For authorised agents
If you carry out identity verification on behalf of a reporting entity, you are an authorised agent — and you are covered by the Privacy Act in your own right, whatever your turnover and whatever your client's contract says.
Sign up free todayThe gap nobody is writing about
Which makes sense — they are the ones who enrol with AUSTRAC, write an AML/CTF program and lodge reports. But the reforms also caught a second, quieter group: the businesses that do the identity work for them.
If that is you, you will not find yourself on AUSTRAC's list of newly regulated professions. You are not a reporting entity and you do not enrol. It is easy to conclude that none of this is your problem.
It is your problem, in one specific and important respect. The Office of the Australian Information Commissioner states that in addition to reporting entities, all authorised agents of reporting entities are required to comply with the Privacy Act when handling personal information for the purposes of, or in connection with, AML/CTF obligations — including those which are small businesses with an annual turnover of less than $3 million.
Are you one?
The Privacy Act defines an authorised agent by pointing at section 37 of the AML/CTF Act: a person authorised to act on a reporting entity's behalf in carrying out customer identification procedures.
In plain terms, if a reporting entity has engaged you to collect and verify a customer's identity so that they can meet their customer due diligence obligations, you are carrying out that procedure on their behalf. Businesses that commonly fall into this include:
What you call the arrangement does not decide it. "Administrative support", "onboarding assistance", "document collection" — none of those labels change the analysis. What matters is whether you are carrying out identification procedures on a reporting entity's behalf.
Why you are covered
Section 6E(1A) of the Privacy Act says that where a small business operator is a reporting entity or an authorised agent of a reporting entity, the Privacy Act applies to the activities it carries on for the purposes of, or in connection with, the AML/CTF Act and Rules — as if it were an organisation.
That provision dates from 2006, inserted alongside the original AML/CTF regime. It was not amended in 2024. What changed was the list of designated services: expanding it created tens of thousands of new reporting entities, and everyone acting as an agent for one was swept in at the same moment, by a rule that had been sitting there for twenty years.
This is why the coverage is not something you can negotiate around. It is not a term your client imposed on you, and it is not a policy position that might soften in the next round of consultation. It is structural.
The practical shift
The OAIC's position is that where a reporting entity provides a designated service to a customer through an agent, both the reporting entity and the authorised agent have responsibilities under the Privacy Act.
Two consequences follow, and they cut in opposite directions.
Your client's privacy policy does not cover you. Obligations under the Privacy Act attach to the entity handling the personal information. A contract can allocate commercial risk between you, but it cannot move a statutory obligation onto someone else. If an individual complains about how their identity documents were handled while they were in your systems, that is your complaint to answer.
But you do not inherit their AML/CTF obligations either. Enrolment, the AML/CTF program, suspicious matter reports, transaction monitoring — those stay with the reporting entity. Outsourcing the identity work does not transfer them to you, and you should be wary of any client who suggests otherwise. What you pick up is the privacy side, because you are the one holding the data.
What you actually have to do
You do not need to become a privacy lawyer. You do need to translate a handful of principles into everyday practice.
You need a clearly expressed, up-to-date privacy policy covering how you collect, hold, use and disclose personal information for AML/CTF purposes. Helpfully, if you would otherwise be exempt as a small business, the OAIC says the policy need only cover your AML/CTF handling — there is no requirement to describe your other activities. You also need to be able to receive and respond to privacy complaints, and the OAIC recommends doing so within 30 days.
The individual whose identity you are verifying needs to be told who you are, what you are collecting and why, that the collection is required or authorised by the AML/CTF Act, what happens if they do not provide it, who you usually disclose to, and whether their information goes overseas. As an agent you have a wrinkle a reporting entity does not: the person often thinks they are dealing with your client, not with you. Your notice should make clear who is actually holding their documents.
This is an objective test, and the burden of justifying a collection sits with you. Agents are particularly exposed here, because it is tempting to collect a standard bundle for every matter regardless of what the engagement needs. The OAIC has been explicit that AML obligations are not a blank cheque to collect from everyone as a matter of routine.
You must take reasonable steps to protect the information you hold, including technical and organisational measures. The OAIC notes that entities holding AML data often hold large volumes of sensitive information for long periods, and that this "honey pot" attracts criminal attention. An agent doing verification across many client firms concentrates that risk in one place. Multi-factor authentication, patching, access monitoring and audit logs are all named as examples of reasonable steps — and the standard is scaled to your size and resources, though the OAIC is clear that taking no steps would not be reasonable.
Once information is no longer needed for a purpose you are permitted to hold it for, you must take reasonable steps to destroy or de-identify it. For an agent this is sharper than it looks: once you have handed the verification result to the reporting entity and your engagement is finished, the question of why you are still holding the underlying documents becomes a live one.
If you hold someone's personal information, they can ask you for it, and you must generally respond within a reasonable time — usually 30 days. Agree with your client in advance who fields these, because the individual will ask whoever they think has their data.
If you use an offshore verification tool, you are generally accountable for how that provider handles the information. Their mishandling becomes your breach. The Privacy Act does not prohibit offshore processing — but it does mean you need to have done the due diligence and be comfortable carrying the risk.
Being covered brings you into the Notifiable Data Breach scheme: assess suspected breaches and, for eligible ones, notify the OAIC and the affected individuals. Have the plan before you need it. In the first civil penalty case under the Privacy Act, two of the three penalty limbs concerned the failure to assess and notify — not the breach itself.
The one that catches people
From 31 March 2026 for Tranche 1 entities and 1 July 2026 for Tranche 2, the AML/CTF Act does not require scanned copies or photocopies of identity documents to be kept for record-keeping purposes.
For an agent, this matters more than for most. The classic pattern is a folder of licence photos and passport scans kept "in case the client firm asks for them later" — which is exactly the holding that APP 11.2 now asks you to justify, and exactly the holding that turns a minor incident into a serious one.
What to keep instead. The OAIC sets out what a compliant record looks like: the information taken from the document — name, date of birth, residential address, date of expiry, passport or licence number — plus the type of document, what you did to identify the customer, and the outcome of your verification and risk assessment.
Do not clean out your archive. Copies made before 31 March 2026 are records for the purposes of the AML/CTF Act and must be kept for 7 years following the end of the business relationship or the last occasional transaction. Deleting those to "get compliant" would put your client in breach of their record-keeping obligations.
Where CompliDesk fits
CompliDesk was built for reporting entities, and it works the same way for the agents acting on their behalf — because the record you both need is the same record.
The Privacy module — privacy policy generator, data inventory, notifiable data breach register, access request log and an APP 5 collection notice generator — is live now, and is free for every CompliDesk customer until 10 December 2026 — when the Privacy Act’s automated decision-making disclosure rules commence and every privacy policy needs updating anyway. Get early access.
Create your CompliDesk account and run identity verification that produces the record you are meant to keep — not the one you are meant to destroy.
Sign up free today