Skip to content

What is the minimum a conveyancer needs to do to be privacy compliant?

There is no certification, no register and no sign-off, so "compliant" is not a status you reach. What you can do is be able to demonstrate six things: a current privacy policy, collection notices actually given, security over what you hold, a retention and destruction practice, a way to handle access and correction requests, and a breach plan you could follow tomorrow. For a conveyancing practice the order matters more than the list, because the enforced cases cluster on two of the six.

By Jon Oates, Founder of Privaproof · Last updated

‹ Conveyancer privacy compliance hub

General information, not legal advice. Your obligations depend on your circumstances.

Is there a checklist that makes us compliant?

No, and it is worth being honest about that before listing anything.

There is no privacy certification for a conveyancing practice, no audit you pass, and no body that issues a clearance. The obligations in the Australian Privacy Principles are mostly framed as reasonable steps in the circumstances, which means the answer scales with what you hold and what would happen if you lost it. A practice holding identity documents, source-of-funds evidence and settlement figures is at the more serious end of that scale, and a sole practitioner and a twenty-person firm can both be doing enough while doing visibly different amounts.

So the question to work to is not "have we ticked the boxes". It is: if someone asked, could we show what we do and evidence that we do it?

That reframing does real work, because most of what follows is a record of what happened rather than a document describing an intention. A policy nobody follows is weaker evidence than a short log showing that requests were answered.

Sources: Privacy Act 1988 (Cth), Schedule 1 (Australian Privacy Principles) · OAIC APP guidelines

What are the six things?

And one thing that is not a document: someone accountable. In a small practice that is usually the principal, and naming them is most of the value.

Sources: Privacy Act 1988 (Cth), APP 1.3, APP 5, APP 11.1, APP 11.2, APP 12, APP 13, Part IIIC · OAIC APP guidelines

What order should we do them in?

By where the enforced matters actually land, which is not where most checklists start.

Most checklists start with the privacy policy, because it is the visible artefact and the one a client might ask for. The published enforcement record points elsewhere: across the outcomes in the enforcement digest we maintain, data-security and breach-handling failures feature more often than any other category, with collection-limit failures next. That is a curated set rather than a population statistic, so treat it as direction of travel.

Read against a conveyancing practice, that suggests:

1. Secure what you already hold. Individual logins rather than shared ones, multi-factor authentication on email, and a known location for identity documents. Most practices already hold years of material and this addresses all of it at once. 2. Have a breach plan. Who is told, who assesses, what gets recorded. Our conveyancer data breach plan page sets out the shape. 3. Fix the collection points. Remove intake fields you cannot justify, and give the notice where you collect. Our collection notice page covers the elements. 4. Publish and maintain the policy. 5. Decide the access and correction process before a request arrives. 6. Give destruction an owner and a date, because nothing is ever destroyed by default.

Steps 1 and 2 are where the record says the exposure is. They are also the two most often left until last, because neither produces a document you can show a client.

Sources: OAIC determinations and enforcement outcomes; Privacy Act 1988 (Cth), APP 11.1, Part IIIC · See also what happens if a conveyancer does not comply

We have just enrolled with AUSTRAC. What is the single first step?

Work out what you are now holding that you were not holding before, and where it is.

That is deliberately not "write a privacy policy". Enrolment does not by itself change what your policy needs to say, but it changes what your practice does: you are now collecting identity evidence, beneficial ownership details and source-of-funds material, systematically, on every matter, and storing it somewhere.

So the first step is an inventory, and it can take an afternoon:

Everything else follows from that answer, including the policy, the notice and the retention decision. Writing the documents first means describing a practice you have not yet examined, which is how a policy ends up saying something the office does not do.

Sources: Privacy Act 1988 (Cth), APP 1.2, APP 11.1 · See also what personal information conveyancers collect for AML

What is genuinely different for a conveyancer?

Three things, and they are the reason a general small-business privacy checklist fits badly.

The collection is compelled, not chosen. Most small businesses ask themselves whether they need a piece of information. A conveyancing practice providing AML/CTF designated services is required to collect a defined core, which means the reasonably-necessary question is already answered for that core and remains live for everything around it.

Retention pulls against destruction, and both are legal obligations. APP 11.2 says destroy what you no longer need; AML/CTF record-keeping and state trust-account rules say keep. They do not actually conflict, because APP 11.2 excepts information you are required by law to retain, but the practice has to know which rule governs which record. Our record retention page works it through.

The information is concentrated and high-consequence. Identity documents plus financial evidence plus a current residential address, in one file, is close to everything needed to impersonate someone. That is why the security step outranks the paperwork step for this vertical specifically.

Sources: Privacy Act 1988 (Cth), APP 3.2, APP 11.1, APP 11.2; Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) · See also what information a conveyancer can collect

How do we keep track of law changes without a lawyer?

Honestly, and the honest answer includes what you cannot do this way.

What a practice can reasonably do itself: subscribe to the OAIC's own updates and to AUSTRAC's, both free and both the primary source rather than commentary. Watch your professional association, which will usually flag changes affecting conveyancers before general coverage does. And diarise a review of your own documents once a year, plus whenever you change a system that touches client information, which is the trigger people forget.

What that will not give you is an answer to whether a change applies to your particular practice, or what to do about it. Tracking is not advice, and the gap between knowing a rule changed and knowing what it means for your file is exactly where a practice either gets advice or accepts a risk knowingly.

Two dated items worth having in the diary now: the automated decision-making transparency requirement commencing 10 December 2026, which is a disclosure obligation rather than a prohibition and is covered on our conveyancer ADM page; and the fact that several widely discussed reforms, including removal of the small-business exemption, are proposals rather than law. Anyone telling you the exemption has gone is describing something that has not happened.

Sources: OAIC · AUSTRAC · Privacy and Other Legislation Amendment Act 2024 (Cth)

Does the Privacy Act apply to us at all?

It turns on turnover and on what services you provide, and the AML answer does not settle the whole question.

A practice whose annual turnover for the previous financial year was A$3 million or less is generally a small business operator and exempt, unless a trigger applies. Turnover counts income from all sources, and once you have crossed the threshold in a completed financial year you do not regain the exemption by later dropping below it.

For most conveyancing practices the trigger is s 6E(1A): where you provide AML/CTF designated services, you are treated as an organisation in relation to the activities you carry on for the purposes of, or in connection with, those obligations. That is scoped, not general. Other triggers catch the whole practice independently: being related to a body corporate that is not a small business operator, being a contracted service provider under a Commonwealth contract, trading in personal information, or opting in.

Ordinary residential leasing and property management are not designated services, so a practice doing only that work is not brought in by the AML route. That exclusion comes from the s 6 definition of "real estate", which excludes a leasehold of 30 years or less.

Note which table you are in, because it is not the agencies' one. Agencies provide the real-estate services in Table 5; a conveyancing practice provides the professional services in Table 6 (s 6(5B)). Three consequences: Table 6 items 1 and 2 do not apply where the transfer is "pursuant to, or resulting from, an order of a court or tribunal", which releases court-ordered family-law and deceased-estate transfers; item 2 reaches transfers of a body corporate or legal arrangement, so some work with no land in it is caught; and ⭐ item 3 makes receiving, holding, disbursing or managing a client's money its own designated service, which for a practice means the trust account. `verify/2026-07-30-amlctf-act-provisions.md`

Most practices find one standard across the office simpler than maintaining a boundary between AML data and the rest of the file. That is a practical judgement, not a legal requirement.

Sources: Privacy Act 1988 (Cth), ss 6C, 6D, 6DA, 6E(1A) · See also do conveyancers need a privacy policy


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Privaproof's conveyancer materials are self-authored and are not independently reviewed by a solicitor.