How long should a conveyancer keep client ID and AML records?
There's no single number. You reconcile two rules. AML/CTF records must be kept for at least seven years, while APP 11 says destroy or de-identify personal information once you no longer need it. The practical answer: keep what the law requires for as long as it requires, hold it securely, and destroy it when the last applicable period ends.
By Jon Oates, Founder of Privaproof · Last updated
‹ Conveyancer privacy compliance hub
General information, not legal advice. Your obligations depend on your circumstances.
Which two rules pull in different directions?
Retention is the one area where a conveyancer's new obligations genuinely pull against each other:
- AML/CTF record-keeping requires you to keep certain records, including customer-due-diligence records, for at least seven years (commonly measured from the end of the business relationship or the transaction).
- APP 11.2 requires an APP entity to take reasonable steps to destroy or de-identify personal information once it's no longer needed for any purpose for which it may be used or disclosed.
At first glance these look like they conflict: one says keep, the other says destroy. They don't.
Why don't the two rules actually conflict?
APP 11.2 has an important qualifier: it doesn't require you to destroy information you're required by law to retain. Because the AML/CTF rules are a legal obligation to keep the records, holding them for the AML period is entirely consistent with APP 11. The reconciliation is straightforward in principle: keep the record for the longest applicable required period, then destroy or de-identify it once no rule still requires it.
The risk isn't keeping AML records for seven years. That's required. The risk is keeping identity documents and source-of-funds evidence indefinitely, out of habit, well beyond any period the law requires, which is exactly what APP 11 is aimed at.
What retention periods apply?
A conveyancing practice is usually juggling more than one retention driver at once. The exact periods depend on your state and your circumstances, so treat these as the shape of the problem, not a substitute for advice:
| Record type | What drives the period | Rough floor |
|---|---|---|
| AML/CDD records (ID, beneficial ownership, source of funds) | AML/CTF Act record-keeping | At least 7 years |
| Trust-account records | State conveyancer / settlement-agent legislation | Mandatory state minimum: varies; confirm |
| Tax records | ATO requirements | Commonly around 5 years |
| Matter file | Professional obligations / limitation periods | Varies; confirm |
Your state trust-account minimum is mandatory (don't shorten it), and it may run alongside the AML seven-year floor. Where two periods overlap, the longest applicable one governs when you can finally destroy.
Can I keep copies of clients' ID documents?
This is the most common practical question, and the answer is a balance. You need to collect and keep enough to meet your AML CDD and VOI obligations, and to evidence that you did. But APP 11 pushes the other way: don't collect or retain more identity data than you need, keep it secure, and destroy or de-identify it when no rule still requires it. "We photograph every client's passport and keep it forever on a shared drive" is the kind of habit that creates privacy risk without adding compliance value. Keep what the standard requires, hold it securely, and let it go when the last applicable period ends.
How do you build a retention schedule?
The workable answer to "how long" is a retention schedule rather than a single figure: a short table that lists each record type, the rule that governs it, the period, and how it's destroyed at the end. That turns a genuine legal tension into a routine you can actually follow. It also feeds your other obligations: the data you map here is the data your privacy policy describes and your data breach response plan protects.
Common questions
How long do I have to keep AML records?
At least seven years: AML/CTF record-keeping generally requires customer-due-diligence and transaction records to be kept for a minimum of seven years. Confirm the exact trigger and period for your records with AUSTRAC guidance.
Doesn't APP 11 say I have to delete personal information?
APP 11.2 says destroy or de-identify it once it's no longer needed, but not where you're required by law to keep it. AML retention is such a legal requirement, so holding those records for the AML period is consistent with APP 11.
Can I keep copies of clients' passports and licences indefinitely?
You should keep them for as long as your AML and VOI obligations require, securely, but not indefinitely out of habit. Retaining identity documents well beyond any required period is the kind of over-retention APP 11 is aimed at.
What if the AML period and my state trust-account period differ?
Keep the record for the longest applicable required period. Your state trust-account minimum is mandatory and may run alongside the AML seven-year floor; the longer one governs when you can destroy.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Privaproof's conveyancer materials are self-authored and are not independently reviewed by a solicitor. Sources: OAIC, APP 11 (security of personal information); AUSTRAC, professional designated services; Privacy Act 1988 (Cth) s 6E(1A).