For conveyancers & settlement agents

Not every file is in scope. The ones that are, are in scope now.

Since 1 July 2026, conveyancers providing designated services under the AML/CTF Act are reporting entities. For the personal information you handle in that work, the Privacy Act small business exemption no longer applies — whatever your turnover.

The first job is working out which parts of your practice that actually covers. We do that in week one, then build the program around it.

No obligation. We'll tell you if you don't need us.

Where the law actually stands

Three dates matter. Only one has already passed.

Plenty of people will tell you every small business is about to fall under the Privacy Act. That isn't law yet. Here is what is in force, what is scheduled, and what is still only proposed.

Date
What changed
Status
10 Jun 2025
Statutory tort for serious invasions of privacy Individuals can sue directly. Applies regardless of your turnover.
In force
01 Jul 2026
AML/CTF Tranche 2 — conveyancing captured as a designated service Assisting a client to buy or sell real property is a designated service. The Privacy Act now applies to the personal information you handle in that work, even under the $3m threshold.
In force
10 Dec 2026
Automated decision-making disclosure obligations If your practice management software screens or scores clients automatically, your privacy policy has to disclose it.
Scheduled
Not set
Removal of the $3m small business exemption entirely Government supports it in principle. No Bill passed, no commencement date. Treat any specific date you're quoted as commentary.
Proposed

General information, current as at the date of publication — not legal advice. We review this table monthly and date every change.

Why conveyancers are exposed

Every settlement leaves a file that no one has decided when to destroy.

A single matter collects certified identity documents, a contract of sale, bank account details for settlement, source of funds evidence, mortgage discharge paperwork and often the client's whole financial position in an email thread. Then it settles, and the file stays — in PEXA, in your practice management system, in the shared drive, and in the inbox of whoever was covering that week.

Verification of identity was already part of the job. What changed on 1 July is that the identity records you keep for AML/CTF purposes now sit under the Australian Privacy Principles as well: how you secure them, who you disclose them to, and when you have to get rid of them.

Most practices we talk to have a retention habit rather than a retention policy — keep everything, forever, just in case. Under APP 11.2 that is now the wrong answer, and it is the single most common gap we find.

What it costs to get this wrong. The OAIC can issue infringement notices of up to $66,000 per contravention for lower-level failures such as not maintaining a compliant privacy policy. Serious or repeated breaches carry substantially higher penalties. Separately, since June 2025, an individual can bring a civil claim against you directly.

What we do

Four ways to work with us.

Start small if you want to see how we work. Start with the foundations if you already know where this is heading.

Privacy health check

$750 + GST, one-off

A half day of our time and a written answer to one question: how exposed are you?

  • Review of your current policy, forms and file handling
  • Written findings memo against the Australian Privacy Principles
  • Prioritised list of what to fix first
  • Credited in full against foundations if you proceed within 60 days

Privacy foundations

$4,500 – $7,500 + GST, one-off

A complete privacy program, built and handed over in four weeks.

  • Data map of every place personal information lives
  • Gap assessment against the 13 Australian Privacy Principles
  • Privacy policy and collection notices written for your practice
  • Notifiable data breach response plan
  • 60-minute staff training session

Most practices choose this

ComplyHub annual

from $10,500 + GST, per year

Foundations plus twelve months of maintenance, bundled.

  • Everything in Privacy foundations
  • Quarterly compliance review
  • Policies and registers updated as the law changes
  • Breach response line — call us first, not your lawyer
  • Annual staff training refresher

Ongoing privacy officer

$400 – $800 + GST, per month

Maintenance only, for practices whose program is already built.

  • Quarterly reviews and register upkeep
  • Regulatory change monitoring
  • Breach response line
  • If someone else built your program, we'll assess it first ($1,500)

The four weeks

What actually happens.

Week 1 — Discovery

Ninety minutes with you and whoever runs the files. We map a live matter end to end — from the first enquiry to the archived file — and identify which of your services are designated services and which aren't.

Week 2 — Data map and gap assessment

We document what you hold, where, who can see it and how long you keep it, then assess it against each of the 13 Australian Privacy Principles. Retention and disclosure to third parties are usually where the gaps are.

Week 3 — Documents

Privacy policy, collection notices for your client intake and VOI forms, a breach response plan, and a retention schedule that says plainly what gets destroyed and when. Written for your practice.

Week 4 — Handover and training

An hour with your team on what changed, plus a written summary you can put in front of your PI insurer, your licensing body or the OAIC.

Fair questions

What principals usually ask us.

Every file I open involves property. Is my whole practice in scope?

Probably not, and this matters. The AML/CTF obligations attach to designated services, not to your ABN. Some of what you do will be captured; some — general advice, some commercial work, matters that never reach a transfer — may not be. Week one is where we draw that line, because it decides how much program you actually need to build. Anyone who tells you the answer before looking at your files is guessing.

Doesn't my AML/CTF program already cover this?

No. Separate Acts, separate regulators. Your AML program tells you to collect and retain identity records; the Privacy Act governs how you secure them, who you can disclose them to and when you must destroy them. Being a reporting entity is what brought you into scope, not what satisfies it.

We're under $3 million turnover.

The exemption no longer applies to personal information you handle for AML/CTF purposes. That's the specific effect of the 1 July change. The broader removal of the $3m exemption for everything else is still only proposed — no Bill, no date.

We already do verification of identity.

Collecting the documents was never the problem. The obligations that changed are about what happens afterwards: storage, access controls, disclosure to third parties, breach notification, and destruction. VOI is the input; the privacy program is the handling.

Are you lawyers?

No. We're privacy and compliance practitioners, and this is implementation work — data mapping, operational documents, training and registers. Where something genuinely requires legal advice we say so and refer you out. Our engagement letter puts that in writing.

Who you're dealing with

A small Australian firm, and you'll deal with a founder.

ComplyHub is based in Melbourne and works with Australian professional services businesses on Privacy Act obligations. Our work is delivered onshore — your data stays in Australia, and we can tell you exactly which systems it touches.

Between us we hold certifications from the International Association of Privacy Professionals in privacy program management, privacy technology and AI governance, alongside security credentials. That matters less than the fact that you'll speak to the person doing the work.

More about us and our credentials →

Find out which of your files are actually in scope.

Twenty minutes on the phone. We'll walk through the services you provide and tell you plainly where your exposure sits. If you're already covered, we'll say so.