Privacy compliance for Australian conveyancers: you were exempt. From 1 July 2026, you're not.
AML/CTF Tranche 2 commenced on 1 July 2026 and made conveyancers reporting entities. The moment that happened, the personal information you collect for AML purposes came under the Privacy Act, for most firms for the first time ever. The AML consultants are helping you enrol with AUSTRAC and write an AML program. Almost none of them are fixing the privacy obligation that came bundled with it. This page is about that overlooked half.
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
The deadline that should have your attention
- Tranche 2 commenced 1 July 2026. Conveyancers, and in WA licensed settlement agents, are named reporting entities alongside lawyers, accountants and real estate agents. An AML/CTF program had to be in place by that date. Read: AML Tranche 2 for conveyancers.
- AUSTRAC enrolment: the cut-off for firms already practising on 1 July 2026 is around 29 July 2026 (28 days from first providing a designated service; confirm your firm's exact date with AUSTRAC). Your privacy obligation attaches from the moment you are providing designated services and are a reporting entity, not the day you enrol.
If you are reading this in mid-2026, you are likely mid-enrolment. The privacy side does not wait for a second deadline. It applies now.
You were exempt. Now you're not.
Most conveyancing firms turn over under A$3 million and have relied on the small-business exemption (s 6D), which meant they never had to comply with the Australian Privacy Principles. Becoming an AUSTRAC reporting entity changes that. Via Privacy Act s 6E, you are treated as an organisation for the activities you carry on in connection with the AML/CTF Act. So the Privacy Act applies to the personal information you handle for AML/CTF purposes: the identity, verification, beneficial-ownership and source-of-funds data you collect for customer due diligence, even below the $3 million threshold. The rest of your practice is not automatically swept in. Read: what personal information is caught.
For most conveyancers this is not an upgrade to an existing privacy setup. It is a first-ever privacy obligation, and nobody told you it came attached to AML.
Why conveyancing data is squarely in scope
Assisting a client to buy, sell or transfer real estate is the core service that pulls conveyancers into the regime. It is the whole of the work, so there is no ancillary edge to sit on. And the data you now hold as a regulated entity is unusually sensitive:
- Verification of identity (VOI): passport, driver's licence, Medicare and other identity documents collected to verify your client, including under the ARNECC "reasonable steps" identity standards used for e-conveyancing. Read: VOI vs AML customer due diligence.
- AML customer due diligence: customer identification, beneficial-owner details, and PEP or sanctions screening results. Read: beneficial ownership.
- Source of funds and source of wealth: where settlement money comes from, including bank statements and gift or loan evidence.
- PEXA / ELNO settlement data: workspace and trust-account details identifying the parties, the property and the flow of funds.
- Trust-account records: client banking details and disbursement records you hold to settle.
This is a concentrated bundle of identity and financial data. That is exactly the kind of information that makes a data breach serious and a privacy claim viable. Read: your data-breach response plan.
Two further pressures you should know about
- A direct right to sue for serious invasions of privacy commenced on 10 June 2025. Individuals can bring a claim directly, no regulator needed, for intentional or reckless conduct. Conveyancers hold precisely the high-sensitivity identity and financial data that makes such a claim concrete.
- From 10 December 2026, automated-decision-making transparency: if you use software that makes, or substantially and directly supports, a decision that significantly affects a person (some electronic VOI, IDV or PEP/sanctions-screening tools may qualify), your privacy policy will need to disclose it. A forward-dated change worth building in now rather than retrofitting later. Read: automated decision-making and your privacy policy.
What conveyancers actually need to do
At a minimum, a conveyancer drawn into the Privacy Act needs:
1. A compliant privacy policy (APP 1) that reflects conveyancing (VOI, source of funds, trust records, PEXA/ELNO data), not a generic fill-in. Read: the conveyancer privacy policy. 2. Collection notices (APP 5) that tell clients what you collect and why, including your VOI and AML customer-due-diligence collection. Read: consent to collect ID for AML. 3. A data-breach response plan for the notifiable-data-breach scheme, tuned to the real conveyancing exposure: compromised settlement credentials, misdirected VOI packs, and payment-redirection fraud. 4. Retention, access and complaint procedures, including reconciling the AML records-retention floor with the Privacy Act's "destroy when no longer needed" principle. Read: how long to keep records.
The AML platforms do not give you these. Free generic templates usually are not written for conveyancing, and most do not keep pace as the law changes.
What Privaproof is building for conveyancers
A dedicated, conveyancer-specific privacy document set, written for conveyancing and WA settlement work, and kept current as the law changes. Not a one-off free download, and not an AML platform bolt-on: the privacy-focused answer to the obligation Tranche 2 just handed you.
- Written for conveyancers and WA settlement agents: VOI, source of funds, trust accounts, PEXA/ELNO.
- Practical, plain-English documents you tailor to your firm, with guidance built in.
- Kept current: while your subscription is active, we monitor the law and aim to provide updated versions as it changes, including the 10 December 2026 ADM change. This is not a guarantee of compliance, and does not replace your own legal advice.
These are compliance tools and templates you tailor to your own business. They are general information, not legal advice, and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner.
Join the founding list
Be first to know when the Conveyancer Kit opens, and get plain-English updates as the 2026 changes land. No cost, no obligation.
✓ You’re on the founding list. We’ll email you as the changes land.
We never sell your data. See our Privacy Policy.
Keep reading
- AML Tranche 2 for conveyancers: what changed on 1 July 2026
- Privacy obligations for conveyancers, state by state
- WA settlement agents and privacy
- What the AML/KYC personal information includes
- VOI vs AML customer due diligence
- Beneficial ownership: what you collect and why
- Overseas disclosure and offshore providers (APP 8)
- The conveyancer privacy policy
- Your data-breach response plan
- Consent to collect ID for AML
- Automated decision-making and your privacy policy (from 10 Dec 2026)
- How long to keep records
- What non-compliance can cost
- The cost of AML-driven privacy compliance
- What your collection notice must say (APP 5)
- The minimum to be privacy compliant
General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC, and it does not replace advice on your specific circumstances. Privaproof's conveyancer documents are self-authored and are not independently reviewed by a solicitor. The Privacy Act 1988 (Cth) and related guidance change over time, so check you are working from a current version.