Do conveyancers need client consent to collect ID and run AML checks?
Usually not for the collection itself: AML/CTF law requires you to collect and verify identity and CDD information, so it is authorised by law, not by consent (APP 3.2, APP 3.4(a)). Two methods are different. A credit-reporting-body identity match needs the client's express agreement and an alternative method (AML/CTF Act s 35A(2)), and an automated face match against the ID photo is sensitive information (Privacy Act s 6(1), 'sensitive information' (d)), so APP 3.3 applies. Either way you owe an APP 5 collection notice.
By Jon Oates, Founder of Privaproof · Last updated
‹ Conveyancer privacy compliance hub
General information, not legal advice. Your obligations depend on your circumstances.
How are consent and "required by law" different?
It's a common assumption that a Privacy Act obligation means a signed consent for everything. It doesn't. A driver licence or passport is not on the closed list of sensitive information in s 6(1), so APP 3.3 never engages for it: you may collect it where it's reasonably necessary for your functions (APP 3.2). Where collection is required or authorised by an Australian law, APP 3.4(a) covers even sensitive information that would otherwise need consent. AML customer due diligence is a legal obligation, so the identity and CDD information the AML rules require is authorised without separate consent.
The practical upshot: for the documents themselves you're not asking permission to run a check the law requires. What you are required to do is be transparent, and to get agreement to two specific verification methods.
Why don't you need consent for the AML collection?
When you collect a client's identity documents, beneficial-ownership details or source-of-funds evidence to meet your AML/CTF obligations, you're doing something the law requires: s 28(3)(d) of the AML/CTF Act requires you to "verify, using reliable and independent data" the KYC information appropriate to the customer's ML/TF risk. That is a "required or authorised by law" footing, not a consent one. Nor can you waive it because a client would rather you didn't check: under s 28(1) a reporting entity must not commence a designated service until it has established the s 28(2) matters on reasonable grounds.
Do you still have to be transparent?
Not needing consent is not the same as not telling anyone. APP 5.1 requires reasonable steps, at or before collection or as soon as practicable afterwards, to notify the client of the APP 5.2 matters. Two do the work here: APP 5.2(c) requires you to name the Australian law that requires or authorises the collection, so the AML/CTF Act has to appear on the face of the notice, and APP 5.2(e) requires the main consequences if it is not collected, which is where the honest one belongs: without the verification you cannot commence the service (s 28(1)). (See Privacy policy vs collection notice.)
Where does consent still matter?
Consent comes back into the picture the moment you step outside what the law requires:
| Situation | Consent needed? | Why |
|---|---|---|
| Collecting the ID and CDD information AML law requires | No | Required or authorised by law (APP 3.2; APP 3.4(a)) |
| Letting the client know you're collecting it | Not "consent", but you must notify | APP 5.1 and the APP 5.2 matters |
| Matching name, address and date of birth against a credit reporting body | Yes: express agreement, an advance explanation and an alternative method | AML/CTF Act s 35A(2); a breach is an interference with privacy (s 35L) |
| An automated face match against the ID photo | Yes | Biometric information used for automated verification is sensitive information (s 6(1), 'sensitive information' (d)); AML law doesn't require it, so APP 3.3(a) |
| Using AML/identity data for marketing | Yes, and reconsider whether you should at all | The client wouldn't reasonably expect it, so APP 7.3, not APP 7.2 |
| Disclosing to an overseas recipient | Only if you first tell them APP 8.1 will not apply | APP 8.1 applies by default; APP 8.2(b) is the exception |
| Collecting more than the standard requires | Don't; minimise instead | APP 3.2, the reasonably-necessary test |
The clearest trap is re-using AML data for something else: adding a client's details to a marketing list off the back of an identity check. APP 6.1 blocks a secondary use unless the client consented (6.1(a)) or an exception in 6.2 applies, and the exception people assume covers them, APP 6.2(a), needs the client to have reasonably expected that use. Nobody expects an identity check to become a newsletter.
Where does VOI consent fit in?
Your electronic-conveyancing VOI process may involve its own client acknowledgements as part of the identity-verification standard. Keep the three ideas distinct: VOI is the lodgment identity standard, AML CDD is the money-laundering check, and Privacy Act consent is about uses and methods the law doesn't already require. Two questions for your VOI or IDV provider: does the check match the client against a credit reporting body, and does it run an automated face match? If either is yes, that's a consent step, not a vendor setting. Outsourcing doesn't move the AML duty either: s 37 lets an agent verify on your behalf, and its note records that "the reporting entity (and not its agent) will be liable to civil penalties" for a CDD failure. (See VOI vs AML customer due diligence.)
Common questions
Do I need a signed consent form to run AML checks?
Generally no for the documents: collecting the ID and CDD information AML law requires is authorised by law, so it doesn't depend on consent. Two verification methods do need agreement, and they're below. You also have to give the client a collection notice explaining what you collect and why.
What if a client refuses to provide their ID?
You collect it because the law requires it, not because the client agrees. Section 28(1) of the AML/CTF Act says a reporting entity "must not commence to provide a designated service to a customer" until it has established the s 28(2) matters on reasonable grounds. That consequence belongs in your collection notice, and APP 5.2(e) is the limb that asks for it.
When do I actually need consent?
Three places, and one is inside the AML law itself. A credit-reporting-body identity match needs express agreement, an advance explanation and an alternative method (AML/CTF Act s 35A(2)). An automated face match against the ID photo is sensitive information, so APP 3.3(a) applies. And any use outside the purpose you collected for: marketing (APP 6.1(a)), or an overseas disclosure under APP 8.2(b), which only works if you expressly tell the client first that APP 8.1 will not apply.
Can I add AML-check clients to my newsletter?
Not off the back of the identity check. That data was collected for a legal purpose, and marketing is a secondary purpose the client wouldn't reasonably expect, so APP 7.3 applies, not APP 7.2: consent, a simple opt-out, and a prominent unsubscribe statement in every message. A commercial email or SMS also needs consent under the Spam Act 2003 (Cth). Ask separately.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: Privacy Act 1988 (Cth); AML/CTF Act 2006 (Cth); OAIC, Australian Privacy Principles; OAIC, privacy guidance for reporting entities under the AML/CTF Act; AUSTRAC.