Skip to content

How long must a buyers agent keep client records? AML 7 years vs APP 11.2

Two rules pull in opposite directions, and both apply once you are a reporting entity. AML/CTF makes you keep your customer due-diligence records for seven years. Privacy Act APP 11.2 makes you destroy or de-identify personal information once you no longer need it. The answer is not to pick one: you hold the AML records for the required period, then dispose of them, and a written retention schedule is how you prove you did both.

By Jon Oates, Founder of Privaproof · Last updated

General information , document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.

The two rules, side by side

Once you broker property purchases you become an AUSTRAC reporting entity from 1 July 2026, and the AML/CTF regime requires you to keep records of the customer due diligence you perform, your identity verification, source-of-funds checks and the like, for seven years . That is a floor. It is there so AUSTRAC and law enforcement can look back at who you verified and how.

At the same time, becoming a reporting entity switches on the Privacy Act for that same identity data through s 6E(1A), and the Privacy Act pulls the other way. APP 11.2 says that where personal information is no longer needed for any purpose you are permitted to use it for, you must take reasonable steps to destroy it or de-identify it. Left alone, that looks like a conflict: one law says keep, the other says delete.

Why there is no real conflict

APP 11.2 does not force you to delete something you are legally required to retain. Its duty to destroy or de-identify does not apply where you are required by an Australian law, or by a court or tribunal order, to keep the information. AML/CTF record-keeping is exactly that kind of legal requirement. So while you are inside the seven-year AML window, holding the customer due-diligence records is not an APP 11.2 breach, it is compliance with the other law.

The reconciliation is a sequence, not a standoff:

The trap is the data APP 11.2 was written for: everything you hold that AML never required you to keep, or that you have held long past its purpose.

The data AML never told you to keep

Your seven-year duty covers the identity and due-diligence records tied to the designated service, which is brokering the purchase of real estate for a buyer (Table 5 item 1, AML/CTF Act s 6(5A)). It does not cover everything in your files. A buyers agent accumulates a lot of personal information that AML/CTF never required and that s 6E(1A) never caught:

None of that is on the AML seven-year clock. For that data, APP 11.2 is the live rule, and the honest position is that most of it should be destroyed or de-identified once your work is finished and you have no ongoing reason to hold it. Keeping everything forever "just in case" is the pattern APP 11.2 is designed to stop, and it is also what turns a breach into a bigger one. Read: your data-breach response plan

Keep the scope honest

Two limits matter here. First, s 6E(1A) catches the AML/KYC identity data, not your whole practice. Your general buyer CRM, newsletter list and property alerts are not pulled under the Privacy Act by the s 6E(1A) route, so do not treat your entire database as if it were reporting-entity data. Second, a general removal of the A$3 million small-business exemption has been proposed as a future reform but is not yet law, so the APP 11.2 duty reaches your non-AML personal information only if a separate trigger makes you an APP entity. For most boutique buyers agents today, the clean reading is: AML data on the seven-year clock, other personal information handled under good-practice destruction habits, and the two written down so you can show your reasoning.

What a retention schedule actually does

A retention and destruction schedule is the one document that makes both rules auditable. For a buyers agent it should, at a minimum:

1. List the record types you hold, separating AML customer due-diligence records from everything else. 2. Set a retention period against each type, with the AML records held for the required period and non-AML personal information held only for as long as you have a purpose. 3. Name a disposal method, secure deletion for digital files and secure destruction for paper, plus de-identification where you want to keep aggregate data without the personal detail. 4. Record who is responsible and when the review happens, so disposal is a scheduled task, not something that never gets done.

This is the retention and destruction piece the AML doc packs leave out. An AML pack tells you to keep records for seven years. It does not give you the APP 11.2 side, the trigger to dispose, the treatment of the non-AML data, or the schedule that reconciles the two. That reconciliation is part of what a buyers-agent privacy set is for. Read: AML kit vs privacy kit, what your AML pack leaves out

So, how long do you keep client records?

Keep your AML customer due-diligence records for the seven-year period the AML/CTF regime requires. That retention does not breach APP 11.2, because you are keeping them under another law. Once that period ends, and for any personal information AML never required you to keep, APP 11.2 expects you to destroy or de-identify what you no longer need. Write it into a retention and destruction schedule so both obligations are covered and evidenced. Read the cornerstone: privacy compliance for Australian buyers agents

Common questions

Do I have to delete a client's identity records after the job settles?

Not while you are inside the AML retention period. AML/CTF requires you to keep your customer due-diligence records for seven years, and APP 11.2 does not force you to destroy information you are legally required to retain. Once that period ends and you have no other purpose for the data, APP 11.2 then expects you to destroy or de-identify it.

Does APP 11.2 conflict with the AML seven-year rule?

No. APP 11.2's duty to destroy or de-identify personal information does not apply where an Australian law requires you to keep it. AML/CTF record-keeping is that kind of requirement, so holding the records for the mandated period is compliance, not a breach. The two rules run in sequence: retain, then dispose.

What about my general CRM, enquiries and buyer briefs?

Those are not on the AML seven-year clock. For personal information AML never required you to keep, APP 11.2 is the live rule, so you should destroy or de-identify it once you no longer have a purpose for holding it. That is exactly the data a retention schedule is meant to catch.

Is a general removal of the $3 million exemption forcing me to keep or delete more?

A general removal of the small-business exemption has been proposed as a future reform, but it is not yet law. Today the Privacy Act reaches your AML/KYC identity data through s 6E(1A), not your whole practice, so treat blanket claims about the exemption being gone with caution.


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, including its record-keeping periods, which are administered by AUSTRAC. Privaproof's buyers-agent documents are self-authored and are not independently reviewed by a solicitor. The Privacy Act 1988 (Cth) and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.