Skip to content

How long should a conveyancer keep client ID and AML records?

There's no single number, and the seven-year figure is the easy half. The AML/CTF Act sets three seven-year clocks that start at three different events, while APP 11.2 says destroy or de-identify personal information once you no longer need it and no Australian law requires you to keep it. The practical answer: work out which rule governs each record, run its own clock, hold it securely, and destroy it when the last applicable period ends. One case runs the other way: where a client gives you a document and you go on to provide the service, s 108 gives that document its own seven-year clock, so how the document reached you changes the answer.

By Jon Oates, Founder of Privaproof · Last updated

‹ Conveyancer privacy compliance hub

General information, not legal advice. Your obligations depend on your circumstances.

Which two rules pull in different directions?

Retention is the one area where a conveyancer's new obligations genuinely pull against each other:

Why don't the two rules actually conflict?

APP 11.2 has four conditions, and the fourth is the qualifier: the destruction duty bites only where "the entity is not required by or under an Australian law, or a court/tribunal order, to retain the information" (APP 11.2(d)). AML/CTF retention is exactly that kind of requirement, so holding those records for the AML period is consistent with APP 11. The reconciliation is straightforward in principle: keep the record for the longest applicable required period, then destroy or de-identify it once no rule still requires it.

The risk isn't keeping AML records for seven years. That's required. The risk is keeping identity documents and source-of-funds evidence indefinitely, out of habit, well beyond any period the law requires. So the test to run on your own files is not "how long", it is: for each record type you hold, can you name the rule that governs it, the date its clock started, and the date it ends?

What retention periods apply?

A conveyancing practice juggles several retention drivers at once, and they do not all start on the same day:

Record typeThe rulePeriodWhen the clock starts
Records that let each transaction be reconstructedAML/CTF Act s 107(3)7 yearsThe day the record is made
Customer due diligence records (identity particulars, beneficial ownership, source of funds, risk assessment)AML/CTF Act s 111(2)7 yearsEnd of the business relationship, or completion of the occasional transaction
A document the client gave you, where you went on to actAML/CTF Act s 108(2)7 yearsThe day it was given to you
Trust-account recordsState conveyancer and settlement-agent legislation5 to 7 yearsA different event in every state: see below
Tax recordsIncome Tax Assessment Act 1936 s 262A(4)(a)5 yearsWhen the record was prepared or obtained, or the transaction completed, whichever is later
Matter fileA general duty in NSW and VIC only; elsewhere APP 11.2 and limitation periods7 years in NSW and VICSee below

Your state trust-account minimum is mandatory, and no two states measure it from the same event:

Your stateMinimumThe clock starts
NSWat least 7 yearswhen the record is made (Conveyancers Licensing Regulation 2021 s 32)
VIC7 yearsgeneral records: when the work was undertaken (Conveyancers Act 2006 s 58(2)). Trust records are excluded from s 58 and run from the last transaction entry, or finalisation of the matter (reg 32(2))
SAat least 5 yearsthe section does not say (Conveyancers Act 1994 s 23(4))
WAnot less than 6 yearsthe date the money was received (Settlement Agents Regulations 1982 r 6F(1)(b))
TAS6 yearsthe last relevant transaction (Conveyancing Act 2004 s 19(2))
NTnot less than 6 yearsthe date of the last entry (Agents Licensing Act 1979 s 55(2)(c))

Where two periods overlap, the longest applicable one governs when you can finally destroy. Victoria is the trap worth knowing, because both of its periods are 7 years: run trust records off the general clock and you have the right number with a start date that can sit years early.

Can I keep copies of clients' ID documents?

This is the most common practical question, and the answer turns on who produced the copy. Where you sight a document and record the particulars, s 111(3)(a) asks for records demonstrating "the type and content of the data collected", not the image, and the OAIC says a copy kept because it is "merely helpful, convenient or desirable" will not meet reasonable necessity (Key stages in the lifecycle of an ID document in the AML/CTF context, updated August 2026). A copy you made yourself therefore has no AML basis to exist once you hold the particulars, and APP 11.2 requires you to destroy or de-identify it when you no longer need it. Your ARNECC verification-of-identity obligation is separate: keep the evidence that reasonable steps were taken. "We photograph every client's passport and keep it forever on a shared drive" is the habit APP 11 is aimed at.

The reversal: how the document reached you changes the answer

⚠️ There is one case where the usual advice runs backwards, and it is a common case in conveyancing. Where your practice provides a designated service, the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) draws a distinction that turns on how the document arrived and on whether you went on to act.

If you sighted the document and recorded the particulars, s 111 applies. It asks for records demonstrating "the type and content of the data collected" (s 111(3)(a)), not the image, and it runs for 7 years from when "the business relationship ends" (s 111(2)), not from the date you verified anyone. AUSTRAC says the same, and volunteers the limit: you "aren't required to make copies" for customer due diligence, but you "may have a legal responsibility to copy these documents outside the Act" (Record keeping overview, 10 July 2026).

If the client sent it to you and you went on to act, a different section applies, and it has two conditions. Section 108(1) applies where "a document relating to the provision, or prospective provision, of a designated service ... is given to the reporting entity by or on behalf of the customer concerned" (s 108(1)(a)) and the entity "commences, or has commenced, to provide the service to the customer" (s 108(1)(b)). Where both are met, s 108(2) requires you to retain "the document; or ... a copy of the document; for 7 years after the giving of the document", and s 108(3) makes that a civil penalty provision. Miss either condition and s 108 does not apply, so it is not "anything a client sends you".

How the ID reached youWhat the Act requires
You sighted it and recorded the particularss 111: keep the type and content of the data collected. The image is not required, and the clock runs 7 years from the end of the business relationship
The client sent it and you went on to acts 108: retain the document, or a copy, for 7 years from the day it was given
An identity image inside a document you must keep anywayKeep that record, and where you practically can, redact or separate the image
Sent on an enquiry that never became a matterNeither. s 108(1)(b) is not satisfied, so s 108 does not apply. Destroy or de-identify it unless another law or a genuine business need applies

So the practical rule is about what arrives, not what you decide afterwards. If a client emails you a licence scan and you go on to act for them, you hold a document they gave you, and destroying it as "over-retention" may be the wrong move. Which is why it is worth telling clients what to send before they send it, and recording which documents came from the client and which you produced yourself. That distinction is what sets the period, and it has to still be visible on the file years later.

⚠️ Two limits on this, and both matter. Sections 108 and 111 bind a reporting entity, so this reaches only a practice providing a designated service; it does not reach a practice that is neither a reporting entity nor an APP entity. And s 108 is headed "Customer-provided transaction documents to be retained" and sits in Part 10 Division 2, "Records of transactions etc.", while the due diligence records sit in Division 3. That placement supports reading it as aimed at service and transaction documents, but the words of s 108(1) are not confined to them, and no AUSTRAC guidance, explanatory memorandum or decided case addresses a client-emailed identity document. Get your own advice from a qualified Australian legal practitioner before you destroy anything a client sent you.

How do you build a retention schedule?

The workable answer to "how long" is a retention schedule rather than a single figure: a short table that lists each record type, the rule that governs it, the period, and how it's destroyed at the end. That turns a genuine legal tension into a routine you can actually follow. It also feeds your other obligations: the data you map here is the data your privacy policy describes and your data breach response plan protects.

Common questions

How long do I have to keep AML records?

Seven years, from three different dates. Records that let a transaction be reconstructed run 7 years from the day the record is made (s 107(3)). A document the customer gave you, where you went on to provide the service, runs 7 years from the day it was given (s 108(2)). Customer due diligence records run 7 years from the end of the business relationship (s 111(2)). All three are civil penalty provisions, so the start date matters as much as the number.

Doesn't APP 11 say I have to delete personal information?

APP 11.2 says destroy or de-identify it once it's no longer needed, but only where "the entity is not required by or under an Australian law, or a court/tribunal order, to retain the information" (APP 11.2(d)). AML retention is such a requirement, so holding those records for the AML period is consistent with APP 11.

Can I keep copies of clients' passports and licences indefinitely?

It depends on who produced the copy. A copy you made after sighting the document is not what the Act asks for: s 111(3)(a) wants records of the type and content of the data collected, so APP 11.2 requires you to destroy or de-identify the image once you no longer need it. A document the client gave you, where you went on to act, is caught by s 108(2) and retained for 7 years from the day it was given. Neither route supports keeping identity documents indefinitely out of habit.

What if the AML period and my state trust-account period differ?

Keep the record for the longest applicable required period, and check the start date as well as the number. The state trust-account minimum is mandatory and runs on its own clock: NSW from when the record is made, Victoria from the last transaction entry or finalisation of the matter, WA from the date the money was received. The AML clocks start elsewhere again, so two records carrying the same seven-year period can expire years apart.


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: OAIC, APP 11 (security of personal information); AML/CTF Act 2006 (Cth) Part 10, ss 107, 108 and 111; AUSTRAC, professional designated services; OAIC, Privacy guidance for reporting entities under the AML/CTF Act.