Do conveyancers need client consent to collect ID and run AML checks?
Usually not for the AML collection itself. Because AML/CTF law requires you to collect and verify identity and customer-due-diligence information, you generally don't need consent to collect it; the law authorises it. But you must tell the client what you're collecting and why (a collection notice), and consent still matters for anything the law doesn't require, like marketing.
By Jon Oates, Founder of Privaproof · Last updated
‹ Conveyancer privacy compliance hub
General information, not legal advice. Your obligations depend on your circumstances.
How are consent and "required by law" different?
It's a common assumption that because the Privacy Act is involved, you now need a signed consent for everything. That's not how it works. The APPs let you collect personal information you reasonably need for your functions, and, importantly, where collection is required or authorised by law, that legal basis removes the need for consent, including for sensitive information that would otherwise need it. AML customer due diligence is a legal obligation, so collecting the identity and CDD information the AML rules require is authorised without separate consent.
The practical upshot: you're not asking permission to run the checks you're legally required to run. What you are required to do is be transparent about it.
Why don't you need consent for the AML collection?
When you collect a client's identity documents, beneficial-ownership details or source-of-funds evidence to meet your AML/CTF obligations, you're doing something the law requires. That places the collection on a "required or authorised by law" footing rather than a consent footing. You don't have to obtain consent to comply with AUSTRAC's requirements, and, in fact, you generally can't waive them if a client would prefer you didn't check.
Do you still have to be transparent?
Not needing consent is not the same as not telling anyone. Under APP 5, you must give the client a collection notice, at or around the time you collect their information, explaining what you're collecting, why, and who you disclose it to. And because the information is essential, your notice can make clear the honest consequence: without the required verification, you can't lawfully provide the service or proceed to settlement. (See Privacy policy vs collection notice.)
Where does consent still matter?
Consent comes back into the picture the moment you step outside what the law requires:
| Situation | Consent needed? | Why |
|---|---|---|
| Collecting the ID and CDD information AML law requires | No | Collection is required or authorised by law |
| Letting the client know you're collecting it | Not "consent", but you must notify | APP 5 collection notice |
| Using AML/identity data for marketing | Yes, and reconsider whether you should at all | APP 7 and purpose limits |
| Disclosing information overseas beyond the routine | Sometimes | APP 8 |
| Collecting more than the standard requires | Don't; minimise instead | APP 3 / data minimisation |
The clearest trap is re-using AML data for something else: for example, adding a client's details to a marketing list off the back of an identity check. The information was collected for a legal purpose; using it for an unrelated one is where consent (and purpose limits) bite.
Where does VOI consent fit in?
Your electronic-conveyancing VOI process may involve its own client acknowledgements as part of the identity-verification standard. That's separate from the AML question and from Privacy Act consent. Keep the three ideas distinct: VOI is the lodgment identity standard, AML CDD is the money-laundering check, and Privacy Act consent is about uses the law doesn't already require. (See VOI vs AML customer due diligence.)
Common questions
Do I need a signed consent form to run AML checks?
Generally no: collecting the ID and CDD information AML law requires is authorised by law, so it doesn't depend on consent. You do, however, have to give the client a collection notice explaining what you collect and why.
What if a client refuses to provide their ID?
You collect it because the law requires it, not because the client agrees, and without the required verification you generally can't lawfully provide the service or proceed to settlement. That consequence belongs in your collection notice.
When do I actually need consent?
For things the law doesn't require: most commonly using the information for marketing, and sometimes for certain overseas disclosures. Re-using AML data for an unrelated purpose is the classic case where consent and purpose limits apply.
Can I add AML-check clients to my newsletter?
Not off the back of the identity check. That data was collected for a legal purpose; marketing is a different purpose that engages APP 7 and purpose-limitation rules. Treat it separately and get consent.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Privaproof's conveyancer materials are self-authored and are not independently reviewed by a solicitor. Sources: OAIC, Australian Privacy Principles; OAIC, privacy guidance for reporting entities under the AML/CTF Act; AUSTRAC.