Last updated: 23 July 2026 · By Cordell Smith, Director, Zettle · General information only — not legal advice.
The short version: An agent asking to rely on the buyer's conveyancer for AML is doing something the rules allow. But the buyer's solicitor shouldn't fill in an emailed web form to make it happen — that means disclosing a client's identity into a system the solicitor doesn't control, which is the solicitor's privacy breach to own. The better way: ask, and the solicitor pushes back a secure link once they've confirmed who's really asking.
Key points — why the emailed web form doesn't work
Over the last few weeks the same request has started landing in my inbox. A real estate agent, on a matter where we're acting as the buyer's solicitor, asking me to click a link and fill in a web form with the buyer's identity details so the agent can tick off their AML check.
The request is legitimate. The law behind it is real, and relying on the buyer's conveyancer is a proper, built-in part of the new AML rules for agents. So this isn't me telling agents they've got it wrong.
But here's the part that I think gets missed: when that request lands, the person being asked to do something risky isn't the agent. It's me.
Whose privacy problem is this, really
Think about what the request actually asks. My client gave me their identity — licence, passport, the lot — in confidence, so I could help them buy a house. The web form asks me to take that identity and type it into a third party's system.
That's a disclosure of my client's personal information to someone outside our relationship. And I can't just do that. Not because I'm being precious, but because the moment I do, I'm the one who's crossed a line — I've handed a client's identity to a platform I don't control, usually through a link that arrived by email, often without my client having agreed to any of it.
So the privacy risk in that exact moment isn't the agent sidestepping anything. It's me, if I respond. My duty of confidence to my client, my obligations under the Privacy Act, my problem if that data goes somewhere it shouldn't. The click is mine to make, which means the exposure is mine to carry.
That's why your buyer's solicitor goes quiet, or says "not like this," instead of just filling it in.
Agents just became privacy-regulated businesses
Here's the part that should stop you in your tracks. The day you started collecting a buyer's or seller's ID for AML, you quietly became a privacy-regulated business. Not eventually — that day.
For years the small-business exemption kept most agencies out of the Privacy Act entirely: under $3 million turnover and it simply didn't apply to you. For your AML work, that shield is gone — one provision switches it off — and the regulator reckons it's about to catch more than 100,000 small businesses who don't know it's coming.
So think about what's sitting on your phone and in your inbox right now: photos of other people's licences, passports, dates of birth — the exact material identity thieves build a whole life out of. Last year that was just admin. Now it's a liability with your name on it. If it leaks — a lost phone, a hacked inbox, a form sent to the wrong place — and someone could be seriously harmed (leaked ID usually clears that bar), you don't just cop the embarrassment: you have to tell the person and the regulator. And since last year, they can take you to court over it directly.
None of this is me having a go — nobody's acting in bad faith, and relying on the buyer's conveyancer is completely legitimate. But the order matters: my disclosure comes first, your handling second, and I'm not going to create my own breach to save you a step. The mechanism is fine. The method — a cold form, an emailed link, a phone full of strangers' IDs — is the problem.
The better way to ask
Now — I know the neat answer is "put a written reliance agreement in place first." And if you and I work together often, we should. But let's be honest: no agent has a signed agreement sitting in a drawer for every solicitor in town, and expecting one before every matter isn't practical. So here's how it works in the real world.
1. Just ask me. When you're relying on the buyer's conveyancer, don't send me a form to fill in — send me a short request, with the buyer's knowledge, and ask for the verification record. That's it. You've started it the right way round.
2. I'll push you a secure share link. This is the key flip. I'm the one holding the verified identity and the client relationship, so I initiate the transfer — through a channel I control — and you receive it. The data never gets typed into a system I can't see. I'm still making a disclosure, but now it's a controlled one, on terms I can stand behind, with my client in the loop.
3. But I'll check you're actually you first. This is the bit I won't skip. A request that lands cold in my inbox could be anyone — a spoofed email wearing your name to harvest a buyer's identity is exactly the kind of scam this whole regime exists to stop. So before I share anything, I'll confirm you're really you, through a channel I trust — not just by hitting reply to whatever arrived. Don't take it personally. It's the same check that protects your buyer, and frankly it protects you too.
4. Keep the details, not the documents. Whatever you end up holding, hold the minimum, keep it secure, and bin it when you're done. The regulator has been explicit: you were never required to keep copies of licences or passports.
5. If we're regular partners, write it down once. For the conveyancers you deal with all the time, a short standing arrangement makes all of the above even quicker — who does what, how records move, who keeps them. Not a prerequisite. Just efficiency.
Do it that way and the thing that's currently a stand-off becomes a two-minute routine: you ask, I verify it's you, I push a link, you're done. Protects the buyer, protects you, and lets me say yes.
Frequently asked questions
Because doing so means disclosing a client's identity into a third party's system — a step the solicitor has to manage under their duty of confidence and the Privacy Act. It's not obstruction; it's the solicitor managing their own obligation.
Ask the solicitor for the verification record, with the buyer's knowledge. If they hold it, they can push you a secure share link — once they've confirmed you're really the person asking.
Not for a one-off. Ask, get verified, receive the link. If you work with the same conveyancers regularly, a short standing arrangement just makes it faster.
Because a request can be spoofed. Confirming the recipient before sending someone's identity is basic protection against exactly the kind of impersonation these rules target — and it protects your buyer.
Yes. The rules expressly allow it. The issue is never the arrangement — it's how the identity data moves.
Where this leaves you
The general picture is settled enough to act on: relying on the buyer's conveyancer is fine, but how you ask decides whether it's clean or a problem — for me first, and for you second. The practical version is simple: ask, get verified, receive a secure link. How it should work on your specific matters isn't something to sort from a blog, though — that's a conversation.
It's one we have all day. If you're sending these requests, come and have it with us — I'd rather build you a way of asking that I can say yes to than keep pausing over web forms I can't.
Zettle is a digital-first conveyancing service. The above is general information about the AML/CTF rules and the Privacy Act and isn't legal advice for your particular situation — for that, it's a Zettle conversation. Getting these requests? Just Zettle it.


