Skip to content

Do conveyancers disclose client data overseas via PEXA, screening or cloud software?

Possibly: it depends on your software. Sending client personal information overseas triggers APP 8, which makes you take reasonable steps to ensure an overseas recipient handles it consistently with the Privacy Act. Australia's e-conveyancing platforms and registries are generally understood to operate onshore, but some screening tools and cloud software aren't, so it's worth knowing where your data actually goes.

By Jon Oates, Founder of Privaproof · Last updated

‹ Conveyancer privacy compliance hub

General information, not legal advice. Your obligations depend on your circumstances.

What does APP 8 require?

APP 8 deals with cross-border disclosure. Before an APP entity discloses personal information to an overseas recipient, it must take reasonable steps to ensure the recipient doesn't breach the APPs in relation to that information. There's also an accountability layer: under section 16C, an entity can remain accountable for what an overseas recipient does with the information, as if the entity had done it itself. In some cases an exception applies (for example, where the recipient is bound by a substantially similar privacy law with enforcement mechanisms, or the individual gave informed consent), but absent one of those, the accountability stays with you. In plain terms: if your data goes offshore, you usually don't get to wash your hands of how it's treated there.

For a conveyancer, this now matters because the AML-connected data you hold (identity documents, screening results, source-of-funds evidence) is exactly the kind you'd least want mishandled overseas.

Where might a conveyancer's data go overseas?

The honest answer is "it depends on your stack," so the useful exercise is knowing which of your tools keep data onshore and which might not:

Tool / recipientTypicallyAPP 8 relevance
PEXA / Sympli (ELNOs)Largely Australian-hostedLower, but confirm with the provider
Land titles / registry portalsOperated by state/territory governments, onshoreLower
PEP / sanctions screeningMay draw on offshore data sourcesCheck where data is sent and stored
Cloud matter-management softwareMay store data offshoreCheck the provider's data location
General cloud, email, storageVaries widelyCheck: this is the easy one to miss

The pattern: the conveyancing-specific rails (ELNOs, registries) are generally understood to be onshore, which reduces (but doesn't remove) exposure. The general-purpose tools (cloud storage, some screening vendors, email providers) are where offshore disclosure quietly happens.

Who's accountable if an overseas provider mishandles data?

The reason APP 8 and s 16C matter isn't paperwork for its own sake. If a cloud provider or overseas screening service you use mishandles a client's identity data, the accountability can flow back to you. That's why "we just use whatever software" isn't a safe answer any more; you're expected to have taken reasonable steps, and to be able to show it.

What should you do?

This is the same accountability logic that runs through the rest of your obligations: know what data you hold, know where it goes, and be able to show you handled it responsibly.

Common questions

Does using PEXA send client data overseas?

Australia's e-conveyancing platforms and land registries are largely Australian-hosted, which keeps that data onshore, but you should confirm each provider's data location rather than assume, since it's your reasonable-steps obligation.

Am I responsible if an overseas provider mishandles my client's data?

Potentially yes. Under s 16C an entity can remain accountable for an overseas recipient's handling of the information as if it had done it itself, unless an APP 8.2 exception applies (such as the recipient being bound by a substantially similar law, or informed consent). Absent an exception, taking reasonable steps under APP 8 is what protects you.

What's the biggest overseas-disclosure risk for a conveyancer?

Usually the general-purpose tools (cloud storage, email, and some screening vendors) rather than the conveyancing-specific platforms. They're the easiest to overlook when you map where data goes.

Do I have to mention overseas disclosure in my privacy policy?

If you disclose personal information overseas, your privacy policy should say so (and, where practicable, the countries involved). Being straight about it is part of APP 1 transparency.


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Privaproof's conveyancer materials are self-authored and are not independently reviewed by a solicitor. Sources: OAIC, Australian Privacy Principles; OAIC, privacy guidance for reporting entities under the AML/CTF Act; Privacy Act 1988 (Cth) s 6E(1A).