How It Works Pricing Privacy Act About Contact Log in Get Started Free

For authorised agents

Doing KYC for someone else? The Privacy Act applies to you.

If you carry out identity verification on behalf of a reporting entity, you are an authorised agent — and you are covered by the Privacy Act in your own right, whatever your turnover and whatever your client's contract says.

Sign up free today

The gap nobody is writing about

Almost everything written about Tranche 2 is addressed to reporting entities

Which makes sense — they are the ones who enrol with AUSTRAC, write an AML/CTF program and lodge reports. But the reforms also caught a second, quieter group: the businesses that do the identity work for them.

If that is you, you will not find yourself on AUSTRAC's list of newly regulated professions. You are not a reporting entity and you do not enrol. It is easy to conclude that none of this is your problem.

It is your problem, in one specific and important respect. The Office of the Australian Information Commissioner states that in addition to reporting entities, all authorised agents of reporting entities are required to comply with the Privacy Act when handling personal information for the purposes of, or in connection with, AML/CTF obligations — including those which are small businesses with an annual turnover of less than $3 million.

Are you one?

What makes someone an authorised agent

The Privacy Act defines an authorised agent by pointing at section 37 of the AML/CTF Act: a person authorised to act on a reporting entity's behalf in carrying out customer identification procedures.

In plain terms, if a reporting entity has engaged you to collect and verify a customer's identity so that they can meet their customer due diligence obligations, you are carrying out that procedure on their behalf. Businesses that commonly fall into this include:

What you call the arrangement does not decide it. "Administrative support", "onboarding assistance", "document collection" — none of those labels change the analysis. What matters is whether you are carrying out identification procedures on a reporting entity's behalf.

Why you are covered

A provision written in 2006, waiting for you

Section 6E(1A) of the Privacy Act says that where a small business operator is a reporting entity or an authorised agent of a reporting entity, the Privacy Act applies to the activities it carries on for the purposes of, or in connection with, the AML/CTF Act and Rules — as if it were an organisation.

That provision dates from 2006, inserted alongside the original AML/CTF regime. It was not amended in 2024. What changed was the list of designated services: expanding it created tens of thousands of new reporting entities, and everyone acting as an agent for one was swept in at the same moment, by a rule that had been sitting there for twenty years.

This is why the coverage is not something you can negotiate around. It is not a term your client imposed on you, and it is not a policy position that might soften in the next round of consultation. It is structural.

The practical shift

Both of you are responsible — not one or the other

The OAIC's position is that where a reporting entity provides a designated service to a customer through an agent, both the reporting entity and the authorised agent have responsibilities under the Privacy Act.

Two consequences follow, and they cut in opposite directions.

Your client's privacy policy does not cover you. Obligations under the Privacy Act attach to the entity handling the personal information. A contract can allocate commercial risk between you, but it cannot move a statutory obligation onto someone else. If an individual complains about how their identity documents were handled while they were in your systems, that is your complaint to answer.

But you do not inherit their AML/CTF obligations either. Enrolment, the AML/CTF program, suspicious matter reports, transaction monitoring — those stay with the reporting entity. Outsourcing the identity work does not transfer them to you, and you should be wary of any client who suggests otherwise. What you pick up is the privacy side, because you are the one holding the data.

What you actually have to do

Your obligations, in the order they will bite

You do not need to become a privacy lawyer. You do need to translate a handful of principles into everyday practice.

A privacy policy that describes this work (APP 1)

You need a clearly expressed, up-to-date privacy policy covering how you collect, hold, use and disclose personal information for AML/CTF purposes. Helpfully, if you would otherwise be exempt as a small business, the OAIC says the policy need only cover your AML/CTF handling — there is no requirement to describe your other activities. You also need to be able to receive and respond to privacy complaints, and the OAIC recommends doing so within 30 days.

Collection notices at the point you collect (APP 5)

The individual whose identity you are verifying needs to be told who you are, what you are collecting and why, that the collection is required or authorised by the AML/CTF Act, what happens if they do not provide it, who you usually disclose to, and whether their information goes overseas. As an agent you have a wrinkle a reporting entity does not: the person often thinks they are dealing with your client, not with you. Your notice should make clear who is actually holding their documents.

Collect only what is reasonably necessary (APP 3)

This is an objective test, and the burden of justifying a collection sits with you. Agents are particularly exposed here, because it is tempting to collect a standard bundle for every matter regardless of what the engagement needs. The OAIC has been explicit that AML obligations are not a blank cheque to collect from everyone as a matter of routine.

Security, and the honeypot problem (APP 11.1)

You must take reasonable steps to protect the information you hold, including technical and organisational measures. The OAIC notes that entities holding AML data often hold large volumes of sensitive information for long periods, and that this "honey pot" attracts criminal attention. An agent doing verification across many client firms concentrates that risk in one place. Multi-factor authentication, patching, access monitoring and audit logs are all named as examples of reasonable steps — and the standard is scaled to your size and resources, though the OAIC is clear that taking no steps would not be reasonable.

Destroy what you no longer need (APP 11.2)

Once information is no longer needed for a purpose you are permitted to hold it for, you must take reasonable steps to destroy or de-identify it. For an agent this is sharper than it looks: once you have handed the verification result to the reporting entity and your engagement is finished, the question of why you are still holding the underlying documents becomes a live one.

Access and correction requests (APPs 12 and 13)

If you hold someone's personal information, they can ask you for it, and you must generally respond within a reasonable time — usually 30 days. Agree with your client in advance who fields these, because the individual will ask whoever they think has their data.

Overseas providers (APP 8 and s 16C)

If you use an offshore verification tool, you are generally accountable for how that provider handles the information. Their mishandling becomes your breach. The Privacy Act does not prohibit offshore processing — but it does mean you need to have done the due diligence and be comfortable carrying the risk.

Data breaches

Being covered brings you into the Notifiable Data Breach scheme: assess suspected breaches and, for eligible ones, notify the OAIC and the affected individuals. Have the plan before you need it. In the first civil penalty case under the Privacy Act, two of the three penalty limbs concerned the failure to assess and notify — not the breach itself.

The one that catches people

Stop keeping copies of the documents

From 31 March 2026 for Tranche 1 entities and 1 July 2026 for Tranche 2, the AML/CTF Act does not require scanned copies or photocopies of identity documents to be kept for record-keeping purposes.

For an agent, this matters more than for most. The classic pattern is a folder of licence photos and passport scans kept "in case the client firm asks for them later" — which is exactly the holding that APP 11.2 now asks you to justify, and exactly the holding that turns a minor incident into a serious one.

What to keep instead. The OAIC sets out what a compliant record looks like: the information taken from the document — name, date of birth, residential address, date of expiry, passport or licence number — plus the type of document, what you did to identify the customer, and the outcome of your verification and risk assessment.

Do not clean out your archive. Copies made before 31 March 2026 are records for the purposes of the AML/CTF Act and must be kept for 7 years following the end of the business relationship or the last occasional transaction. Deleting those to "get compliant" would put your client in breach of their record-keeping obligations.

Where CompliDesk fits

Structured verification records instead of a folder of scans

CompliDesk was built for reporting entities, and it works the same way for the agents acting on their behalf — because the record you both need is the same record.

The Privacy module — privacy policy generator, data inventory, notifiable data breach register, access request log and an APP 5 collection notice generator — is live now, and is free for every CompliDesk customer until 10 December 2026 — when the Privacy Act’s automated decision-making disclosure rules commence and every privacy policy needs updating anyway. Get early access.

Questions authorised agents ask us most

Probably yes. The Privacy Act defines an authorised agent by reference to section 37 of the AML/CTF Act — a person authorised to carry out customer identification procedures on a reporting entity's behalf. If a firm has engaged you to collect and verify a client's identity so that the firm can meet its customer due diligence obligations, that is what you are doing, whatever your engagement letter calls it. The label on the arrangement does not decide it; what you actually do does.
Not for this work. The small business exemption normally takes businesses under $3 million turnover out of the Privacy Act entirely. Section 6E(1A) switches that off for reporting entities and their authorised agents, in relation to the activities they carry on for the purposes of, or in connection with, the AML/CTF Act and Rules. The OAIC states this directly: authorised agents must comply with the Privacy Act when handling personal information for AML/CTF purposes, including those which are small businesses with an annual turnover of less than $3 million.
No. The OAIC's position is that where a reporting entity provides a designated service through an agent, both the reporting entity and the agent have responsibilities under the Privacy Act. Your obligations are your own — they do not sit behind your client's, and a contract cannot move them onto someone else. Your client may well impose obligations on you as well, but that is in addition to the law, not instead of it.
Not because you are an agent. Enrolment applies to reporting entities — businesses providing designated services. Acting as an agent for one does not make you a reporting entity, and outsourcing does not transfer the reporting entity's AML/CTF obligations to you; those stay with them. What you pick up is the Privacy Act side, because you are the one handling the personal information. If your own business separately provides a designated service, that is a different question and enrolment may apply on that basis.
The personal information you handle in connection with AML/CTF obligations. The OAIC is clear that small businesses are not covered for their other business activities, and that a privacy policy for an otherwise-exempt business need only describe its AML/CTF data handling. In practice, if identity verification work is most of what you do, that is most of your data — which is why agents often find it simpler to hold one standard across the business.
Then APP 8 and section 16C apply to you. If you disclose personal information to an overseas recipient, you are generally accountable for how that recipient handles it — their mishandling becomes your breach. Exceptions apply, including where the disclosure is required or authorised by the AML/CTF Act or Rules. Before you engage anyone, the OAIC expects you to have reviewed how they collect, handle and store personal information, and to have satisfied yourself they have appropriate processes in place.

Covered in your own right. Get set up properly.

Create your CompliDesk account and run identity verification that produces the record you are meant to keep — not the one you are meant to destroy.

Sign up free today