VOI and source-of-funds: the privacy rules for buyers agent identity checks
The identity documents and source-of-funds evidence you collect to verify a buyer under AML customer due diligence are personal information. Once you are an AUSTRAC reporting entity, Privacy Act s 6E(1A) brings that data under the Australian Privacy Principles. In practice that means collecting only what the check reasonably requires, securing it, using it only for the AML purpose, and not repurposing it for your marketing.
By Jon Oates, Founder of Privaproof · Last updated
General information , document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.
What VOI and source-of-funds actually mean here
Verification of identity (VOI) is the step where you confirm a client is who they say they are, usually from a driver licence, passport or other government-issued document. Source-of-funds evidence goes further: it shows where the money for the purchase came from, from bank and savings statements, a mortgage pre-approval, proof of deposit, a gift letter or a sale of another asset.
The two are not collected in the same volume. You verify identity for essentially every client you act for. Source-of-funds and source-of-wealth evidence is a customer-due-diligence step you reach for when a client is higher-risk, so treat it as data you may hold on some files, not something on every file. Both, when you do hold them, are personal information about an identifiable individual.
How this data comes under the Privacy Act: s 6E(1A)
Most boutique buyers agents turn over under A$3 million and have relied on the small-business exemption in s 6D, which meant the Australian Privacy Principles did not apply. Becoming an AML reporting entity changes that for one defined slice of your data. Because brokering the purchase of real estate is a designated service (Table 5 item 1, AML/CTF Act s 6(5A)), you become a reporting entity from 1 July 2026, and Privacy Act s 6E(1A) then treats you as an organisation for your AML activities. The identity, verification and source-of-funds data you collect for customer due diligence comes under the APPs regardless of turnover.
Scope, stated honestly: s 6E(1A) reaches the AML/KYC customer-due-diligence data, and only that data. It does not pull your general buyer CRM, your newsletter list, your property alerts or your web enquiries into the Privacy Act. So the rules below apply to the VOI and source-of-funds material specifically, not to your whole practice. Read: does becoming an AML reporting entity trigger the Privacy Act?
Collect only what the check reasonably requires (APP 3)
APP 3 limits you to collecting personal information that is reasonably necessary for your functions. For a buyers agent that means matching what you collect to what the customer-due-diligence check actually calls for, rather than sweeping up more than you need because it is easy to ask.
A few practical consequences follow. You generally do not need to keep a full colour copy of every identity document when the check can be satisfied by recording the verification and the document's key details. You collect source-of-funds evidence when the client's risk rating calls for it, not as a default on every engagement. And when a document reveals more than you need, you take only the part the check requires.
Tell the client why you are collecting it (APP 5)
APP 5 requires you to notify the client, at or around the time you collect their information, why you are collecting it, what you will do with it and who you may give it to. For VOI and source-of-funds data, the natural moment is when the buyer's-agency agreement is signed, which is also when the AML obligation attaches. A collection notice at that point sets the expectation that this financial and identity material is being gathered for the anti-money-laundering check, not for general marketing. Read: the collection notice you need at engagement
Use it for the AML purpose, not for marketing (APP 6)
APP 6 limits how you may use and disclose personal information to the purpose you collected it for, plus purposes the client would reasonably expect that are related to it. Source-of-funds and financial-capacity data collected for customer due diligence sits at the strict end of that test. A client hands over bank statements to satisfy an identity and funds check, not so they can be mined to pitch other services or shared with a mortgage broker or developer. Using AML data for marketing, or passing it to a third party the client did not expect, is where a use-and-disclosure problem arises.
Two related points. Government-related identifiers such as a driver licence or passport number carry their own limits under APP 9 on how you adopt, use and disclose them, so do not turn a licence number into your own internal client reference. And the buyer brief you build alongside the checks often carries sensitive personal context, a relocation, a divorce, an inheritance, an SMSF purchase, which deserves the same care even where it is not "sensitive information" in the Act's technical sense.
Secure it, because it is concentrated and high-value (APP 11)
APP 11 requires reasonable steps to protect the information you hold from misuse, loss and unauthorised access or disclosure. This is the principle that bites hardest for a buyers agent, because you hold few files but each one is deep: identity documents, financial-capacity evidence and, on higher-risk files, source-of-funds material, all on high-net-worth clients. A breach of that concentration is very likely to cause serious harm, which is exactly the test that makes it notifiable under the data-breach scheme. Access controls, encryption, and not leaving identity scans in an email inbox or a shared drive are the everyday version of APP 11. Read: your data-breach response plan
APP 11 also has a second limb: once you no longer need the information, you take reasonable steps to destroy or de-identify it. That runs straight into the AML rule that requires you to keep customer-due-diligence records for seven years, so the two have to be reconciled in a retention schedule rather than left to collide. Read: how long must a buyers agent keep client records?
If any of this identity or funds data is handled by an offshore virtual assistant or an overseas-hosted cloud tool, APP 8 adds a separate overseas-disclosure duty. Read: offshore VAs and cloud tools, your APP 8 duty
From 10 December 2026: automated ID and sanctions screening
If you run VOI, PEP or sanctions checks through automated tools, a transparency rule commences on 10 December 2026. From that date, APP 1.7 expects your privacy policy to disclose where automated decision-making significantly affects a person's rights or interests. Whether it applies to your screening is fact-specific, but if a tool's output materially drives whether you take a client on, it is worth flagging in your policy rather than discovering the gap later. Read the cornerstone: privacy compliance for Australian buyers agents
Common questions
Do I have to keep a copy of every client's driver licence?
Not necessarily. APP 3 limits you to what the check reasonably requires, and the AML customer-due-diligence rules set what you must verify and record. Often that can be satisfied by recording the verification and the document's key details rather than storing full colour scans of every ID indefinitely. Collect and retain what the check needs, secure it under APP 11, and dispose of it in line with your retention schedule.
Can I use a client's bank statements or source-of-funds evidence for anything else?
No, not without care. APP 6 limits you to the purpose you collected it for, which is the AML check, plus closely related purposes the client would reasonably expect. Source-of-funds and financial-capacity evidence should not be repurposed for marketing, cross-sold to a broker or developer, or shared with a third party the client did not anticipate.
Is a passport or driver licence "sensitive information" under the Privacy Act?
Not automatically. "Sensitive information" is a defined category in the Act (health, biometric, racial or political information and a few others). An identity document is personal information and, in the case of a licence or passport number, a government-related identifier with its own limits under APP 9, but it is not sensitive information simply because it verifies identity. It still deserves strong security either way.
Does this mean my whole client database is now under the Privacy Act?
No. s 6E(1A) reaches the AML/KYC customer-due-diligence data, and only that data. Your general buyer CRM, newsletter list and property alerts stay outside that route unless a separate trigger applies. The rules on this page are about the VOI and source-of-funds material specifically.
Am I even a reporting entity if I only research and advise?
It depends on what you actually do. Brokering the purchase of a property for a fee is the caught activity, and a buyers agency retained to acquire property is doing it. A genuinely advice-only or research-only service that never finds a specific property and never negotiates may fall outside the brokering definition, but that is fact-specific, so confirm your own position rather than assuming either way. Read: advice-only or research-only buyers agent, are you caught?
This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC. Privaproof's buyers-agent documents are self-authored and are not independently reviewed by a solicitor. The Privacy Act 1988 (Cth) and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.