Skip to content

Do conveyancers need a privacy policy in 2026?

If you provide a conveyancing designated service: yes. That makes your firm an AUSTRAC reporting entity, and Privacy Act s 6E(1A) then applies the Act to the activities you carry on for the purposes of, or in connection with, the AML/CTF Act, whatever your turnover. APP 1.3 requires an APP entity to have a clearly expressed and up-to-date privacy policy, and APP 1.4 lists the seven things it must contain.

By Jon Oates, Founder of Privaproof · Last updated

‹ Conveyancer privacy compliance hub

General information, not legal advice. Your obligations depend on your circumstances.

How does the small-business exemption work?

Under section 6D of the Privacy Act 1988 (Cth), a business is a small business if its annual turnover for the previous financial year is $3,000,000 or less (s 6D(1)), and a small business operator is generally exempt from the Act and the Australian Privacy Principles (APPs). Before relying on that, ask one question: has the practice ever had an annual turnover of more than $3,000,000 for a financial year that has ended? Section 6D(4)(a) takes the exemption away, and a later fall in turnover does not give it back. Sections 6D(4)(b) to (f) and 6D(9) list the others, from health services to related bodies corporate. None of them switch off simply because you become a reporting entity. That switch works a different way, and getting the mechanism right matters.

Why are conveyancers caught from 31 March 2026?

The capturing service is a designated service under the AML/CTF Act (s 6(5B), Table 6, item 1, inserted by the AML/CTF Amendment Act 2024): assisting a person in the planning or execution of a transaction, or otherwise acting for or on behalf of a person in a transaction, to sell, buy or otherwise transfer real estate, in the course of carrying on a business, where the transfer is not pursuant to, or resulting from, an order of a court or tribunal. That is the core of conveyancing: preparing and lodging the transfer, running title and strata searches, coordinating discharge of mortgage, and holding and disbursing settlement funds. The obligation attaches to the activity, not the job title.

Because this is your everyday work, a practising conveyancer generally cannot avoid the trigger the way a one-off or ancillary provider might. Table 6 commenced on 31 March 2026, so reporting-entity status is already in place, and the obligations themselves apply from 1 July 2026. Enrolment is a fixed statutory date, not a calculation: for a business already providing a designated service before 1 July 2026, Schedule 3 Part 4 item 12 of the amending Act sets AUSTRAC enrolment at 29 July 2026. A business that starts providing a designated service later applies to enrol no later than 28 days after the day it starts (s 51B(1)). (For the AML side in full, see the companion guide, AML Tranche 2 for conveyancers: the privacy half nobody mentions.)

What exactly does the privacy switch cover?

Here is the part most AML guidance skips. Becoming a reporting entity does not remove your s 6D exemption across the whole firm. Section 6E(1A) applies the Privacy Act "in relation to the activities carried on by the small business operator for the purposes of, or in connection with, activities relating to" the AML/CTF Act, as if the operator were an organisation. The unit is the activity, not a category of data: customer identification and verification, beneficial-ownership enquiries, PEP and sanctions screening, source-of-funds enquiries, AML record-keeping and reporting. Everything you do in carrying those out sits inside the Act, even though you turn over less than $3 million.

The coverage is targeted at those activities, not automatically the whole practice. Your general marketing list does not come under the Act by force of s 6E(1A) alone, and you may genuinely sit outside the Act for the rest of what you do. In a conveyancing file, though, the AML work and the conveyancing work run through the same documents, so drawing the line inside a single matter is harder than it sounds. The cleaner path for most practices is Privacy-Act-standard handling across the whole matter file. That is a practical recommendation, not a statement of law, and where your line sits is worth professional advice.

At a glance

ObligationWhat it means for a conveyancerSource
Privacy Act applies (AML/CTF activities)s 6E(1A) applies the Act to the activities you carry on for the purposes of, or in connection with, the AML/CTF Act, whatever your turnoverPrivacy Act 1988 (Cth) s 6E(1A)
APP 1.3 and 1.4: privacy policyAn APP entity must have a clearly expressed and up-to-date privacy policy, and APP 1.4(a) to (g) sets the seven things it must containPrivacy Act 1988 (Cth) Sch 1, APP 1.3 and 1.4
APP 5: collection noticeTell people at the point of collection what you collect, why, and who you disclose it toOAIC (APP 5)
APP 11 + NDB schemeSecure the identity and financial data you hold; assess and notify eligible data breaches likely to cause serious harmPrivacy Act Part IIIC
Retention: two clockss 111 CDD records run 7 years from the end of the business relationship; s 108 runs 7 years from the giving of a customer-supplied document, where you commence the service. APP 11.2 governs what neither requiresAML/CTF Act ss 108, 111; Privacy Act Sch 1 APP 11.2

What does a compliant conveyancer need beyond the policy?

A privacy policy is the headline, but APP 1.4 tells you what has to be in it. Check your current policy against the seven matters it lists:

You also need an APP 5 collection notice at or near the point of collection, with a purpose-built notice for the identity and source-of-funds material you collect for verification, and a breach response plan, because the Notifiable Data Breaches scheme puts the duty to assess and to notify on you. Access, correction and complaint procedures (APPs 12 and 13, APP 1.2) round out the set.

What's different for a conveyancer vs a general business?

So, do you need one?

If you provide conveyancing designated services, you are an AUSTRAC reporting entity, and s 6E(1A) applies the Privacy Act to the activities you carry on for AML/CTF purposes. That means a privacy policy and collection notices for the first time, plus a breach response plan. The obligation is narrower than "the whole firm is now regulated," and that is worth saying plainly: outside those activities the s 6D exemption still stands. Inside them, APP 1.3 and APP 1.4 are civil penalty provisions in their own right (s 13K(1)(b)(i) and (ii)), with a court maximum of 200 penalty units and five times that for a body corporate (s 13K(4); Regulatory Powers (Standard Provisions) Act 2014 s 82(5)(a)). The Australian Information Commissioner's 2026 sweep assessed sixty privacy policies against APP 1.4 and reported "instances of non-compliance in a significant proportion". So the question is not whether you have a policy. It is whether yours contains the seven things APP 1.4 lists.

Common questions

Do conveyancers really need a privacy policy now?

If you provide a conveyancing designated service, yes. Becoming an AUSTRAC reporting entity applies the Privacy Act, through s 6E(1A), to the activities you carry on for AML/CTF purposes, whatever your turnover, and APP 1.3 requires an APP entity to have a clearly expressed and up-to-date privacy policy.

Does the $3 million small-business exemption still protect me?

For your practice generally, yes, but not for your AML/CTF work. Section 6E(1A) applies the Privacy Act to the activities you carry on for the purposes of, or in connection with, the AML/CTF Act regardless of turnover; the s 6D exemption still stands for the rest of the firm, unless something in s 6D(4) or s 6D(9) takes it away.

Is a privacy policy the only document I need?

No. It's the headline, but you generally also need APP 5 collection notices and a data breach response plan for the sensitive identity and financial data you now hold.

Do WA settlement agents need one too?

Yes. The obligation is defined by the activity, not the job title, so a WA settlement agent is caught the same way. Only the title and state licensing differ. See our WA settlement agents guide.


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: Privacy Act 1988 (Cth), Compilation No. 104 (compilation date 4 June 2026), ss 6D, 6E(1A) and 13K and Schedule 1 (APPs 1, 5 and 11) and Schedule 2 (cl 7); Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) s 6(5B) Table 6 and ss 108 and 111; OAIC, privacy guidance for reporting entities under the AML/CTF Act; OAIC, small business; AUSTRAC, professional designated services; ARNECC, Model Participation Rules v7; OAIC, statutory tort for serious invasions of privacy. Written by Privaproof.