What is the minimum a conveyancer needs to do to be privacy compliant?
There is no certification, no register and no sign-off, so "compliant" is not a status you reach. If the Act reaches your practice, and the last section works that out, what you can do is be able to demonstrate six things: a current privacy policy, collection notices actually given, security over what you hold, a retention and destruction practice, a way to handle access and correction requests, and a breach plan you could follow tomorrow. For a conveyancing practice the order matters more than the list, because the published outcomes we digest cluster on two of the six.
By Jon Oates, Founder of Privaproof · Last updated
‹ Conveyancer privacy compliance hub
General information, not legal advice. Your obligations depend on your circumstances.
Is there a checklist that makes us compliant?
No, and it is worth being honest about that before listing anything.
There is no privacy certification for a conveyancing practice, no audit you pass, and no body that issues a clearance. The obligations in the Australian Privacy Principles are mostly framed as reasonable steps in the circumstances, which means the answer scales with what you hold and what would happen if you lost it. A practice holding identity documents, source-of-funds evidence and settlement figures is at the more serious end of that scale, and a sole practitioner and a twenty-person firm can both be doing enough while doing visibly different amounts.
So the question to work to is not "have we ticked the boxes". It is: if someone asked, could we show what we do and evidence that we do it?
That reframing does real work, because most of what follows is a record of what happened rather than a document describing an intention. A policy nobody follows is weaker evidence than a short log showing that requests were answered.
Sources: Privacy Act 1988 (Cth), Schedule 1 (Australian Privacy Principles) · OAIC APP guidelines
What are the six things?
- A current privacy policy that is easy to find and describes what you actually do. The policy itself is APP 1.3, the required contents including whether information goes overseas are APP 1.4(f) and (g), and making it available is APP 1.5. It is the only one of the six that is a public document.
- Collection notices that are actually given, at the engagement, at verification of identity and at the source-of-funds request. Written but not given does not satisfy APP 5.
- Security over what you hold. APP 11.1 requires reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. For a conveyancing practice the concentration of risk is the mailbox and the document store.
- Retention and destruction that happens. APP 11.2 requires steps that are reasonable in the circumstances to destroy or de-identify once you no longer need the information, unless an Australian law or a court or tribunal order requires you to keep it. AML/CTF record-keeping and your state's trust-account rules are such laws, which is why this is a reconciliation rather than a purge.
- A way to handle access and correction requests, with an owner, decided before the first one arrives rather than during it.
- A data breach response plan you could follow tomorrow, because the assessment clock starts on suspicion and not on confirmation: s 26WH(2) requires a reasonable and expeditious assessment and all reasonable steps to complete it within 30 days.
And one thing that is not a document: someone accountable. In a small practice that is usually the principal, and naming them is most of the value.
Sources: Privacy Act 1988 (Cth), APP 1.3, APP 5, APP 11.1, APP 11.2, APP 12, APP 13, Part IIIC · OAIC APP guidelines
What order should we do them in?
By where the enforced matters actually land, which is not where most checklists start.
Most checklists start with the privacy policy, because it is the visible artefact and the one a client might ask for. The published outcomes point elsewhere: across the five decisions in our enforcement digest, breach assessment and notification failures under ss 26WH and 26WK appear in three and security under APP 11.1 in two, against collection limits under APP 3 in two. That is a curated set of five, not a population statistic, so treat it as direction of travel.
Read against a conveyancing practice, that suggests:
- 1. Secure what you already hold. Individual logins rather than shared ones, multi-factor authentication on email, and a known location for identity documents. Most practices already hold years of material and this addresses all of it at once.
- 2. Have a breach plan. Who is told, who assesses, what gets recorded. Our conveyancer data breach plan page sets out the shape.
- 3. Fix the collection points. Remove intake fields you cannot justify, and give the notice where you collect. Our collection notice page covers the elements.
- 4. Publish and maintain the policy.
- 5. Decide the access and correction process before a request arrives.
- 6. Give destruction an owner and a date, because nothing is ever destroyed by default.
Steps 1 and 2 are where the record says the exposure is. In Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224 the Federal Court set A$800,000 for the slow assessment under s 26WH(2) and A$800,000 for the late notification under s 26WK(2), on the facts of an ASX-listed pathology company and 223,000 people rather than a conveyancing practice. They are also the two steps most often left until last, because neither produces a document you can show a client.
Sources: OAIC determinations and enforcement outcomes; Privacy Act 1988 (Cth), APP 11.1, Part IIIC · See also what happens if a conveyancer does not comply
We have just enrolled with AUSTRAC. What is the single first step?
Work out what you are now holding that you were not holding before, and where it is.
That is deliberately not "write a privacy policy". Enrolment does not by itself change what your policy needs to say, but it changes what your practice does: you are now collecting identity evidence, beneficial ownership details and source-of-funds material, systematically, on every matter where you provide a designated service, and storing it somewhere.
So the first step is an inventory, and it can take an afternoon:
- What are we collecting, field by field, for customer due diligence.
- Where does it land when a client emails it, when a staff member saves it, and when a verification provider returns a result.
- Who can reach it, which in most practices is a longer list than expected.
Everything else follows from that answer, including the policy, the notice and the retention decision. Writing the documents first means describing a practice you have not yet examined, which is how a policy ends up saying something the office does not do.
Sources: Privacy Act 1988 (Cth), APP 1.2, APP 11.1 · See also what personal information conveyancers collect for AML
What is genuinely different for a conveyancer?
Three things, and they are the reason a general small-business privacy checklist fits badly.
The collection is compelled, not chosen. Most small businesses ask themselves whether they need a piece of information. A conveyancing practice providing AML/CTF designated services is required to collect a defined core, which means the reasonably-necessary question is already answered for that core and remains live for everything around it.
Retention pulls against destruction, and both are legal obligations. APP 11.2 says destroy what you no longer need; AML/CTF record-keeping and state trust-account rules say keep. They do not actually conflict, because APP 11.2 excepts information you are required by law to retain, but the practice has to know which rule governs which record. Our record retention page works it through.
The information is concentrated and high-consequence. Identity documents plus financial evidence plus a current residential address, in one file, is close to everything needed to impersonate someone. That is why the security step outranks the paperwork step for this vertical specifically.
Sources: Privacy Act 1988 (Cth), APP 3.2, APP 11.1, APP 11.2; Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) · See also what information a conveyancer can collect
How do we keep track of law changes without a lawyer?
Honestly, and the honest answer includes what you cannot do this way.
What a practice can reasonably do itself: subscribe to the OAIC's own updates and to AUSTRAC's, both free and both the primary source rather than commentary. Watch your professional association, which will usually flag changes affecting conveyancers before general coverage does. And diarise a review of your own documents once a year, plus whenever you change a system that touches client information, which is the trigger people forget.
What that will not give you is an answer to whether a change applies to your particular practice, or what to do about it. Tracking is not advice, and the gap between knowing a rule changed and knowing what it means for your file is exactly where a practice either gets advice or accepts a risk knowingly.
Two dated items worth having in the diary now: the automated decision-making transparency requirement in APP 1.7 to 1.9, commencing 10 December 2026, which is a disclosure obligation rather than a prohibition and, like every APP, binds APP entities, so a practice brought in only by s 6E(1A) is reached only for its AML-connected activities. It is covered on our conveyancer ADM page. Second, several widely discussed reforms, including removal of the small-business exemption, are proposals rather than law. Anyone telling you the exemption has gone is describing something that has not happened.
Sources: OAIC · AUSTRAC · Privacy and Other Legislation Amendment Act 2024 (Cth)
Does the Privacy Act apply to us at all?
It turns on turnover and on what services you provide, and the AML answer does not settle the whole question.
A practice whose annual turnover for the previous financial year was A$3 million or less is generally a small business operator and exempt, unless a trigger applies. Turnover counts income from all sources earned in the course of the business, including commission, rent, interest and dividends (s 6DA(1)), and once you have crossed the threshold in a completed financial year you do not regain the exemption by later dropping below it (s 6D(4)(a)).
The trigger to check first is s 6E(1A): where you provide AML/CTF designated services, you are treated as an organisation in relation to the activities you carry on for the purposes of, or in connection with, those obligations. That is scoped, not general. Other routes catch the whole practice: s 6D(4) has six limbs, including a completed year over A$3m, disclosing personal information about someone for a benefit, and being a contracted service provider for a Commonwealth contract; s 6D(9) covers a body corporate related to one carrying on a business that is not a small business; and s 6EA is the opt-in.
Ordinary residential leasing is not a designated service, so a practice doing only that work is not brought in by the AML route. That exclusion comes from the s 5 definition of "real estate", which excludes a leasehold interest under a lease for a term of 30 years or less. Money held in property management is excluded by a separate route, s 6(5C)(b), whose Note names property management services as its example.
⭐ Note which table you are in, because it is not the agencies' one. Agencies provide the real-estate services in Table 5 (s 6(5A)); a conveyancing practice provides the professional services in Table 6 (s 6(5B)). Three consequences: Table 6 items 1 and 2 do not apply where the transfer is "pursuant to, or resulting from, an order of a court or tribunal", which is a question about the transfer itself rather than about the type of matter; item 2 reaches transfers of a body corporate or legal arrangement, so some work with no land in it is caught; and ⭐ item 3 covers receiving, holding and controlling (including disbursing) or managing a person's money, but only "as part of assisting" them in a transaction and only "other than in a circumstance covered by subsection (5C)". Of the six limbs in s 6(5C), (c) excludes money receivable under a court or tribunal order and (e) excludes item 3 where the service is any other designated service, so a trust account is not automatically a second trigger. Does your file show which of those the money moved under?
One standard across the office is usually simpler than maintaining a boundary between AML data and the rest of the file. That is a practical judgement, not a legal requirement.
Sources: Privacy Act 1988 (Cth), ss 6C, 6D, 6DA, 6E(1A) · See also do conveyancers need a privacy policy
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC.