How It Works Pricing Privacy Act About Contact Log in Get Started Free

AML compliance × Privacy

Enrolled with AUSTRAC? The Privacy Act now applies to you.

From 1 July 2026, AML/CTF reporting entities are covered by the Privacy Act for their AML-related data handling — even under $3 million turnover. The KYC data you collect is now regulated personal information.

Get early access Read the OAIC guidance

What changed on 1 July 2026

Becoming a reporting entity triggered Privacy Act obligations

From 1 July 2026, Tranche 2 reporting entities — real estate professionals, lawyers, conveyancers, accountants, dealers in high-value goods, and trust and company service providers — are covered by the Privacy Act for personal information handled in connection with their AML/CTF obligations. This applies regardless of the $3 million small business exemption. In announcing its guidance, the OAIC put the number of small businesses affected at more than 100,000.

What actually triggers coverage. It is not your turnover, and it is not enrolment on its own. Coverage is triggered by being a reporting entity providing designated services, and it applies to the personal information you handle in connection with your AML/CTF obligations. Your AUSTRAC enrolment is simply the marker that you hold that status.

This is worth being precise about, because it cuts the other way too: if you are providing designated services but have not enrolled yet, the Privacy Act still applies to you. Enrolment is not what switches it on.

Nothing in the Privacy Act changed — the trigger was already there. Section 6E(1A) of the Privacy Act was written in 2006, alongside the original AML/CTF regime. It says that a small business operator that is a reporting entity is treated as an organisation — and so must comply with the Australian Privacy Principles — for the activities it carries on "for the purposes of, or in connection with" the AML/CTF Act and Rules. What changed in 2024 was the list of designated services. Expanding that list expanded who counts as a reporting entity, and s 6E(1A) did the rest automatically.

How much of your business is covered. Only the personal information you handle in connection with your AML/CTF obligations — the OAIC is clear that small businesses are not covered for their other business activities, and that an otherwise-exempt firm's privacy policy need only cover its AML/CTF data handling.

In practice the footprint is wider than that sounds, because the test follows the data rather than the department. Where you collect personal information for an AML/CTF purpose as well as another purpose — client details and transaction records gathered both to deliver your service and to meet your CDD obligations — the OAIC's guidance says the Privacy Act applies to that information. For most professional firms a great deal of client data is dual-purpose, which is why we recommend applying the APPs across the business as the simplest defensible position. That is our recommendation, not a claim that the whole of your business is automatically covered.

Authorised agents are covered too. If you carry out identity verification on behalf of a reporting entity — an outsourced KYC provider, a settlement agent, a paralegal service running client identity checks — you are covered in your own right, regardless of your turnover. The OAIC states that where a reporting entity provides a designated service through an agent, both the entity and the agent have Privacy Act responsibilities. We've written a full guide for authorised agents.

A hidden compliance risk

You probably don't need to keep that passport scan — but don't delete the old ones

From 31 March 2026 for Tranche 1 entities and 1 July 2026 for Tranche 2, the AML/CTF Act no longer requires you to keep scanned copies or photocopies of identity documents for record-keeping purposes. Under APP 11.2 you should take reasonable steps to destroy or de-identify copies of full ID documents once you no longer need them.

Read that carefully — it is not a ban on holding ID copies. It is the removal of a requirement to keep them, plus a duty to destroy them once they are genuinely no longer needed for an AML/CTF purpose or any other purpose you are permitted to hold them for. And the OAIC has explicitly said it expects this to take time: "reasonable steps" are judged against your size, resources and complexity, and against the scale of the task of changing your systems.

Copies you made before 31 March 2026 must be kept, not deleted. The OAIC's guidance is direct on this: those copies are records for the purposes of the AML/CTF Act and must be kept for 7 years following the end of the business relationship, or 7 years after the last occasional transaction. Do not run a clean-out across your historical files.

What to keep instead. For new verifications, the OAIC sets out what a compliant record looks like: the personal information taken from the document — name, date of birth, residential address, date of expiry, passport or licence number — plus the type of document, what you did to identify the customer, and the outcome of your verification and ML/TF risk assessment.

That is close to a specification, and it is exactly what CompliDesk stores. Structured, access-controlled verification records and audit trails give you the evidence AUSTRAC expects without accumulating document scans in inboxes and shared drives.

The CompliDesk Privacy module

Everything you need for Privacy Act compliance, alongside your AML/CTF program

The Privacy module is live now. Each tool is being built to work with the AML/CTF records you already keep in CompliDesk — so your KYC data and your privacy obligations live in one place.

Privacy policy generator

Generate a privacy policy aligned to the 13 Australian Privacy Principles, tailored to a reporting entity's AML/CTF data handling.

Launching August 2026

Notifiable data breach register

Log and assess suspected breaches, with a built-in OAIC notification workflow for eligible data breaches.

Launching August 2026

Data inventory

Keep records of what personal information you hold, where it is stored, and why — the foundation of defensible privacy compliance.

Launching August 2026

Access request log

Track individuals' requests to access their personal information from first contact through to response.

Launching August 2026

APP 5 collection notice generator

Produce collection notices aligned to the OAIC's template collection notice, so you tell people what you're collecting and why.

Launching August 2026

Who it's for

Built for the professions brought into AML/CTF scope

If you provide designated services and handle KYC data, the Privacy Act now applies to that data. CompliDesk is built for the Tranche 2 professions.

Go to the source

The official guidance

Everything on this page is grounded in the OAIC's guidance for reporting entities. Read it directly.

Privacy Act questions from reporting entities

Yes. The OAIC has confirmed the Privacy Act applies to AML/CTF-related personal information handling regardless of the small business exemption. Being under the $3 million turnover threshold does not take a reporting entity out of scope for the personal information it handles in connection with its AML/CTF obligations.
The personal information you handle in connection with your AML/CTF obligations. The OAIC is clear that small businesses are not covered for their other business activities — and that an otherwise-exempt firm's privacy policy need only describe its AML/CTF data handling. But the test follows the data, not the department: where information is collected for an AML/CTF purpose as well as another purpose, the Privacy Act applies to it. Because so much client data in a professional firm is dual-purpose, we recommend applying the Australian Privacy Principles across the business as the simplest defensible position.
Yes. Authorised agents of reporting entities — anyone carrying out customer identification procedures on a reporting entity's behalf — are covered in their own right, whatever their turnover. The OAIC states that where a designated service is provided through an agent, both the reporting entity and the agent have Privacy Act responsibilities.
There are three tiers. For a serious interference with privacy (s 13G), a company faces the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover for the breach turnover period; for anyone other than a company it is $2.5 million. For an interference that is not serious (s 13H), 2,000 penalty units, or 10,000 for a company — $728,000 and $3.64 million. For administrative breaches such as not having a compliant privacy policy (s 13K), 200 penalty units, or 1,000 for a company — $72,800 and $364,000, with infringement notices at $4,368 for an individual and $21,840 for a company. A penalty unit rose from $330 to $364 on 1 July 2026, and penalties use the value in force when the conduct occurred — so as a Tranche 2 entity, everything you do is priced at $364. Enforcement is real: in Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224 the Federal Court imposed the first civil penalty under the Privacy Act — $5.8 million, plus $400,000 costs. Note that two of the three limbs concerned the failure to assess and notify the breach, not the breach itself.
It is an obligation to assess suspected data breaches and, for eligible data breaches, notify the OAIC and the affected individuals. The CompliDesk Privacy module's breach register is being built to guide you through this workflow.
Yes, but you mostly no longer need to. The AML/CTF Act does not require scanned copies or photocopies of ID documents for record keeping from 31 March 2026 (Tranche 1) or 1 July 2026 (Tranche 2), and under APP 11.2 you should take reasonable steps to destroy or de-identify full copies once they are no longer needed. Important exception: copies you made before 31 March 2026 are AML/CTF records that must be kept for 7 years after the end of the business relationship or the last occasional transaction — do not delete those. For new verifications, keep the details taken from the document (name, date of birth, address, expiry, document number), the document type, what you did to verify the customer, and the outcome.
You are dual-regulated: AUSTRAC for your AML/CTF compliance and the OAIC for privacy. Both regulators oversee different obligations that now apply to the same client data.
A broader removal of the small business exemption is part of a second tranche of privacy reforms being progressed by the Attorney-General's Department. It is not yet legislated and there is no confirmed date. The coverage that applies now is specifically for personal information handled in connection with AML/CTF obligations.

Get ahead of your Privacy Act obligations.

Join the early-access list for the CompliDesk Privacy module — free for every customer until 10 December 2026.

Get early access