What personal information do conveyancers collect for AML, and is it now regulated?
More than you might think, and it is now regulated. For AML you collect identity documents, beneficial-ownership details, PEP and sanctions-screening results and source-of-funds evidence. If that work makes you a reporting entity, s 6E(1A) applies the Privacy Act to the activities you carry on "for the purposes of, or in connection with" the AML/CTF Act, whatever your turnover, and that reaches wider than the identity documents alone.
By Jon Oates, Founder of Privaproof · Last updated
‹ Conveyancer privacy compliance hub
General information, not legal advice. Your obligations depend on your circumstances.
What data does conveyancing now have to formalise?
Conveyancers have always handled personal information, but AML/CTF customer due diligence pushes you to collect a richer, more sensitive set than before, and to do it in a structured, evidenced way. The Privacy Act does not stop at the documents: s 6E(1A) reaches the activities you carry on in connection with the AML/CTF Act, so it is worth knowing precisely what's in the pile.
What do you now collect for AML?
Initial customer due diligence typically involves collecting and recording:
- Identity / KYC data: the customer's identity verified from documents such as passport, driver licence or Medicare card.
- Who they act for: whether the person is acting for themselves or on behalf of someone else.
- Beneficial-ownership details: where the customer is not an individual, the individual who ultimately owns 25% or more of it, or who controls it directly or indirectly (AML/CTF Act s 5).
- PEP and sanctions-screening results: whether the person is a politically exposed person or appears on a sanctions list.
- The nature and purpose of the transaction or business relationship.
- Source of funds / source of wealth: for higher-risk matters, evidence of where the settlement money comes from (bank statements, gift or loan evidence).
At a glance
| Data category | What it includes | Why you collect it |
|---|---|---|
| Identity / KYC documents | Passport, driver licence, Medicare, and similar | Verify the customer's identity (KYC) |
| Beneficial ownership | An individual owning 25% or more of a non-individual customer, or controlling it (s 5) | Know who ultimately controls the customer |
| PEP / sanctions results | Screening outcomes | Assess money-laundering / sanctions risk |
| Source of funds / wealth | Bank statements, gift or loan evidence | Understand where settlement money originates (higher-risk) |
Why is this higher-sensitivity than a typical small business?
Put together, this is a concentrated dataset of exactly the kind that causes serious harm if it leaks: government identity documents, financial records, and screening results, tied to a specific property transaction and often to trust-account details. In the first civil penalty imposed under the Privacy Act, Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224, A$800,000 of the A$5.8 million was for failing to assess a suspected breach reasonably and expeditiously (s 26WH(2)), and the Court found playbooks that "did not clearly define roles and responsibilities for incident response". That was an ASX-listed company and 223,000 people, not a conveyancing practice. Does your plan name who decides, and by when? A data breach response plan is that document.
Why does the Privacy Act now reach this work?
The key legal point: assisting in a transaction to transfer real estate is a designated service under AML/CTF Act s 6(5B) table 6 item 1, unless the transfer is pursuant to a court or tribunal order. Table 6 commenced on 31 March 2026; the deferred obligation Parts, including customer due diligence, applied from 1 July 2026. If that makes you a reporting entity, s 6E(1A) applies the Privacy Act to you "in relation to the activities carried on ... for the purposes of, or in connection with, activities relating to" the AML/CTF Act, even if you turn over less than $3 million (see Does becoming an AUSTRAC reporting entity trigger the Privacy Act?). Read that scope as the AML-connected activities as a whole, which is wider than the identity documents alone, and not as words that reach activities unconnected with the AML/CTF Act. For that work the APPs apply: you need a privacy policy, a collection notice at the point you take it, secure storage, and a considered retention schedule.
Why not collect extra data just in case?
One habit worth building early: tell clients what to send before they send it, and collect only what the AML and VOI standards require. The order matters. Once a document relating to a designated service is given to you by or on behalf of the customer, and you have commenced providing that service, AML/CTF Act s 108(2) requires you to retain the document, or a copy, for 7 years after it was given, and s 108(3) makes that a civil penalty provision. All three limbs have to be met, so minimisation does its work at the point of collection, not afterwards. Get advice before destroying anything a client has already sent.
Common questions
Is a beneficial owner the same as the client?
Not necessarily. Where the customer is not an individual, a beneficial owner is an individual who ultimately owns 25% or more of it, or who controls it directly or indirectly (AML/CTF Act s 5). That may be a different person from the one in front of you, especially for company or trust clients.
Is the AML data I collect covered by the Privacy Act?
Yes, if the AML work makes you a reporting entity. s 6E(1A) then applies the Privacy Act "in relation to the activities carried on ... for the purposes of, or in connection with, activities relating to" the AML/CTF Act, regardless of your turnover. Being activity-scoped, it covers more than the identity documents themselves.
Do I have to collect source-of-funds information for every client?
Source-of-funds and source-of-wealth checks are generally associated with higher-risk matters rather than every client. Whether a given matter requires it is an AML judgement. Privaproof doesn't assess AML/CTF obligations; AUSTRAC does.
Does collecting more information make me safer?
Usually the opposite. Over-collecting sensitive identity and financial data increases your breach exposure without adding compliance value. Collect what the standard requires, and no more.
Does this apply to WA settlement agents too?
Yes. A WA settlement agent providing the table 6 item 1 designated service collects the same AML data, and s 6E(1A) reaches those activities the same way; only the job title and state licensing differ. See our guide for WA settlement agents.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: OAIC, privacy guidance for reporting entities under the AML/CTF Act; AUSTRAC, professional designated services; Privacy Act 1988 (Cth) s 6E(1A); Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) ss 5, 6(5B), 108.