What happens if a conveyancer doesn't meet the new privacy obligations?
More than before, and now on more fronts. As an AUSTRAC reporting entity you can face enforcement from AUSTRAC for AML/CTF breaches and from the OAIC for privacy breaches. Separately, and regardless of that status, an individual can sue you directly under the statutory tort for serious invasions of privacy that were intentional or reckless. Carelessness alone is not enough. The scale is worth knowing before you worry about it: the Commissioner can issue an infringement notice directly for a listed set of APP breaches, capped by Regulatory Powers Act s 104(2) at 12 penalty units for an individual and 60 for a body corporate, while a civil penalty requires a court order on the Commissioner's application (ss 13G, 80U).
By Jon Oates, Founder of Privaproof · Last updated
‹ Conveyancer privacy compliance hub
General information, not legal advice. Your obligations depend on your circumstances.
Which regulators can now act against you?
Before 31 March 2026, a conveyancing practice whose annual turnover kept it under the s 6D(1) small-business test sat outside both regimes. Conveyancing became a designated service on 31 March 2026, when table 6 of the AML/CTF Act commenced; the program, customer due diligence, reporting and record-keeping obligations were deferred to 1 July 2026. Becoming an AUSTRAC reporting entity changes that on two fronts at once:
- AUSTRAC oversees your AML/CTF obligations: enrolment, your compliance program, customer due diligence, record-keeping and reporting. Enrolment is s 51B(1) of the AML/CTF Act, s 51B(3) makes it a civil penalty provision, and s 51B(2C) treats each day past the deadline as a separate contravention. For practices already providing a designated service, that deadline was set at 29 July 2026 by the amending Act (Sch 3 Pt 4 item 12) rather than by the ordinary 28-day rule. (Privaproof does not assess AML/CTF obligations; AUSTRAC does.)
- The OAIC oversees the Privacy Act, which s 6E(1A) applies to "the activities carried on ... for the purposes of, or in connection with, activities relating to" the AML/CTF Act: an APP 1 privacy policy, APP 5 collection notices, data security, and the Notifiable Data Breaches scheme. s 13K(1)(b) names the APP breaches the Commissioner can act on by infringement notice, and APP 1.3 (having a policy) and APP 1.4 (what it must contain) are subparagraphs (i) and (ii) of that list. From 10 December 2026, APP 1.7 automated decision-making joins the same list.
The practical shift is simple: two regulators can now take an interest in the same conveyancing file, from two different angles.
Can an individual sue you directly?
There's also a route that doesn't involve any regulator. Since 10 June 2025, the statutory tort in Privacy Act Sch 2 cl 7(1) lets an individual sue directly for intrusion into seclusion or misuse of information, where the person had a reasonable expectation of privacy, the invasion was serious, it was intentional or reckless (mere negligence isn't enough), and the public interest in privacy outweighed any countervailing public interest. It is actionable without proof of damage (cl 7(2)), and damages for non-economic loss are capped at the greater of $478,550 and the defamation cap (cl 11(5)).
This matters for conveyancers specifically because you concentrate identity documents, source-of-funds evidence and trust-account and settlement details, and cl 7(5)(f)(i) puts "the nature of the information, including whether the information related to ... financial matters" among the factors a court may weigh. It's a direct-liability exposure that sits alongside, not instead of, the regulators.
At a glance: where the exposure comes from
| Source | What it covers | Who acts |
|---|---|---|
| AML/CTF obligations | Enrolment, program, CDD, record-keeping, reporting | AUSTRAC |
| Privacy Act (APPs) | Privacy policy, collection notices, data security | OAIC |
| Notifiable Data Breaches | Assessing and notifying eligible breaches | OAIC |
| Statutory tort | Serious invasion of privacy that was intentional or reckless | The affected individual (courts) |
Why is doing nothing no longer a neutral option?
None of this is a reason to panic, and the headline numbers are not your numbers. In the first civil penalty ever imposed under the Privacy Act, Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224, the Federal Court ordered A$5.8m against an ASX-listed pathology company over a breach affecting 223,000 people, A$800,000 of it for failing to assess the breach expeditiously under s 26WH(2). That is not a conveyancing practice. What does transfer is the Court's finding at paragraph 53(a) that the company's incident playbooks "did not clearly define roles and responsibilities for incident response": the document was the problem, not the size of the business. Before 31 March 2026, doing nothing about privacy carried little consequence for a small practice; now it carries exposure on three fronts, and the proportionate response is to get the baseline in place (the privacy policy, the collection notices and a breach response plan).
For what that baseline looks like, see Do conveyancers need a privacy policy in 2026? and Do conveyancers need a data breach response plan?. For how the obligation arises in the first place, see Does becoming an AUSTRAC reporting entity trigger the Privacy Act?.
Common questions
Can I be penalised by both AUSTRAC and the OAIC for the same file?
Yes in principle, because they are different statutes. AUSTRAC enforces the AML/CTF Act (enrolment is s 51B, made a civil penalty provision by s 51B(3)); the OAIC enforces the Privacy Act (s 13K(3) makes the APP-breach provision a civil penalty provision, with the Commissioner as authorised applicant under s 80U(2)). One incident can raise issues under both. The narrower question worth asking yourself is this: does the identity pack you collect for customer due diligence have a privacy policy and an APP 5 collection notice sitting behind it?
Is there a fine just for not having a privacy policy?
There is a provision that names it. s 13K(1)(b) lists APP 1.3 (the requirement to have an APP privacy policy) and APP 1.4 (what the policy must contain) by number, and s 80UB makes s 13K(1) subject to an infringement notice the Commissioner can issue without going to court. Regulatory Powers Act s 104(2) caps that notice at 12 penalty units for an individual and 60 for a body corporate. A court penalty under s 13K is larger (200 penalty units, multiplied by five for a body corporate under Regulatory Powers Act s 82(5)(a)) but it requires a court order on the Commissioner's application (s 80U). Whether anything follows in a given case is for the Commissioner.
Can a client sue me personally over a privacy breach?
Since 10 June 2025 an individual can bring a statutory-tort claim directly, without a regulator, and it is actionable without proof of damage (Privacy Act Sch 2 cl 7(2)). The limits are worth knowing too: the invasion has to be intentional or reckless rather than merely careless, and it has to be serious (cl 7(1)(c) and (d)). Proceedings run out a year after the plaintiff became aware of it, or three years after it happened, whichever is earlier, subject to a court extension (cl 14).
Do I need to worry about this if I'm under the $3 million threshold?
Yes, for the AML-connected side of the practice. s 6E(1A) is activity-scoped rather than data-scoped: where a small business operator is a reporting entity, the Act applies "in relation to the activities carried on ... for the purposes of, or in connection with, activities relating to" the AML/CTF Act. Turnover is also not the only trigger. s 6D(4) has six limbs, and under s 6D(4)(a) once a business has had turnover over $3 million in a financial year it stays outside the small-business exemption even if turnover later falls.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: OAIC, privacy guidance for reporting entities under the AML/CTF Act; OAIC, statutory tort for serious invasions of privacy; AUSTRAC; Privacy Act 1988 (Cth).