Skip to content

What client information can a conveyancer collect under APP 3?

Only what is reasonably necessary for your functions or activities. For a conveyancing practice that is a wider net than most small businesses get, because AML/CTF customer due diligence is compelled by law, and information you are required to collect is necessary by definition. But that core is narrower than it looks: the Rules set a minimum you must collect, while s 28(3)(d) makes verification risk-scaled and prescribes no document at all. The limit bites either side of it: the extra fields on your intake form, the copies you keep out of habit, and the information you collect about people who are not your client.

By Jon Oates, Founder of Privaproof · Last updated

‹ Conveyancer privacy compliance hub

General information, not legal advice. Your obligations depend on your circumstances.

Why does a conveyancer get to collect more than most small businesses?

Because a large part of the collection is not discretionary.

APP 3.2 is a prohibition, not a permission: an organisation must not collect personal information (other than sensitive information) unless the information is reasonably necessary for one or more of the entity's functions or activities. The wider "or directly related to" limb is APP 3.1, for agencies only. The test is done against what you actually do, and a conveyancing practice moves title and money between parties, and since 31 March 2026 provides AML/CTF designated services. (AML/CTF Act 2006 (Cth) s 6(5B) Table 6, Compilation 62)

⭐ And a conveyancing practice is caught under a different table from a real-estate agency, which changes three things. Agencies provide the real-estate services in Table 5. A conveyancer providing the professional services in Table 6:

⚠️ And the customer is different. Table 6 names the customer as "the person", meaning your client. Table 5 item 1 names both the seller and the buyer, so an agency brokering a sale has two customers where a conveyancer acting for a purchaser has one. Advice written for agencies does not transfer.

The 30-year leasehold exclusion still applies, because it sits in the s 6 definition of "real estate" rather than in either table, so ordinary leasing work stays outside for a conveyancer too. ⚠️ Paragraph (f) measures the term "excluding options for further terms", so 25 years plus two 10-year options is still outside.

So the compelled core is real, but narrower than "whatever AML touches". The Rules set a collection floor (AML/CTF Rules 2025 ss 6-1 to 6-4, "must collect at least the following KYC information"), and where they require the collection, APP 3.2's reasonably-necessary test is satisfied without argument. ⚠️ Source of funds is not in that floor: it is enhanced due diligence, reached through s 32 of the Act and s 6-21 of the Rules, not taken from everyone. You do not need consent for the compelled core either, which our consent and AML page sets out in full.

The trap is treating that as a general licence. The AML regime authorises the AML collection. It authorises nothing else on your intake form.

Sources: Privacy Act 1988 (Cth), APP 3.2, s 6E(1A); Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), s 6 (definition of "real estate"), s 6(5A), s 6(5B), s 6(5C), s 28(3); AML/CTF Rules 2025, ss 6-1 to 6-4, s 6-21 · OAIC APP 3 guidelines

Where does the limit actually bite in a conveyancing file?

On three things, and none of them are the AML documents.

The intake form. Open yours and ask where each field came from. ⭐ For a private client the Rules prescribe no minimum list: ss 6-1 to 6-4 of the AML/CTF Rules 2025 cover sole traders, bodies corporate, trusts and government bodies, so an individual buyer or seller falls to s 28(3)(c), "appropriate to the ML/TF risk". What you collect is your documented choice. Marital status, employer, number of children, second contact numbers "for the file": ask what function each one serves. If the answer is that it is occasionally handy, that is not the test.

The copies you keep. This one hides because it feels like diligence. Both AUSTRAC and the OAIC have said the AML/CTF Act does not require you to keep scanned copies of identity documents (OAIC, Privacy guidance for reporting entities under the AML/CTF Act, April 2026, citing AUSTRAC's initial-CDD guidance and s 111). What s 111 asks for is the extracted detail: name, date of birth, address, the document's expiry date, number and type, what you did to verify, and the outcome of your risk assessment. ⭐ Count the licence and passport scans in your own file store, then ask which of them s 111 asked for. Our retention page sets out the reversal that matters: a document the client gives you attracts the separate seven-year retention in s 108 only where you commence, or have commenced, providing the service.

Information about people who are not your client. Beneficial owners, directors, trustees, a spouse being removed from a title, an executor. You are collecting personal information about each of them, and the fact that your client handed it over does not change whose information it is.

⚠️ And there is a genuine tension here, because the guidance and the statute pull in different directions. The regulators' position is that you record the identifying data you relied on rather than retaining an image (OAIC, Privacy guidance for reporting entities under the AML/CTF Act, April 2026). But s 108 requires retention only on two conditions. A document "relating to the provision, or prospective provision, of a designated service" must be "given to the reporting entity by or on behalf of the customer" (s 108(1)(a)) and the reporting entity must "commence, or has commenced, to provide the service to the customer" (s 108(1)(b)). Then s 108(2) requires you to "retain: (a) the document; or (b) a copy of the document; for 7 years after the giving of the document", and s 108(3) makes that a civil penalty provision. ⛔ Both limbs, or s 108 does not apply.

So the practical rule is about what arrives, not what you decide afterwards. If you record the details and keep no copy, you are following the guidance. If the client emails you a scan unprompted and you go on to act for them, s 108 is engaged and the seven-year clock runs from the day they sent it, not from settlement. Which is why it is worth telling clients what to send before they send it, and worth getting advice before destroying anything a client has already sent.

Sources: Privacy Act 1988 (Cth), APP 3.2 · OAIC APP 3 guidelines

Can we collect information about someone who is not our client?

Yes, and there is a rule attached that is routinely missed.

APP 3.6 says you must collect personal information about an individual only from that individual, and for an organisation there is one exception: APP 3.6(b), that it is unreasonable or impracticable to do so. ⚠️ The consent and "required or authorised by or under an Australian law" exceptions are in APP 3.6(a), which opens "if the entity is an agency". Collecting beneficial ownership details from your client, about the beneficial owners, is a collection from someone other than the individual.

In practice it is usually fine, but on one limb only. Where the AML rules require you to obtain beneficial ownership information from the customer, going to each beneficial owner directly is impracticable, and that is APP 3.6(b). ⭐ Being required by law does the work under APP 3.2; under APP 3.6 it does none. Your file note has to say "impracticable", not "required by law".

But two things follow that people do not expect:

Sources: Privacy Act 1988 (Cth), APP 3.6, APP 5.1 · OAIC APP 3 guidelines

Is any of it sensitive information?

More often than a conveyancing practice expects, and sensitive information has a higher bar.

APP 3.3 says you must not collect sensitive information unless the individual consents and, for an organisation, it is "reasonably necessary for one or more of the entity's functions or activities" (APP 3.3(a)(ii)), or an APP 3.4 exception applies, the first being a collection "required or authorised by or under an Australian law or a court/tribunal order" (APP 3.4(a)).

Sensitive information is a closed list in s 6(1): health and genetic information, biometric information used for automated biometric verification or identification, biometric templates, racial or ethnic origin, political opinions, religious or philosophical beliefs, union or association membership, sexual orientation or practices, and criminal record. ⭐ A driver licence or passport is not on that list. In a conveyancing file the sensitive material shows up in ways that are easy to miss:

The practical answer is not to refuse the information. It is to notice that you are holding it, keep it to what is needed, and not let it sit in a general file note when it was never needed at all.

Sources: Privacy Act 1988 (Cth), APP 3.3, s 6(1) definition of sensitive information · OAIC APP 3 guidelines

What if a client sends us information we never asked for?

This is APP 4, and it has a step most practices skip.

Where you receive personal information you did not solicit, you must within a reasonable period determine whether you could have collected it under APP 3. If you could have, APP 4.4 applies APPs 5 to 13 as though you had. If you could not have, and it is not contained in a Commonwealth record, APP 4.3 requires you to destroy or de-identify it as soon as practicable, "but only if it is lawful and reasonable to do so". ⚠️ Those are the only two conditions. A retention duty such as s 108 is not a third one; it bites through "lawful and reasonable".

For a conveyancing practice the everyday version is a client who forwards an entire email chain, or attaches a bundle of documents "in case it helps", containing information about third parties, previous transactions, or a family dispute. You did not ask for it. You are now holding it.

The releasing point: you are not obliged to keep it, and in many cases you are obliged not to. Deleting the attachment you never needed is the compliant answer, not the careless one.

Sources: Privacy Act 1988 (Cth), APP 4 · OAIC APP 4 guidelines

How should we collect it?

APP 3.5 requires that personal information be collected by lawful and fair means. That is a low bar in ordinary practice and it is worth knowing where it can be crossed: collecting information about a party through a pretext, or in a way that misleads them about who is collecting it or why, is unfair collection even where the information itself was collectable.

The everyday application is duller and more useful. Collect it in a way you could describe to the person afterwards without embarrassment, and record where each piece came from. Provenance matters later, because a correction request under APP 13 and a data breach assessment both turn on knowing what you hold and where it came from.

Sources: Privacy Act 1988 (Cth), APP 3.5 · OAIC APP 3 guidelines

Does the Privacy Act apply to our practice at all?

It depends on your turnover and on what services you provide, and the AML answer does not settle it.

A business whose annual turnover for the previous financial year was A$3 million or less is generally a small business operator and exempt, unless a trigger applies. Turnover counts income from all sources, and once you have crossed the threshold in any completed financial year you do not regain the exemption by later dropping below it.

For a conveyancing practice the trigger that usually applies is s 6E(1A): where you provide AML/CTF designated services, you are treated as an organisation in relation to the activities you carry on for the purposes of, or in connection with, those obligations. That is a scoped carve-in, not a general one.

Other triggers apply independently and catch the whole practice: being related to a body corporate that is not a small business operator (s 6D(9)), being a contracted service provider under a Commonwealth contract (s 6D(4)(e)), disclosing or collecting personal information for a benefit, service or advantage (s 6D(4)(c) and (d)), or opting in (s 6EA). s 6D(4) runs (a) to (f).

⭐ Ask whether you could actually draw the boundary in your own file store. One standard across the office is usually simpler than maintaining a line between AML data and the rest of the file, but that is a practical judgement, not a legal requirement, and it should not be presented as one.

Sources: Privacy Act 1988 (Cth), ss 6C, 6D, 6DA, 6E(1A) · See also conveyancer privacy obligations by state


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC.