If you enrolled with AUSTRAC as a Tranche 2 reporting entity, something else changed at the same time that got far less attention: the Privacy Act now applies to the personal information you handle in connection with your AML/CTF obligations. It's worth being precise about what actually triggered this. It isn't your turnover, and enrolment on its own isn't the legal trigger either β coverage flows from becoming a reporting entity that provides designated services. Your AUSTRAC enrolment is simply the public marker that you now hold that status.
From 1 July 2026, that status brings your AML-related data handling under the Privacy Act, according to guidance published by the Office of the Australian Information Commissioner (OAIC).
That distinction cuts both ways, and the second direction is the one worth pausing on. If you are providing designated services but haven't enrolled yet, you are still covered. Enrolment isn't the switch.
Nothing in the Privacy Act actually changed
The part almost every summary gets wrong is that the 2024 AML/CTF reforms did not amend the Privacy Act at all. The provision that catches you, section 6E(1A), was written in 2006 alongside the original AML/CTF regime, and it has been sitting there ever since.
It says that where a small business operator is a reporting entity β or an authorised agent of one β the Privacy Act applies to the activities it carries on "for the purposes of, or in connection with" the AML/CTF Act and Rules, as if it were an organisation. In other words, the trigger was built two decades ago and left loaded. What changed in 2024 was the list of designated services. Expanding that list expanded who counts as a reporting entity, and section 6E(1A) did the rest automatically.
This is worth knowing because it tells you something about how durable the change is. This isn't a policy position that might be softened in the next round of consultation β it's structural.
Who is affected
The OAIC guidance covers Tranche 2 reporting entities β real estate professionals, lawyers, conveyancers, accountants, dealers in high-value goods, and trust and company service providers. Crucially, coverage applies regardless of the $3 million small business exemption that would otherwise take many of these firms out of the Privacy Act. In announcing the guidance, the OAIC put the number of small businesses affected at more than 100,000.
So if you're a sole-practitioner conveyancer or a two-partner accounting firm turning over well under $3 million, the exemption you may have relied on in the past does not apply to the personal information you handle for AML/CTF purposes. The KYC data you collect to verify a client β names, dates of birth, identification details β is regulated personal information.
There's a group here that almost nobody is writing for: authorised agents. If you carry out customer identification on behalf of a reporting entity β an outsourced KYC provider, a settlement agent, a paralegal service running client ID checks β you're covered in your own right, whatever your turnover. The OAIC puts it plainly: where a reporting entity provides a designated service through an agent, both the entity and the agent have Privacy Act responsibilities. You don't have to be the reporting entity to be on the hook. If that's you, we've written a separate guide for authorised agents covering what you're responsible for and β just as usefully β what you aren't.
You now answer to two regulators
The practical shift is that you are dual-regulated. AUSTRAC oversees your AML/CTF compliance β your program, your customer due diligence, your reporting. The OAIC oversees how you handle the personal information that sits inside all of that. Two regulators, two sets of obligations, applying to the same client files.
What the 13 Australian Privacy Principles ask of you day-to-day
The Privacy Act is built around the 13 Australian Privacy Principles (APPs). You don't need to become a privacy lawyer, but you do need to translate them into everyday habits. In practice that means:
- Having an up-to-date privacy policy that reflects how your firm actually handles personal information (APP 1).
- Telling people what you're collecting and why at the point you collect it β a collection notice β aligned to the OAIC's template collection notice (APP 5).
- Only collecting the personal information you genuinely need for your AML/CTF obligations, and being clear about how you'll use it (APPs 3 and 6).
- Keeping that information secure with appropriate access controls, and deleting or de-identifying it when it's no longer required (APP 11).
- Being able to respond when an individual asks to access or correct the personal information you hold about them (APPs 12 and 13).
How much of your business is actually covered
Strictly, only the personal information you handle in connection with your AML/CTF obligations. The OAIC says so directly: small businesses aren't covered for their other business activities, and if you'd otherwise be exempt, your privacy policy only needs to describe your AML/CTF data handling β not everything else you do.
But the test follows the data, not the department. The OAIC's own worked example is a real estate agency turning over $1.1 million: where it collects client details and transaction records to deliver the service and to meet its AML obligations, the Privacy Act applies to that information. Dual-purpose data is covered data.
In a professional firm, a great deal of what you hold is dual-purpose. That's why our recommendation is to apply the APPs across the business β not because the law demands it everywhere, but because drawing the line precisely is harder than just holding one standard. That's a practical recommendation, not a legal requirement.
The notifiable data breach scheme
Being covered by the Privacy Act also brings you into the notifiable data breach scheme. In short, you have an obligation to assess suspected data breaches and, for eligible data breaches, to notify both the OAIC and the individuals affected. For a firm holding identity documents and financial details, a lost laptop or a misdirected email is no longer just an awkward moment β it may be a reportable event with a defined process attached.
One wrinkle specific to AML: notification doesn't apply where it would be inconsistent with a secrecy provision, including the tipping-off prohibition. In some cases that means notifying the OAIC but not the individual. The same logic runs through your access requests β if refusing someone access to their information is required to avoid tipping off, your refusal notice must not explain why. Most off-the-shelf privacy templates get that backwards.
The ID document rule that catches people out
Here's the one most firms don't see coming β and the one most often reported wrongly. From 31 March 2026 for Tranche 1 entities and 1 July 2026 for Tranche 2, the AML/CTF Act no longer requires you to keep scanned copies or photocopies of identity documents for record-keeping. Under APP 11.2, you should take reasonable steps to destroy or de-identify full copies once you no longer need them.
Note what that is and isn't. It's the removal of a requirement to keep them, plus a duty to destroy them once they're genuinely no longer needed. It is not a ban on ever holding an ID copy. And the OAIC has explicitly said it expects this to take time β "reasonable steps" are judged against your size, your resources, and the scale of the job of changing your systems.
One thing you should not do is a clean-out of your archive. Copies you made before 31 March 2026 are records for the purposes of the AML/CTF Act, and the OAIC's guidance says they must be kept for 7 years after the end of the business relationship or the last occasional transaction. Deleting those to "get compliant" would put you in breach.
For new verifications, the OAIC sets out what a good record looks like: the details taken from the document β name, date of birth, residential address, expiry date, passport or licence number β plus the document type, what you did to identify the customer, and the outcome of your verification and risk assessment. That's the evidence you need. The scan itself isn't.
What the penalties look like
Since December 2024 the Privacy Act has had a three-tier civil penalty regime, introduced by the Privacy and Other Legislation Amendment Act 2024:
- Serious interference with privacy (s 13G). For a company, the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover for the breach turnover period. For anyone other than a company, $2.5 million. These are fixed dollar figures, so indexation doesn't move them.
- Interference that isn't "serious" (s 13H). 2,000 penalty units, or 10,000 for a company β $728,000 and $3.64 million.
- Administrative breaches (s 13K) β such as not having a compliant privacy policy. 200 penalty units, or 1,000 for a company β $72,800 and $364,000. These can also be dealt with by infringement notice, at $4,368 for an individual and $21,840 for a company.
One note on those numbers, because a lot of published commentary is now out of date. A Commonwealth penalty unit rose from $330 to $364 on 1 July 2026. Penalties are calculated using the value in force when the conduct happened β and since Tranche 2 obligations only began on 1 July 2026, everything you do as a newly covered reporting entity is priced at $364. If you see $3.3 million quoted for the middle tier, that's the old figure.
Enforcement is real. In Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224, the Federal Court imposed the first civil penalty in the history of the Privacy Act: $5.8 million, made up of $4.2 million for failing to take reasonable steps to secure personal information β 223,000 separate contraventions of APP 11 β plus $800,000 for failing to assess a suspected breach (s 26WH) and $800,000 for failing to notify one (s 26WK), and $400,000 in costs. Two of those three limbs were about the response, not the breach itself.
That said, it's worth reading what the regulator has actually said about firms in your position. The OAIC describes its approach as risk-based and harm-focused, states that its expectations for small business are not the same as for large businesses, and says it recognises these reforms may require significant change β treating that as relevant to the proportionate use of its powers. This is a regulator signalling a soft landing rather than a crackdown. But it's explicit on the other side too: it would not be reasonable for a small business to take no steps.
First steps to comply
You don't have to solve all of this at once, but you can make meaningful progress quickly:
- Read the OAIC's guidance for reporting entities so you're working from the source, not second-hand summaries.
- Publish or update a privacy policy that reflects how you actually handle client data.
- Add a collection notice to your onboarding so clients are told what you're collecting and why.
- Audit where identity documents currently live β inboxes, drives, desktops. Stop collecting full copies you no longer need, and check the date on anything before you delete it: pre-31 March 2026 copies stay.
- Build a simple record of what personal information you hold, where it sits, and why.
- Know your data breach process before you need it.
A quick note on what hasn't happened: a broader removal of the small business exemption for all businesses is part of a second tranche of privacy reforms being progressed by the Attorney-General's Department. It is not yet legislated and there is no confirmed date. What applies right now is specific β the Privacy Act covering the personal information you handle in connection with your AML/CTF obligations.
You can read the OAIC's guidance in full here: Privacy guidance for reporting entities under the AML/CTF Act.
The CompliDesk Privacy module is live now.
Privacy policy generator, data inventory, notifiable data breach register, access request log and an APP 5 collection notice generator β built to work alongside the AML/CTF records you already keep. Free for every CompliDesk customer until 10 December 2026.
Get early accessRelated reading: Privacy Act compliance for AML reporting entities Β· For authorised agents Β· For real estate Β· For accountants Β· For lawyers Β· For conveyancers