AML compliance × Privacy
From 1 July 2026, AML/CTF reporting entities are covered by the Privacy Act for their AML-related data handling — even under $3 million turnover. The KYC data you collect is now regulated personal information.
What changed on 1 July 2026
From 1 July 2026, Tranche 2 reporting entities — real estate professionals, lawyers, conveyancers, accountants, dealers in high-value goods, and trust and company service providers — are covered by the Privacy Act for personal information handled in connection with their AML/CTF obligations. This applies regardless of the $3 million small business exemption. The OAIC estimates more than 100,000 small businesses are affected.
What actually triggers coverage. It is not your turnover, and it is not enrolment on its own. Coverage is triggered by being a reporting entity providing designated services, and it applies to the personal information you handle in connection with your AML/CTF obligations. Your AUSTRAC enrolment is simply the marker that you hold that status.
At a minimum, your AML data handling is covered — but we recommend full APP compliance. The Privacy Act reaches the parts of your business providing designated services. In practice, the personal information you collect for AML/CTF purposes is difficult to quarantine from the rest of your files and workflows, so applying the Australian Privacy Principles across the business is the safe and practical position. This is a recommendation, not a claim that the whole of your business is automatically covered.
A hidden compliance risk
The OAIC's guidance tells reporting entities not to hold onto full copies of identification documents, and to delete personal information when it is no longer required. Allowances to keep full ID documents apply only to documents collected before the AML/CTF reforms.
That driver's licence copy sitting in an email inbox, or the passport scan on a shared drive, is now a compliance risk rather than a convenience. CompliDesk replaces ad-hoc ID copies with structured, access-controlled verification records and audit trails — so you keep the evidence you need to show AUSTRAC without accumulating full document copies you are no longer meant to retain.
The CompliDesk Privacy module
The Privacy module is launching August 2026. Each tool is being built to work with the AML/CTF records you already keep in CompliDesk — so your KYC data and your privacy obligations live in one place.
Generate a privacy policy aligned to the 13 Australian Privacy Principles, tailored to a reporting entity's AML/CTF data handling.
Launching August 2026Log and assess suspected breaches, with a built-in OAIC notification workflow for eligible data breaches.
Launching August 2026Keep records of what personal information you hold, where it is stored, and why — the foundation of defensible privacy compliance.
Launching August 2026Track individuals' requests to access their personal information from first contact through to response.
Launching August 2026Produce collection notices aligned to the OAIC's template collection notice, so you tell people what you're collecting and why.
Launching August 2026Who it's for
If you provide designated services and handle KYC data, the Privacy Act now applies to that data. CompliDesk is built for the Tranche 2 professions.
Agents and agencies handling vendor and purchaser ID.
For real estate → 📊Accountants and tax agents collecting client identity data.
For accountants → ⚖️Law firms verifying clients for designated services.
For lawyers → 📑Conveyancers running KYC on property transfers.
For conveyancers →Go to the source
Everything on this page is grounded in the OAIC's guidance for reporting entities. Read it directly.
Join the early-access list for the CompliDesk Privacy module — first 50 firms free for 3 months.
Get early access