Skip to content

Buyers agent collection notice: the AML-CDD notice you need at engagement

When you collect a buyer-client's identity documents and, where the client is higher-risk, their source-of-funds evidence for AML customer due diligence, Australian Privacy Principle 5 requires a collection notice: a short, plain statement of who you are, what you are collecting, why you must collect it and what you do with it. The practical time to give it is at buyer's-agency-agreement signing, the moment the obligation attaches.

By Jon Oates, Founder of Privaproof · Last updated

General information , document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.

Why a collection notice applies to you now

Brokering the purchase of real estate for a buyer-client is a "designated service" under the AML/CTF Act, so from 1 July 2026 a buyers agent who finds, identifies or negotiates a purchase is an AUSTRAC reporting entity. Once that happens, Privacy Act s 6E(1A) switches the Australian Privacy Principles on for the client-identity data you collect for those checks, even if your practice turns over less than A$3 million. Australian Privacy Principle 5 is one of the principles that then applies. Read: does the Privacy Act apply to buyers agents under $3 million?

Scope, stated honestly. s 6E(1A) reaches the AML customer-due-diligence data: the identity, verification, source-of-funds and beneficial-ownership information you collect to meet your AML obligations. It does not pull your general buyer CRM, your newsletter list or your property alerts under the Privacy Act, so the collection notice this page is about is the one for that AML collection point, not a notice on every web enquiry.

What a collection notice is (and is not)

A collection notice is specific and timely. Under APP 5, at or before the time you collect a person's personal information, or as soon as practicable afterwards, you take reasonable steps to make them aware of certain things about that collection. It is not a document that lives on your website. It is the short notice you give the client at the point you take their details.

It is a different document from your privacy policy. The privacy policy (APP 1) is your standing public statement of how your practice handles personal information overall. The collection notice is the point-of-collection heads-up for a particular collection. One does not replace the other, and a buyers agent who is a reporting entity generally needs both. Read: the buyers agent privacy policy, what it must cover

What your collection notice must cover

For the AML customer-due-diligence step, a collection notice should make the client aware of, at a minimum:

Keep it short and readable. A collection notice is a heads-up, not a second privacy policy.

Information you collect about other people

APP 5 is not limited to the person in front of you. A buyers agent often collects personal information about people from a third party or from a document: a co-purchaser, a spouse, a guarantor, or the beneficial owners behind a company or trust buyer. Where you collect someone's information from a source other than that person, APP 5 still expects you to take reasonable steps to make them aware of the collection, so your notice, or the way you deliver it, needs to reach those people too, not only the signing client.

The higher-sensitivity data behind the notice

The reason this notice matters more for a buyers agent than for a general business is the data sitting behind it. Your AML collection point can gather identity and verification documents, and, for higher-risk clients under your customer due diligence, source-of-funds and source-of-wealth evidence: bank and savings statements, proof of deposit, borrowing capacity, and the financial picture behind the purchase. This is data you may hold, not every file, but where you do hold it, it is concentrated and sensitive. Collect only what the CDD actually requires (APP 3), and do not repurpose identity or financial data gathered for AML into your marketing (APP 6). Read: VOI and source-of-funds, the privacy rules for identity checks

Because those records are few, deep and often high-net-worth, a breach of them is very likely to cause serious harm, which is what makes it notifiable. The collection notice and a data-breach plan are part of the same set. Read: your data-breach response plan

When to give it: at engagement

The clean answer is at buyer's-agency-agreement signing. Your obligation to provide the designated service starts when the client signs the agreement to find or identify a property, before any property is found, and that onboarding moment is also when you collect the identity data. Building the collection notice into your engagement pack, alongside the agency agreement and your privacy policy link, means the APP 5 notice lands at or before the point of collection, which is what the principle asks.

The AML interaction to be aware of: tipping-off

There is one wrinkle to know about. The AML/CTF regime includes "tipping-off" rules, and a collection notice must not be worded or timed so as to reveal that a suspicious matter has been, or may be, reported. In the ordinary course this rarely bites, but where a specific matter raises a suspicion, it can affect what you say and when. That is a point to get professional advice on for the specific case. Privaproof provides general information and does not assess AML/CTF obligations, which are administered by AUSTRAC.

A trust anchor, and where a generic notice falls short

The OAIC publishes a free "Template privacy collection notice for reporting entities under the AML/CTF Act", which is a sensible reference point and worth reading. What it is not is a notice written for a buyers agent. A generic template names none of your real collection points, tends to describe "a business" rather than a buy-side broker, and does not sit inside a buyers-agent engagement pack alongside the agency agreement and the source-of-funds step. The defensible value is the sector fit and staying current, not a longer document.

Common questions

Do I need a collection notice as well as a privacy policy?

Generally yes. They do different jobs. The privacy policy (APP 1) is your standing public statement of how you handle personal information overall. The collection notice (APP 5) is the short heads-up you give at the point you collect someone's details, most importantly at the AML identity and source-of-funds step. Having one does not satisfy the other.

When do I give the collection notice?

At or before the time you collect the person's personal information, or as soon as practicable afterwards. For a buyers agent the practical time is buyer's-agency-agreement signing, when you onboard the client and collect their identity data.

Does the notice have to be a separate signed form?

No. APP 5 requires you to take reasonable steps to make the person aware of the matters, not to obtain a signature. It can be a short notice in your engagement pack, on a collection form, or in an onboarding email. What matters is that it reaches the person at or around the point of collection and is clear.

What if my client is a company or trust buyer?

You will often collect information about individuals behind the entity, such as beneficial owners or guarantors, sometimes from a document rather than from the person. APP 5 still expects reasonable steps to make those individuals aware of the collection, so plan how your notice reaches them, not only the signing representative.

Does this mean my whole database is now under the Privacy Act?

No. s 6E(1A) carves in the AML customer-due-diligence identity data you collect as a reporting entity. It does not pull your general buyer CRM, newsletter list or property alerts under the Privacy Act by that route. The collection notice this page is about is for the AML collection point.

Where Privaproof fits

Privaproof is building a dedicated, buyers-agent-specific privacy document set: a privacy policy, collection notices including the AML customer-due-diligence notice at engagement, a data-breach response plan and a retention and destruction schedule, written for buy-side broking and kept current as the law changes. Not an AML bolt-on, not a generic download.

→ Join the founding list. Be first to know when the Buyers-Agent Kit opens, and get the plain-English updates as the 2026 changes land. No cost, no obligation.

Keep reading


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Privaproof's buyers-agent documents are self-authored and are not independently reviewed by a solicitor. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC. The Privacy Act 1988 (Cth) and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.