Do conveyancers disclose client data overseas via PEXA, screening or cloud software?
Possibly: it depends on your software. Sending client personal information overseas triggers APP 8, which makes you take reasonable steps to ensure an overseas recipient handles it consistently with the Privacy Act. Australia's e-conveyancing platforms and registries are generally understood to operate onshore, but some screening tools and cloud software aren't, so it's worth knowing where your data actually goes.
By Jon Oates, Founder of Privaproof · Last updated
‹ Conveyancer privacy compliance hub
General information, not legal advice. Your obligations depend on your circumstances.
What does APP 8 require?
APP 8 deals with cross-border disclosure. Before an APP entity discloses personal information to an overseas recipient, it must take reasonable steps to ensure the recipient doesn't breach the APPs in relation to that information. There's also an accountability layer: under section 16C, an entity can remain accountable for what an overseas recipient does with the information, as if the entity had done it itself. In some cases an exception applies (for example, where the recipient is bound by a substantially similar privacy law with enforcement mechanisms, or the individual gave informed consent), but absent one of those, the accountability stays with you. In plain terms: if your data goes offshore, you usually don't get to wash your hands of how it's treated there.
For a conveyancer, this now matters because the AML-connected data you hold (identity documents, screening results, source-of-funds evidence) is exactly the kind you'd least want mishandled overseas.
Where might a conveyancer's data go overseas?
The honest answer is "it depends on your stack," so the useful exercise is knowing which of your tools keep data onshore and which might not:
| Tool / recipient | Typically | APP 8 relevance |
|---|---|---|
| PEXA / Sympli (ELNOs) | Largely Australian-hosted | Lower, but confirm with the provider |
| Land titles / registry portals | Operated by state/territory governments, onshore | Lower |
| PEP / sanctions screening | May draw on offshore data sources | Check where data is sent and stored |
| Cloud matter-management software | May store data offshore | Check the provider's data location |
| General cloud, email, storage | Varies widely | Check: this is the easy one to miss |
The pattern: the conveyancing-specific rails (ELNOs, registries) are generally understood to be onshore, which reduces (but doesn't remove) exposure. The general-purpose tools (cloud storage, some screening vendors, email providers) are where offshore disclosure quietly happens.
Who's accountable if an overseas provider mishandles data?
The reason APP 8 and s 16C matter isn't paperwork for its own sake. If a cloud provider or overseas screening service you use mishandles a client's identity data, the accountability can flow back to you. That's why "we just use whatever software" isn't a safe answer any more; you're expected to have taken reasonable steps, and to be able to show it.
What should you do?
- Map your providers. List the tools that touch client personal information and note, for each, whether data leaves Australia.
- Check your contracts and provider terms. Reputable providers document their data locations and safeguards; that's part of your "reasonable steps."
- Cover it in your policy and notices. Your privacy policy should be honest about whether you disclose information overseas, and your collection process should reflect it.
- Prefer onshore where you sensibly can for the most sensitive data; it narrows your APP 8 exposure.
This is the same accountability logic that runs through the rest of your obligations: know what data you hold, know where it goes, and be able to show you handled it responsibly.
Common questions
Does using PEXA send client data overseas?
Australia's e-conveyancing platforms and land registries are largely Australian-hosted, which keeps that data onshore, but you should confirm each provider's data location rather than assume, since it's your reasonable-steps obligation.
Am I responsible if an overseas provider mishandles my client's data?
Potentially yes. Under s 16C an entity can remain accountable for an overseas recipient's handling of the information as if it had done it itself, unless an APP 8.2 exception applies (such as the recipient being bound by a substantially similar law, or informed consent). Absent an exception, taking reasonable steps under APP 8 is what protects you.
What's the biggest overseas-disclosure risk for a conveyancer?
Usually the general-purpose tools (cloud storage, email, and some screening vendors) rather than the conveyancing-specific platforms. They're the easiest to overlook when you map where data goes.
Do I have to mention overseas disclosure in my privacy policy?
If you disclose personal information overseas, your privacy policy should say so (and, where practicable, the countries involved). Being straight about it is part of APP 1 transparency.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Privaproof's conveyancer materials are self-authored and are not independently reviewed by a solicitor. Sources: OAIC, Australian Privacy Principles; OAIC, privacy guidance for reporting entities under the AML/CTF Act; Privacy Act 1988 (Cth) s 6E(1A).