Do conveyancers need a privacy policy in 2026?
For most conveyancers from 1 July 2026: yes. Providing a conveyancing designated service makes your firm an AUSTRAC reporting entity, and under Privacy Act s 6E(1A) that switches the Privacy Act on for the personal information you handle for AML/CTF purposes, even under the $3 million small-business threshold. An APP 1 privacy policy is the baseline it requires.
By Jon Oates, Founder of Privaproof · Last updated
‹ Conveyancer privacy compliance hub
General information, not legal advice. Your obligations depend on your circumstances.
How does the small-business exemption work?
Under section 6D of the Privacy Act 1988 (Cth), a business with annual turnover of $3 million or less is generally a "small business operator" and is exempt from the Act and the Australian Privacy Principles (APPs). Most conveyancing practices have sat under that threshold and, until now, have never had to comply with the APPs. The exemption has a handful of carve-outs (health-service providers, businesses that trade in personal information, Commonwealth contractors), but it does not switch off simply because you become a reporting entity. That switch works a different way, and getting the mechanism right matters.
Why are conveyancers caught from 1 July 2026?
The capturing service is a designated service under the AML/CTF Act (inserted by the AML/CTF Amendment Act 2024): assisting a person in the planning or execution of a transaction to sell, buy or otherwise transfer real estate, in the course of a business. That is the core of conveyancing: preparing and lodging the transfer, running title and strata searches, coordinating discharge of mortgage, and holding and disbursing settlement funds. The obligation attaches to the activity, not the job title.
Because this is your everyday work, a practising conveyancer generally cannot avoid the trigger the way a one-off or ancillary provider might. From 1 July 2026 you are a reporting entity, and AUSTRAC enrolment must be completed within the window: 28 days from first providing a designated service. The reforms treat 29 July 2026 as the practical enrolment cut-off for firms already operating on 1 July 2026; confirm your firm's exact date with AUSTRAC. (For the AML side in full, see the companion guide, AML Tranche 2 for conveyancers: the privacy half nobody mentions.)
What exactly does the privacy switch cover?
Here is the part most AML guidance skips. Becoming a reporting entity does not remove your s 6D exemption across the whole firm. Instead, section 6E(1A) of the Privacy Act deems a small business operator that is a reporting entity to be an "organisation", an APP entity, but only in relation to the activities it carries on for the purposes of, or in connection with, the AML/CTF Act. So the Privacy Act applies to the personal information you handle for AML/CTF: customer identification and KYC records, beneficial-ownership details, PEP and sanctions-screening results, and source-of-funds evidence, even though you turn over less than $3 million.
The coverage is targeted at that AML/CTF-connected information, not automatically the whole practice. Your general marketing list doesn't come under the Act by force of s 6E(1A) alone. In a conveyancing file, though, the AML data and the transaction data are deeply intertwined (the same identity documents, the same settlement records), so in practice many firms find it simplest to apply Privacy-Act-standard handling across the whole matter file. That is a practical recommendation, not a statement of law, and where your line sits is worth professional advice.
At a glance
| Obligation | What it means for a conveyancer | Source |
|---|---|---|
| Privacy Act applies (AML data) | s 6E(1A) deems you an APP entity for AML/CTF-connected personal information, regardless of turnover | Privacy Act 1988 s 6E(1A) |
| APP 1: privacy policy | Have a clearly expressed, up-to-date privacy policy, the baseline public document | OAIC (APP 1) |
| APP 5: collection notice | Tell people at the point of collection what you collect, why, and who you disclose it to | OAIC (APP 5) |
| APP 11 + NDB scheme | Secure the identity and financial data you hold; assess and notify eligible data breaches likely to cause serious harm | Privacy Act Part IIIC |
| Retention tension | AML record-keeping (at least 7 years) must be reconciled with APP 11's "destroy or de-identify when no longer needed" | AUSTRAC; OAIC (APP 11) |
What does a compliant conveyancer need beyond the policy?
A privacy policy is the headline, but it rarely stands alone. To meet the APPs on your AML/CTF data you generally need, at minimum: an APP 1 privacy policy; an APP 5 collection notice given at or near the point of collection (with a purpose-built notice for the high-sensitivity identity and source-of-funds data you collect for verification); and, because the Notifiable Data Breaches scheme requires you to assess and notify eligible breaches, a breach response plan so you're ready to meet that duty for the concentrated identity and financial data you hold. Access, correction and complaint procedures (APPs 12–13, APP 1) round out the set.
What's different for a conveyancer vs a general business?
- Higher-sensitivity data. You hold identity documents (passport, licence, Medicare), source-of-funds evidence, beneficial-ownership and PEP/sanctions results, and trust-account banking details, a heavier, riskier dataset than a typical small business.
- A 7-year AML retention floor. AML/CTF records must be kept for at least seven years, which pulls against APP 11's "don't keep it longer than you need it." The two are reconcilable (AML law is a lawful basis to retain), but they need a considered retention schedule so identity documents aren't kept indefinitely beyond the AML floor.
- Two separate identity regimes: don't conflate them. For electronic conveyancing you take "reasonable steps" to verify identity under the ARNECC Model Participation Rules (Version 7), Schedule 8, a safe-harbour standard, not a mandatory one. That is distinct from AML customer due diligence, which is AUSTRAC's identity requirement for money-laundering purposes. They collect similar documents but are different obligations under different regulators.
- Settlement-platform disclosure. Routine disclosure to PEXA, Sympli and other ELNOs, and to land titles offices and revenue authorities, should be covered in your policy and collection notices.
- The statutory tort. Since 10 June 2025, a statutory tort for serious invasions of privacy lets an individual sue directly, with no regulator involved, where the invasion was intentional or reckless rather than merely careless. The concentrated identity and financial data conveyancers hold makes such a claim concrete.
- Automated decision-making disclosure: conditional, from 10 December 2026. If you use identity-verification (IDV/electronic-VOI) or sanctions-screening software that makes, or substantially supports, a decision that could significantly affect a person's rights or interests, then from 10 December 2026 the new APP 1.7 will require your privacy policy to disclose that automated decision-making. Whether a given tool crosses that threshold is fact-specific. Treat it as a "check this," not an automatic obligation.
- State-fragmented terminology. Licensed conveyancers in most states; "settlement agents" in WA; in QLD and the ACT this work is largely done by solicitors. The obligation is the same. Only the label and the state licensing regime differ.
So, do you need one?
If you provide conveyancing designated services, then from 1 July 2026 you are almost certainly an AUSTRAC reporting entity, and s 6E(1A) brings the personal information you handle for AML/CTF under the Privacy Act. For most firms that means a privacy policy and collection notices for the first time, plus a breach response plan for the sensitive dataset you now concentrate. The obligation is narrower than "the whole firm is now regulated," but for the identity and financial data at the heart of every settlement, it is real, and it is live now.
Common questions
Do conveyancers really need a privacy policy now?
For most firms, yes, from 1 July 2026. Becoming an AUSTRAC reporting entity brings the personal information you handle for AML/CTF under the Privacy Act via s 6E(1A), even below the $3 million threshold, and an APP 1 privacy policy is the baseline that requires.
Does the $3 million small-business exemption still protect me?
For your practice generally, yes, but not for your AML data. Section 6E(1A) applies the Privacy Act to the personal information you handle for AML/CTF regardless of turnover; the s 6D exemption still stands for the rest of the firm.
Is a privacy policy the only document I need?
No. It's the headline, but you generally also need APP 5 collection notices and a data breach response plan for the sensitive identity and financial data you now hold.
Do WA settlement agents need one too?
Yes. The obligation is defined by the activity, not the job title, so a WA settlement agent is caught the same way. Only the title and state licensing differ. See our WA settlement agents guide.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Privaproof's conveyancer materials are self-authored and are not independently reviewed by a solicitor. Sources: OAIC, privacy guidance for reporting entities under the AML/CTF Act; Privacy Act 1988 (Cth) s 6E(1A) and s 6D; AUSTRAC, professional designated services; ARNECC, Model Participation Rules v7; OAIC, statutory tort for serious invasions of privacy.