Skip to content

Do conveyancers need a privacy policy in 2026?

For most conveyancers from 1 July 2026: yes. Providing a conveyancing designated service makes your firm an AUSTRAC reporting entity, and under Privacy Act s 6E(1A) that switches the Privacy Act on for the personal information you handle for AML/CTF purposes, even under the $3 million small-business threshold. An APP 1 privacy policy is the baseline it requires.

By Jon Oates, Founder of Privaproof · Last updated

‹ Conveyancer privacy compliance hub

General information, not legal advice. Your obligations depend on your circumstances.

How does the small-business exemption work?

Under section 6D of the Privacy Act 1988 (Cth), a business with annual turnover of $3 million or less is generally a "small business operator" and is exempt from the Act and the Australian Privacy Principles (APPs). Most conveyancing practices have sat under that threshold and, until now, have never had to comply with the APPs. The exemption has a handful of carve-outs (health-service providers, businesses that trade in personal information, Commonwealth contractors), but it does not switch off simply because you become a reporting entity. That switch works a different way, and getting the mechanism right matters.

Why are conveyancers caught from 1 July 2026?

The capturing service is a designated service under the AML/CTF Act (inserted by the AML/CTF Amendment Act 2024): assisting a person in the planning or execution of a transaction to sell, buy or otherwise transfer real estate, in the course of a business. That is the core of conveyancing: preparing and lodging the transfer, running title and strata searches, coordinating discharge of mortgage, and holding and disbursing settlement funds. The obligation attaches to the activity, not the job title.

Because this is your everyday work, a practising conveyancer generally cannot avoid the trigger the way a one-off or ancillary provider might. From 1 July 2026 you are a reporting entity, and AUSTRAC enrolment must be completed within the window: 28 days from first providing a designated service. The reforms treat 29 July 2026 as the practical enrolment cut-off for firms already operating on 1 July 2026; confirm your firm's exact date with AUSTRAC. (For the AML side in full, see the companion guide, AML Tranche 2 for conveyancers: the privacy half nobody mentions.)

What exactly does the privacy switch cover?

Here is the part most AML guidance skips. Becoming a reporting entity does not remove your s 6D exemption across the whole firm. Instead, section 6E(1A) of the Privacy Act deems a small business operator that is a reporting entity to be an "organisation", an APP entity, but only in relation to the activities it carries on for the purposes of, or in connection with, the AML/CTF Act. So the Privacy Act applies to the personal information you handle for AML/CTF: customer identification and KYC records, beneficial-ownership details, PEP and sanctions-screening results, and source-of-funds evidence, even though you turn over less than $3 million.

The coverage is targeted at that AML/CTF-connected information, not automatically the whole practice. Your general marketing list doesn't come under the Act by force of s 6E(1A) alone. In a conveyancing file, though, the AML data and the transaction data are deeply intertwined (the same identity documents, the same settlement records), so in practice many firms find it simplest to apply Privacy-Act-standard handling across the whole matter file. That is a practical recommendation, not a statement of law, and where your line sits is worth professional advice.

At a glance

ObligationWhat it means for a conveyancerSource
Privacy Act applies (AML data)s 6E(1A) deems you an APP entity for AML/CTF-connected personal information, regardless of turnoverPrivacy Act 1988 s 6E(1A)
APP 1: privacy policyHave a clearly expressed, up-to-date privacy policy, the baseline public documentOAIC (APP 1)
APP 5: collection noticeTell people at the point of collection what you collect, why, and who you disclose it toOAIC (APP 5)
APP 11 + NDB schemeSecure the identity and financial data you hold; assess and notify eligible data breaches likely to cause serious harmPrivacy Act Part IIIC
Retention tensionAML record-keeping (at least 7 years) must be reconciled with APP 11's "destroy or de-identify when no longer needed"AUSTRAC; OAIC (APP 11)

What does a compliant conveyancer need beyond the policy?

A privacy policy is the headline, but it rarely stands alone. To meet the APPs on your AML/CTF data you generally need, at minimum: an APP 1 privacy policy; an APP 5 collection notice given at or near the point of collection (with a purpose-built notice for the high-sensitivity identity and source-of-funds data you collect for verification); and, because the Notifiable Data Breaches scheme requires you to assess and notify eligible breaches, a breach response plan so you're ready to meet that duty for the concentrated identity and financial data you hold. Access, correction and complaint procedures (APPs 12–13, APP 1) round out the set.

What's different for a conveyancer vs a general business?

So, do you need one?

If you provide conveyancing designated services, then from 1 July 2026 you are almost certainly an AUSTRAC reporting entity, and s 6E(1A) brings the personal information you handle for AML/CTF under the Privacy Act. For most firms that means a privacy policy and collection notices for the first time, plus a breach response plan for the sensitive dataset you now concentrate. The obligation is narrower than "the whole firm is now regulated," but for the identity and financial data at the heart of every settlement, it is real, and it is live now.

Common questions

Do conveyancers really need a privacy policy now?

For most firms, yes, from 1 July 2026. Becoming an AUSTRAC reporting entity brings the personal information you handle for AML/CTF under the Privacy Act via s 6E(1A), even below the $3 million threshold, and an APP 1 privacy policy is the baseline that requires.

Does the $3 million small-business exemption still protect me?

For your practice generally, yes, but not for your AML data. Section 6E(1A) applies the Privacy Act to the personal information you handle for AML/CTF regardless of turnover; the s 6D exemption still stands for the rest of the firm.

Is a privacy policy the only document I need?

No. It's the headline, but you generally also need APP 5 collection notices and a data breach response plan for the sensitive identity and financial data you now hold.

Do WA settlement agents need one too?

Yes. The obligation is defined by the activity, not the job title, so a WA settlement agent is caught the same way. Only the title and state licensing differ. See our WA settlement agents guide.


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Privaproof's conveyancer materials are self-authored and are not independently reviewed by a solicitor. Sources: OAIC, privacy guidance for reporting entities under the AML/CTF Act; Privacy Act 1988 (Cth) s 6E(1A) and s 6D; AUSTRAC, professional designated services; ARNECC, Model Participation Rules v7; OAIC, statutory tort for serious invasions of privacy.