Skip to content

VOI and source-of-funds: the privacy rules for buyers agent identity checks

The identity documents and source-of-funds evidence you collect to verify a buyer under AML customer due diligence are personal information. Once you are an AUSTRAC reporting entity, Privacy Act s 6E(1A) applies the Act to you as if you were an organisation in relation to your AML-related activities, which brings that material under the Australian Privacy Principles whatever your turnover. In practice that means collecting only what the check reasonably requires, securing it, keeping it to the purpose you collected it for and to closely related purposes the client would reasonably expect, and not repurposing it for your marketing.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice and does not assess your AML/CTF obligations, which are administered by AUSTRAC.

What VOI and source-of-funds actually mean here

"VOI" is the identity-check language of conveyancing practice, and it is worth keeping it apart from the obligation that actually binds a buyers agent. That obligation is initial customer due diligence under the AML/CTF Act: s 28(1) says a reporting entity "must not commence to provide a designated service to a customer" without having established the matters in s 28(2) on reasonable grounds, the first of which is "the identity of the customer". Source-of-funds evidence is a further matter again, showing where the money for the purchase came from, which in practice can mean bank and savings statements, a mortgage pre-approval, proof of deposit, a gift letter or the sale of another asset. Those are examples of what firms use, not a prescribed list: neither the Act nor the AML/CTF Rules names documents you must obtain. Section 28(3)(c) and (d) instead require you to collect KYC information "appropriate to the ML/TF risk of the customer" and to verify it "using reliable and independent data", so what you ask for is a risk-based judgement.

The two are not collected in the same volume. Identity is established for every customer, because s 28(1) of the AML/CTF Act says a reporting entity must not commence to provide a designated service without first establishing the customer's identity on reasonable grounds. Source of wealth and source of funds sit in a narrower box. Under s 6-21 of the AML/CTF Rules they become a matter you must establish only where enhanced customer due diligence applies because s 32(a), (b) or (d) of the Act catches the customer, that is high ML/TF risk, a suspicious matter reporting obligation where you propose to keep acting, or a link to a high-risk jurisdiction, and only where the matter is "relevant to the nature of the ML/TF risk of the customer". So treat source-of-funds material as data you may hold on some files, not something on every file. Both, when you do hold them, are personal information about an identifiable individual.

How this data comes under the Privacy Act: s 6E(1A)

A buyers agency whose annual turnover for the previous financial year was A$3,000,000 or less is a small business at that time under s 6D(1) of the Privacy Act, and if it carries on no other business it is a small business operator under s 6D(3), so the Australian Privacy Principles did not apply to it. Two qualifications sit behind that. Section 6D(4) sets out other ways to fall outside the exemption, and s 6D(4)(a) is a one-way ratchet: a business that has had an annual turnover of more than A$3,000,000 for a financial year ending after it started is not a small business operator, and a later fall in turnover does not restore the exemption. Becoming an AML reporting entity changes the position again. Brokering the sale, purchase or transfer of real estate on behalf of a buyer in the course of carrying on a business is a designated service (Table 5 item 1, AML/CTF Act s 6(5A)), and Table 5 commenced on 31 March 2026. Privacy Act s 6E(1A) then applies the Privacy Act to you as if you were an organisation in relation to your AML-related activities, whatever your turnover.

Scope, stated honestly: s 6E(1A) is activity-scoped. Its words are that the Act applies "in relation to the activities carried on by the small business operator for the purposes of, or in connection with, activities relating to" the AML/CTF Act, its regulations or the AML/CTF Rules, "as if the small business operator were an organisation". That reaches the personal information you handle in the course of those activities, which is wider than the identity file on its own: it takes in the customer due diligence you carry out, the records you keep for it, your risk assessment and your reporting. What it does not do is make your whole practice an organisation, so a general buyer CRM, a newsletter list, property alerts or web enquiries that have nothing to do with your AML activities are not brought in by this route. Where one record serves both, the safer reading is that it is inside. Read: does becoming an AML reporting entity trigger the Privacy Act?

Collect only what the check reasonably requires (APP 3)

APP 3.2 provides that an organisation "must not collect personal information (other than sensitive information) unless the information is reasonably necessary for one or more of the entity's functions or activities". For a buyers agent that runs with the AML test rather than against it, because s 28(3)(c) of the AML/CTF Act asks you to collect KYC information "appropriate to the ML/TF risk of the customer". Both point the same way: match what you collect to what the check actually calls for, rather than sweeping up more than you need because it is easy to ask.

A few practical consequences follow. Where you sighted the document and recorded the check, s 111(3)(a) of the AML/CTF Act asks for records demonstrating "the type and content of the data collected", not the document image, so keeping a full colour copy of every identity document is not what that section requires. Where the client sent the document to you the choice may not be yours: if the document relates to the provision, or prospective provision, of a designated service and you commence, or have commenced, to provide that service, s 108(2) requires you to retain it, or a copy, for seven years after it was given, and s 108(3) makes that a civil penalty provision. So do not read "we do not need the scan" as permission to delete something a client sent you, and check the s 108 position in your retention and destruction schedule first. You collect source-of-funds evidence when the enhanced customer due diligence triggers call for it, not as a default on every engagement. And when a document reveals more than you need, you take only the part the check requires.

Tell the client why you are collecting it (APP 5)

APP 5.1 requires you to take such steps (if any) as are reasonable in the circumstances to notify the client of the matters in APP 5.2, or otherwise ensure they are aware of them, at or before the time you collect their information or, if that is not practicable, as soon as practicable after. Those matters include why you are collecting it, what you will do with it and who you may give it to. For VOI and source-of-funds data, the natural moment is when the buyer's-agency agreement is signed, which is also when the AML obligation attaches. A collection notice at that point sets the expectation that this financial and identity material is being gathered for the anti-money-laundering check, not for general marketing. Read: the collection notice you need at engagement

Use it for the AML purpose, not for marketing (APP 6)

APP 6 limits how you may use and disclose personal information to the purpose you collected it for, plus purposes the client would reasonably expect that are related to it. Source-of-funds and financial-capacity data collected for customer due diligence sits at the strict end of that test. A client hands over bank statements to satisfy an identity and funds check, not so they can be mined to pitch other services or shared with a mortgage broker or developer. Using AML data for marketing, or passing it to a third party the client did not expect, is where a use-and-disclosure problem arises.

Two related points. Government-related identifiers such as a driver licence or passport number carry their own limits under APP 9 on how you adopt, use and disclose them, so do not turn a licence number into your own internal client reference. And the buyer brief you build alongside the checks often carries sensitive personal context, a relocation, a divorce, an inheritance, an SMSF purchase, which deserves the same care even where it is not "sensitive information" in the Act's technical sense.

Secure it, because it is concentrated and high-value (APP 11)

APP 11.1 requires an APP entity to take "such steps as are reasonable in the circumstances" to protect the information it holds "from misuse, interference and loss" and "from unauthorised access, modification or disclosure". This is the principle that bites hardest for a buyers agent, because you hold few files but each one is deep: identity documents, financial-capacity evidence and, on higher-risk files, source-of-funds material. That depth is what makes the notification question live. Under s 26WE(2)(a) a breach is an eligible data breach where there is unauthorised access to or disclosure of the information and "a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates". That is an assessment you make on the facts of the actual breach, not something a page can decide in advance. Access controls, encryption, and not leaving identity scans in an email inbox or a shared drive are the everyday version of APP 11. Read: your data-breach response plan

APP 11.2 has a second limb: once you no longer need the information for any purpose for which you may use or disclose it, you take reasonable steps to destroy or de-identify it. It does not collide with the AML retention rules, because APP 11.2(d) applies that duty only where "the entity is not required by or under an Australian law, or a court/tribunal order, to retain the information". AML/CTF record keeping is that kind of legal requirement, so holding customer due diligence records for the statutory period is compliance with another law, not an APP 11.2 breach. What a retention schedule does is record the two clocks and the point at which the AML reason to hold the data runs out: s 111(2) runs seven years from the end of the business relationship, while s 108(2) runs seven years from the day the customer gave you the document. Read: how long must a buyers agent keep client records?

If any of this identity or funds data is handled by an offshore virtual assistant or an overseas-hosted cloud tool, APP 8 adds a separate overseas-disclosure duty. Read: offshore VAs and cloud tools, your APP 8 duty

From 10 December 2026: automated ID and sanctions screening

If you run identity, PEP or sanctions checks through automated tools, a transparency rule commences on 10 December 2026. From that date APP 1.7 provides that your APP privacy policy "must contain the information covered by subclause 1.8" where you have arranged for a computer program to make, or to do a thing substantially and directly related to making, a decision that "could reasonably be expected to significantly affect the rights or interests of an individual", and personal information about the individual is used in the operation of that program. Two points are easy to miss. APP 1.8(c) reaches part-automated processes where a person still makes the final call, and APP 1.9(c) says a decision counts whether the individual is "adversely or beneficially affected", so a tool that clears people is caught as much as one that declines them. It binds APP entities, which on this route means it reaches your screening so far as s 6E(1A) makes you an organisation for those AML-related activities. Whether a particular tool is caught turns on the facts, so it is worth working out now rather than discovering the gap later. Read the cornerstone: privacy compliance for Australian buyers agents

Common questions

Do I have to keep a copy of every client's driver licence?

It depends on how the document reached you. Where you sighted it and recorded the check, s 111(3)(a) of the AML/CTF Act asks for records demonstrating "the type and content of the data collected", not the document image, so the extracted detail can be enough and APP 3.2 keeps you to what is reasonably necessary. Where the client sent the document to you, s 108 can require the opposite: if the document relates to the provision, or prospective provision, of a designated service and you commence, or have commenced, to provide that service, s 108(2) requires you to retain it, or a copy, for seven years after it was given, and s 108(3) makes that a civil penalty provision. So collect and retain what the check needs, secure it under APP 11, and check the s 108 position in your retention and destruction schedule before you destroy anything a client sent you.

Can I use a client's bank statements or source-of-funds evidence for anything else?

No, not without care. APP 6 limits you to the purpose you collected it for, which is the AML check, plus closely related purposes the client would reasonably expect. Source-of-funds and financial-capacity evidence should not be repurposed for marketing, cross-sold to a broker or developer, or shared with a third party the client did not anticipate.

Is a passport or driver licence "sensitive information" under the Privacy Act?

Not automatically. "Sensitive information" is a defined category in the Act (health, biometric, racial or political information and a few others). An identity document is personal information and, in the case of a licence or passport number, a government-related identifier with its own limits under APP 9, but it is not sensitive information simply because it verifies identity. It still deserves strong security either way.

Does this mean my whole client database is now under the Privacy Act?

No, not by this route. s 6E(1A) applies the Privacy Act to you "in relation to the activities carried on ... for the purposes of, or in connection with, activities relating to" the AML/CTF Act and the AML/CTF Rules, so it reaches the personal information you handle in the course of those activities rather than everything you hold. A general buyer CRM, a newsletter list and property alerts that have nothing to do with your AML activities are not brought in by s 6E(1A), although a separate trigger such as one of the s 6D(4) limbs or the s 6EA opt-in can bring them in for another reason. The rules on this page are about the VOI and source-of-funds material specifically.

Am I even a reporting entity if I only research and advise?

It depends on what you actually do. Brokering the purchase of a property for a fee is the caught activity, and a buyers agency retained to acquire property is doing it. A genuinely advice-only or research-only service that never finds a specific property and never negotiates may fall outside the brokering definition, but that is fact-specific, so confirm your own position rather than assuming either way. Read: advice-only or research-only buyers agent, are you caught?


This is general information and document templates you tailor to your own business, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC. The Privacy Act 1988 (Cth) and related guidance change over time, so check you are working from a current version. For advice on your specific circumstances, consult a qualified Australian legal practitioner.