What must a conveyancer tell clients when collecting their information?
At or before the time you collect it, or if that is not practicable as soon as practicable after, you have to take such steps (if any) as are reasonable to make the person aware of who you are, why you are collecting it, who you usually disclose it to, the fact that an Australian law requires it and the name of that law, what happens if they do not provide it, and how to access, correct or complain. For a conveyancing practice the sharp one is naming the law: APP 5.2(c) requires the name of the Australian law that compels the identity collection, and for conveyancing that is the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). A generic notice cannot name it for you.
By Jon Oates, Founder of Privaproof · Last updated
‹ Conveyancer privacy compliance hub
General information, not legal advice. Your obligations depend on your circumstances.
What exactly has to be in the notice?
APP 5.2 lists ten matters, and APP 5 binds APP entities. Under s 6E(1A) a small conveyancing practice that is a reporting entity is an organisation for the activities it carries on in connection with the AML/CTF Act, whatever its turnover. In a conveyancing context they translate as:
- Who you are. Your identity and contact details, meaning the practice, not the individual acting.
- The fact and circumstances of collection, where you collect from someone other than the individual, or where the individual may not be aware you have collected it.
- ⚠️ That the collection is required or authorised by or under an Australian law, and the name of that law. For customer due diligence that name is the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), written out; for VOI, add the state land-titles or conveyancing requirement that applies where you practise. Naming it is part of the obligation, not a nicety.
- The purposes of collection.
- The main consequences, if any, for the individual if you do not collect it. For a conveyancer that is concrete and worth saying plainly: without the identity evidence you cannot complete customer due diligence, and the matter stops there.
- Your usual disclosures, meaning the entities or kinds of entities you ordinarily disclose this information to. The settlement-file list is on our who a conveyancer shares client information with page.
- That your APP privacy policy contains information about how to access and correct the information, and how to complain, and how the complaint will be dealt with.
- Whether you are likely to disclose the information to overseas recipients, and if so, the countries, where it is practicable to specify them. Do your practice management, VOI and settlement platforms hold data offshore? That is what engages this limb, and our overseas disclosure page covers it.
Sources: Privacy Act 1988 (Cth), APP 5.1, APP 5.2 · OAIC APP 5 guidelines
Is this the same thing as our privacy policy?
No, and conflating the two is the most common structural mistake in this area.
The privacy policy is a standing document about how the practice handles personal information generally. It sits on your website and satisfies APP 1.3. The collection notice is given to a specific person at the moment you collect from them, about that collection.
A privacy policy on your website does not discharge APP 5, because APP 5 is about making this person aware at this collection. Pointing to the policy can form part of the notice, and it cannot be the whole of it.
We treat the distinction in full on the privacy policy versus collection notice page.
Sources: Privacy Act 1988 (Cth), APP 1.3, APP 5.1 · OAIC APP 5 guidelines
When do we have to give it?
At or before the time of collection if that is practicable, and otherwise as soon as practicable after.
For a conveyancing practice that maps to a small number of moments, and the useful discipline is to know which one is your first collection:
- The engagement or retainer. Usually the first collection, and the natural home for the full notice.
- The VOI appointment, whether you do it, an agent does it, or a client uses an electronic product.
- The source-of-funds request, which often comes later in the matter and often lands as a bare email asking for bank statements. That is a collection, and it usually arrives with no notice attached.
- Beneficial ownership questions on a company or trust purchaser.
The releasing point, and it is real: APP 5.1 requires such steps if any as are reasonable in the circumstances. The words "if any" mean that in some circumstances no steps are reasonable. And APP 5.1(b) is satisfied by otherwise ensuring the individual is aware, so a notice given at engagement can carry a later collection in the same matter that it actually described. What you should not do is assume the engagement notice covered a collection it never described.
Sources: Privacy Act 1988 (Cth), APP 5.1 · OAIC APP 5 guidelines
What about people who are not our client?
This is the harder half of APP 5, and the one a template notice cannot do for you. Does your last company or trust file show what you did to make the beneficial owners aware?
Where you collect personal information about an individual from someone else, APP 5 still applies, and the steps have to be directed at making that individual aware. In a conveyancing practice that means beneficial owners, directors and trustees identified through a corporate or trust client, and sometimes a party being removed from a title.
The obligation is to take reasonable steps, and what is reasonable is affected by practicability, the sensitivity of the information and the consequences for the person. Realistic options:
- Ask your client to pass the notice on when they provide the information, and record that you asked.
- Include a short notice in the correspondence that goes to any of those individuals directly, which for beneficial owners is often a certification or declaration request.
- Where you genuinely cannot reach them, record the reason. APP 5 is a reasonable-steps obligation, not a guarantee of contact, and a documented judgement is a defensible one.
What is not defensible is never having considered it at all.
Sources: Privacy Act 1988 (Cth), APP 5.1, APP 5.2(b), APP 3.6 · OAIC APP 5 guidelines
What does a conveyancer's notice actually look like?
Short, at the point of collection, and specific to what you are collecting. A long notice that nobody reads is worse than a short one that lands, and APP 5 is about awareness rather than volume.
The shape that works for a settlement file:
- Who is collecting it and how to contact them.
- What you are collecting and why, in the client's terms: to verify identity, to meet AML/CTF obligations, and to complete the transaction.
- The law that requires it, named.
- What happens if they do not provide it: the matter cannot proceed.
- Who you will give it to: the other side's representative, the lender, the electronic lodgment network, the revenue office, the land titles authority, and your software providers.
- Where the policy is, covering access, correction and complaints, and whether information goes overseas.
That is six lines, not a page. The value sits in the named law and the stated consequence, because those are the two a client will otherwise guess at, and guessing generates the complaint.
Sources: Privacy Act 1988 (Cth), APP 5.2 · OAIC APP 5 guidelines
Do we need consent as well as a notice?
Usually not for the identity collection, and this is worth being precise about because the two get merged.
Where the collection is required or authorised by or under an Australian law, you do not need consent for it. Customer due diligence under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) sits there. Asking a client to consent to something the law compels is not just unnecessary, it misdescribes the position: consent implies a choice to decline, and there is none.
Consent still matters where you want to do something beyond the compelled collection, and APP 3.3 separately requires it for sensitive information unless an exception in APP 3.4 applies. Watch what that catches in electronic VOI: s 6(1) makes biometric templates, and biometric information used for automated biometric verification, sensitive information.
Our consent and AML page works through where the line falls.
Sources: Privacy Act 1988 (Cth), APP 3.3, APP 3.4, APP 5 · OAIC APP 5 guidelines
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC.