Buyers agent collection notice: the AML-CDD notice you need at engagement
When you collect a buyer-client's identity documents and, where the client is higher-risk, their source-of-funds evidence for AML customer due diligence, Australian Privacy Principle 5 requires a collection notice: a short, plain statement of who you are, what you are collecting, why you must collect it and what you do with it. The practical time to give it is at buyer's-agency-agreement signing, the moment the obligation attaches.
By Jon Oates, Founder of Privaproof · Last updated
General information , document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.
Why a collection notice applies to you now
Brokering the purchase of real estate for a buyer-client is a "designated service" under the AML/CTF Act, so from 1 July 2026 a buyers agent who finds, identifies or negotiates a purchase is an AUSTRAC reporting entity. Once that happens, Privacy Act s 6E(1A) switches the Australian Privacy Principles on for the client-identity data you collect for those checks, even if your practice turns over less than A$3 million. Australian Privacy Principle 5 is one of the principles that then applies. Read: does the Privacy Act apply to buyers agents under $3 million?
Scope, stated honestly. s 6E(1A) reaches the AML customer-due-diligence data: the identity, verification, source-of-funds and beneficial-ownership information you collect to meet your AML obligations. It does not pull your general buyer CRM, your newsletter list or your property alerts under the Privacy Act, so the collection notice this page is about is the one for that AML collection point, not a notice on every web enquiry.
What a collection notice is (and is not)
A collection notice is specific and timely. Under APP 5, at or before the time you collect a person's personal information, or as soon as practicable afterwards, you take reasonable steps to make them aware of certain things about that collection. It is not a document that lives on your website. It is the short notice you give the client at the point you take their details.
It is a different document from your privacy policy. The privacy policy (APP 1) is your standing public statement of how your practice handles personal information overall. The collection notice is the point-of-collection heads-up for a particular collection. One does not replace the other, and a buyers agent who is a reporting entity generally needs both. Read: the buyers agent privacy policy, what it must cover
What your collection notice must cover
For the AML customer-due-diligence step, a collection notice should make the client aware of, at a minimum:
- Who you are and how to contact you. Your practice's identity and contact details.
- That you are collecting their information, and the purposes. In plain terms: to verify their identity and, where required, their source of funds, so you can meet your obligations as an AUSTRAC reporting entity and act for them in the purchase.
- That the collection is required or authorised by law. The identity and CDD collection is tied to the AML/CTF Act, not simply something you choose to ask for. Say so, and name the law where you can.
- Who you usually disclose it to. For example your verification or electronic-VOI provider, and, where a reporting obligation arises, AUSTRAC.
- Any overseas disclosure. If any of that data is handled by an overseas-hosted tool or an offshore virtual assistant, note the countries where practicable, because your APP 8 duty travels with it. Read: buyers agents, offshore VAs and cloud tools
- The main consequence if they do not provide it. Plainly, that you may be unable to verify them and therefore unable to act on the purchase.
- Where to find your privacy policy. So they can see how to access or correct their information and how to make a complaint. APP 5 expects the notice to point to that.
Keep it short and readable. A collection notice is a heads-up, not a second privacy policy.
Information you collect about other people
APP 5 is not limited to the person in front of you. A buyers agent often collects personal information about people from a third party or from a document: a co-purchaser, a spouse, a guarantor, or the beneficial owners behind a company or trust buyer. Where you collect someone's information from a source other than that person, APP 5 still expects you to take reasonable steps to make them aware of the collection, so your notice, or the way you deliver it, needs to reach those people too, not only the signing client.
The higher-sensitivity data behind the notice
The reason this notice matters more for a buyers agent than for a general business is the data sitting behind it. Your AML collection point can gather identity and verification documents, and, for higher-risk clients under your customer due diligence, source-of-funds and source-of-wealth evidence: bank and savings statements, proof of deposit, borrowing capacity, and the financial picture behind the purchase. This is data you may hold, not every file, but where you do hold it, it is concentrated and sensitive. Collect only what the CDD actually requires (APP 3), and do not repurpose identity or financial data gathered for AML into your marketing (APP 6). Read: VOI and source-of-funds, the privacy rules for identity checks
Because those records are few, deep and often high-net-worth, a breach of them is very likely to cause serious harm, which is what makes it notifiable. The collection notice and a data-breach plan are part of the same set. Read: your data-breach response plan
When to give it: at engagement
The clean answer is at buyer's-agency-agreement signing. Your obligation to provide the designated service starts when the client signs the agreement to find or identify a property, before any property is found, and that onboarding moment is also when you collect the identity data. Building the collection notice into your engagement pack, alongside the agency agreement and your privacy policy link, means the APP 5 notice lands at or before the point of collection, which is what the principle asks.
The AML interaction to be aware of: tipping-off
There is one wrinkle to know about. The AML/CTF regime includes "tipping-off" rules, and a collection notice must not be worded or timed so as to reveal that a suspicious matter has been, or may be, reported. In the ordinary course this rarely bites, but where a specific matter raises a suspicion, it can affect what you say and when. That is a point to get professional advice on for the specific case. Privaproof provides general information and does not assess AML/CTF obligations, which are administered by AUSTRAC.
A trust anchor, and where a generic notice falls short
The OAIC publishes a free "Template privacy collection notice for reporting entities under the AML/CTF Act", which is a sensible reference point and worth reading. What it is not is a notice written for a buyers agent. A generic template names none of your real collection points, tends to describe "a business" rather than a buy-side broker, and does not sit inside a buyers-agent engagement pack alongside the agency agreement and the source-of-funds step. The defensible value is the sector fit and staying current, not a longer document.
Common questions
Do I need a collection notice as well as a privacy policy?
Generally yes. They do different jobs. The privacy policy (APP 1) is your standing public statement of how you handle personal information overall. The collection notice (APP 5) is the short heads-up you give at the point you collect someone's details, most importantly at the AML identity and source-of-funds step. Having one does not satisfy the other.
When do I give the collection notice?
At or before the time you collect the person's personal information, or as soon as practicable afterwards. For a buyers agent the practical time is buyer's-agency-agreement signing, when you onboard the client and collect their identity data.
Does the notice have to be a separate signed form?
No. APP 5 requires you to take reasonable steps to make the person aware of the matters, not to obtain a signature. It can be a short notice in your engagement pack, on a collection form, or in an onboarding email. What matters is that it reaches the person at or around the point of collection and is clear.
What if my client is a company or trust buyer?
You will often collect information about individuals behind the entity, such as beneficial owners or guarantors, sometimes from a document rather than from the person. APP 5 still expects reasonable steps to make those individuals aware of the collection, so plan how your notice reaches them, not only the signing representative.
Does this mean my whole database is now under the Privacy Act?
No. s 6E(1A) carves in the AML customer-due-diligence identity data you collect as a reporting entity. It does not pull your general buyer CRM, newsletter list or property alerts under the Privacy Act by that route. The collection notice this page is about is for the AML collection point.
Where Privaproof fits
Privaproof is building a dedicated, buyers-agent-specific privacy document set: a privacy policy, collection notices including the AML customer-due-diligence notice at engagement, a data-breach response plan and a retention and destruction schedule, written for buy-side broking and kept current as the law changes. Not an AML bolt-on, not a generic download.
→ Join the founding list. Be first to know when the Buyers-Agent Kit opens, and get the plain-English updates as the 2026 changes land. No cost, no obligation.
Keep reading
- Privacy compliance for Australian buyers agents
- The buyers agent privacy policy: what it must cover
- VOI and source-of-funds: the privacy rules for identity checks
- Data-breach response plan for buyers agents
- Buyers agents, offshore VAs and cloud tools: your APP 8 duty
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. Privaproof's buyers-agent documents are self-authored and are not independently reviewed by a solicitor. This page does not assess your obligations under the AML/CTF Act, which are administered by AUSTRAC. The Privacy Act 1988 (Cth) and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.