The question only arises where your client is a company, trust or other structure (s 28(2)(d)), and answering it means collecting personal information about people who aren't sitting in front of you, activities the Privacy Act reaches through s 6E(1A).
By Jon Oates, Founder of Privaproof · Last updated
‹ Conveyancer privacy compliance hub
General information, not legal advice. Your obligations depend on your circumstances.
What is a beneficial owner?
When your client is an individual buying or selling in their own name, there is no beneficial owner to find. The AML/CTF Act defines the beneficial owner "of a person (other than an individual)" (s 5), and s 28(2)(d) asks the question only where the customer is not an individual. Once the client is a company, trust or other structure, a beneficial owner is an individual who ultimately owns, directly or indirectly, 25% or more of the customer, or who controls it directly or indirectly. The 25% sits on the ownership limb only. There is no threshold on control.
The idea is to see past the entity to the real people behind it, which is the whole point of anti-money-laundering checks, and also why it raises privacy questions a conveyancer didn't use to face.
Why do conveyancers have to identify them?
Under the AML/CTF Act a reporting entity must establish, on reasonable grounds, the identity of any beneficial owners of a customer that is not an individual before it commences to provide the designated service: s 28(1) and s 28(2)(d). Who counts is fixed by the definition in s 5, not by the Rules. What the Rules add is a collection floor: for a company, partnership or unincorporated association, at least KYC information about the ownership and control structure (AML/CTF Rules 2025 s 6-2(3)); for a trust, the control structure and any settlor, appointor, guardian or protector (s 6-3(5)). (Privaproof doesn't assess AML/CTF obligations; AUSTRAC does. Confirm the specifics with AUSTRAC guidance.)
| Client type | Who the beneficial owner is |
|---|---|
| Individual in their own name | Nobody. s 28(2)(d) applies only where the customer is not an individual. Ask instead who the client is receiving the service on behalf of (s 28(2)(b)) and who is acting for the client (s 28(2)(c)) |
| Company | An individual who ultimately owns 25% or more, directly or indirectly, or who controls it directly or indirectly at any percentage (s 5) |
| Trust | The same s 5 test. The Rules also require the control structure and any settlor, appointor, guardian or protector (s 6-3(5)) |
| Partnership / association | The same s 5 test. If you take all reasonable steps and still cannot establish it, s 6-8 of the Rules substitutes the chief executive officer, recorded and verified |
Why is beneficial ownership a privacy issue too?
Here's what makes beneficial ownership a privacy issue and not just an AML one. To identify a beneficial owner you collect personal information about people who may not be your direct client: a company's shareholders, a trust's controllers. Those individuals are data subjects too. If your practice would otherwise sit outside the Privacy Act as a small business operator, s 6E(1A) applies the Act to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act. It is scoped to those activities, not to a category of data (see what personal information you now collect for AML).
That means the beneficial-ownership information you hold needs the same care as the rest: it's covered by your privacy policy, it should be flagged in your collection process, and it has to be stored securely and kept no longer than the law requires. APP 11.1(b) reached a court for the first time in Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224, where A$4.2m of the A$5.8m ordered was for the security contraventions, against an ASX-listed pathology company holding data on 223,000 people, not a conveyancing practice.
How should I handle beneficial-ownership data?
Practically, beneficial-ownership data isn't a special category with its own rulebook; it's part of the AML dataset you now protect. Two duties are easy to run together. s 28(3)(c) requires you to collect KYC information appropriate to the ML/TF risk of the customer. s 28(3)(d) requires you to verify, using reliable and independent data, only such of that information as is appropriate to that risk. Neither the Act nor the Rules prescribe a document, so "always take a company extract" is a policy choice, not a statutory requirement. Does your AML pack say which fields you collect, which you verify, and why? Fold the answer into your retention schedule so it isn't kept indefinitely.
Common questions
Is the beneficial owner always my client?
No. A beneficial owner is never the customer: s 5 defines the beneficial owner of a person other than an individual, so for a company or trust client it is the shareholder or controller behind the entity, not the person instructing you. Where the client is an individual in their own name, the s 28(2)(d) matter does not arise at all.
What does "25%" mean?
s 5 of the AML/CTF Act splits it in two. A beneficial owner is an individual who ultimately owns, either directly or indirectly, 25% or more of the customer, or who controls the customer directly or indirectly. The 25% attaches to ownership only. There is no threshold on the control limb, so someone with no shareholding at all can be a beneficial owner.
Do I collect beneficial-owner data for an individual client?
No. s 28(2)(d) applies only where the customer is not an individual, so for a client acting in their own name there are no beneficial owners to collect. Two neighbouring matters still apply: s 28(2)(b), any person on whose behalf the customer is receiving the service, and s 28(2)(c), any person acting on behalf of the customer and their authority to act.
Is beneficial-owner information covered by the Privacy Act?
Yes. If your practice is already an APP entity, it is covered like any other personal information you hold. If it would otherwise be a small business operator, s 6E(1A) applies the Privacy Act to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act, and identifying beneficial owners is one of them. The section is scoped to the activity, not to a class of data.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) ss 5, 28 (Compilation No. 62); Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 ss 6-2, 6-3, 6-8 (Compilation No. 1); Privacy Act 1988 (Cth) s 6E(1A) (Compilation No. 104); AUSTRAC, professional designated services; OAIC, privacy guidance for reporting entities under the AML/CTF Act.