Skip to content

What personal information do conveyancers collect for AML, and is it now regulated?

More than you might think, and most of it is now regulated. For AML you collect identity documents, beneficial-ownership details, PEP and sanctions-screening results and source-of-funds evidence. Because you gather that information in connection with your AML/CTF obligations, the Privacy Act now applies to it under s 6E(1A), regardless of your turnover.

By Jon Oates, Founder of Privaproof · Last updated

‹ Conveyancer privacy compliance hub

General information, not legal advice. Your obligations depend on your circumstances.

What data does conveyancing now have to formalise?

Conveyancers have always handled personal information, but AML/CTF customer due diligence pushes you to collect a richer, more sensitive set than before, and to do it in a structured, evidenced way. The information you gather to satisfy AUSTRAC is exactly the information the Privacy Act now regulates, so it helps to know precisely what's in the pile.

What do you now collect for AML?

Initial customer due diligence typically involves collecting and recording:

At a glance

Data categoryWhat it includesWhy you collect it
Identity / KYC documentsPassport, driver licence, Medicare, and similarVerify the customer's identity (KYC)
Beneficial ownershipIndividuals owning/controlling 25% or moreKnow who ultimately controls the customer
PEP / sanctions resultsScreening outcomesAssess money-laundering / sanctions risk
Source of funds / wealthBank statements, gift or loan evidenceUnderstand where settlement money originates (higher-risk)

Why is this higher-sensitivity than a typical small business?

Put together, this is a concentrated dataset of exactly the kind that causes serious harm if it leaks: government identity documents, financial records, and screening results, tied to a specific property transaction and often to trust-account details. A general small business rarely holds this combination. That's why the privacy stakes for a conveyancer are higher than the turnover of the firm might suggest, and why a data breach response plan matters.

Why is this now Privacy-Act data?

The key legal point: because you collect this information for the purposes of, or in connection with, your AML/CTF obligations, it is brought under the Privacy Act by s 6E(1A), even if you turn over less than $3 million (see Does becoming an AUSTRAC reporting entity trigger the Privacy Act?). The coverage is targeted at this AML-connected data, not automatically your whole practice. In practice, that means the APPs apply: you need a privacy policy, a collection notice at the point you take it, secure storage, and a considered retention schedule.

Why not collect extra data just in case?

One habit worth building early: collect the information the AML and VOI standards actually require, and no more. Over-collection (taking extra documents "just in case," or keeping more than you need) doesn't add compliance value and increases the size of the target if you're ever breached. Data minimisation is good privacy practice; for a firm holding this dataset, it's also risk management.

Common questions

Is a beneficial owner the same as the client?

Not necessarily. A beneficial owner is the individual who ultimately owns or controls the customer (broadly, someone owning or controlling 25% or more, or otherwise in control), which may be a different person from the one in front of you, especially for company or trust clients.

Is the AML data I collect covered by the Privacy Act?

Yes. Because you collect it in connection with your AML/CTF obligations, s 6E(1A) applies the Privacy Act to it regardless of your turnover.

Do I have to collect source-of-funds information for every client?

Source-of-funds and source-of-wealth checks are generally associated with higher-risk matters rather than every client. Whether a given matter requires it is an AML judgement. Privaproof doesn't assess AML/CTF obligations; AUSTRAC does.

Does collecting more information make me safer?

Usually the opposite. Over-collecting sensitive identity and financial data increases your breach exposure without adding compliance value. Collect what the standard requires, and no more.

Does this apply to WA settlement agents too?

Yes. A WA settlement agent providing the property-transfer designated service collects the same AML data and is brought under the Privacy Act by s 6E(1A) the same way; only the job title and state licensing differ. See our guide for WA settlement agents.


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Privaproof's conveyancer materials are self-authored and are not independently reviewed by a solicitor. Sources: OAIC, privacy guidance for reporting entities under the AML/CTF Act; AUSTRAC, professional designated services; Privacy Act 1988 (Cth) s 6E(1A).