Privacy policy vs collection notice: do conveyancers need both?
Yes: most conveyancers now need both, and they do different jobs. A privacy policy (APP 1) is your standing public statement of how you handle personal information; a collection notice (APP 5) is given to a person at the moment you collect their details, telling them what you're collecting and why. One doesn't replace the other.
By Jon Oates, Founder of Privaproof · Last updated
General information, not legal advice. Your obligations depend on your circumstances.
Why do both apply to you now?
Since 1 July 2026, providing a conveyancing designated service makes your firm an AUSTRAC reporting entity, and under Privacy Act s 6E(1A) the Privacy Act applies to the personal information you handle for AML/CTF, regardless of turnover. (The mechanism is set out in Does becoming an AUSTRAC reporting entity trigger the Privacy Act?.) Once the APPs apply to that data, APP 1 and APP 5 are two separate obligations, and they're easy to confuse, because both are about being transparent with personal information.
What does a privacy policy do (APP 1)?
A privacy policy is your standing, public document. Under APP 1, an APP entity must have a clearly expressed and up-to-date policy about how it manages personal information, and make it available free of charge (typically on your website). It's written once, kept current, and speaks to the world at large. It covers the whole picture: what kinds of information you collect, how you hold and secure it, the purposes you use it for, who you disclose it to, how someone can access or correct their information or make a complaint, and whether you disclose information overseas.
Think of it as the reference document a client, regulator or journalist can read at any time to understand your practice's approach. (For what a conveyancer's policy needs to say, see Do conveyancers need a privacy policy in 2026?.)
What does a collection notice do (APP 5)?
A collection notice is specific and timely. Under APP 5, at or before the time you collect someone's personal information (or as soon as practicable after), you must take reasonable steps to make them aware of certain things about that collection: who you are, the fact and purposes of collection, who you usually disclose to, that your privacy policy explains access/correction/complaints, and any consequences if the information isn't provided.
It isn't a document that lives on your website; it's the short notice you give a client at the point you collect their data: for a conveyancer, most importantly when you collect identity documents and source-of-funds evidence for verification. It's tied to a moment and a purpose, not to your practice in general.
What's the difference in one line?
The privacy policy is the standing "how we handle personal information" statement; the collection notice is the "here's what we're doing with the details we're taking from you right now" heads-up. You need the policy because APP 1 requires it, and the notice because APP 5 requires it; they don't substitute for each other.
| Aspect | Privacy policy (APP 1) | Collection notice (APP 5) |
|---|---|---|
| Purpose | How your practice manages personal information overall | What you're collecting now, and why |
| When | Standing document, always available | At or around the point of collection |
| Audience | The public / anyone | The specific person whose data you're collecting |
| Where it lives | Usually your website | Given in the moment (form, email, spoken script) |
| Typical trigger for a conveyancer | Published once, kept current | Client onboarding; collecting VOI / AML CDD data |
Why does a conveyancer need both?
For a conveyancing practice the collection notice matters more than it might for a general business, because your highest-sensitivity collection point (taking identity documents, beneficial-ownership details and source-of-funds evidence for AML customer due diligence) is exactly the moment APP 5 is about. A generic "we collect your info to provide our services" line doesn't do that collection justice. Many firms use a purpose-built collection notice for the VOI/AML step, on top of their general privacy policy.
What's the AML tipping-off wrinkle?
The AML/CTF regime includes "tipping-off" rules, and a collection notice must not reveal, or be timed so as to reveal, that a suspicious matter has been or may be reported. Where notifying would be inconsistent with those rules, you may withhold some or all of the APP 5 matters. In the ordinary course this rarely bites, but where a matter raises a suspicion it can affect what you say and when, a point to get professional advice on for a specific case. Privaproof provides general information and does not assess AML/CTF obligations, which are administered by AUSTRAC.
A conveyancer who is a reporting entity generally needs both documents as part of the same set: the policy, the notice, and a data breach response plan for the sensitive identity and settlement data behind them.
Common questions
Can a privacy policy replace a collection notice?
No. They're separate obligations: APP 1 requires the standing policy; APP 5 requires the point-of-collection notice. Having one doesn't satisfy the other.
When do I give a collection notice?
At or before the time you collect the person's personal information, or as soon as practicable afterwards: for a conveyancer, most importantly when you collect identity and source-of-funds data for verification.
Do I need a special collection notice for AML/VOI data?
It's good practice. The identity and source-of-funds data you collect for AML customer due diligence is your highest-sensitivity collection point, and a purpose-built notice for that step is clearer than a generic one.
Does my collection notice need to mention my privacy policy?
Yes: APP 5 expects the notice to point the person to how they can access or correct their information and make a complaint, which your privacy policy sets out.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Privaproof's conveyancer materials are self-authored and are not independently reviewed by a solicitor. Sources: OAIC, Australian Privacy Principles; OAIC, privacy guidance for reporting entities under the AML/CTF Act; Privacy Act 1988 (Cth) s 6E(1A); AUSTRAC.