How long must a buyers agent keep client records? AML 7 years vs APP 11.2
Two rules pull in opposite directions once you are a reporting entity. The AML/CTF Act makes you keep records for seven years, and the seven years runs from a different point under each limb: s 107(3) from the day the record is made, s 108(2) from the giving of the document, s 111(2) from the end of the business relationship. Privacy Act APP 11.2 makes you take reasonable steps to destroy or de-identify personal information you no longer need, but only where no Australian law requires you to keep it (APP 11.2(d)). The answer is not to pick one: you hold the AML records for their own periods, then dispose of them, and a written retention schedule is how you prove you did both.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.
The two rules, side by side
Once you broker property purchases you become an AUSTRAC reporting entity (designated-service status began 31 March 2026), and since 1 July 2026 the record-keeping Divisions of Part 10 have applied to you, so you keep records of the customer due diligence you perform, your identity verification, source-of-funds checks and the like, for seven years. The period is seven years in each case, but three different provisions start the clock at three different points, and collapsing them into a single "seven-year floor" is the common error. Section 107(3) covers the records that allow individual transactions to be reconstructed, and runs "for a period of 7 years beginning on the day the record is made". Section 108(2) covers a document the client gave you, and runs the seven years "after the giving of the document". Section 111(2) covers your customer due diligence records, and runs "until the end of the 7 year period that begins when the business relationship ends or the reporting entity completes the provision of the occasional transaction". Each is a floor. They are there so AUSTRAC and law enforcement can look back at who you verified and how.
At the same time, becoming a reporting entity switches the Privacy Act on through s 6E(1A), which applies the Act "in relation to the activities carried on by the small business operator for the purposes of, or in connection with, activities relating to" the AML/CTF Act. That is an activity test, not a list of documents, and it reaches the personal information you handle in carrying those activities on. The Privacy Act then pulls the other way. APP 11.2 says that where an APP entity holds personal information it no longer needs for any purpose it may use or disclose it for, the entity must take such steps as are reasonable in the circumstances to destroy it or ensure it is de-identified. Left alone, that looks like a conflict: one law says keep, the other says delete.
Why there is no real conflict
APP 11.2 does not force you to delete something you are legally required to retain, and it says so on its face. The destruction duty is conditional, and one of those conditions, APP 11.2(d), is that "the entity is not required by or under an Australian law, or a court/tribunal order, to retain the information". AML/CTF record-keeping is exactly that kind of legal requirement. So while an AML retention period is still running, holding those records is not an APP 11.2 breach, it is compliance with the other law.
The reconciliation is a sequence, not a standoff:
- During the AML retention period: keep the customer due-diligence records. APP 11.2's destroy-when-no-longer-needed duty is suspended for that data because another law requires you to hold it.
- When the AML period ends: you are no longer required by an Australian law to retain them, so the APP 11.2(d) carve-out stops applying. If you have no other permitted purpose for the personal information, APP 11.2 requires you to take such steps as are reasonable in the circumstances to destroy it or ensure it is de-identified.
The trap is the data APP 11.2 was written for: everything you hold that AML never required you to keep, or that you have held long past its purpose.
The data AML never told you to keep
Your seven-year duty covers the transaction and due-diligence records tied to the designated service, which is "brokering the sale, purchase or transfer of real estate on behalf of a buyer, seller, transferee or transferor in the course of carrying on a business" (Table 5 item 1, AML/CTF Act s 6(5A)). It does not cover everything in your files. A buyers agent accumulates a lot of personal information that AML/CTF never required you to keep, and that you do not handle in carrying on the AML/CTF activities s 6E(1A) reaches:
- The buyer brief and search notes, which can carry sensitive context such as a relocation, a divorce, an inheritance or an SMSF purchase.
- Financial-capacity evidence you collected to shortlist and negotiate, such as pre-approval letters and statements, beyond what your due diligence strictly required you to verify and keep.
- Old enquiries and cold leads who never engaged you, sitting in your CRM.
- Losing-bid and withdrawn-purchase files where the deal never proceeded.
None of that is on an AML clock. For that data, APP 11.2 is the live rule wherever you are an APP entity, and what it points to is that personal information you no longer have a permitted purpose for should be destroyed or de-identified once your work is finished. Keeping everything forever "just in case" is the pattern APP 11.2 is written against, and it also widens the set of personal information exposed in a breach. Read: your data-breach response plan
Keep the scope honest
Two limits matter here. First, s 6E(1A) is scoped to the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act, not to your whole practice. Your general buyer CRM, newsletter list and property alerts are not pulled under the Privacy Act by the s 6E(1A) route alone, so do not treat your entire database as if it were reporting-entity data. Second, a general removal of the A$3 million small-business exemption has been proposed as a future reform but is not yet law, so the APP 11.2 duty reaches your non-AML personal information only where a separate trigger makes you an APP entity, such as one of the exits in s 6D(4)(a) to (f), s 6D(9), or the s 6EA opt-in. Note that the turnover exit is a one-way ratchet: s 6D(4)(a) bites once a business "has had an annual turnover of more than $3,000,000 for a financial year that has ended", so a later fall in turnover does not put you back inside the exemption. Where no separate trigger reaches the rest of your files, the clean reading is: AML records on their own statutory clocks, other personal information handled under good-practice destruction habits, and the two written down so you can show your reasoning.
What a retention schedule actually does
A retention and destruction schedule is the one document that makes both rules auditable. For a buyers agent it should, at a minimum:
- 1. List the record types you hold, separating AML customer due-diligence records from everything else.
- 2. Set a retention period against each type, with the AML records held for the required period and non-AML personal information held only for as long as you have a purpose.
- 3. Name a disposal method, secure deletion for digital files and secure destruction for paper, plus de-identification where you want to keep aggregate data without the personal detail.
- 4. Record who is responsible and when the review happens, so disposal is a scheduled task, not something that never gets done.
This is the retention and destruction piece the AML doc packs leave out. An AML pack tells you to keep records for seven years. It does not give you the APP 11.2 side, the trigger to dispose, the treatment of the non-AML data, or the schedule that reconciles the two. That reconciliation is part of what a buyers-agent privacy set is for. Read: AML kit vs privacy kit, what your AML pack leaves out
So, how long do you keep client records?
Keep your AML records for seven years, and diary the right start date against each type: s 107(3) runs from the day the record is made, s 108(2) from the day the client gave you the document, and s 111(2) from the end of the business relationship. That retention does not breach APP 11.2, because APP 11.2(d) switches the destruction duty off while an Australian law requires you to retain the information. Once a period ends, and for any personal information AML never required you to keep, APP 11.2 requires reasonable steps to destroy or de-identify what you no longer need. Write it into a retention and destruction schedule so both obligations are covered and evidenced. Read the cornerstone: privacy compliance for Australian buyers agents
The reversal: how the document reached you changes the answer
⚠️ There is one case where the usual "don't keep more than you need" advice runs backwards, and it arises wherever onboarding runs by email. Clients email you things. Pre-approval letters, bank statements, a photo of a licence, proof of deposit. The Act treats a document the client sent you differently from one you looked at and made a note about.
If you sighted it and recorded the particulars, s 111(3)(a) asks for records demonstrating "the type and content of the data collected". The image itself is not required.
If the client sent it to you, s 108 can apply, but only where two things are true: "a document relating to the provision, or prospective provision, of a designated service by a reporting entity is given to the reporting entity by or on behalf of the customer concerned" (s 108(1)(a)), and "the reporting entity commences, or has commenced, to provide the service to the customer" (s 108(1)(b)). ⛔ So it is not simply "anything a client emails you": an attachment sent during an enquiry that never becomes an engagement does not meet the second limb. Where both are met, s 108(2) requires you to retain "(a) the document; or (b) a copy of the document; for 7 years after the giving of the document". Section 108(3) makes that a civil penalty provision.
| How it reached you | What the Act requires |
|---|---|
| You sighted it and noted the particulars | s 111: records of the type and content of the data collected. The image is not required |
| The client emailed it to you, it relates to the designated service, and the engagement proceeds | s 108: retain the document, or a copy, for 7 years from when they gave it to you |
| The client emailed it during an enquiry that never became an engagement | Neither. s 108(1)(b) is not met, so the ordinary "keep only what you need" position applies |
So the practical rule is about what arrives, not what you decide afterwards. Once you have commenced the service for that client, deleting their emailed bank statement as tidy-up runs against s 108(2). Tell clients what to send before they send it.
⚠️ Two limits. Both sections bind a reporting entity, so this reaches you only where you are providing a designated service. And s 108 is headed "Customer-provided transaction documents to be retained" and sits in the Division dealing with records of transactions, while customer due diligence records sit in a separate Division, which supports reading it as aimed at service and transaction documents. The words of s 108(1) are not expressly confined to them, but we have not identified any AUSTRAC guidance, explanatory memorandum or decided case addressing a client-emailed identity or financial document specifically. Get your own advice before destroying anything a client sent you.
Common questions
Do I have to delete a client's identity records after the job settles?
Not while you are inside the AML retention period. Section 111(2) of the AML/CTF Act requires your customer due diligence records to be kept until the end of the seven year period that begins when the business relationship ends, and APP 11.2(d) means the Privacy Act does not force you to destroy information an Australian law requires you to retain. Once that period ends and you have no other purpose for the data, APP 11.2 requires you to take reasonable steps to destroy or de-identify it.
Does APP 11.2 conflict with the AML seven-year rule?
No. APP 11.2's duty to destroy or de-identify personal information does not apply where an Australian law requires you to keep it. AML/CTF record-keeping is that kind of requirement, so holding the records for the mandated period is compliance, not a breach. The two rules run in sequence: retain, then dispose.
What about my general CRM, enquiries and buyer briefs?
Those are not on an AML clock. For personal information AML never required you to keep, APP 11.2 is the live rule wherever you are an APP entity, so take reasonable steps to destroy or de-identify it once you no longer have a purpose for holding it. That is exactly the data a retention schedule is meant to catch.
Is a general removal of the $3 million exemption forcing me to keep or delete more?
A general removal of the small-business exemption has been proposed as a future reform, but it is not yet law. Section 6E(1A) reaches the activities you carry on for the purposes of, or in connection with, activities relating to the AML/CTF Act, not your whole practice, and the s 6D exemption otherwise stands as written, with the exits Parliament already put in it (s 6D(4)(a) to (f), s 6D(9) and the s 6EA opt-in). Treat blanket claims about the exemption being gone with caution.
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, including its record-keeping periods, which are administered by AUSTRAC. The Privacy Act 1988 (Cth) and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.