Call us on  03 8685 8788 or 0425 785 180

Home » Privacy Policy

Privacy Policy

1. About this policy

Morgan Conveyancing (“we“, “us“, “our“) is a licensed conveyancing practice operating in Victoria. Handling your personal information is central to what we do — we cannot transfer a property without knowing who you are, where you live, how you are funding the transaction and how you hold title.

This policy explains what we collect, why we collect it, who we pass it to, how we protect it, how long we keep it, and what you can do if you are unhappy with any of that.

It applies to clients, prospective clients, the other side’s parties where we hold their details, referrers, website visitors, and job applicants.

2. The law we work under

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) made under it.

From 1 July 2026, conveyancers became “reporting entities” under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (“AML/CTF Act“). The small business exemption in the Privacy Act does not apply to a reporting entity’s handling of information collected for AML/CTF purposes. We do not rely on the small business exemption at all. We apply the APPs to everything we hold, whether or not it was collected for an AML/CTF purpose.

We are also bound by confidentiality and record-keeping duties under the Conveyancers Act 2006 (Vic) and its regulations, the Sale of Land Act 1962 (Vic), the Transfer of Land Act 1958 (Vic), the Electronic Conveyancing National Law (Victoria) and the Registrar of Titles’ Participation Rules and Requirements, and by our professional obligations as a member of the Australian Institute of Conveyancers (Victorian Division).

3. What we collect

Identity and contact information — your full legal name and any former names, residential and postal address, date of birth, email addresses and phone numbers, and your occupation where a concession or exemption depends on it.

Identity verification (VOI) information — the type, number, issuing authority and expiry of the identity documents we sight (for example a passport, driver licence, birth certificate, Medicare card or citizenship certificate), the date and method of verification, and the name of the person or service that carried it out. Where verification is done by a face-to-face or digital identity service, that service may capture a photograph or a biometric template of your face.

Transaction information — the property address and title particulars, the contract and Section 32 statement, your capacity (individual, trustee, company, SMSF), directorship and ACN/ABN details for corporate parties, details of any trust or superannuation fund, and details of related parties such as a guarantor or nominee.

Financial information — bank account and BSB details for settlement, loan and mortgage details, your lender and broker, deposit and adjustment figures, source of funds information, tax file details only where a legislative form requires them, foreign resident status, and any concession, exemption or grant you are claiming.

Sensitive information — we collect sensitive information only where it is directly relevant to the matter or required by law: for example biometric information used in identity verification, health information where a duty concession or a family law or capacity issue depends on it, or information about a criminal matter where it affects the transaction. Where a matter involves a person who lacks capacity, is a party to family violence proceedings, or is deceased, we may also hold associated documents such as a power of attorney, a grant of probate or a court order.

AML/CTF information — the results of customer due diligence, beneficial ownership information for companies and trusts, politically exposed person (PEP) and sanctions screening results, and information about the source of funds and wealth where our risk assessment requires it.

Website and technical information — pages viewed, referring site, browser and device type, approximate location, and cookie identifiers. See section 10.

Recruitment information — where you apply for a role with us, your resume, references, qualifications, licence status and right-to-work evidence.

4. How we collect it

Wherever it is reasonable and practicable, we collect personal information directly from you — by phone, email, in person, through our engagement and instruction forms, and through our client portal.

We also receive information about you from:

  • your real estate agent, mortgage broker, accountant, financial adviser or lawyer;
  • the conveyancer or solicitor acting for the other party to your transaction;
  • your lender or incoming mortgagee;
  • identity verification agents and digital identity service providers we engage;
  • Land Use Victoria, ASIC, the Australian Business Register, VicRoads and other public registers;
  • councils, water and other authorities in response to certificate requests;
  • owners corporation and building managers;
  • sanctions, PEP and adverse media screening providers; and
  • anyone you authorise to give us information on your behalf.

If you give us personal information about someone else — a co-purchaser, a nominee, a guarantor, an attorney, a beneficiary — you must have their authority to do so, and you should show them this policy.

5. Why we collect, hold, use and disclose it

We use your personal information to:

  • act for you in your conveyancing matter, including reviewing and preparing contracts and Section 32 statements, ordering certificates, preparing transfer and duty documents, and settling and lodging the transaction;
  • verify your identity and your right to deal with the property, as required by the Registrar of Titles’ Participation Rules and Verification of Identity Requirements;
  • prepare and complete Client Authorisations and lodge and settle electronically through an Electronic Lodgment Network Operator;
  • meet duty, land tax, GST withholding, foreign resident capital gains withholding and other revenue obligations;
  • meet our customer due diligence, screening, reporting and record-keeping obligations under the AML/CTF Act;
  • open and manage your file, issue costs disclosures, invoices and receipts, operate our trust and general accounts, and collect payment;
  • correspond with the other side, your lender, your agent and relevant authorities to bring the matter to settlement;
  • respond to your enquiries, including where you do not go on to engage us;
  • comply with a subpoena, court order, statutory notice, regulator request or audit, and to obtain our own legal and insurance advice;
  • manage complaints, claims and our professional indemnity insurance;
  • maintain and improve our systems and train our staff; and
  • send you occasional updates about our services, where you have not opted out.

We will not use your information for a purpose unrelated to the above without your consent, unless we are required or authorised by law to do so.

6. Who we disclose it to

Completing a conveyance necessarily involves disclosing your information. Depending on the matter, we may disclose it to:

  • the conveyancer or solicitor for the other party, and their client where the document requires it;
  • your lender, incoming and outgoing mortgagees, and mortgage brokers;
  • Land Use Victoria and the Registrar of Titles;
  • the State Revenue Office Victoria and the Australian Taxation Office;
  • our Electronic Lodgment Network Operator (currently PEXA) and, where a workspace requires it, other subscribers to that workspace;
  • identity verification agents and digital identity service providers;
  • AUSTRAC, where we are required to lodge a suspicious matter report, threshold transaction report or other report, and to law enforcement or regulators where required or authorised by law;
  • sanctions, PEP and adverse media screening providers;
  • local councils, water corporations, the owners corporation and its manager, and other certificate issuers — but only the information those bodies are legally entitled to receive. In particular, we do not provide a Notice of Acquisition to an owners corporation, because it contains information (including the price, deposit and your date of birth) that an owners corporation has no entitlement to, unless you give us written authority;
  • your real estate agent, and any depositholder or stakeholder;
  • your accountant, adviser, attorney or other representative, where you have authorised it;
  • our practice management, document storage, email, telephony, e-signature, accounting and backup providers;
  • our professional indemnity insurer, broker, auditor, lawyers and debt recovery agents;
  • Consumer Affairs Victoria and the Australian Institute of Conveyancers (Victorian Division), in connection with our licensing, audit and professional obligations; and
  • a purchaser of our practice, under confidentiality obligations, if we sell or merge the business.

We do not sell your personal information, and we do not disclose it to third parties for their own marketing.

7. Overseas disclosure

Some of the cloud services we use to run the practice store or process data outside Australia. Before we use an overseas provider we take reasonable steps to ensure it handles personal information in a way consistent with the APPs, including through contractual commitments and by reviewing where the data is hosted.

8. AML/CTF: extra detail about identity information

Because identity documents are attractive to criminals, we take a deliberately minimal approach:

  • We collect only what is reasonably necessary to verify you. We do not collect information “just in case”.
  • Where possible, we record only the facts of verification — document type, number, issuer and date — rather than retaining full copies of your identity documents. Where a copy is taken during onboarding, we destroy or de-identify it once verification is complete and it is no longer required for a lawful purpose.
  • Where a verification service uses facial recognition or another biometric method, that biometric information is sensitive information. We will only collect it with your consent or where the law requires it, and we will tell you before it happens. If you would prefer not to be verified biometrically, tell us and we will arrange an alternative method.
  • We keep AML/CTF records for seven years after the end of the relationship or transaction, as the AML/CTF Act requires.
  • We remain responsible for your information even where a verification agent or software platform collects it on our behalf.
  • In limited circumstances the AML/CTF Act’s “tipping off” provisions prohibit us from telling you that we have collected, used or reported particular information. Where that applies, we cannot give you a collection notice or explain why.

9. Security

We take reasonable steps to protect your personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure.

  • role-based access controls and unique logins, with multi-factor authentication on email, our practice management system and our ELNO account;
  • encryption of data in transit and at rest;
  • a secure client portal for exchanging identity and banking documents, in preference to email attachments;
  • locked storage for any paper file, and secure destruction of paper and electronic records;
  • staff training on privacy, cyber-fraud and payment redirection scams, with confidentiality obligations in employment contracts;
  • vendor due diligence and contractual privacy obligations for our service providers; and
  • a documented data breach response plan.

Payment redirection warning. Email is not secure and account details in emails are a common target for fraud. We will never advise you of a change to our bank account details by email alone. Before transferring any funds, call us on the number published on our website — not a number in an email — and confirm the details verbally.

No system is perfectly secure, and information sent to us over the internet travels at your own risk.

10. Our website

Our website collects limited technical information automatically, and whatever you choose to enter into an enquiry or quote form.

We use cookies and similar technologies for site functionality, analytics and, at times, advertising. You can block or delete cookies through your browser settings, though some parts of the site may then not work properly.

Our website may link to other sites. We are not responsible for their privacy practices and encourage you to read their policies.

Our services are not directed at children, and we do not knowingly collect personal information from anyone under 18 other than in the course of a matter in which a minor is a party.

11. Direct marketing

We may send you occasional updates about property law changes and our services. Every message will include an unsubscribe facility, and you can opt out at any time by contacting our Privacy Officer. Opting out will not affect the communications we must send you about your matter.

We do not use sensitive information for marketing and we do not provide your details to other organisations for their marketing.

12. How long we keep your information

  • AML/CTF records: seven years from the end of the relationship or the transaction.
  • Matter files: seven years from the completion of the matter, consistent with our obligations under the Conveyancers Act 2006 (Vic) and our insurer’s requirements. Title-critical documents may be kept longer where you ask us to.
  • Trust account records: as required under the Conveyancers Act 2006 (Vic) and its regulations.
  • Enquiries that do not become matters: 12 months, then deleted.
  • Unsuccessful job applications: 12 months, then deleted.

When information is no longer needed for any purpose for which it may lawfully be used, and we are not required to retain it, we destroy it securely or de-identify it.

13. Accessing and correcting your information

You can ask us for a copy of the personal information we hold about you, and ask us to correct it if it is wrong, out of date, incomplete or misleading. Write to our Privacy Officer at the address in section 15.

We do not charge for making a request. We may charge a reasonable fee for the cost of compiling and providing a large volume of material, and we will tell you the amount before we do the work.

We will ask you to verify your identity before we release anything. We will respond within 30 days.

There are limited situations where the Privacy Act allows us to refuse — for example where giving access would unreasonably affect another person’s privacy, or would reveal information subject to legal professional privilege or a tipping-off prohibition. If we refuse, we will tell you why in writing and explain how to complain.

14. Data breaches

If we suspect a data breach, we will contain and assess it promptly. If a breach is likely to result in serious harm to you and we cannot remediate that risk, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

15. Complaints and contact

Please raise any privacy concern with us first — most issues are resolved quickly.

Privacy Officer

Morgan Conveyancing

Email: julie@morganconveyancing.com.au

Phone: 03 8685 8788

We will acknowledge your complaint within 5 business days and give you a written response within 30 days.

If you are not satisfied with our response, you can complain to:

Office of the Australian Information Commissioner (OAIC)

Website: oaic.gov.au

Phone: 1300 363 992

Post: GPO Box 5288, Sydney NSW 2001

Complaints about our professional conduct or trust account, as distinct from privacy, can be directed to Consumer Affairs Victoria (consumer.vic.gov.au, 1300 55 81 81).

16. Changes to this policy

We review this policy at least annually, and update it whenever our practices change — for example when we adopt a new identity verification tool, change practice management systems, or alter our AML/CTF procedures. The current version is always available here and we will provide a copy free of charge on request in another format if you need one.