HPG Reality

INFORMATION SECURITY POLICY

INFORMATION SECURITY POLICY

  1. AML/CTF
  • About AML/CTF

In 2024, the Federal Government passed further reforms to monitor and mitigate against money laundering and counter-terrorism finance. Consequently, a suite of Australian businesses, including HPG, are now required, by law, to cooperate with and assist the Federal Government in its anti-money laundering (AML) and counter-terrorism finance (CTF) endeavours.

This Policy is published to inform our valued clients and industry stakeholders as to the obligations that need to be complied with, and the manner and method in which relevant processes will be followed and information protected and disseminated. 

HPG may be required by law to disclose information to Australian Transaction Reports and Analysis Centre (AUSTRAC) or other Government authorities.  HPG may use and disclose Personal information to comply with its obligations under AML/CTF Laws, including reporting obligations to AUSTRAC or other authorities where required or authorised by law.  In some circumstances, AML/CTF Laws may prevent HPG from telling you about certain uses or disclosures.

Where identity documentation is required to be compliant with AML/CTF Laws, HPG is not obliged to keep scanned copies of photocopies of identity documents, but rather HPG is required to keep records of the information needed to demonstrate compliance.

If required to be compliant, HPG may scan, upload or store identity documents securely.  Such digitally stored information is protected pursuant to this policy, and retained and/or disposed pursuant to the data retention and disposal policy set out below.

  • What risks are assessed?
  • Money laundering risk
  • Terrorism financing risk
  • High‑risk client types
  • High‑risk geographic locations
  • Unusual transaction behaviour
  • Politically exposed persons (PEPs)
  • Complex ownership structures

HPG resources utilised to identify risks:

  • APLYiD identity verification
  • AMLHUB risk scoring
  • Enhanced due diligence when required
  • Documenting any suspicious matters
  • Lodging Suspicious Matter Reports (SMRs) when appropriate
  1. Purpose

This Information Security Policy outlines how HPG Realty deals with and protects personal information, business records, and AML/CTF‑related data from unauthorised access, loss, misuse, or disclosure. It supports compliance with:

  • Privacy Act 1988
  • Australian Privacy Principles (APPs)
  • Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth) and Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (Cth) (AML/CTF Laws)
  • AUSTRAC’s requirements for reporting entities
  1. Information that may be collected
  • Personal Information that needs to be collected and stored for the purposes of the AML/CTF Laws, includes the following:
  • full name;
  • date of birth;
  • residential address;
  • contact details;
  • occupation or business information;
  • copies or details of identity documents where collected or sighted;
  • document numbers, expiry dates and issuing authority;
  • information about citizenship, residency or country connections where relevant to risk;
  • information about whether a person is a politically exposed person;
  • sanctions screening results;
  • information about beneficial owners;
  • information about directors, trustees, attorneys or authorised representatives;
  • source of funds or source of wealth information where Enhanced Due Diligence is required;
  • transaction details, including property details, purchase price, deposit and settlement information;
  • information obtained from identify verification providers, Government registers, electronic verification systems or other reporting entities.
  • The collection of the above data is required in order to comply with AML/CTF Laws as follows:
  • verifying the identity of sellers, buyers, transferors and transferees;
  • verifying the authority of any agent, attorney, director, trustee or other representative;
  • identifying beneficial owners of non-individual clients;
  • assessing and managing money laundering, terrorism financing and proliferation financing risk;
  • conducting sanctions and politically exposed persons screening;
  • carrying out initial and ongoing client due diligence;
  • monitoring transactions and client behaviour for unusual or suspicious matters;
  • reporting to AUSTRAC where required;
  • complying with AML/CTF record keeping obligations;
  • maintaining and improving AML/CTF systems, controls and audit trails.
  1. How Information is Collected
  • Information may be collected from a number of miscellaneous sources, including:
  • directly from sellers, buyers, transferors or transferees;
  • from authorised representatives, attorneys, directors, trustees or agents;
  • from real estate transaction documents;
  • from identity documents presented for verification;
  • from electronic verification systems;
  • from Government databases or registers;
  • from conveyancers, solicitors, mortgagees, financiers or other transactional participants where lawful
  • from third party AML/CTF service providers;
  • from sanctions, politically exposed persons, or adverse media screening tools.
  1. Categories of Recipients to Whom AML/CTF Related Personal Information may be Disclosed
  • These entities may include:
  • AUSTRAC;
  • law enforcement, regulatory or Government bodies where required or authorised by law;
  • identity verification service providers;
  • electronic verification of identity (VOI) providers;
  • sanctions, politically exposed persons, and adverse media screening providers;
  • cloud storage, customer relationship management (CRM), trust accounting, transaction management and practice management providers;
  • insurers, auditors, external consultants and professional advisers;
  • other members of HPG’s corporate or franchise group (if applicable);
  • other reporting entities where reliance or information sharing arrangements are lawfully obliged or used.
  1. Sources Utilised for Collection of Personal Information
  • All AML/CTF information (Know Your Customer (KYC), Customer Due Diligence (CDD), verification reports, risk assessments)
  • All devices used for business purposes (phone, laptop, email, cloud storage)
  • All third‑party systems (AMLHUB, APLYiD, email provider, CRM)
  1. Security of Personal Information
  • HPG implements a range of processes to protect and maintain the security of personal information collected for AML/CTF purposes.  They include the following:
  • Information Security Principles
  • Confidentiality protection policies
  • Systems to prevent unauthorised access
  • Systems to detect and respond to security incidents
  • Maintain integrity of systems
  • Staff training and staff confidentiality obligations
  • Compliance Officer
  • Pursuant to AML/CTF Laws, HPG must appoint an AML/CTF Compliance Officer.  The Compliance Officer in this instance shall be Mr Dion Hannant.  The key responsibilities of the Compliance Office are as follows:
  • Oversight – coordinating and managing day to day adherence by HPG to this policy and AML/CTF Laws and obligations;
  • Reporting – acting as the primary conduit for communicating with AUSTRAC (for example, submitting suspicious matter reports and annual compliance reports);
  • Risk Management – ensuring regular updates to the HPG money laundering / counter-terrorism risk assessment and AML/CTF programs.
  1. Security Controls Applied
  • Device Security
  • All devices (phone, laptop) secured with password, PIN, or biometric lock
  • Automatic screen lock enabled
  • Full‑disk encryption enabled (standard on modern iPhones/Samsung/Windows devices)
  • Devices kept updated with latest security patches
    • Access Control
  • access to AML/CTF information only available to HPG Management
  • No shared accounts
  • Access to AMLHUB/APLYiD protected by unique login
  • Multi‑factor authentication (MFA) enabled wherever available
    • Cloud Storage & Email Security
  • Business documents stored in secure cloud storage (OneDrive, Google Drive, or similar)
  • Email account protected with MFA
  • Sensitive documents not stored on unsecured USBs or local drives
    • Data Transmission
  • Personal Information and client documents only sent via secure email or encrypted platforms
  • No Personal Information or client information sent via SMS or social media messaging
  • AML/CTF documents only uploaded through AMLHUB/APLYiD
    • Physical Security
  • Devices kept with the business owner at all times
  • No printed copies of AML/CTF documents unless required
  • Any printed documents stored in a locked cabinet
    • Third‑Party Providers

The business uses trusted, compliant providers:

  • AMLHUB (AML/CTF compliance platform)
  • APLYiD (digital identity verification)
  • Microsoft/Google (email + cloud storage)

Each provider maintains its own security certifications and encryption standards.

  • Data Retention & Disposal
  • Where possible or appropriate, deidentification of identity documents
  • AML/CTF records retained for 7 years(AUSTRAC requirement)
  • Records securely deleted when no longer required
  • Digital deletion must include removal from cloud storage and device backups
  • Paper documents shredded
  1. Security Incident Response

If a breach occurs (lost phone, hacked email, suspicious access), the following steps will be undertaken:

  1. Secure the device or account immediately
  2. Change passwords and enable MFA
  3. Notify AMLHUB if AML/CTF data may be affected
  4. Assess whether a Privacy Act Notifiable Data Breach applies
  5. Document the incident and actions taken
  1. Complaints
  • In the event that any concerns or complaints arise in relation to adherence by HPG to this Policy or the AML/CT Laws and processes, such complaint or concern should be raised with the Compliance Officer.
  1. Review

This policy is reviewed annually or after any major change in systems or AML/CTF requirements.

  1. Risk Management Policy
    • Purpose

This Risk Management Policy outlines how HPG Realty identifies, assesses, and manages risks to information, systems, and AML/CTF compliance.

It supports compliance with:

  • Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth) and Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (Cth) (AML/CTF Laws)
  • AUSTRAC’s reporting entity obligations
  • Privacy Act 1988
  • Australian Privacy Principles
  • Scope

Covers risks relating to:

  • Client personal information
  • AML/CTF data (KYC, CDD, verification reports, SMRs)
  • Business systems (email, cloud storage, AMLHUB, APLYiD)
  • Operational processes (property listings, client onboarding, settlements)
  • Risk Management Approach
    • Identify Risks

Common risks include:

  • Cyber‑attack or hacking
  • Email compromise
  • Lost or stolen phone/laptop
  • Incorrect client verification
  • Fraudulent or high‑risk clients
  • Human error (sending documents to wrong person)
  • System outages (email, AMLHUB, APLYiD)
    • Assess Risks

Each risk is assessed by:

  • Likelihood(Low / Medium / High)
  • Impact(Low / Medium / High)
    • Control Risks

Controls include:

  • MFA on all accounts
  • Secure cloud storage
  • Device encryption
  • Strong password policy
  • Verified third‑party providers
  • AMLHUB risk scoring
  • APLYiD identity verification
  • Annual AML/CTF training
  • Incident response plan
    • Risk Register (Example)

Maintain a risk register

Risk

Likelihood

Impact

Controls

Email hacked

Medium

High

MFA, strong passwords, monitoring

Lost phone

Medium

Medium

Device encryption, remote wipe

Fraudulent client

Medium

High

APLYiD verification, AMLHUB risk scoring

Wrong document sent

Low

Medium

Double‑check process, secure email

Cloud storage breach

Low

High

Trusted providers, MFA

AMLHUB outage

Low

Medium

Delay onboarding until system restored

 

  • Monitoring & Review
  • Risks reviewed annually
  • Controls updated when new technology or threats emerge
  • Any incidents documented and used to improve future controls

Reset password

Enter your email address and we will send you a link to change your password.

Get started with your account

to save your favourite homes and more

Sign up with email

Get started with your account

to save your favourite homes and more

By clicking the «SIGN UP» button you agree to the Terms of Use and Privacy Policy