If you enrolled with AUSTRAC as a Tranche 2 reporting entity, something else changed at the same time that got far less attention: the Privacy Act now applies to the personal information you handle in connection with your AML/CTF obligations. It's worth being precise about what actually triggered this. It isn't your turnover, and enrolment on its own isn't the legal trigger either โ€” coverage flows from becoming a reporting entity that provides designated services. Your AUSTRAC enrolment is simply the public marker that you now hold that status.

From 1 July 2026, that status brings your AML-related data handling under the Privacy Act, according to guidance published by the Office of the Australian Information Commissioner (OAIC).

Who is affected

The OAIC guidance covers Tranche 2 reporting entities โ€” real estate professionals, lawyers, conveyancers, accountants, dealers in high-value goods, and trust and company service providers. Crucially, coverage applies regardless of the $3 million small business exemption that would otherwise take many of these firms out of the Privacy Act. The OAIC estimates that more than 100,000 small businesses are affected.

So if you're a sole-practitioner conveyancer or a two-partner accounting firm turning over well under $3 million, the exemption you may have relied on in the past does not apply to the personal information you handle for AML/CTF purposes. The KYC data you collect to verify a client โ€” names, dates of birth, identification details โ€” is regulated personal information.

You now answer to two regulators

The practical shift is that you are dual-regulated. AUSTRAC oversees your AML/CTF compliance โ€” your program, your customer due diligence, your reporting. The OAIC oversees how you handle the personal information that sits inside all of that. Two regulators, two sets of obligations, applying to the same client files.

What the 13 Australian Privacy Principles ask of you day-to-day

The Privacy Act is built around the 13 Australian Privacy Principles (APPs). You don't need to become a privacy lawyer, but you do need to translate them into everyday habits. In practice that means:

Because it's difficult to cleanly separate the personal information you handle for AML from the rest of your client records, the safe and practical position is to apply the APPs across your business rather than trying to quarantine one slice of it.

The notifiable data breach scheme

Being covered by the Privacy Act also brings you into the notifiable data breach scheme. In short, you have an obligation to assess suspected data breaches and, for eligible data breaches, to notify both the OAIC and the individuals affected. For a firm holding identity documents and financial details, a lost laptop or a misdirected email is no longer just an awkward moment โ€” it may be a reportable event with a defined process attached.

The ID document retention rule that catches people out

Here's the one most firms don't see coming. The OAIC's guidance tells reporting entities not to hold onto full copies of identification documents, and to delete personal information when it is no longer required. Any allowance to keep full ID documents applies only to documents collected before the AML/CTF reforms.

That matters because of how most firms have historically worked. Driver's licence photos sitting in an email inbox. Passport scans on a shared drive. A folder of PDFs "just in case". Under the new guidance, those ad-hoc copies are a compliance risk rather than a safeguard. The goal is to retain the evidence that you verified someone โ€” without accumulating full document copies you're no longer meant to hold.

What the penalties look like

The Privacy Act's penalty regime is serious. For a serious interference with privacy, a company faces the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover. Non-serious interferences carry penalties of up to $3.3 million. And enforcement is real: the Federal Court has already imposed its first civil penalty under the Privacy Act โ€” $5.8 million against Australian Clinical Labs.

First steps to comply

You don't have to solve all of this at once, but you can make meaningful progress quickly:

A quick note on what hasn't happened: a broader removal of the small business exemption for all businesses is part of a second tranche of privacy reforms being progressed by the Attorney-General's Department. It is not yet legislated and there is no confirmed date. What applies right now is specific โ€” the Privacy Act covering the personal information you handle in connection with your AML/CTF obligations.

You can read the OAIC's guidance in full here: Privacy guidance for reporting entities under the AML/CTF Act.

The CompliDesk Privacy module is launching August 2026.

Privacy policy generator, data inventory, notifiable data breach register, access request log and an APP 5 collection notice generator โ€” built to work alongside the AML/CTF records you already keep. First 50 firms free for 3 months.

Get early access

Related reading: Privacy Act compliance for AML reporting entities ยท For real estate ยท For accountants ยท For lawyers ยท For conveyancers