Privacy Act 2026

AML Tranche 2 Just Dragged Your Agency Into the Australian Privacy Act — Here's What That Means

From 1 July 2026, AML/CTF Tranche 2 makes real estate, legal, accounting, conveyancing, TCSP and precious-metals firms reporting entities — and the moment you collect KYC, the Privacy Act 1988 applies to that information regardless of turnover. What that means, and what to do.

By Daniel Ebiau, AMLCompliant ·

If you run a real estate agency, law practice, accounting firm, conveyancing business, trust and company service provider, or you deal in precious metals and stones, you already know AML/CTF Tranche 2 starts on 1 July 2026. Here is the part that catches firms off guard: the same reform quietly pulls you into Australia's Privacy Act 1988 as well — and for that part, your turnover does not matter.

The hinge: KYC is personal information

To meet your new AML/CTF obligations, you will collect more personal information than ever before — identity documents, beneficial-ownership details, source-of-funds information, ongoing customer due diligence records. That is exactly the kind of data the Privacy Act governs.

And here is the key fact: once you are an AML/CTF reporting entity, you must comply with the Privacy Act for that AML/CTF personal information regardless of turnover. That brings around 100,000 small businesses under the Privacy Act from 1 July 2026 — independent of the broader, still-proposed removal of the $3M small-business exemption. This is the certain route, not the speculative one. (Sources: AUSTRAC; OAIC guidance for organisations.)

The dates that matter

DateWhat happens
31 March 2026AUSTRAC enrolment opened for newly regulated entities
1 July 2026AML/CTF obligations commence for Tranche 2 sectors — and Privacy Act obligations attach to the personal information you collect for them
29 July 2026Deadline to apply to enrol with AUSTRAC (within 28 days of first providing a designated service)

Note: the correct enrolment deadline is 29 July 2026, not 29 June. If you have seen "29 June" anywhere, it is a transposition error. (Source: AUSTRAC.)

What "Privacy Act compliance" actually means here

Because you are now an APP entity for this information, you should expect to:

  • Have a compliant privacy policy (APP 1) that describes what personal

information you collect, why, and how you handle it — including your AML/KYC collection.

  • Give collection notices (APP 5) at the point you collect identity and KYC

information.

  • Handle access, correction and complaints in line with the APPs, with complaints

ultimately able to go to the OAIC.

  • Meet the Notifiable Data Breaches scheme — assess a suspected eligible breach

within 30 days and notify the OAIC and affected individuals if serious harm is likely. KYC document stores are an obvious target. See the data-breach response plan guide.

  • If you use any tool to help make decisions that significantly affect people

(e.g. risk-scoring a customer), get ready for the ADM disclosure obligation from 10 December 2026 — see ADM disclosure in your privacy policy.

Treat privacy and AML as one project

The smart move is not to run two separate compliance projects. You are standing up customer onboarding, identity verification and record-keeping for AML anyway — bake the privacy obligations in at the same time. The collection notice you write for KYC is a privacy document and an AML document at once.

Industry-specific walkthroughs: real estate · accounting · law firms · conveyancers.

Start here

Run the free checker — tell it you are a Tranche 2 firm and it will lay out your AML and privacy obligations and deadlines together. Then grab the free readiness checklist so nothing slips between the two regimes.

General information only, not legal or compliance advice. Current to June 2026; confirm your obligations with AUSTRAC (austrac.gov.au), the OAIC (oaic.gov.au) or a qualified adviser before acting. Last verified: 8 June 2026.

Run the free ML/TF risk assessment →

Frequently asked questions

I'm getting ready for AML Tranche 2 — does the Privacy Act really apply to me too?
Yes. Once you are an AML/CTF reporting entity, you must comply with the Privacy Act for the personal information you handle for AML/CTF — IDs, beneficial ownership, KYC documents — regardless of your turnover. The two regimes hit the same buyer in the same week. Sources — AUSTRAC; OAIC.
When does this start?
AML/CTF Tranche 2 obligations begin 1 July 2026. Enrolment opened 31 March 2026, and you must apply to enrol with AUSTRAC within 28 days of first providing a designated service — a deadline of 29 July 2026. (Do not confuse this with any "29 June" figure — that is incorrect.) Source — AUSTRAC.
Is this legal advice?
No. General information drawn from AUSTRAC and OAIC guidance, current to June 2026. Confirm your obligations with AUSTRAC, the OAIC or a qualified adviser.
aml tranche 2privacy act 1988kycreporting entityaustracoaic