Privacy policy vs collection notice: do conveyancers need both?
Yes, wherever the Privacy Act applies to you. A privacy policy (APP 1.3) is your standing public statement of how you manage personal information; a collection notice (APP 5.1) is the reasonable steps you take, at or before you collect a person's details or, if that is not practicable, as soon as practicable after, to make them aware of what you are collecting and why. Both bind APP entities, and neither discharges the other.
By Jon Oates, Founder of Privaproof · Last updated
General information, not legal advice. Your obligations depend on your circumstances.
Why do both apply to you now?
Since 31 March 2026, providing a Table 6 conveyancing designated service makes your firm an AUSTRAC reporting entity, and Privacy Act s 6E(1A) then applies the Act, regardless of turnover, "in relation to the activities carried on ... for the purposes of, or in connection with, activities relating to" the AML/CTF Act. The reach is to those activities, not to a folder of documents. (The mechanism is set out in Does becoming an AUSTRAC reporting entity trigger the Privacy Act?.) Once you are an APP entity for those activities, APP 1 and APP 5 are two separate obligations, easy to confuse because both are about being transparent.
What does a privacy policy do (APP 1)?
A privacy policy is your standing, public document, kept current and addressed to the world at large. Under APP 1.3 an APP entity must have a clearly expressed and up-to-date policy about the management of personal information by the entity, and under APP 1.5 make it available free of charge and in an appropriate form (the note says usually on your website). APP 1.4 sets seven things it must contain: the kinds of personal information you collect and hold; how you collect and hold it; the purposes you collect, hold, use and disclose it for; how a person accesses and corrects it; how a person complains and how you will deal with it; whether you are likely to disclose overseas; and if so, the countries, where practicable to specify them.
Think of it as the reference document a client, regulator or journalist can read at any time to understand your practice's approach. (For what a conveyancer's policy needs to say, see Do conveyancers need a privacy policy in 2026?.)
What does a collection notice do (APP 5)?
A collection notice is specific and timely. Under APP 5.1, at or before the time you collect someone's personal information or, if that is not practicable, as soon as practicable after, you must take such steps (if any) as are reasonable in the circumstances to notify them of the APP 5.2 matters about that collection, or otherwise ensure they are aware. There are ten: your identity and contact details; the fact and circumstances of collection, where you collect from a third party or the person may not be aware; the name of the Australian law or court order requiring or authorising the collection, where one does; the purposes; the main consequences if it is not collected; who you usually disclose that kind of information to; that your policy covers access and correction; that it covers complaints; whether you are likely to disclose overseas; and if so, the countries, where practicable to specify them.
It isn't a page on your website; it's what you tell a client, or otherwise make them aware of, at the point you collect their data, most importantly at the VOI and source-of-funds step. It's tied to a moment and a purpose, not to your practice in general.
What's the difference in one line?
The privacy policy is the standing "how we handle personal information" statement; the collection notice is the "here's what we're doing with the details we're taking from you right now" heads-up. You need the policy because APP 1.3 requires it, and the notice because APP 5.1 requires it; complying with one does not discharge the other.
| Aspect | Privacy policy (APP 1) | Collection notice (APP 5) |
|---|---|---|
| Purpose | How your practice manages personal information overall | What you're collecting now, and why |
| When | Standing document, always available | At or before collection, or as soon as practicable after if that is not practicable |
| Audience | The public / anyone | The specific person whose data you're collecting |
| Where it lives | Usually your website | Given in the moment (form, email, spoken script) |
| Typical trigger for a conveyancer | Published once, kept current | Client onboarding; collecting VOI / AML CDD data |
Why does a conveyancer need both?
For a conveyancing practice the collection notice matters more than it might for a general business, because your highest-sensitivity collection point (taking identity documents, beneficial-ownership details and source-of-funds evidence for AML customer due diligence) is exactly the moment APP 5 is about. A generic "we collect your info to provide our services" line doesn't do that collection justice. Two questions for your own onboarding pack: at the VOI step, does your notice name the Australian law authorising the collection, as APP 5.2(c) requires, and state the main consequences if the client doesn't provide it, as APP 5.2(e) requires?
What's the AML tipping-off wrinkle?
The AML/CTF Act's tipping-off offence, s 123, is narrower than the folklore. Its limbs are cumulative: a reporting entity discloses s 123(2) information, essentially a suspicious matter report under s 41(2), a copy of one, or a document setting out the suspicion, to a person other than an AUSTRAC entrusted person, and the disclosure "would or could reasonably be expected to prejudice an investigation" (s 123(1)(d)). Section 123(3) makes it immaterial whether an investigation has commenced. Because APP 5.1 requires only such steps as are reasonable in the circumstances, what you say and when can change where a matter raises a suspicion, a point to get professional advice on for a specific case. Privaproof provides general information and does not assess AML/CTF obligations, which are administered by AUSTRAC.
A conveyancer who is a reporting entity generally needs both documents as part of the same set: the policy, the notice, and a data breach response plan for the sensitive identity and settlement data behind them.
Common questions
Can a privacy policy replace a collection notice?
No, publishing a policy is not by itself notification: APP 1.3 requires the standing policy, APP 5.1 requires reasonable steps to notify the person of the APP 5.2 matters for that collection or otherwise ensure they are aware. The OAIC guidance is conditional, though. At APP guidelines 5.6, "where it is not reasonable to notify or ensure awareness of the full range of APP 5 matters, an entity could alert the individual to specific sections of its APP Privacy Policy". The policy can carry part of the load; it does not remove the APP 5.1 step.
When do I give a collection notice?
At or before the time you collect the person's personal information or, if that is not practicable, as soon as practicable after (APP 5.1). The fallback is conditional on the earlier timing not being practicable, not a free choice. For a conveyancer the collection that matters most is identity and source-of-funds data taken for verification.
Do I need a special collection notice for AML/VOI data?
The law doesn't require a separate document, only that the APP 5.2 matters are right for that collection. The AML/VOI step is where they differ most: 5.2(c) requires you to name the Australian law that requires or authorises the collection, and 5.2(e) the main consequences if it isn't provided. A purpose-built notice for that step is easier to keep accurate than a generic one.
Does my collection notice need to mention my privacy policy?
Yes in substance. APP 5.2(g) and (h) are two of the ten matters: that your privacy policy contains information about how the person may access and correct their information, and about how they may complain and how you will deal with it. APP 5.1 subjects that to reasonable steps in the circumstances, so in practice the notice points to the policy.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: Privacy Act 1988 (Cth), Schedule 1 (APP 1 and APP 5); OAIC, Australian Privacy Principles; OAIC, APP guidelines Chapter 5; OAIC, privacy guidance for reporting entities under the AML/CTF Act; AUSTRAC.