What client information can a conveyancer collect under APP 3?
Only what is reasonably necessary for your functions or activities. For a conveyancing practice that is a wider net than most small businesses get, because AML/CTF customer due diligence and verification of identity are compelled by law, and information you are required to collect is necessary by definition. The limit bites on everything either side of that compelled core: the extra fields on your intake form, the documents you keep copies of out of habit, and the information you collect about people who are not your client.
By Jon Oates, Founder of Privaproof · Last updated
‹ Conveyancer privacy compliance hub
General information, not legal advice. Your obligations depend on your circumstances.
Why does a conveyancer get to collect more than most small businesses?
Because a large part of the collection is not discretionary.
APP 3.2 lets an organisation collect personal information that is reasonably necessary for one or more of its functions or activities. That test is done against what you actually do, not against an abstract standard, and a conveyancing practice does something that requires identity evidence: it moves title and money between parties, and from 1 July 2026 it provides AML/CTF designated services. (AML/CTF Act 2006 (Cth) s 6(5B) Table 6, Compilation 62, `verify/2026-07-30-amlctf-act-provisions.md`)
⭐ And a conveyancing practice is caught under a different table from a real-estate agency, which changes three things. Agencies provide the real-estate services in Table 5. A conveyancer providing the professional services in Table 6:
- Item 1 covers "assisting a person in the planning or execution of a transaction, or otherwise acting for or on behalf of a person in a transaction, to sell, buy or otherwise transfer real estate", where the service is provided in the course of carrying on a business and ⭐ the transfer is not "pursuant to, or resulting from, an order of a court or tribunal". That carve-out is a genuine release, and it covers family-law property transfers, deceased-estate transmissions under court order and partition orders.
- Item 2 extends the same to transferring a body corporate or legal arrangement, so business-sale and trust-restructure work can be in scope on a transaction with no land in it at all.
- ⭐ Item 3 makes handling client money its own designated service: "receiving, holding and controlling (including disbursing) or managing" a person's money, accounts, securities, virtual assets or other property as part of assisting in the transaction. For a practice that is the trust account, so you can conclude item 1 does not apply and still be caught by item 3.
⚠️ And the customer is different. Table 6 names the customer as "the person", meaning your client. Table 5 item 1 names both the seller and the buyer, so an agency brokering a sale has two customers where a conveyancer acting for a purchaser has one. Advice written for agencies does not transfer.
The 30-year leasehold exclusion still applies, because it sits in the s 6 definition of "real estate" rather than in either table, so ordinary leasing work stays outside for a conveyancer too.
So the compelled core is straightforward. Where the AML/CTF regime requires you to identify a customer, collect beneficial ownership information or establish source of funds, that collection is required or authorised by or under an Australian law, and the reasonably-necessary test is satisfied without argument. You do not need consent for it either, which is the point our consent and AML page sets out in full.
The trap is treating that as a general licence. The AML regime authorises the AML collection. It authorises nothing else on your intake form.
Sources: Privacy Act 1988 (Cth), APP 3.2, APP 3.4; Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth); Privacy Act 1988 (Cth), s 6E(1A) · OAIC APP 3 guidelines
Where does the limit actually bite in a conveyancing file?
On three things, and none of them are the AML documents.
The intake form. Most practices use a client-details form inherited from a precedent, and the fields nobody can justify are the ones that were there when they got it. Date of birth and identity details you need. Marital status, employer, number of children, second contact numbers "for the file": ask what function each one serves. If the answer is that it is occasionally handy, that is not the test.
The copies you keep. This is the largest single over-collection in a conveyancing practice, and it hides because it feels like diligence. AUSTRAC's position is that you record the identifying data you relied on, not that you retain an image of the document. A folder of licence and passport scans is the highest-consequence holding in most offices and much of it is not required. Our retention page sets out the one reversal that matters: if the client emails you a scan unprompted, it becomes a record you hold and the retention obligation attaches to it.
Information about people who are not your client. Beneficial owners, directors, trustees, a spouse being removed from a title, an executor. You are collecting personal information about each of them, and the fact that your client handed it over does not change whose information it is.
⚠️ And there is a genuine tension here that a practice needs to know about, because the guidance and the statute pull in different directions. AUSTRAC's position is that you record the identifying data you relied on rather than retaining an image of the document. But the Act requires retention. Part 10 of the AML/CTF Act provides that where "a customer of a reporting entity gives the reporting entity a document relating to the provision of a designated service, the reporting entity must retain the document for 7 years".
So the practical rule is about what arrives, not what you decide afterwards. If you record the details and keep no copy, you are following the guidance. If the client emails you a scan unprompted, you now hold a document they gave you, and the seven-year retention attaches to it. Which is why it is worth telling clients what to send before they send it.
Sources: Privacy Act 1988 (Cth), APP 3.2 · OAIC APP 3 guidelines
Can we collect information about someone who is not our client?
Yes, and there is a rule attached that is routinely missed.
APP 3.6 says you must collect personal information about an individual only from that individual, unless it is unreasonable or impracticable to do so, or the collection is required or authorised by law. Collecting beneficial ownership details from your client, about the beneficial owners, is a collection from someone other than the individual.
In practice that is usually fine, on both limbs. Where the AML rules require you to obtain beneficial ownership information from the customer, the collection is authorised by law. And it is often genuinely impracticable to go to each beneficial owner directly.
But two things follow that people do not expect:
- The information is still personal information about them, so your security, retention and access obligations run to it. A beneficial owner can make an access request about their own information in your file.
- APP 5 is engaged. Where you collect information about someone from a third party, you have to take such steps as are reasonable to make that person aware of the collection. That is the harder half of the notice obligation and it is covered on our collection notice page.
Sources: Privacy Act 1988 (Cth), APP 3.6, APP 5.1 · OAIC APP 3 guidelines
Is any of it sensitive information?
More often than a conveyancing practice expects, and sensitive information has a higher bar.
APP 3.3 says you must not collect sensitive information unless the individual consents and it is reasonably necessary, subject to exceptions including where the collection is required or authorised by or under an Australian law.
Sensitive information is a defined subset: health information, biometric information used for automated biometric verification or identification, biometric templates, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record and a few others. In a conveyancing file it shows up in ways that are easy to miss:
- A medical circumstance offered to explain a delay, a hardship, or a power of attorney. Once it is in a file note it is health information you hold.
- Biometric verification in a VOI process. Some electronic VOI products perform a facial comparison. ⚠️ Whether that produces "biometric information used for automated biometric verification or identification" within the meaning of s 6(1) is not something we can answer for your particular product, and we are not going to guess at it. Ask your provider, in writing, what the check does and what it retains, and keep the answer. That written answer is the evidence either way.
- Country of birth or citizenship evidence, where it is collected in a way that reveals ethnic origin.
The practical answer is not to refuse the information. It is to notice that you are holding it, keep it to what is needed, and not let it sit in a general file note when it was never needed at all.
Sources: Privacy Act 1988 (Cth), APP 3.3, s 6(1) definition of sensitive information · OAIC APP 3 guidelines
What if a client sends us information we never asked for?
This is APP 4, and it has a step most practices skip.
Where you receive personal information you did not solicit, you must within a reasonable period determine whether you could have collected it under APP 3. If you could have, it is treated as though you collected it and the ordinary rules apply. If you could not have, and it is not contained in a Commonwealth record and you are not required by law or a court or tribunal order to retain it, you must destroy or de-identify it as soon as practicable, if it is lawful and reasonable to do so.
For a conveyancing practice the everyday version is a client who forwards an entire email chain, or attaches a bundle of documents "in case it helps", containing information about third parties, previous transactions, or a family dispute. You did not ask for it. You are now holding it.
The releasing point: you are not obliged to keep it, and in many cases you are obliged not to. Deleting the attachment you never needed is the compliant answer, not the careless one.
Sources: Privacy Act 1988 (Cth), APP 4 · OAIC APP 4 guidelines
How should we collect it?
APP 3.5 requires that personal information be collected by lawful and fair means. That is a low bar in ordinary practice and it is worth knowing where it can be crossed: collecting information about a party through a pretext, or in a way that misleads them about who is collecting it or why, is unfair collection even where the information itself was collectable.
The everyday application is duller and more useful. Collect it in a way you could describe to the person afterwards without embarrassment, and record where each piece came from. Provenance matters later, because a correction request under APP 13 and a data breach assessment both turn on knowing what you hold and where it came from.
Sources: Privacy Act 1988 (Cth), APP 3.5 · OAIC APP 3 guidelines
Does the Privacy Act apply to our practice at all?
It depends on your turnover and on what services you provide, and the AML answer does not settle it.
A business whose annual turnover for the previous financial year was A$3 million or less is generally a small business operator and exempt, unless a trigger applies. Turnover counts income from all sources, and once you have crossed the threshold in any completed financial year you do not regain the exemption by later dropping below it.
For a conveyancing practice the trigger that usually applies is s 6E(1A): where you provide AML/CTF designated services, you are treated as an organisation in relation to the activities you carry on for the purposes of, or in connection with, those obligations. That is a scoped carve-in, not a general one.
Other triggers apply independently and catch the whole practice: being related to a body corporate that is not a small business operator, being a contracted service provider under a Commonwealth contract, trading in personal information, or opting in.
Most practices find one standard across the office simpler than maintaining a boundary between AML data and the rest of the file. That is a practical judgement, not a legal requirement, and it should not be presented as one.
Sources: Privacy Act 1988 (Cth), ss 6C, 6D, 6DA, 6E(1A) · See also conveyancer privacy obligations by state
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Privaproof's conveyancer materials are self-authored and are not independently reviewed by a solicitor.