Skip to content

What client information can a conveyancer collect under APP 3?

Only what is reasonably necessary for your functions or activities. For a conveyancing practice that is a wider net than most small businesses get, because AML/CTF customer due diligence and verification of identity are compelled by law, and information you are required to collect is necessary by definition. The limit bites on everything either side of that compelled core: the extra fields on your intake form, the documents you keep copies of out of habit, and the information you collect about people who are not your client.

By Jon Oates, Founder of Privaproof · Last updated

‹ Conveyancer privacy compliance hub

General information, not legal advice. Your obligations depend on your circumstances.

Why does a conveyancer get to collect more than most small businesses?

Because a large part of the collection is not discretionary.

APP 3.2 lets an organisation collect personal information that is reasonably necessary for one or more of its functions or activities. That test is done against what you actually do, not against an abstract standard, and a conveyancing practice does something that requires identity evidence: it moves title and money between parties, and from 1 July 2026 it provides AML/CTF designated services. (AML/CTF Act 2006 (Cth) s 6(5B) Table 6, Compilation 62, `verify/2026-07-30-amlctf-act-provisions.md`)

And a conveyancing practice is caught under a different table from a real-estate agency, which changes three things. Agencies provide the real-estate services in Table 5. A conveyancer providing the professional services in Table 6:

⚠️ And the customer is different. Table 6 names the customer as "the person", meaning your client. Table 5 item 1 names both the seller and the buyer, so an agency brokering a sale has two customers where a conveyancer acting for a purchaser has one. Advice written for agencies does not transfer.

The 30-year leasehold exclusion still applies, because it sits in the s 6 definition of "real estate" rather than in either table, so ordinary leasing work stays outside for a conveyancer too.

So the compelled core is straightforward. Where the AML/CTF regime requires you to identify a customer, collect beneficial ownership information or establish source of funds, that collection is required or authorised by or under an Australian law, and the reasonably-necessary test is satisfied without argument. You do not need consent for it either, which is the point our consent and AML page sets out in full.

The trap is treating that as a general licence. The AML regime authorises the AML collection. It authorises nothing else on your intake form.

Sources: Privacy Act 1988 (Cth), APP 3.2, APP 3.4; Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth); Privacy Act 1988 (Cth), s 6E(1A) · OAIC APP 3 guidelines

Where does the limit actually bite in a conveyancing file?

On three things, and none of them are the AML documents.

The intake form. Most practices use a client-details form inherited from a precedent, and the fields nobody can justify are the ones that were there when they got it. Date of birth and identity details you need. Marital status, employer, number of children, second contact numbers "for the file": ask what function each one serves. If the answer is that it is occasionally handy, that is not the test.

The copies you keep. This is the largest single over-collection in a conveyancing practice, and it hides because it feels like diligence. AUSTRAC's position is that you record the identifying data you relied on, not that you retain an image of the document. A folder of licence and passport scans is the highest-consequence holding in most offices and much of it is not required. Our retention page sets out the one reversal that matters: if the client emails you a scan unprompted, it becomes a record you hold and the retention obligation attaches to it.

Information about people who are not your client. Beneficial owners, directors, trustees, a spouse being removed from a title, an executor. You are collecting personal information about each of them, and the fact that your client handed it over does not change whose information it is.

⚠️ And there is a genuine tension here that a practice needs to know about, because the guidance and the statute pull in different directions. AUSTRAC's position is that you record the identifying data you relied on rather than retaining an image of the document. But the Act requires retention. Part 10 of the AML/CTF Act provides that where "a customer of a reporting entity gives the reporting entity a document relating to the provision of a designated service, the reporting entity must retain the document for 7 years".

So the practical rule is about what arrives, not what you decide afterwards. If you record the details and keep no copy, you are following the guidance. If the client emails you a scan unprompted, you now hold a document they gave you, and the seven-year retention attaches to it. Which is why it is worth telling clients what to send before they send it.

Sources: Privacy Act 1988 (Cth), APP 3.2 · OAIC APP 3 guidelines

Can we collect information about someone who is not our client?

Yes, and there is a rule attached that is routinely missed.

APP 3.6 says you must collect personal information about an individual only from that individual, unless it is unreasonable or impracticable to do so, or the collection is required or authorised by law. Collecting beneficial ownership details from your client, about the beneficial owners, is a collection from someone other than the individual.

In practice that is usually fine, on both limbs. Where the AML rules require you to obtain beneficial ownership information from the customer, the collection is authorised by law. And it is often genuinely impracticable to go to each beneficial owner directly.

But two things follow that people do not expect:

Sources: Privacy Act 1988 (Cth), APP 3.6, APP 5.1 · OAIC APP 3 guidelines

Is any of it sensitive information?

More often than a conveyancing practice expects, and sensitive information has a higher bar.

APP 3.3 says you must not collect sensitive information unless the individual consents and it is reasonably necessary, subject to exceptions including where the collection is required or authorised by or under an Australian law.

Sensitive information is a defined subset: health information, biometric information used for automated biometric verification or identification, biometric templates, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record and a few others. In a conveyancing file it shows up in ways that are easy to miss:

The practical answer is not to refuse the information. It is to notice that you are holding it, keep it to what is needed, and not let it sit in a general file note when it was never needed at all.

Sources: Privacy Act 1988 (Cth), APP 3.3, s 6(1) definition of sensitive information · OAIC APP 3 guidelines

What if a client sends us information we never asked for?

This is APP 4, and it has a step most practices skip.

Where you receive personal information you did not solicit, you must within a reasonable period determine whether you could have collected it under APP 3. If you could have, it is treated as though you collected it and the ordinary rules apply. If you could not have, and it is not contained in a Commonwealth record and you are not required by law or a court or tribunal order to retain it, you must destroy or de-identify it as soon as practicable, if it is lawful and reasonable to do so.

For a conveyancing practice the everyday version is a client who forwards an entire email chain, or attaches a bundle of documents "in case it helps", containing information about third parties, previous transactions, or a family dispute. You did not ask for it. You are now holding it.

The releasing point: you are not obliged to keep it, and in many cases you are obliged not to. Deleting the attachment you never needed is the compliant answer, not the careless one.

Sources: Privacy Act 1988 (Cth), APP 4 · OAIC APP 4 guidelines

How should we collect it?

APP 3.5 requires that personal information be collected by lawful and fair means. That is a low bar in ordinary practice and it is worth knowing where it can be crossed: collecting information about a party through a pretext, or in a way that misleads them about who is collecting it or why, is unfair collection even where the information itself was collectable.

The everyday application is duller and more useful. Collect it in a way you could describe to the person afterwards without embarrassment, and record where each piece came from. Provenance matters later, because a correction request under APP 13 and a data breach assessment both turn on knowing what you hold and where it came from.

Sources: Privacy Act 1988 (Cth), APP 3.5 · OAIC APP 3 guidelines

Does the Privacy Act apply to our practice at all?

It depends on your turnover and on what services you provide, and the AML answer does not settle it.

A business whose annual turnover for the previous financial year was A$3 million or less is generally a small business operator and exempt, unless a trigger applies. Turnover counts income from all sources, and once you have crossed the threshold in any completed financial year you do not regain the exemption by later dropping below it.

For a conveyancing practice the trigger that usually applies is s 6E(1A): where you provide AML/CTF designated services, you are treated as an organisation in relation to the activities you carry on for the purposes of, or in connection with, those obligations. That is a scoped carve-in, not a general one.

Other triggers apply independently and catch the whole practice: being related to a body corporate that is not a small business operator, being a contracted service provider under a Commonwealth contract, trading in personal information, or opting in.

Most practices find one standard across the office simpler than maintaining a boundary between AML data and the rest of the file. That is a practical judgement, not a legal requirement, and it should not be presented as one.

Sources: Privacy Act 1988 (Cth), ss 6C, 6D, 6DA, 6E(1A) · See also conveyancer privacy obligations by state


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Privaproof's conveyancer materials are self-authored and are not independently reviewed by a solicitor.