Skip to content

Do conveyancers need a data breach response plan in 2026?

For most conveyancers from 1 July 2026, yes. Because the Privacy Act now covers your AML data, the Notifiable Data Breaches scheme applies: you must assess a suspected breach within 30 days and notify the OAIC and affected people if serious harm is likely. A response plan is how you meet that duty for the sensitive data you concentrate.

By Jon Oates, Founder of Privaproof · Last updated

‹ Conveyancer privacy compliance hub

General information, not legal advice. Your obligations depend on your circumstances.

Why does the breach scheme now reach conveyancers?

Since 1 July 2026, providing a conveyancing designated service makes your firm an AUSTRAC reporting entity, and under Privacy Act s 6E(1A) the Privacy Act applies to the personal information you handle for AML/CTF: identity documents, KYC and beneficial-ownership records, and source-of-funds evidence. (The full mechanism is set out in Do conveyancers need a privacy policy in 2026?.)

Once the Privacy Act applies to that data, so does the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Act. The NDB scheme is not a "have a document" rule on its own; it's an obligation to assess and notify certain breaches. A response plan is simply how a busy practice meets that obligation quickly and correctly instead of improvising during a crisis.

What counts as a notifiable breach?

The scheme is triggered by an eligible data breach: unauthorised access to, or unauthorised disclosure of, personal information (or its loss in circumstances where that's likely to happen), where a reasonable person would conclude it is likely to result in serious harm to an affected individual, and the risk can't be removed by prompt remedial action (the s 26WF exception). Not every incident is notifiable; the test is whether serious harm is likely.

For a conveyancing practice, the data you hold makes serious harm easy to reach. Identity documents, source-of-funds evidence and trust-account and settlement details are precisely the combination that enables identity theft and financial fraud, so a breach that would be low-risk for a general small business can be high-risk for you.

What is the 30-day breach clock?

If you have reasonable grounds to suspect an eligible breach but aren't sure, you must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days, and the OAIC expects you to move faster where you can, treating 30 days as a ceiling, not a default. If the assessment confirms an eligible breach, you must notify the OAIC and the affected individuals as soon as practicable. The clock is short, which is exactly why the decisions are better made in advance.

At a glance: the NDB steps

StepWhat you doReference
1. ContainStop the breach and limit further access or disclosureOAIC data-breach guidance
2. AssessIf you suspect an eligible breach, assess it, reasonably and expeditiously, within 30 daysPrivacy Act s 26WH
3. Evaluate serious harmWeigh the risk factors: the kind of information, its sensitivity, whether it's protected, who obtained itPrivacy Act s 26WG
4. NotifyIf serious harm is likely, notify the OAIC and affected individuals as soon as practicablePrivacy Act ss 26WK–26WL
5. Record and reviewLog the incident and fix the cause so it can't recurAPP 11.1 "reasonable steps"

What's the conveyancing breach that matters most?

The breach vector that should be front of mind for a conveyancing or settlement practice is payment-redirection and settlement fraud. A compromised email account, a spoofed message, or intercepted correspondence lets a criminal substitute their own bank details for a genuine party's, and settlement money is gone. The same email compromise often exposes the identity documents and source-of-funds evidence attached to a matter.

That is both a fraud problem and, very likely, a data-breach problem. A good plan treats them together: it names who to call, how to freeze a settlement, how to check whether personal information was exposed, and when the NDB assessment clock starts. Leading on this scenario, rather than a generic "lost laptop" example, is what makes a conveyancer's plan actually useful.

How do AML tipping-off rules affect breach timing?

There is one wrinkle worth flagging. The AML/CTF regime includes "tipping-off" rules that limit what a reporting entity can say when a suspicious-matter report may be involved. In a case that touches both a possible fraud and a suspected suspicious matter, the timing and wording of any notification can interact with those AML rules. This is a point to get professional advice on for a specific incident. Privaproof provides general information and does not assess AML/CTF obligations, which are administered by AUSTRAC. (For the AML side of Tranche 2, see AML Tranche 2 for conveyancers: the privacy half nobody mentions.)

So, do you need a plan?

If you provide conveyancing designated services, the NDB scheme now applies to your AML-connected data, and the 30-day assessment window doesn't wait for you to work out a process. A written response plan (containment, the assessment test, the serious-harm factors, notification templates and a breach register) is how you meet the obligation calmly instead of scrambling. For WA settlement agents the position is identical; see Do WA settlement agents need a privacy policy and AUSTRAC enrolment in 2026?.

Common questions

When does a conveyancer have to report a data breach?

When there is an eligible data breach: unauthorised access to, disclosure of, or loss of personal information that is likely to result in serious harm and can't be fixed by prompt remedial action. If serious harm is likely, you notify the OAIC and the affected individuals as soon as practicable.

How long do I have to assess a suspected breach?

Up to 30 days. If you have reasonable grounds to suspect an eligible breach, you must carry out a reasonable and expeditious assessment within 30 days, and the OAIC treats that as a ceiling, expecting you to move faster where you can.

What's the most common data breach for a conveyancing practice?

Payment-redirection and settlement fraud: a compromised or spoofed email that substitutes fraudulent bank details, which often also exposes the identity and source-of-funds documents attached to the matter.

Is a written breach response plan legally required?

The NDB scheme requires you to assess and notify eligible breaches; it does not mandate a specific document. A written plan is simply how you meet that duty quickly and correctly under the 30-day clock, instead of improvising during a crisis.


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Privaproof's conveyancer materials are self-authored and are not independently reviewed by a solicitor. Sources: OAIC, Notifiable Data Breaches scheme; OAIC, data breach preparation and response; Privacy Act 1988 (Cth) Part IIIC; AUSTRAC.