If you enrolled with AUSTRAC as a Tranche 2 reporting entity, something else changed at the same time that got far less attention: the Privacy Act now applies to the personal information you handle in connection with your AML/CTF obligations. It's worth being precise about what actually triggered this. It isn't your turnover, and enrolment on its own isn't the legal trigger either โ coverage flows from becoming a reporting entity that provides designated services. Your AUSTRAC enrolment is simply the public marker that you now hold that status.
From 1 July 2026, that status brings your AML-related data handling under the Privacy Act, according to guidance published by the Office of the Australian Information Commissioner (OAIC).
Who is affected
The OAIC guidance covers Tranche 2 reporting entities โ real estate professionals, lawyers, conveyancers, accountants, dealers in high-value goods, and trust and company service providers. Crucially, coverage applies regardless of the $3 million small business exemption that would otherwise take many of these firms out of the Privacy Act. The OAIC estimates that more than 100,000 small businesses are affected.
So if you're a sole-practitioner conveyancer or a two-partner accounting firm turning over well under $3 million, the exemption you may have relied on in the past does not apply to the personal information you handle for AML/CTF purposes. The KYC data you collect to verify a client โ names, dates of birth, identification details โ is regulated personal information.
You now answer to two regulators
The practical shift is that you are dual-regulated. AUSTRAC oversees your AML/CTF compliance โ your program, your customer due diligence, your reporting. The OAIC oversees how you handle the personal information that sits inside all of that. Two regulators, two sets of obligations, applying to the same client files.
What the 13 Australian Privacy Principles ask of you day-to-day
The Privacy Act is built around the 13 Australian Privacy Principles (APPs). You don't need to become a privacy lawyer, but you do need to translate them into everyday habits. In practice that means:
- Having an up-to-date privacy policy that reflects how your firm actually handles personal information (APP 1).
- Telling people what you're collecting and why at the point you collect it โ a collection notice โ aligned to the OAIC's template collection notice (APP 5).
- Only collecting the personal information you genuinely need for your AML/CTF obligations, and being clear about how you'll use it (APPs 3 and 6).
- Keeping that information secure with appropriate access controls, and deleting or de-identifying it when it's no longer required (APP 11).
- Being able to respond when an individual asks to access or correct the personal information you hold about them (APPs 12 and 13).
Because it's difficult to cleanly separate the personal information you handle for AML from the rest of your client records, the safe and practical position is to apply the APPs across your business rather than trying to quarantine one slice of it.
The notifiable data breach scheme
Being covered by the Privacy Act also brings you into the notifiable data breach scheme. In short, you have an obligation to assess suspected data breaches and, for eligible data breaches, to notify both the OAIC and the individuals affected. For a firm holding identity documents and financial details, a lost laptop or a misdirected email is no longer just an awkward moment โ it may be a reportable event with a defined process attached.
The ID document retention rule that catches people out
Here's the one most firms don't see coming. The OAIC's guidance tells reporting entities not to hold onto full copies of identification documents, and to delete personal information when it is no longer required. Any allowance to keep full ID documents applies only to documents collected before the AML/CTF reforms.
That matters because of how most firms have historically worked. Driver's licence photos sitting in an email inbox. Passport scans on a shared drive. A folder of PDFs "just in case". Under the new guidance, those ad-hoc copies are a compliance risk rather than a safeguard. The goal is to retain the evidence that you verified someone โ without accumulating full document copies you're no longer meant to hold.
What the penalties look like
The Privacy Act's penalty regime is serious. For a serious interference with privacy, a company faces the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover. Non-serious interferences carry penalties of up to $3.3 million. And enforcement is real: the Federal Court has already imposed its first civil penalty under the Privacy Act โ $5.8 million against Australian Clinical Labs.
First steps to comply
You don't have to solve all of this at once, but you can make meaningful progress quickly:
- Read the OAIC's guidance for reporting entities so you're working from the source, not second-hand summaries.
- Publish or update a privacy policy that reflects how you actually handle client data.
- Add a collection notice to your onboarding so clients are told what you're collecting and why.
- Audit where identity documents currently live โ inboxes, drives, desktops โ and stop retaining full copies you're not meant to keep.
- Build a simple record of what personal information you hold, where it sits, and why.
- Know your data breach process before you need it.
A quick note on what hasn't happened: a broader removal of the small business exemption for all businesses is part of a second tranche of privacy reforms being progressed by the Attorney-General's Department. It is not yet legislated and there is no confirmed date. What applies right now is specific โ the Privacy Act covering the personal information you handle in connection with your AML/CTF obligations.
You can read the OAIC's guidance in full here: Privacy guidance for reporting entities under the AML/CTF Act.
The CompliDesk Privacy module is launching August 2026.
Privacy policy generator, data inventory, notifiable data breach register, access request log and an APP 5 collection notice generator โ built to work alongside the AML/CTF records you already keep. First 50 firms free for 3 months.
Get early accessRelated reading: Privacy Act compliance for AML reporting entities ยท For real estate ยท For accountants ยท For lawyers ยท For conveyancers