The Forgotten Privacy Problem in Property Settlements: Who Is Sharing Your Personal Information?

Why Privacy Must Become the Next Major Reform Discussion for the Property Industry

By David Dawn, Licensed Conveyancer

Introduction

For more than a decade, the Australian property industry has focused on digitisation.

The introduction of electronic conveyancing has transformed what was once a heavily paper-based process into a sophisticated digital environment connecting conveyancers, solicitors, financial institutions, government agencies, Electronic Lodgment Network Operators (ELNOs), identity verification providers and property owners.

The benefits have been significant.

Settlements occur faster.

Documents are lodged electronically.

Funds are transferred within minutes.

The risks associated with lost documents, bank cheques and manual settlement processes have been substantially reduced.

The transition to electronic conveyancing is rightly regarded as one of the most successful reforms undertaken within the Australian property industry.

Yet while the industry has focused heavily on efficiency, cybersecurity and fraud prevention, another issue has received comparatively little attention.

Privacy.

More specifically, the collection, use, disclosure and retention of personal information obtained during property transactions.

As Australia prepares for the implementation of Tranche 2 Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) reforms, property professionals are about to become custodians of unprecedented quantities of personal information.

The profession therefore faces an important question.

Have we become so focused on moving information efficiently that we have forgotten to ask whether it should be moving at all?

The Information Explosion

A conveyancing file from twenty years ago contained relatively modest amounts of personal information.

Today, a single transaction may involve:

  • Full legal names

  • Dates of birth

  • Current residential addresses

  • Future residential addresses

  • Telephone numbers

  • Email addresses

  • Driver licence details

  • Passport information

  • Medicare information

  • Banking information

  • Identity verification reports

  • Foreign Resident Capital Gains Withholding Tax information

  • Company ownership structures

  • Trust documentation

  • Beneficial ownership records

  • Source of funds information

  • Source of wealth information

Much of this information is collected because legislation requires it.

Some is required for identity verification.

Some is required by land registries.

Some is required by taxation authorities.

Increasingly, substantial amounts of information will be collected for AML/CTF compliance purposes.

The issue is not whether information should be collected.

The issue is what happens after collection.

The Legislative Framework

Australia's privacy regime is principally governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Three principles are particularly relevant to electronic conveyancing.

APP 3 – Collection

Personal information should only be collected where reasonably necessary for the organisation's functions or activities.

APP 6 – Use and Disclosure

Personal information collected for one purpose should generally only be used or disclosed for that purpose unless an exception applies.

APP 11 – Security

Organisations must take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.

These principles are straightforward.

Collect what is required.

Use it for the purpose for which it was collected.

Protect it from inappropriate disclosure.

While the property industry frequently discusses collection and storage obligations, considerably less attention is often given to disclosure.

Yet disclosure is where many privacy risks arise.

Collection Is Not the Same as Disclosure

One of the most important principles in privacy law is that authority to collect information does not automatically create authority to disclose it.

A conveyancer may be required to collect:

  • A client's date of birth.

  • A future residential address.

  • Taxation information.

  • Banking information.

  • Identity verification material.

That does not mean every participant in a transaction requires access to that information.

A government agency may legitimately require information for statutory purposes.

A lender may require information for lending purposes.

A regulator may require information for compliance purposes.

The fact that information has been collected for one purpose does not automatically justify its disclosure for another.

This distinction is fundamental.

Yet it is often overlooked.

The Notice of Acquisition Is Not the Problem

One of the most common examples arises through the use of Notices of Acquisition generated during electronic conveyancing transactions.

The Notice of Acquisition itself is not the problem.

In fact, the document serves a legitimate and important purpose.

It allows information to be collected and provided to government agencies responsible for land registration, rating, taxation and electoral administration.

The information contained within the notice may include:

  • Full legal names

  • Property addresses

  • Future postal addresses

  • Date of birth information

  • Transfer consideration

  • Principal Place of Residence declarations

  • Ownership details

The collection of this information is generally justified because different government authorities have different statutory responsibilities.

Indeed, local councils are among the few organisations outside the State Revenue Office and the Land Registry that may legitimately require a substantial portion of the information contained within a Notice of Acquisition.

A council may need:

  • The owner's identity.

  • The property address.

  • A future postal address.

  • Date of birth information.

  • Principal Place of Residence information.

  • Transfer value information.

These requirements arise from a range of statutory functions relating to rating, electoral administration, valuation processes and other government responsibilities.

The issue therefore is not the collection of information.

Nor is it the transmission of that information to authorities that genuinely require it.

The issue arises when a document created for multiple statutory purposes becomes a universal information-sharing tool.

When One Document Becomes Many Disclosures

Consider what happens after settlement.

A participant downloads a Notice of Acquisition.

That document is then distributed to a range of third parties.

At first glance this may appear efficient.

However, each recipient has different information requirements.

A water authority generally needs to know:

  • The property address.

  • The identity of the person responsible for future charges.

  • A service address for correspondence.

A water authority generally does not require:

  • Date of birth.

  • Previous residential address.

  • Transfer consideration.

  • Principal Place of Residence information.

  • Information collected for taxation administration.

Likewise, an Owners Corporation manager often requires even less information.

An Owners Corporation may need:

  • The owner's name.

  • An address for service.

  • Contact details.

In many cases, that information can be reduced to a simple notification:

"Lot 12 has transferred ownership. The owner is Fred Nurk. Future correspondence should be sent to PO Box 123, Melbourne Victoria."

That notification allows the Owners Corporation to perform its function.

The additional information contained within a Notice of Acquisition is often unnecessary for that purpose.

This is where the privacy issue arises.

The problem is not the Notice of Acquisition.

The problem is treating a multi-purpose statutory document as a universal information-sharing document.

The Convenience Culture

Why does this happen?

The answer is simple.

Convenience.

Preparing separate notifications takes time.

Forwarding a document takes seconds.

Across hundreds of transactions each year, those seconds become commercially attractive.

Yet convenience has never been recognised as a justification for unnecessary disclosure.

The Privacy Act does not contain an exception for administrative efficiency.

Nor does the fact that a practice is widespread make it appropriate.

The phrase:

"Everybody does it"

has never been a particularly persuasive legal or ethical defence.

Privacy requires professionals to ask difficult questions about long-established practices.

The Consumer Expectation Test

Perhaps the most useful test is not found in legislation at all.

Instead, ask what an ordinary consumer would expect.

When a client provides information to a conveyancer, they generally understand that:

  • Government agencies may require it.

  • Banks may require it.

  • Identity verification providers may require it.

What they often do not expect is that information being distributed beyond those purposes simply because it is readily available.

Most consumers would likely ask a simple question:

Why does this organisation need my information?

If a convincing answer cannot be provided, disclosure should be reconsidered.

Tranche 2 AML Reforms Will Magnify the Issue

The upcoming AML/CTF reforms will dramatically increase the amount of information collected by property professionals.

Practitioners will increasingly be required to understand:

  • Who owns assets.

  • Who ultimately controls assets.

  • Source of funds.

  • Source of wealth.

  • Beneficial ownership structures.

  • Transaction risk indicators.

Every additional document collected creates additional privacy obligations.

Every additional database creates additional security risks.

Every additional disclosure creates additional opportunities for error.

The industry's discussion cannot stop at collection.

It must extend to disclosure, retention and destruction.

The Principle of Data Minimisation

Privacy professionals often refer to data minimisation.

The concept is simple.

Collect only what is necessary.

Use only what is necessary.

Disclose only what is necessary.

Retain only what is necessary.

Destroy what is no longer necessary.

The property industry has embraced digital efficiency.

It should now embrace data minimisation with equal enthusiasm.

The safest information is often information that was never unnecessarily disclosed in the first place.

Information Should Be Treated Like Trust Money

Conveyancers understand trust accounting.

Every practitioner appreciates the importance of safeguarding client funds.

Every practitioner understands the consequences of mishandling trust money.

Personal information deserves the same level of respect.

Information entrusted to a professional is a valuable client asset.

It should not be treated as an administrative by-product of a transaction.

Before disclosing information, every practitioner should ask:

  • Who is receiving it?

  • Why are they receiving it?

  • What information do they genuinely require?

  • What authority exists for disclosure?

These questions should become as routine as balancing a trust account.

Recommendations for Reform

1. Adopt an Industry Data Minimisation Standard

Professional bodies should develop clear guidance requiring practitioners to consider necessity before disclosure.

2. Review ELNO Export Functions

Electronic Lodgment Network Operators should review whether certain documents containing personal information should be subject to additional controls, warnings, audit trails or redaction mechanisms.

3. Introduce Purpose-Specific Notifications

Councils, water authorities and Owners Corporations should receive information tailored to their actual requirements rather than complete multi-purpose statutory documents.

4. Develop OAIC Guidance for Electronic Conveyancing

The Office of the Australian Information Commissioner should publish industry-specific guidance addressing disclosure practices within electronic conveyancing environments.

5. Conduct Privacy Impact Assessments for AML Implementation

Industry bodies should assess the privacy implications of expanded AML obligations before implementation becomes embedded practice.

6. Improve Retention and Destruction Policies

Property professionals should actively review what information is retained, for how long and whether continued retention remains necessary.

7. Create a Privacy-First Professional Culture

Privacy should be regarded as a professional responsibility rather than merely a compliance requirement.

Conclusion

The Australian property industry has spent years discussing cybersecurity, settlement fraud, identity theft and electronic conveyancing risk.

These discussions remain essential.

However, the next major consumer protection issue is likely to be privacy.

As property professionals collect increasing quantities of personal information, consumers will rightly expect greater accountability regarding how that information is used and disclosed.

The Notice of Acquisition is not the problem.

Electronic conveyancing is not the problem.

The problem arises when information collected for one legitimate purpose is disclosed for another without sufficient consideration of necessity.

The fact that information exists does not mean it should be distributed.

The fact that information is available does not mean it is required.

And the fact that a practice has become common does not mean it is correct.

The next chapter of electronic conveyancing reform should not focus solely on how information is collected.

It should focus equally on how information is protected.

References

Privacy Act 1988 (Cth)

Australian Privacy Principles (APP 3, APP 6 and APP 11)

Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)

Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth)

Electronic Conveyancing National Law

Model Participation Rules

Participation Agreement applicable to ELNO Subscribers

Office of the Australian Information Commissioner, Australian Privacy Principles Guidelines

Office of the Australian Information Commissioner, Guide to Securing Personal Information

Land transfer, duties and rating legislation applicable within participating Australian jurisdictions.