Skip to content

Privacy compliance for Australian conveyancers: you were exempt. From 1 July 2026, you're not.

AML/CTF Tranche 2 commenced on 1 July 2026 and made conveyancers reporting entities. The moment that happened, the personal information you collect for AML purposes came under the Privacy Act, for most firms for the first time ever. The AML consultants are helping you enrol with AUSTRAC and write an AML program. Almost none of them are fixing the privacy obligation that came bundled with it. This page is about that overlooked half.

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

The deadline that should have your attention

If you are reading this in mid-2026, you are likely mid-enrolment. The privacy side does not wait for a second deadline. It applies now.

You were exempt. Now you're not.

Most conveyancing firms turn over under A$3 million and have relied on the small-business exemption (s 6D), which meant they never had to comply with the Australian Privacy Principles. Becoming an AUSTRAC reporting entity changes that. Via Privacy Act s 6E, you are treated as an organisation for the activities you carry on in connection with the AML/CTF Act. So the Privacy Act applies to the personal information you handle for AML/CTF purposes: the identity, verification, beneficial-ownership and source-of-funds data you collect for customer due diligence, even below the $3 million threshold. The rest of your practice is not automatically swept in. Read: what personal information is caught.

For most conveyancers this is not an upgrade to an existing privacy setup. It is a first-ever privacy obligation, and nobody told you it came attached to AML.

Why conveyancing data is squarely in scope

Assisting a client to buy, sell or transfer real estate is the core service that pulls conveyancers into the regime. It is the whole of the work, so there is no ancillary edge to sit on. And the data you now hold as a regulated entity is unusually sensitive:

This is a concentrated bundle of identity and financial data. That is exactly the kind of information that makes a data breach serious and a privacy claim viable. Read: your data-breach response plan.

Two further pressures you should know about

What conveyancers actually need to do

At a minimum, a conveyancer drawn into the Privacy Act needs:

1. A compliant privacy policy (APP 1) that reflects conveyancing (VOI, source of funds, trust records, PEXA/ELNO data), not a generic fill-in. Read: the conveyancer privacy policy. 2. Collection notices (APP 5) that tell clients what you collect and why, including your VOI and AML customer-due-diligence collection. Read: consent to collect ID for AML. 3. A data-breach response plan for the notifiable-data-breach scheme, tuned to the real conveyancing exposure: compromised settlement credentials, misdirected VOI packs, and payment-redirection fraud. 4. Retention, access and complaint procedures, including reconciling the AML records-retention floor with the Privacy Act's "destroy when no longer needed" principle. Read: how long to keep records.

The AML platforms do not give you these. Free generic templates usually are not written for conveyancing, and most do not keep pace as the law changes.

What Privaproof is building for conveyancers

A dedicated, conveyancer-specific privacy document set, written for conveyancing and WA settlement work, and kept current as the law changes. Not a one-off free download, and not an AML platform bolt-on: the privacy-focused answer to the obligation Tranche 2 just handed you.

These are compliance tools and templates you tailor to your own business. They are general information, not legal advice, and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner.

Join the founding list

Be first to know when the Conveyancer Kit opens, and get plain-English updates as the 2026 changes land. No cost, no obligation.

We never sell your data. See our Privacy Policy.

Keep reading


General information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC, and it does not replace advice on your specific circumstances. Privaproof's conveyancer documents are self-authored and are not independently reviewed by a solicitor. The Privacy Act 1988 (Cth) and related guidance change over time, so check you are working from a current version.