Skip to content

What must a conveyancer tell clients when collecting their information?

At or before the time you collect it, or if that is not practicable as soon as practicable after, you have to take such steps (if any) as are reasonable to make the person aware of who you are, why you are collecting it, who you usually disclose it to, the fact that an Australian law requires it and the name of that law, what happens if they do not provide it, and how to access, correct or complain. For a conveyancing practice the sharp one is naming the law: APP 5.2(c) requires the name of the Australian law that compels the identity collection, and for conveyancing that is the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). A generic notice cannot name it for you.

By Jon Oates, Founder of Privaproof · Last updated

‹ Conveyancer privacy compliance hub

General information, not legal advice. Your obligations depend on your circumstances.

What exactly has to be in the notice?

APP 5.2 lists ten matters, and APP 5 binds APP entities. Under s 6E(1A) a small conveyancing practice that is a reporting entity is an organisation for the activities it carries on in connection with the AML/CTF Act, whatever its turnover. In a conveyancing context they translate as:

Sources: Privacy Act 1988 (Cth), APP 5.1, APP 5.2 · OAIC APP 5 guidelines

Is this the same thing as our privacy policy?

No, and conflating the two is the most common structural mistake in this area.

The privacy policy is a standing document about how the practice handles personal information generally. It sits on your website and satisfies APP 1.3. The collection notice is given to a specific person at the moment you collect from them, about that collection.

A privacy policy on your website does not discharge APP 5, because APP 5 is about making this person aware at this collection. Pointing to the policy can form part of the notice, and it cannot be the whole of it.

We treat the distinction in full on the privacy policy versus collection notice page.

Sources: Privacy Act 1988 (Cth), APP 1.3, APP 5.1 · OAIC APP 5 guidelines

When do we have to give it?

At or before the time of collection if that is practicable, and otherwise as soon as practicable after.

For a conveyancing practice that maps to a small number of moments, and the useful discipline is to know which one is your first collection:

The releasing point, and it is real: APP 5.1 requires such steps if any as are reasonable in the circumstances. The words "if any" mean that in some circumstances no steps are reasonable. And APP 5.1(b) is satisfied by otherwise ensuring the individual is aware, so a notice given at engagement can carry a later collection in the same matter that it actually described. What you should not do is assume the engagement notice covered a collection it never described.

Sources: Privacy Act 1988 (Cth), APP 5.1 · OAIC APP 5 guidelines

What about people who are not our client?

This is the harder half of APP 5, and the one a template notice cannot do for you. Does your last company or trust file show what you did to make the beneficial owners aware?

Where you collect personal information about an individual from someone else, APP 5 still applies, and the steps have to be directed at making that individual aware. In a conveyancing practice that means beneficial owners, directors and trustees identified through a corporate or trust client, and sometimes a party being removed from a title.

The obligation is to take reasonable steps, and what is reasonable is affected by practicability, the sensitivity of the information and the consequences for the person. Realistic options:

What is not defensible is never having considered it at all.

Sources: Privacy Act 1988 (Cth), APP 5.1, APP 5.2(b), APP 3.6 · OAIC APP 5 guidelines

What does a conveyancer's notice actually look like?

Short, at the point of collection, and specific to what you are collecting. A long notice that nobody reads is worse than a short one that lands, and APP 5 is about awareness rather than volume.

The shape that works for a settlement file:

That is six lines, not a page. The value sits in the named law and the stated consequence, because those are the two a client will otherwise guess at, and guessing generates the complaint.

Sources: Privacy Act 1988 (Cth), APP 5.2 · OAIC APP 5 guidelines

Usually not for the identity collection, and this is worth being precise about because the two get merged.

Where the collection is required or authorised by or under an Australian law, you do not need consent for it. Customer due diligence under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) sits there. Asking a client to consent to something the law compels is not just unnecessary, it misdescribes the position: consent implies a choice to decline, and there is none.

Consent still matters where you want to do something beyond the compelled collection, and APP 3.3 separately requires it for sensitive information unless an exception in APP 3.4 applies. Watch what that catches in electronic VOI: s 6(1) makes biometric templates, and biometric information used for automated biometric verification, sensitive information.

Our consent and AML page works through where the line falls.

Sources: Privacy Act 1988 (Cth), APP 3.3, APP 3.4, APP 5 · OAIC APP 5 guidelines


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC.