How It Works Pricing Privacy Act About Contact Log in Get Started Free

AML compliance × Privacy

Enrolled with AUSTRAC? The Privacy Act now applies to you.

From 1 July 2026, AML/CTF reporting entities are covered by the Privacy Act for their AML-related data handling — even under $3 million turnover. The KYC data you collect is now regulated personal information.

Get early access Read the OAIC guidance

What changed on 1 July 2026

Becoming a reporting entity triggered Privacy Act obligations

From 1 July 2026, Tranche 2 reporting entities — real estate professionals, lawyers, conveyancers, accountants, dealers in high-value goods, and trust and company service providers — are covered by the Privacy Act for personal information handled in connection with their AML/CTF obligations. This applies regardless of the $3 million small business exemption. The OAIC estimates more than 100,000 small businesses are affected.

What actually triggers coverage. It is not your turnover, and it is not enrolment on its own. Coverage is triggered by being a reporting entity providing designated services, and it applies to the personal information you handle in connection with your AML/CTF obligations. Your AUSTRAC enrolment is simply the marker that you hold that status.

At a minimum, your AML data handling is covered — but we recommend full APP compliance. The Privacy Act reaches the parts of your business providing designated services. In practice, the personal information you collect for AML/CTF purposes is difficult to quarantine from the rest of your files and workflows, so applying the Australian Privacy Principles across the business is the safe and practical position. This is a recommendation, not a claim that the whole of your business is automatically covered.

A hidden compliance risk

You may be holding ID documents you shouldn't be

The OAIC's guidance tells reporting entities not to hold onto full copies of identification documents, and to delete personal information when it is no longer required. Allowances to keep full ID documents apply only to documents collected before the AML/CTF reforms.

That driver's licence copy sitting in an email inbox, or the passport scan on a shared drive, is now a compliance risk rather than a convenience. CompliDesk replaces ad-hoc ID copies with structured, access-controlled verification records and audit trails — so you keep the evidence you need to show AUSTRAC without accumulating full document copies you are no longer meant to retain.

The CompliDesk Privacy module

Everything you need for Privacy Act compliance, alongside your AML/CTF program

The Privacy module is launching August 2026. Each tool is being built to work with the AML/CTF records you already keep in CompliDesk — so your KYC data and your privacy obligations live in one place.

Privacy policy generator

Generate a privacy policy aligned to the 13 Australian Privacy Principles, tailored to a reporting entity's AML/CTF data handling.

Launching August 2026

Notifiable data breach register

Log and assess suspected breaches, with a built-in OAIC notification workflow for eligible data breaches.

Launching August 2026

Data inventory

Keep records of what personal information you hold, where it is stored, and why — the foundation of defensible privacy compliance.

Launching August 2026

Access request log

Track individuals' requests to access their personal information from first contact through to response.

Launching August 2026

APP 5 collection notice generator

Produce collection notices aligned to the OAIC's template collection notice, so you tell people what you're collecting and why.

Launching August 2026

Who it's for

Built for the professions brought into AML/CTF scope

If you provide designated services and handle KYC data, the Privacy Act now applies to that data. CompliDesk is built for the Tranche 2 professions.

Go to the source

The official guidance

Everything on this page is grounded in the OAIC's guidance for reporting entities. Read it directly.

Privacy Act questions from reporting entities

Yes. The OAIC has confirmed the Privacy Act applies to AML/CTF-related personal information handling regardless of the small business exemption. Being under the $3 million turnover threshold does not take a reporting entity out of scope for the personal information it handles in connection with its AML/CTF obligations.
The parts providing designated services and handling personal information in connection with your AML/CTF obligations. In practice, AML data handling is hard to separate from the rest of the business, so treating full compliance with the Australian Privacy Principles as your baseline is the safe position.
For a serious interference with privacy, a company faces the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover. Non-serious interferences carry penalties up to $3.3 million. Enforcement is real — the Federal Court has already imposed its first civil penalty under the Privacy Act, $5.8 million against Australian Clinical Labs.
It is an obligation to assess suspected data breaches and, for eligible data breaches, notify the OAIC and the affected individuals. The CompliDesk Privacy module's breach register is being built to guide you through this workflow.
OAIC guidance says not to retain full copies of identification documents, and to delete personal information when it is no longer required. Allowances to keep full ID documents apply only to documents collected before the AML/CTF reforms.
You are dual-regulated: AUSTRAC for your AML/CTF compliance and the OAIC for privacy. Both regulators oversee different obligations that now apply to the same client data.
A broader removal of the small business exemption is part of a second tranche of privacy reforms being progressed by the Attorney-General's Department. It is not yet legislated and there is no confirmed date. The coverage that applies now is specifically for personal information handled in connection with AML/CTF obligations.

Get ahead of your Privacy Act obligations.

Join the early-access list for the CompliDesk Privacy module — first 50 firms free for 3 months.

Get early access