Skip to content

What must a conveyancer tell clients when collecting their information?

At or before the time you collect it, or as soon as practicable afterwards, you have to take reasonable steps to make the person aware of who you are, why you are collecting it, who you usually disclose it to, the fact that the law requires it and the name of that law, what happens if they do not provide it, and how to access, correct or complain. For a conveyancing practice the element most often missing is the third one: naming the AML/CTF law that compels the identity collection, rather than leaving the client to assume you are just being thorough.

By Jon Oates, Founder of Privaproof · Last updated

‹ Conveyancer privacy compliance hub

General information, not legal advice. Your obligations depend on your circumstances.

What exactly has to be in the notice?

APP 5.2 lists the matters. In a conveyancing context they translate as:

Sources: Privacy Act 1988 (Cth), APP 5.1, APP 5.2 · OAIC APP 5 guidelines

Is this the same thing as our privacy policy?

No, and conflating the two is the most common structural mistake in this area.

The privacy policy is a standing document about how the practice handles personal information generally. It sits on your website and satisfies APP 1.3. The collection notice is given to a specific person at the moment you collect from them, about that collection.

A privacy policy on your website does not discharge APP 5, because APP 5 is about making this person aware at this collection. Pointing to the policy can form part of the notice, and it cannot be the whole of it.

We treat the distinction in full on the privacy policy versus collection notice page.

Sources: Privacy Act 1988 (Cth), APP 1.3, APP 5.1 · OAIC APP 5 guidelines

When do we have to give it?

At or before the time of collection if that is practicable, and otherwise as soon as practicable after.

For a conveyancing practice that maps to a small number of moments, and the useful discipline is to know which one is your first collection:

The releasing point, and it is real: APP 5.1 requires such steps if any as are reasonable in the circumstances. The words "if any" mean that in some circumstances no steps are reasonable. And where you have already given a client the notice at engagement, you are not required to reissue it at every subsequent collection in the same matter. What you should not do is assume the engagement notice covered a collection it never described.

Sources: Privacy Act 1988 (Cth), APP 5.1 · OAIC APP 5 guidelines

What about people who are not our client?

This is the harder half of APP 5 and the part almost nobody does.

Where you collect personal information about an individual from someone else, APP 5 still applies, and the steps have to be directed at making that individual aware. In a conveyancing practice that means beneficial owners, directors and trustees identified through a corporate or trust client, and sometimes a party being removed from a title.

The obligation is to take reasonable steps, and what is reasonable is affected by practicability, the sensitivity of the information and the consequences for the person. Realistic options:

What is not defensible is never having considered it, which is the ordinary position.

Sources: Privacy Act 1988 (Cth), APP 5.1, APP 5.2(b), APP 3.6 · OAIC APP 5 guidelines

What does a conveyancer's notice actually look like?

Short, at the point of collection, and specific to what you are collecting. A long notice that nobody reads is worse than a short one that lands, and APP 5 is about awareness rather than volume.

The shape that works for a settlement file:

1. Who is collecting it and how to contact them. 2. What you are collecting and why, in the client's terms: to verify identity, to meet AML/CTF obligations, and to complete the transaction. 3. The law that requires it, named. 4. What happens if they do not provide it: the matter cannot proceed. 5. Who you will give it to: the other side's representative, the lender, the electronic lodgment network, the revenue office, the land titles authority, and your software providers. 6. Where the policy is, covering access, correction and complaints, and whether information goes overseas.

That is six lines, not a page. The value is in points 3 and 4, because they are the two a client will otherwise guess at, and guessing generates the complaint.

Sources: Privacy Act 1988 (Cth), APP 5.2 · OAIC APP 5 guidelines

Usually not for the identity collection, and this is worth being precise about because the two get merged.

Where the collection is required or authorised by or under an Australian law, you do not need consent for it. AML/CTF customer due diligence sits there. Asking a client to consent to something the law compels is not just unnecessary, it misdescribes the position: consent implies a choice to decline, and there is none.

Consent still matters where you want to do something beyond the compelled collection, and it is separately required for sensitive information under APP 3.3 unless an exception applies.

Our consent and AML page works through where the line falls.

Sources: Privacy Act 1988 (Cth), APP 3.3, APP 3.4, APP 5 · OAIC APP 5 guidelines


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Privaproof's conveyancer materials are self-authored and are not independently reviewed by a solicitor.