The usual framing of this question is security against convenience: portals are safer, email is easier, pick your trade-off.
That framing skips the requirement that actually constrains the decision. Section 56(2)(c) of the Code requires the client file to include copies of all written communications, expressly including electronic communications, between you and the client — and between you and anyone else, to the extent the communication relates to the client.
Whatever channel you choose, everything sent through it has to end up on the file. Email satisfies that by accident, because a sent message is its own record. A portal only satisfies it if it was built to, and a messaging app almost never does.
So the real comparison has three axes, not one: what it protects, what record it leaves, and whether clients will actually use it.
What each one is genuinely good and bad at
No channel is secure in the abstract, and any claim that one is should be treated sceptically. Both have distinct failure modes.
Email attachments fail in ways that are hard to undo. A message sent to the wrong address cannot be recalled in any way you can rely on. The attachment now exists in at least two mailboxes indefinitely, plus any forward. There is no expiry and no revocation. The ASD's small business guidance is direct about the risk concentrated in mailboxes, and a compromised mailbox exposes not one document but every attachment ever sent or received.
What email does well is the record. Every exchange is captured, threaded and searchable without anyone deciding to file it.
Portals address most of those failure modes: access can be revoked, links can expire, a document exists in one place rather than propagating, and access can be logged. They introduce different ones. A portal is only as strong as how clients authenticate to it — a password-only login for a client uploading their passport is weaker than most people assume. Shared or forwarded links defeat the model entirely. Dormant accounts accumulate. And if the portal does not write to the client file, you have improved security while degrading your record.
The channel nobody chose
Messaging apps are where the honest conversation gets uncomfortable. Clients prefer them, they get faster responses, and the messages are unambiguously written communications relating to the client. That makes them part of the file the Code requires you to maintain, sitting on a personal phone outside every control you have. Our guide to file note requirements covers what has to be captured.
The obligations that apply whichever you pick
Section 53 requires documents belonging or relating to a client or former client, in the possession of you or anyone in your business, to be kept securely. A copy on a personal phone is in the possession of a member of your business.
Section 35 prohibits disclosing a client's personal information to a third person without written consent. This is the one that catches sponsored matters: sending a document set to an employer, or copying a family member on an email, is a disclosure unless you hold consent.
The Privacy Act's concept of holding, where the APPs apply, extends beyond physical possession to any record an entity has the right or power to deal with. Documents in a cloud service you administer, or reachable by an offshore team, are held by you.
None of these tells you which channel to use. All of them tell you that the choice cannot be made per-message by whoever is typing.
Choosing by document class
A single rule for everything is what breaks down in practice. Splitting by what is being sent is more workable.
Identity and sensitive documents in. Passports, police certificates, medical results, relationship evidence. This is the strongest case for a portal: high sensitivity, and the client is uploading rather than reading, so link-forwarding is not an issue. Ask for them once and do not have clients re-send them.
Advice and correspondence out. Email is defensible and often better — it reaches the client where they read, threads into a record, and does not require them to log in to receive news. The sensitivity is in the content rather than in a large document set.
Third-party exchanges. Sponsors, employers, translators, medical providers. These need the confidentiality analysis first and the channel decision second. Check consent, then send the minimum.
Anything the client must sign. Purpose-built signing, so the record shows what was signed, by whom, and when.
Departmental correspondence. Straight onto the matter first, forwarded second — so the file is authoritative rather than someone's inbox.
Getting clients to actually use it
A portal nobody logs into is worse than email, because the practice ends up running both and the record fragments.
Adoption is largely determined in the first interaction:
- Introduce it while they are motivated. The moment they are asked for documents is when the login gets created. A portal introduced two weeks later competes with a habit already formed.
- Do not make them choose. If you accept documents by email as well, you have chosen email.
- Assume a phone. Most clients will upload photographs of documents from a phone. If that is awkward, they will email instead.
- Do not require an account to receive something. Reading a letter should not need a login even where uploading a passport does.
- Say why, once, briefly. "So your passport is not sitting in an email inbox" persuades better than a policy.
- Give a fallback for the client who cannot. Some clients genuinely cannot use a portal. Have an answer that is not "email it then", and record the exception.
The channel test
- If a document went to the wrong recipient today, what could you actually do?
- Can you produce every written communication on a matter from one place?
- Are any client documents on a personal phone right now?
- Does your portal require more than a password for clients?
- When a matter closes, does client access lapse?
- Are messaging threads part of the file, or of someone's phone?
- Does sending a document set to a sponsor require a consent check first?
Where a system helps
The distinction that matters is not portal versus email. It is whether the channel writes to the file.
A portal bolted alongside a case management system creates a second place documents live and a second thing to reconcile. A portal that is a view onto the matter — where an upload lands on the file, a message becomes part of the record, and access follows the matter's status — solves the security problem and the record-keeping problem with the same mechanism.
That is also what makes email manageable rather than banned. Correspondence captured against the matter as it is sent and received keeps the convenience of email without the record living in a mailbox.
LodgeHQ gives clients a portal that writes to the matter, and files email correspondence against it too, so one file holds the whole exchange. Our comparison of CRM options for migration agents covers the wider choice; start a free trial to see how it handles document collection.
Verify before you rely on it
No channel is secure in every circumstance, and any vendor claim to the contrary is marketing. Check what your provider actually offers — how clients authenticate, whether links expire, whether access is logged, and what happens to documents when a matter closes. Whether the Privacy Act binds your practice depends on your structure and turnover; read the Act and take advice.
This is general information for migration practices, not security advice tailored to your environment. Where a matter carries physical risk to someone, choose the channel for that matter deliberately.