Skip to content

Who can a conveyancer share client information with?

Anyone the disclosure is part of completing the transaction for: the other side's representative, the lender, the electronic lodgment network, the revenue office, the land titles authority, and the agent where they have a role in the settlement. That is the primary purpose the client came to you for, and APP 6 does not stand in its way. What APP 6 controls is everything else, and the two disclosures a conveyancing practice most often gets wrong are marketing and referrals.

By Jon Oates, Founder of Privaproof · Last updated

‹ Conveyancer privacy compliance hub

General information, not legal advice. Your obligations depend on your circumstances.

What is the actual rule?

APP 6.1 says that where you hold personal information about an individual that was collected for a particular purpose, you must not use or disclose it for another purpose unless an exception applies.

The language matters. The primary purpose is what you collected it for. A secondary purpose is anything else, and it needs a route.

The routes in APP 6.2 that a conveyancing practice will actually use:

Note what the reasonable-expectation test is anchored to: what the client would expect, judged objectively, not what is convenient for the practice.

Sources: Privacy Act 1988 (Cth), APP 6.1, APP 6.2, s 16A · OAIC APP 6 guidelines

Who is in the primary purpose for a settlement?

The disclosures that make a conveyance happen. A client instructing you to act in a purchase or sale expects their information to move to the parties who have to receive it, and it is not a secondary purpose to send it there.

In the ordinary matter that includes:

That last group deserves a note. Giving information to a provider that holds it on your behalf is often a use rather than a disclosure, and either way the accountability does not leave you. Where any of it is stored or accessed overseas, APP 8 is engaged on top of APP 6, and that is a different obligation with its own conditions. Our overseas disclosure page sets it out.

Being in the primary purpose is not a licence to send everything. The other side needs what the settlement requires. It does not need your client's source-of-funds evidence, their identity documents, or your file notes.

Sources: Privacy Act 1988 (Cth), APP 6.1, APP 8 · OAIC APP 6 guidelines

Can we pass client details to a broker, an agent or an insurer?

This is where practices get into trouble, and the honest answer is that it depends on whether the client agreed.

A referral to a mortgage broker, a building insurer, a depreciation firm or a removalist is a secondary purpose. It is not what the client engaged you to do. Whether you can rely on the reasonable-expectations route is doubtful for a cold pass, because a client giving you their details to complete a settlement does not obviously expect those details to arrive at a company they have never dealt with.

The clean version is consent, and it is not hard: ask, record the answer, pass the details only if the answer is yes. A referral the client agreed to is outside the problem entirely.

⚠️ And there is a second reason to do it that way. Under s 6D(4)(c) a business that discloses personal information about another individual for a benefit, service or advantage may lose the small-business exemption, and under s 6D(4)(d) so may one that pays for personal information. Both limbs are released by ss 6D(7) and 6D(8) where the disclosure or collection is made with the consent of the individual, or is required or authorised by law.

So a paid referral arrangement conducted without consent can put your whole practice inside the Privacy Act, and the same arrangement conducted with consent does not. The compliant version and the exemption-preserving version are the same behaviour.

And this has been applied to a real business in the property sector, which is worth knowing before assuming turnover settles it. In Property Lovers Pty Ltd (Privacy) [2024] AICmr 249 the respondent produced a tax statement showing it had turned over under A$3 million. The Commissioner held it to the APPs anyway:

"the respondent advised that it did not ultimately turnover more than $3 million during that financial year and produced a copy of the relevant tax statement. In any event, the respondent carries on a business in which it discloses the personal information of individuals to paying Program participants... thereby deriving a financial benefit. Therefore, I am satisfied that the respondent is an APP entity."
Property Lovers Pty Ltd (Privacy) [2024] AICmr 249 at [26], footnoting s 6D(4)(c) ⚠️ It does not follow that any particular arrangement engages the limb. Whether yours does depends on the arrangement, and no court has decided it. Fuller treatment on the coverage page.

s 6D lettering CLOSED against A's Compilation 104 pin (`verify/2026-07-29-s6D-6DA-turnover-ratchet.md`): (4)(a) the turnover ratchet · (4)(b) health service provider holding health information · (4)(c) discloses personal information about another for a benefit, service or advantage · (4)(d) provides a benefit, service or advantage to collect personal information about another · (4)(e) Commonwealth contracted service provider · (4)(f) credit reporting body · (7) and (8) the consent and required-by-law carve-outs to (c) and (d) · (9) related bodies corporate.

Sources: Privacy Act 1988 (Cth), APP 6.2(b), ss 6D(4), 6D(7), 6D(8) · OAIC APP 6 guidelines

Can we email past clients about our services?

Not under APP 6, because direct marketing by an organisation is not governed by APP 6 at all.

APP 7 is the direct marketing principle, and it applies instead of APP 6 where an organisation uses or discloses personal information for direct marketing. It permits it in defined circumstances, including where you collected the information from the individual, they would reasonably expect you to use it for direct marketing, you provide a simple means of opting out, and they have not opted out. Separate rules apply where the information came from a third party, and stricter ones to sensitive information.

And APP 7 is not the only regime, or even the most mechanical one. Marketing emails and text messages are governed by the Spam Act 2003, which requires consent, accurate sender identification and a working unsubscribe. Marketing calls are governed by the Do Not Call Register Act 2006.

⚠️ Neither of those has a small-business exemption or a turnover threshold. A practice that is genuinely outside the Privacy Act is still squarely inside both. "We are too small" answers the Privacy Act question and answers nothing about how you market.

Sources: Privacy Act 1988 (Cth), APP 7; Spam Act 2003 (Cth); Do Not Call Register Act 2006 (Cth) · ACMA

What if we have to report something to AUSTRAC?

Reporting is authorised, and there is a companion rule that runs the other way and surprises people.

A suspicious matter report to AUSTRAC is a disclosure required or authorised by or under an Australian law, so APP 6.2(c) covers it. No consent is needed and none should be sought.

⚠️ The companion rule, stated accurately, because this is a criminal provision. Section 123 makes it an offence to disclose suspicious-matter-report information to a person other than an AUSTRAC entrusted person where the disclosure would or could reasonably be expected to prejudice an investigation. That is three cumulative limbs, not a blanket prohibition on ever mentioning it. ⚠️ But s 123(3) closes the obvious gap: "it is immaterial whether an investigation has commenced", so "no investigation exists yet" is not an answer.

So the operational rule really is: do not tell the client, because telling someone you have reported them would ordinarily satisfy all three limbs. Penalty: imprisonment for 2 years or 120 penalty units, or both.

And there is an exception that may or may not be available to you, depending on what kind of practice you are. Section 123(4) permits disclosure where the person is a legal practitioner (however described) or a qualified accountant, or works for a firm of either, and the disclosure is made "in good faith, for the purposes of dissuading the customer from engaging in conduct that constitutes, or could constitute, an offence".

⚠️⚠️ A licensed conveyancer who is not a legal practitioner is not in that list, unless specified in the AML/CTF Rules. So a solicitor doing conveyancing may have this exception and a licensed conveyancer, on the face of the section, may not. The defendant also bears an evidential burden on it (Criminal Code s 13.3(3)), so it is a defence to establish rather than a permission to rely on casually. ⛔ If you are considering saying anything to a client in this territory, get advice on your own status first.

The practical consequence for your privacy documents: a collection notice and a privacy policy that promise to tell the client about every disclosure are promising something you cannot deliver. Write them so they do not.

Sources: Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth); Privacy Act 1988 (Cth), APP 6.2(c) · AUSTRAC

Can we tell the other side, or the agent, why our client is delayed?

Carefully, and less than the phone call usually contains.

The settlement disclosures are in the primary purpose, but the primary purpose is completing the transaction, not explaining your client's circumstances. "We will not be ready to settle on Friday" is within it. "Our client's finance fell through because of a health issue" adds personal information, quite possibly sensitive information, that the recipient does not need and your client has not agreed to share.

The test to apply in the moment is simple: what does this person need in order to do their part of the settlement? Say that. A conveyancing practice leaks far more through helpful phone calls than through systems.

Sources: Privacy Act 1988 (Cth), APP 6.1, APP 6.2(a) · OAIC APP 6 guidelines

Do we have to keep a record of what we disclosed?

There is no general APP 6 requirement to keep a disclosure register, and a note in the file is worth more than the rule suggests.

Two later obligations run straight into it. If the client asks you to correct something under APP 13, they can ask you to notify the third parties you previously disclosed it to, and you can only do that if you know who they are. And if you suffer a data breach, the assessment turns on what information went where.

A line in the matter file recording non-routine disclosures is a few seconds of work that answers both.

Sources: Privacy Act 1988 (Cth), APP 13.3; Privacy Act 1988 (Cth), Part IIIC · See also correcting client information


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Privaproof's conveyancer materials are self-authored and are not independently reviewed by a solicitor.