Skip to content

What happens if a conveyancer doesn't meet the new privacy obligations?

More than before, and now on more fronts. As a reporting entity you can face enforcement from AUSTRAC for AML/CTF breaches and from the OAIC for privacy breaches. Separately, and regardless of that status, an individual can sue you directly under the statutory tort for serious invasions of privacy that were intentional or reckless. Carelessness alone is not enough. Exact consequences depend on the breach; get advice.

By Jon Oates, Founder of Privaproof · Last updated

‹ Conveyancer privacy compliance hub

General information, not legal advice. Your obligations depend on your circumstances.

Which regulators can now act against you?

Until 1 July 2026, most small conveyancing practices sat outside both regimes. Becoming an AUSTRAC reporting entity changes that on two fronts at once:

The practical shift is simple: two regulators can now take an interest in the same conveyancing file, from two different angles.

Can an individual sue you directly?

There's also a route that doesn't involve any regulator. Since 10 June 2025, a statutory tort for serious invasions of privacy lets an individual sue directly, for intrusion into seclusion or misuse of information, where the person had a reasonable expectation of privacy, the invasion is serious, and it was intentional or reckless (mere negligence isn't enough). Notably, no proof of financial loss is required, and remedies can include damages.

This matters for conveyancers specifically because you concentrate exactly the kind of data (identity documents, source-of-funds evidence, trust-account and settlement details) whose mishandling most readily supports a "serious" invasion claim. It's a direct-liability exposure that sits alongside, not instead of, the regulators.

At a glance: where the exposure comes from

SourceWhat it coversWho acts
AML/CTF obligationsEnrolment, program, CDD, record-keeping, reportingAUSTRAC
Privacy Act (APPs)Privacy policy, collection notices, data securityOAIC
Notifiable Data BreachesAssessing and notifying eligible breachesOAIC
Statutory tortSerious invasion of privacy (identity + financial data)The affected individual (courts)

Why is doing nothing no longer a neutral option?

None of this is a reason to panic, and it isn't about worst-case penalty figures. Those depend entirely on the circumstances and are a matter for the regulators and, ultimately, the courts. The realistic takeaway is narrower: before 1 July 2026, doing nothing about privacy carried little consequence for a small firm; now it carries exposure on three distinct fronts. The proportionate response is to get the baseline in place (the privacy policy, the collection notices and a breach response plan) rather than to leave the gap open.

For what that baseline looks like, see Do conveyancers need a privacy policy in 2026? and Do conveyancers need a data breach response plan?. For how the obligation arises in the first place, see Does becoming an AUSTRAC reporting entity trigger the Privacy Act?.

Common questions

Can I be penalised by both AUSTRAC and the OAIC for the same file?

They regulate different obligations (AUSTRAC the AML/CTF duties, the OAIC the privacy duties), so a single incident can raise issues under both. What any specific situation attracts depends on the circumstances; get advice.

Is there a fine just for not having a privacy policy?

The consequences of non-compliance are a matter for the OAIC and depend on the circumstances. This page doesn't quantify them. The reliable point is that having a compliant APP 1 policy is the baseline obligation, and not having one is a gap.

Can a client sue me personally over a privacy breach?

Since 10 June 2025, an individual can bring a statutory-tort claim for a serious invasion of privacy directly, without a regulator, and no proof of financial loss is required. The concentrated data conveyancers hold makes that exposure real.

Do I need to worry about this if I'm under the $3 million threshold?

Yes, for your AML-connected data. Turnover doesn't shield that data; s 6E(1A) applies the Privacy Act to it regardless of size.


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Privaproof's conveyancer materials are self-authored and are not independently reviewed by a solicitor. Sources: OAIC, privacy guidance for reporting entities under the AML/CTF Act; OAIC, statutory tort for serious invasions of privacy; AUSTRAC; Privacy Act 1988 (Cth).