An agent I've never heard of sent me a link to upload my client's ID to

By
Cordell Smith
on
23 July 2026
Blog
eConveyancing
Illustration of a buyer's ID being shared securely for an AML check — an emailed link, an identity form, a verification shield and a padlock.

Last updated: 27 July 2026 · By Cordell Smith, Director, Zettle · General information only — not legal advice.

The short version: An agent asking to rely on the buyer's conveyancer for AML is doing something the rules allow. The problem is the emailed web form. Filling one in means the buyer's conveyancer hands their client's identity into a system they don't control, without the client having agreed to it — and that hand-over is the conveyancer's to answer for. Ask instead, and the conveyancer can get their client's consent and provide the necessary information.

Key points — why the emailed web form doesn't work

Over the last few weeks the same request has kept landing in my inbox. A real estate agent, on a matter where we're acting for the buyer, asking me to click a link and fill in a web form with the buyer's identity details so the agent can tick off their AML check. Different agency each time, same form, same link. Somewhere out there is a compliance product with a very good sales team.

The request is legitimate. Relying on the buyer's conveyancer is built into the new AML rules for agents, so this isn't me telling agents they've got it wrong.

What the request misses is that the risky step belongs to me. I'm the one being asked to move a client's identity somewhere new.

Whose privacy problem is this, really

Think about what the request actually asks. My client gave me their identity — licence, passport, the lot — in confidence, so I could help them buy a house. The web form asks me to take that identity and type it into a third party's system.

That's a disclosure of my client's personal information to someone outside our relationship, and I can't just do it. Once I've typed it in, a client's identity is sitting in a platform I don't control, reached through a link that arrived by email, usually without my client having agreed to any of it.

So the privacy risk in that moment isn't the agent sidestepping anything. It's mine, if I respond. My duty of confidence to my client, my obligations under the Privacy Act. My problem if that data goes somewhere it shouldn't.

That's why your buyer's conveyancer goes quiet, or says "not like this," instead of filling it in.

The better way to ask

Worth saying first: no conveyancer has to agree to this. Being relied on means my verification is carrying part of your compliance, so some will simply decline. I'm not one of them — but the way you ask decides whether I can say yes.

Now, the neat answer is a written reliance agreement before any of this. If you and I work together often, we should. But nobody has a folder of signed agreements for every conveyancer in town, and the law didn't arrive with one either. So here's how it works in the real world.

1. Just ask me. When you're relying on the buyer's conveyancer, don't send me a form to fill in. Send me a short request asking for the verification record, and tell me what you need it for.

2. I'll get my client's consent first. The identity itself was verified up front: document checks plus facial biometrics, done digitally when the buyer engaged us. But they consented to me onboarding them, not to me handing their ID to a third party. The OAIC expects consent that's voluntary, informed, current and specific. So my client hears who's asking, what I'd be sending, why, and what it means for them, and then decides. A general authorisation sitting in my engagement terms doesn't do that work. Neither does your assurance that they're happy with it, because they didn't give it to you. It's one email on my end.

3. I'll check you're actually you. A request that lands cold in my inbox could be anyone — a spoofed email wearing your name to harvest a buyer's identity is exactly the kind of scam this whole regime exists to stop. So before I share anything, I'll confirm you're really you, through a channel I trust, not just by hitting reply to whatever arrived. Don't take it personally. It's the same check that protects your buyer.

4. Then I'll push you a secure share link. I'm the one holding the verified identity and the client relationship, so I start the transfer and you receive it — a link I've issued, sent to an address I've confirmed, that expires. Your buyer's details never get typed into a system I can't see. I'm still sharing a client's identity, but in a controlled way, on terms I can stand behind, with my client having agreed to it.

5. Keep the details, not the documents. Whatever you end up holding, hold the minimum, keep it secure, and bin it when you're done. The privacy regulator has been explicit: don't retain copies of licences or passports unless there's an overriding reason to. Keep the record of what you verified — what you checked and when — not the document itself.

6. If we're regular partners, write it down once. For the conveyancers you deal with all the time, a reliance agreement makes all of the above quicker — who does what, how records move, who keeps them. Not a prerequisite. Just efficiency.

Do it that way and the thing that's currently a stand-off becomes routine: you ask, I check with my client, I confirm it's you, I push a link, you're done. No unnecessary duplication of your buyer's personal information, nothing sitting on your phone that becomes your problem later, and I get to say yes.

Frequently asked questions

Why won't the buyer's conveyancer just fill in my AML web form?
Because doing so means handing a client's identity into a third party's system — a step the conveyancer has to manage under their duty of confidence and the Privacy Act, and one that needs the client's consent first. It's not obstruction; it's the conveyancer managing their own obligation.

What should I do instead?
Ask the conveyancer for the verification record. They'll get the buyer's consent, confirm you're really the person asking, then push you a secure share link.

Do I need a written reliance agreement first?
Not for a one-off. Ask, get verified, receive the link. If you work with the same conveyancers regularly, a reliance agreement just makes it faster.

Why does the conveyancer need to verify who I am?
Because a request can be spoofed. Confirming the recipient before sending someone's identity is basic protection against exactly the kind of impersonation these rules target — and it protects your buyer.

Can a real estate agent rely on the buyer's conveyancer for AML?
Yes. The AML rules expressly allow an agent to rely on the identity check done by another reporting entity in the same transaction, such as the buyer's conveyancer. The issue is never the arrangement — it's how the identity data moves.

Where this leaves you

Relying on the buyer's conveyancer is fine. How you ask determines whether it's creating a problem for me or not. Ask, let me square it with my client, confirm you're really you, and receive what you need.

How that works on your specific matters isn't something to sort out from a blog. It's a conversation, and it's one we have all day. If you're sending these requests, come and have it with us — I'd rather build you a way of asking I can say yes to than keep pausing over web forms I can't.

Zettle is a digital-first conveyancing service. The above is general information about the AML/CTF rules and the Privacy Act, not legal advice for your situation.

Next request that lands in your inbox — send it to us instead of the form. Just Zettle it.

Contact Zettle Support

Need more help?

If you have any queries you cannot locate an answer for:

Contact us
Get a Free Conveyancing Quote

Get a quote

Our fixed upfront pricing ensures there are no surprises down the road:

Get a quote