Skip to content

Do conveyancers need client consent to collect ID and run AML checks?

Usually not for the collection itself: AML/CTF law requires you to collect and verify identity and CDD information, so it is authorised by law, not by consent (APP 3.2, APP 3.4(a)). Two methods are different. A credit-reporting-body identity match needs the client's express agreement and an alternative method (AML/CTF Act s 35A(2)), and an automated face match against the ID photo is sensitive information (Privacy Act s 6(1), 'sensitive information' (d)), so APP 3.3 applies. Either way you owe an APP 5 collection notice.

By Jon Oates, Founder of Privaproof · Last updated

‹ Conveyancer privacy compliance hub

General information, not legal advice. Your obligations depend on your circumstances.

It's a common assumption that a Privacy Act obligation means a signed consent for everything. It doesn't. A driver licence or passport is not on the closed list of sensitive information in s 6(1), so APP 3.3 never engages for it: you may collect it where it's reasonably necessary for your functions (APP 3.2). Where collection is required or authorised by an Australian law, APP 3.4(a) covers even sensitive information that would otherwise need consent. AML customer due diligence is a legal obligation, so the identity and CDD information the AML rules require is authorised without separate consent.

The practical upshot: for the documents themselves you're not asking permission to run a check the law requires. What you are required to do is be transparent, and to get agreement to two specific verification methods.

When you collect a client's identity documents, beneficial-ownership details or source-of-funds evidence to meet your AML/CTF obligations, you're doing something the law requires: s 28(3)(d) of the AML/CTF Act requires you to "verify, using reliable and independent data" the KYC information appropriate to the customer's ML/TF risk. That is a "required or authorised by law" footing, not a consent one. Nor can you waive it because a client would rather you didn't check: under s 28(1) a reporting entity must not commence a designated service until it has established the s 28(2) matters on reasonable grounds.

Do you still have to be transparent?

Not needing consent is not the same as not telling anyone. APP 5.1 requires reasonable steps, at or before collection or as soon as practicable afterwards, to notify the client of the APP 5.2 matters. Two do the work here: APP 5.2(c) requires you to name the Australian law that requires or authorises the collection, so the AML/CTF Act has to appear on the face of the notice, and APP 5.2(e) requires the main consequences if it is not collected, which is where the honest one belongs: without the verification you cannot commence the service (s 28(1)). (See Privacy policy vs collection notice.)

Consent comes back into the picture the moment you step outside what the law requires:

SituationConsent needed?Why
Collecting the ID and CDD information AML law requiresNoRequired or authorised by law (APP 3.2; APP 3.4(a))
Letting the client know you're collecting itNot "consent", but you must notifyAPP 5.1 and the APP 5.2 matters
Matching name, address and date of birth against a credit reporting bodyYes: express agreement, an advance explanation and an alternative methodAML/CTF Act s 35A(2); a breach is an interference with privacy (s 35L)
An automated face match against the ID photoYesBiometric information used for automated verification is sensitive information (s 6(1), 'sensitive information' (d)); AML law doesn't require it, so APP 3.3(a)
Using AML/identity data for marketingYes, and reconsider whether you should at allThe client wouldn't reasonably expect it, so APP 7.3, not APP 7.2
Disclosing to an overseas recipientOnly if you first tell them APP 8.1 will not applyAPP 8.1 applies by default; APP 8.2(b) is the exception
Collecting more than the standard requiresDon't; minimise insteadAPP 3.2, the reasonably-necessary test

The clearest trap is re-using AML data for something else: adding a client's details to a marketing list off the back of an identity check. APP 6.1 blocks a secondary use unless the client consented (6.1(a)) or an exception in 6.2 applies, and the exception people assume covers them, APP 6.2(a), needs the client to have reasonably expected that use. Nobody expects an identity check to become a newsletter.

Your electronic-conveyancing VOI process may involve its own client acknowledgements as part of the identity-verification standard. Keep the three ideas distinct: VOI is the lodgment identity standard, AML CDD is the money-laundering check, and Privacy Act consent is about uses and methods the law doesn't already require. Two questions for your VOI or IDV provider: does the check match the client against a credit reporting body, and does it run an automated face match? If either is yes, that's a consent step, not a vendor setting. Outsourcing doesn't move the AML duty either: s 37 lets an agent verify on your behalf, and its note records that "the reporting entity (and not its agent) will be liable to civil penalties" for a CDD failure. (See VOI vs AML customer due diligence.)

Common questions

Generally no for the documents: collecting the ID and CDD information AML law requires is authorised by law, so it doesn't depend on consent. Two verification methods do need agreement, and they're below. You also have to give the client a collection notice explaining what you collect and why.

What if a client refuses to provide their ID?

You collect it because the law requires it, not because the client agrees. Section 28(1) of the AML/CTF Act says a reporting entity "must not commence to provide a designated service to a customer" until it has established the s 28(2) matters on reasonable grounds. That consequence belongs in your collection notice, and APP 5.2(e) is the limb that asks for it.

Three places, and one is inside the AML law itself. A credit-reporting-body identity match needs express agreement, an advance explanation and an alternative method (AML/CTF Act s 35A(2)). An automated face match against the ID photo is sensitive information, so APP 3.3(a) applies. And any use outside the purpose you collected for: marketing (APP 6.1(a)), or an overseas disclosure under APP 8.2(b), which only works if you expressly tell the client first that APP 8.1 will not apply.

Can I add AML-check clients to my newsletter?

Not off the back of the identity check. That data was collected for a legal purpose, and marketing is a secondary purpose the client wouldn't reasonably expect, so APP 7.3 applies, not APP 7.2: consent, a simple opt-out, and a prominent unsubscribe statement in every message. A commercial email or SMS also needs consent under the Spam Act 2003 (Cth). Ask separately.


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: Privacy Act 1988 (Cth); AML/CTF Act 2006 (Cth); OAIC, Australian Privacy Principles; OAIC, privacy guidance for reporting entities under the AML/CTF Act; AUSTRAC.