Buyers agent collection notice: the AML-CDD notice you need at engagement
Australian Privacy Principle 5 binds APP entities. A buyers agent brokering a purchase in the course of a business is an AUSTRAC reporting entity, and Privacy Act s 6E(1A) then applies the Act to the AML activities you carry on. So when you collect a buyer-client's identity documents and, where the client is higher-risk, their source-of-funds evidence for AML customer due diligence, APP 5.1 asks you to take such steps as are reasonable in the circumstances to make the person aware of the APP 5.2 matters: in plain terms, who you are, what you are collecting, why you must collect it and what you do with it. The practical time to give it is at buyer's-agency-agreement signing, the moment you start providing the designated service and collect the data.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.
Why a collection notice applies to you now
AML/CTF Act s 6(5A) table 5 item 1 makes "brokering the sale, purchase or transfer of real estate on behalf of a buyer, seller, transferee or transferor in the course of carrying on a business" a designated service, and that table commenced on 31 March 2026, so a buyers agent brokering a purchase in the course of a business has been an AUSTRAC reporting entity since that date. The AML/CTF obligations themselves were deferred to 1 July 2026 and enrolment was fixed at 29 July 2026. Once you are a reporting entity, Privacy Act s 6E(1A) applies the Act to you as if you were an organisation "in relation to the activities carried on ... for the purposes of, or in connection with, activities relating to" the AML/CTF Act, even if your practice turns over less than A$3 million. It is scoped by activity, not by a category of data. Australian Privacy Principle 5 is one of the principles that then applies. Read: does the Privacy Act apply to buyers agents under $3 million?
Scope, stated honestly. s 6E(1A) is scoped by activity, not by data type: it applies the Act in relation to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act. In practice that reaches the customer due diligence you do as a reporting entity and the personal information you handle in doing it, including identity, verification, source-of-funds and beneficial-ownership information. It does not, by that route, reach your general buyer CRM, your newsletter list or your property alerts, so the collection notice this page is about is the one for that AML collection point, not a notice on every web enquiry. Other routes into the Act can still cover your whole practice, including annual turnover over A$3 million, which under s 6D(4)(a) is not undone by a later fall in turnover, and the other limbs of s 6D.
What a collection notice is (and is not)
A collection notice is specific and timely. APP 5.1 puts it on an APP entity: at or before the time it collects personal information about an individual or, if that is not practicable, as soon as practicable after, the entity must take such steps (if any) as are reasonable in the circumstances to notify the individual of the APP 5.2 matters, or to otherwise ensure the individual is aware of them. The after-the-fact timing is the fallback where notifying at or before collection is not practicable, not a free choice. It is not a document that lives on your website. It is the short notice you give the client at the point you take their details.
It is a different document from your privacy policy. The privacy policy (APP 1) is your standing public statement of how your practice handles personal information overall. The collection notice is the point-of-collection heads-up for a particular collection. One does not replace the other, and a buyers agent who is a reporting entity generally needs both. Read: the buyers agent privacy policy, what it must cover
What your collection notice must cover
APP 5.1 requires only such steps, and such of the APP 5.2 matters, as are reasonable in the circumstances. For the AML customer-due-diligence step, the matters it will usually be reasonable to cover are:
- Who you are and how to contact you. Your practice's identity and contact details.
- That you are collecting their information, and the purposes. In plain terms: to verify their identity and, where required, their source of funds, so you can meet your obligations as an AUSTRAC reporting entity and act for them in the purchase.
- That the collection is required or authorised by law. The identity and CDD collection is tied to the AML/CTF Act, not simply something you choose to ask for. Say so, and name the law where you can.
- Who you usually disclose it to. For example your verification or electronic-VOI provider, and, where a reporting obligation arises, AUSTRAC.
- Any overseas disclosure. If any of that data is handled by an overseas-hosted tool or an offshore virtual assistant, note the countries where practicable, because your APP 8 duty travels with it. Read: buyers agents, offshore VAs and cloud tools
- The main consequence if they do not provide it. Plainly, that you may be unable to verify them and therefore unable to act on the purchase.
- That your privacy policy carries the access, correction and complaint information. APP 5.2(g) and (h) are that your APP privacy policy contains information about how the individual may access and seek correction of their personal information, and how they may complain about a breach of the Australian Privacy Principles and how you will deal with that complaint. Pointing the client to the policy is the usual way to cover both.
Keep it short and readable. A collection notice is a heads-up, not a second privacy policy.
Information you collect about other people
APP 5 is not limited to the person in front of you. A buyers agent often collects personal information about people from a third party or from a document: a co-purchaser, a spouse, a guarantor, or the beneficial owners behind a company or trust buyer. Where you collect someone's information from a source other than that person, APP 5 still expects you to take reasonable steps to make them aware of the collection, so your notice, or the way you deliver it, needs to reach those people too, not only the signing client.
The higher-sensitivity data behind the notice
The reason this notice matters more for a buyers agent than for a general business is the data sitting behind it. Your AML collection point can gather identity and verification documents, and, for higher-risk clients under your customer due diligence, source-of-funds and source-of-wealth evidence: bank and savings statements, proof of deposit, borrowing capacity, and the financial picture behind the purchase. This is data you may hold, not every file, but where you do hold it, it is concentrated and sensitive. Collect only what the CDD actually requires (APP 3), and do not repurpose identity or financial data gathered for AML into your marketing (APP 6). Read: VOI and source-of-funds, the privacy rules for identity checks
Notifiability is not a property of the data. Under Privacy Act s 26WE(2) there is an eligible data breach where there is unauthorised access to, or unauthorised disclosure of, personal information, or a loss of it in the circumstances set out in s 26WE(2)(b), and a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals the information relates to, subject to the remedial-action exception in s 26WF. Identity, verification and source-of-funds records are concentrated financial information, which is the kind of material that weighs in that assessment, so the collection notice and a data-breach plan belong to the same set. Read: your data-breach response plan
When to give it: at engagement
The clean answer is at buyer's-agency-agreement signing. AUSTRAC states that "a person acting as a buyer's agent starts providing a designated service to a buyer or transferee when an agreement to find or identify a property is signed", so the service starts before any property is found, and that onboarding moment is also when you collect the identity data (AUSTRAC, real estate designated services). Building the collection notice into your engagement pack, alongside the agency agreement and your privacy policy link, means the APP 5 notice lands at or before the point of collection, which is the primary timing APP 5.1 sets.
The AML interaction to be aware of: tipping-off
There is one wrinkle to know about. AML/CTF Act s 123 makes it an offence for a reporting entity, or its officer, employee or agent, to disclose information covered by s 123(2), which includes that the entity has given, or is required to give, a suspicious matter report under s 41(2), where the disclosure would or could reasonably be expected to prejudice an investigation of a kind listed in s 123(1)(d). The penalty is imprisonment for 2 years or 120 penalty units, or both. So where a specific matter has raised a suspicion, the wording and timing of a notice can matter. That is a point to get professional advice on for the specific case. Privaproof provides general information and does not assess AML/CTF obligations, which are administered by AUSTRAC.
A trust anchor, and where a generic notice falls short
The OAIC publishes a free Template privacy collection notice for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act, which is a sensible reference point and worth reading. What it is not is a notice written for a buyers agent. A generic template names none of your real collection points, tends to describe "a business" rather than a buy-side broker, and does not sit inside a buyers-agent engagement pack alongside the agency agreement and the source-of-funds step. The defensible value is the sector fit and staying current, not a longer document.
Common questions
Do I need a collection notice as well as a privacy policy?
If you are an APP entity, generally yes. Both APP 1 and APP 5 bind APP entities, and for a buyers agent that status usually arrives through being an AUSTRAC reporting entity, which Privacy Act s 6E(1A) uses to apply the Act to your AML activities, or through annual turnover over A$3 million. They then do different jobs. The privacy policy (APP 1.3) is your standing "clearly expressed and up-to-date" public statement about how your practice manages personal information. The collection notice (APP 5) is the short heads-up you give at the point you collect someone's details, most importantly at the AML identity and source-of-funds step. Having one does not satisfy the other.
When do I give the collection notice?
At or before the time you collect the person's personal information. APP 5.1 allows the notice to come as soon as practicable after collection only where notifying at or before that time is not practicable. For a buyers agent the practical time is buyer's-agency-agreement signing, when you onboard the client and collect their identity data.
Does the notice have to be a separate signed form?
No. APP 5 requires you to take reasonable steps to make the person aware of the matters, not to obtain a signature. It can be a short notice in your engagement pack, on a collection form, or in an onboarding email. What matters is that it reaches the person at or around the point of collection and is clear.
What if my client is a company or trust buyer?
You will often collect information about individuals behind the entity, such as beneficial owners or guarantors, sometimes from a document rather than from the person. APP 5 still expects reasonable steps to make those individuals aware of the collection, so plan how your notice reaches them, not only the signing representative.
Does this mean my whole database is now under the Privacy Act?
Not by that route. s 6E(1A) applies the Act to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act, so it reaches your customer due diligence and the personal information you handle in doing it. It does not, by itself, bring your general buyer CRM, newsletter list or property alerts under the Privacy Act. Other routes can, including annual turnover over A$3 million, which under s 6D(4)(a) is not undone by a later fall in turnover, and the other limbs of s 6D. The collection notice this page is about is for the AML collection point.
Where Privaproof fits
Privaproof provides a dedicated, buyers-agent-specific privacy document set: a privacy policy, collection notices including the AML customer-due-diligence notice at engagement, a data-breach response plan and a retention and destruction schedule, written for buy-side broking and kept current as the law changes. Not an AML bolt-on, not a generic download.
→ Get the Buyers-Agent Kit. The complete document set for an Australian buyers agency, A$449 per year including GST, kept current as the privacy rules change. No lock-in.
Keep reading
- Privacy compliance for Australian buyers agents
- The buyers agent privacy policy: what it must cover
- VOI and source-of-funds: the privacy rules for identity checks
- Data-breach response plan for buyers agents
- Buyers agents, offshore VAs and cloud tools: your APP 8 duty
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC. The Privacy Act 1988 (Cth) and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.