Do conveyancers need a privacy policy in 2026?
If you provide a conveyancing designated service: yes. That makes your firm an AUSTRAC reporting entity, and Privacy Act s 6E(1A) then applies the Act to the activities you carry on for the purposes of, or in connection with, the AML/CTF Act, whatever your turnover. APP 1.3 requires an APP entity to have a clearly expressed and up-to-date privacy policy, and APP 1.4 lists the seven things it must contain.
By Jon Oates, Founder of Privaproof · Last updated
‹ Conveyancer privacy compliance hub
General information, not legal advice. Your obligations depend on your circumstances.
How does the small-business exemption work?
Under section 6D of the Privacy Act 1988 (Cth), a business is a small business if its annual turnover for the previous financial year is $3,000,000 or less (s 6D(1)), and a small business operator is generally exempt from the Act and the Australian Privacy Principles (APPs). Before relying on that, ask one question: has the practice ever had an annual turnover of more than $3,000,000 for a financial year that has ended? Section 6D(4)(a) takes the exemption away, and a later fall in turnover does not give it back. Sections 6D(4)(b) to (f) and 6D(9) list the others, from health services to related bodies corporate. None of them switch off simply because you become a reporting entity. That switch works a different way, and getting the mechanism right matters.
Why are conveyancers caught from 31 March 2026?
The capturing service is a designated service under the AML/CTF Act (s 6(5B), Table 6, item 1, inserted by the AML/CTF Amendment Act 2024): assisting a person in the planning or execution of a transaction, or otherwise acting for or on behalf of a person in a transaction, to sell, buy or otherwise transfer real estate, in the course of carrying on a business, where the transfer is not pursuant to, or resulting from, an order of a court or tribunal. That is the core of conveyancing: preparing and lodging the transfer, running title and strata searches, coordinating discharge of mortgage, and holding and disbursing settlement funds. The obligation attaches to the activity, not the job title.
Because this is your everyday work, a practising conveyancer generally cannot avoid the trigger the way a one-off or ancillary provider might. Table 6 commenced on 31 March 2026, so reporting-entity status is already in place, and the obligations themselves apply from 1 July 2026. Enrolment is a fixed statutory date, not a calculation: for a business already providing a designated service before 1 July 2026, Schedule 3 Part 4 item 12 of the amending Act sets AUSTRAC enrolment at 29 July 2026. A business that starts providing a designated service later applies to enrol no later than 28 days after the day it starts (s 51B(1)). (For the AML side in full, see the companion guide, AML Tranche 2 for conveyancers: the privacy half nobody mentions.)
What exactly does the privacy switch cover?
Here is the part most AML guidance skips. Becoming a reporting entity does not remove your s 6D exemption across the whole firm. Section 6E(1A) applies the Privacy Act "in relation to the activities carried on by the small business operator for the purposes of, or in connection with, activities relating to" the AML/CTF Act, as if the operator were an organisation. The unit is the activity, not a category of data: customer identification and verification, beneficial-ownership enquiries, PEP and sanctions screening, source-of-funds enquiries, AML record-keeping and reporting. Everything you do in carrying those out sits inside the Act, even though you turn over less than $3 million.
The coverage is targeted at those activities, not automatically the whole practice. Your general marketing list does not come under the Act by force of s 6E(1A) alone, and you may genuinely sit outside the Act for the rest of what you do. In a conveyancing file, though, the AML work and the conveyancing work run through the same documents, so drawing the line inside a single matter is harder than it sounds. The cleaner path for most practices is Privacy-Act-standard handling across the whole matter file. That is a practical recommendation, not a statement of law, and where your line sits is worth professional advice.
At a glance
| Obligation | What it means for a conveyancer | Source |
|---|---|---|
| Privacy Act applies (AML/CTF activities) | s 6E(1A) applies the Act to the activities you carry on for the purposes of, or in connection with, the AML/CTF Act, whatever your turnover | Privacy Act 1988 (Cth) s 6E(1A) |
| APP 1.3 and 1.4: privacy policy | An APP entity must have a clearly expressed and up-to-date privacy policy, and APP 1.4(a) to (g) sets the seven things it must contain | Privacy Act 1988 (Cth) Sch 1, APP 1.3 and 1.4 |
| APP 5: collection notice | Tell people at the point of collection what you collect, why, and who you disclose it to | OAIC (APP 5) |
| APP 11 + NDB scheme | Secure the identity and financial data you hold; assess and notify eligible data breaches likely to cause serious harm | Privacy Act Part IIIC |
| Retention: two clocks | s 111 CDD records run 7 years from the end of the business relationship; s 108 runs 7 years from the giving of a customer-supplied document, where you commence the service. APP 11.2 governs what neither requires | AML/CTF Act ss 108, 111; Privacy Act Sch 1 APP 11.2 |
What does a compliant conveyancer need beyond the policy?
A privacy policy is the headline, but APP 1.4 tells you what has to be in it. Check your current policy against the seven matters it lists:
- the kinds of personal information you collect and hold
- how you collect and hold it
- the purposes for which you collect, hold, use and disclose it
- how an individual may access their personal information and seek its correction
- how an individual may complain about a breach of the APPs, and how you will deal with the complaint
- whether you are likely to disclose personal information to overseas recipients
- if you are, the countries those recipients are likely to be in, where it is practicable to name them
You also need an APP 5 collection notice at or near the point of collection, with a purpose-built notice for the identity and source-of-funds material you collect for verification, and a breach response plan, because the Notifiable Data Breaches scheme puts the duty to assess and to notify on you. Access, correction and complaint procedures (APPs 12 and 13, APP 1.2) round out the set.
What's different for a conveyancer vs a general business?
- Higher-sensitivity data. You hold identity documents (passport, licence, Medicare), source-of-funds evidence, beneficial-ownership and PEP/sanctions results, and trust-account banking details, a heavier, riskier dataset than a typical small business.
- Two seven-year clocks, and they start on different days. The s 111 customer due diligence record is the extracted particulars and the verification outcome, not the image, and it runs seven years from the end of the business relationship. Section 108 is the one people miss: where a document relating to the provision, or prospective provision, of a designated service is given to you by or on behalf of the customer (s 108(1)(a)) and you commence, or have commenced, providing that service (s 108(1)(b)), you must retain it or a copy for seven years from the day it was given, and s 108(3) is a civil penalty provision. Both limbs must be met, so something emailed during an enquiry that never becomes a file is caught by neither and APP 11.2 governs it. No AUSTRAC guidance, explanatory memorandum or decided case addresses a client-emailed identity document, so have that reviewed by a qualified Australian legal practitioner before you destroy anything a client sent you.
- Two separate identity regimes: don't conflate them. For electronic conveyancing you take "reasonable steps" to verify identity under the ARNECC Model Participation Rules (Version 7), Schedule 8, a safe-harbour standard, not a mandatory one. That is distinct from AML customer due diligence, which is AUSTRAC's identity requirement for money-laundering purposes. They collect similar documents but are different obligations under different regulators.
- Settlement-platform disclosure. Routine disclosure to PEXA, Sympli and other ELNOs, and to land titles offices and revenue authorities, should be covered in your policy and collection notices.
- The statutory tort. Since 10 June 2025, a statutory tort for serious invasions of privacy lets an individual sue directly, with no regulator involved. Every limb of Schedule 2 clause 7(1) has to be met: a reasonable expectation of privacy, an invasion that was intentional or reckless, seriousness, and the public interest in privacy outweighing any countervailing interest. Carelessness alone does not ground it.
- Automated decision-making disclosure: conditional, from 10 December 2026. If you use identity-verification (IDV/electronic-VOI) or sanctions-screening software that makes, or substantially supports, a decision that could significantly affect a person's rights or interests, then from 10 December 2026 the new APP 1.7 will require your privacy policy to disclose that automated decision-making. Whether a given tool crosses that threshold is fact-specific. Treat it as a "check this," not an automatic obligation.
- State-fragmented terminology. Licensed or registered conveyancers in NSW, Victoria, South Australia and Tasmania; "settlement agents" in WA; "conveyancing agents" in the NT. Privaproof writes for the states and territories that licence non-lawyer conveyancers. The federal obligation is defined by the activity, so what differs is the label and the licensing regime, not the duty.
So, do you need one?
If you provide conveyancing designated services, you are an AUSTRAC reporting entity, and s 6E(1A) applies the Privacy Act to the activities you carry on for AML/CTF purposes. That means a privacy policy and collection notices for the first time, plus a breach response plan. The obligation is narrower than "the whole firm is now regulated," and that is worth saying plainly: outside those activities the s 6D exemption still stands. Inside them, APP 1.3 and APP 1.4 are civil penalty provisions in their own right (s 13K(1)(b)(i) and (ii)), with a court maximum of 200 penalty units and five times that for a body corporate (s 13K(4); Regulatory Powers (Standard Provisions) Act 2014 s 82(5)(a)). The Australian Information Commissioner's 2026 sweep assessed sixty privacy policies against APP 1.4 and reported "instances of non-compliance in a significant proportion". So the question is not whether you have a policy. It is whether yours contains the seven things APP 1.4 lists.
Common questions
Do conveyancers really need a privacy policy now?
If you provide a conveyancing designated service, yes. Becoming an AUSTRAC reporting entity applies the Privacy Act, through s 6E(1A), to the activities you carry on for AML/CTF purposes, whatever your turnover, and APP 1.3 requires an APP entity to have a clearly expressed and up-to-date privacy policy.
Does the $3 million small-business exemption still protect me?
For your practice generally, yes, but not for your AML/CTF work. Section 6E(1A) applies the Privacy Act to the activities you carry on for the purposes of, or in connection with, the AML/CTF Act regardless of turnover; the s 6D exemption still stands for the rest of the firm, unless something in s 6D(4) or s 6D(9) takes it away.
Is a privacy policy the only document I need?
No. It's the headline, but you generally also need APP 5 collection notices and a data breach response plan for the sensitive identity and financial data you now hold.
Do WA settlement agents need one too?
Yes. The obligation is defined by the activity, not the job title, so a WA settlement agent is caught the same way. Only the title and state licensing differ. See our WA settlement agents guide.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: Privacy Act 1988 (Cth), Compilation No. 104 (compilation date 4 June 2026), ss 6D, 6E(1A) and 13K and Schedule 1 (APPs 1, 5 and 11) and Schedule 2 (cl 7); Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) s 6(5B) Table 6 and ss 108 and 111; OAIC, privacy guidance for reporting entities under the AML/CTF Act; OAIC, small business; AUSTRAC, professional designated services; ARNECC, Model Participation Rules v7; OAIC, statutory tort for serious invasions of privacy. Written by Privaproof.