Do conveyancers need a data breach response plan in 2026?
If you provide a conveyancing designated service, yes. You have been an AUSTRAC reporting entity since 31 March 2026, so Privacy Act s 6E(1A) applies the Act to your AML/CTF activities, and the Notifiable Data Breaches scheme in Part IIIC comes with it: s 26WH(2) requires a reasonable and expeditious assessment of a suspected breach, and all reasonable steps to complete it within 30 days; ss 26WK–26WL require notification once serious harm is likely. A response plan is how you meet that duty for the sensitive data you concentrate.
By Jon Oates, Founder of Privaproof · Last updated
‹ Conveyancer privacy compliance hub
General information, not legal advice. Your obligations depend on your circumstances.
Why does the breach scheme now reach conveyancers?
Since 31 March 2026, providing a conveyancing designated service makes your firm an AUSTRAC reporting entity, and under Privacy Act s 6E(1A) the Act applies to the activities you carry on for the purposes of, or in connection with, the AML/CTF Act: collecting and verifying identity documents, KYC and beneficial-ownership records, and source-of-funds evidence. (The full mechanism is set out in Do conveyancers need a privacy policy in 2026?.)
Once the Privacy Act applies to that data, so does the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Act. The NDB scheme is not a "have a document" rule on its own; it's an obligation to assess and notify certain breaches. A response plan is simply how a busy practice meets that obligation quickly and correctly instead of improvising during a crisis.
What counts as a notifiable breach?
The scheme is triggered by an eligible data breach. Section 26WE(2) has two limbs: unauthorised access to, or disclosure of, personal information where a reasonable person would conclude it would be likely to result in serious harm to any individual it relates to; or loss of it where such access or disclosure is likely to occur and would be likely to cause serious harm. Section 26WF is a separate exception, not a third limb: act before serious harm results, so that a reasonable person would conclude serious harm is no longer likely, and the breach "is not, and is taken never to have been" eligible. Not every incident is notifiable; the test is whether serious harm is likely.
For a conveyancing practice, the s 26WG factors point one way. Two of them are the kind of information and its sensitivity: identity documents, source-of-funds evidence and trust-account and settlement details are the combination that enables identity theft and financial fraud, so an incident that would sit low on those factors for a general small business can sit high for you. Which of your matter files would a single mailbox compromise expose?
What is the 30-day breach clock?
If you have reasonable grounds to suspect an eligible breach but are not sure, s 26WH(2) puts two duties on you, not on the regulator: carry out "a reasonable and expeditious assessment", and "take all reasonable steps to ensure that the assessment is completed within 30 days" after you become aware. Expedition is the statutory standard; 30 days is the outer limit, not the target. If the assessment confirms an eligible breach, s 26WK(2) requires a statement to the Commissioner as soon as practicable and s 26WL(2) sets who else you tell. In Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224 the Federal Court put A$800,000 of the penalty against the s 26WH(2) assessment failure alone, in a case about an ASX-listed pathology company and 223,000 people, not an agency. The clock is short, which is exactly why the decisions are better made in advance.
At a glance: the NDB steps
| Step | What you do | Reference |
|---|---|---|
| 1. Contain | Stop the breach and limit further access or disclosure | OAIC data-breach guidance |
| 2. Assess | Reasonable and expeditious assessment, with all reasonable steps taken to complete it within 30 days of becoming aware | Privacy Act s 26WH(2) |
| 3. Evaluate serious harm | Weigh the risk factors: the kind of information, its sensitivity, whether it's protected, who obtained it | Privacy Act s 26WG |
| 4. Notify | Statement to the Commissioner as soon as practicable, then notify every individual the information relates to, or only those at risk, or publish and publicise | Privacy Act ss 26WK(2), 26WL(2) |
| 5. Record and review | Log the incident and fix the cause so it can't recur | APP 11.1 "reasonable steps" |
What's the conveyancing breach that matters most?
The breach vector that should be front of mind for a conveyancing or settlement practice is payment-redirection and settlement fraud. A compromised email account, a spoofed message, or intercepted correspondence lets a criminal substitute their own bank details for a genuine party's, and settlement money is gone. The same email compromise often exposes the identity documents and source-of-funds evidence attached to a matter.
That is both a fraud problem and, very likely, a data-breach problem. A good plan treats them together: it names who to call, how to freeze a settlement, how to check whether personal information was exposed, and when the NDB assessment clock starts. Leading on this scenario, rather than a generic "lost laptop" example, is what makes a conveyancer's plan actually useful.
How do AML tipping-off rules affect breach timing?
One wrinkle. AML/CTF Act s 123 makes it an offence to disclose suspicious-matter reporting information where the disclosure "would or could reasonably be expected to prejudice an investigation", and s 123(3) provides that "it is immaterial whether an investigation has commenced". Where an incident touches both a possible fraud and a suspected suspicious matter, the timing and wording of any notification can interact with s 123, and the s 123(4) crime-prevention exception is written for legal practitioners and qualified accountants, not for licensed conveyancers as such unless the AML/CTF Rules specify them. Get professional advice on the specific incident. Privaproof provides general information and does not assess AML/CTF obligations, which are administered by AUSTRAC. (For the AML side of Tranche 2, see AML Tranche 2 for conveyancers: the privacy half nobody mentions.)
So, do you need a plan?
If you provide conveyancing designated services, the NDB scheme applies to your AML-connected data, and the s 26WH(2) clock does not wait for you to work out a process. Among the Federal Court's findings in Australian Clinical Labs (No 2) was that the company's "cyber incidents playbooks did not clearly define roles and responsibilities for incident response" [53]. Open your own: does it name who decides, who calls the bank, and when the 30 days start? A written response plan (containment, the assessment test, the s 26WG factors, the s 26WK statement and a breach register) is how you answer that before the day you need it. For WA settlement agents the position is identical; see Do WA settlement agents need a privacy policy and AUSTRAC enrolment in 2026?.
Common questions
When does a conveyancer have to report a data breach?
When there is an eligible data breach under s 26WE(2): unauthorised access to or disclosure of personal information that a reasonable person would conclude is likely to result in serious harm, or loss where that is likely to follow. Prompt remedial action is a separate exception in s 26WF, not part of the definition. Once you have reasonable grounds to believe there has been one, s 26WK(2) requires a statement to the Commissioner as soon as practicable, and s 26WL(2) then requires you to notify all the individuals concerned, or only those at risk, or, if neither is practicable, publish the statement and publicise it.
How long do I have to assess a suspected breach?
Thirty days is the outer limit, not the target. Section 26WH(2) requires you to carry out "a reasonable and expeditious assessment" and to "take all reasonable steps to ensure that the assessment is completed within 30 days" after you become aware. Both duties sit on you as the entity, not on the OAIC.
What's the most common data breach for a conveyancing practice?
Payment-redirection and settlement fraud: a compromised or spoofed email that substitutes fraudulent bank details, which often also exposes the identity and source-of-funds documents attached to the matter.
Is a written breach response plan legally required?
No. Part IIIC requires you to assess and notify eligible breaches; it does not mandate a document. But in Australian Clinical Labs (No 2) [2025] FCA 1224 the Federal Court's findings included playbooks that "did not clearly define roles and responsibilities for incident response" [53]. A written plan is how you meet the s 26WH(2) duty inside the 30-day limit instead of improvising during a crisis.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: OAIC, Notifiable Data Breaches scheme; OAIC, data breach preparation and response; Privacy Act 1988 (Cth) Part IIIC; AUSTRAC.