Privacy Act 2026
AML Tranche 2 Just Dragged Your Agency Into the Australian Privacy Act — Here's What That Means
From 1 July 2026, AML/CTF Tranche 2 makes real estate, legal, accounting, conveyancing, TCSP and precious-metals firms reporting entities — and the moment you collect KYC, the Privacy Act 1988 applies to that information regardless of turnover. What that means, and what to do.
If you run a real estate agency, law practice, accounting firm, conveyancing business, trust and company service provider, or you deal in precious metals and stones, you already know AML/CTF Tranche 2 starts on 1 July 2026. Here is the part that catches firms off guard: the same reform quietly pulls you into Australia's Privacy Act 1988 as well — and for that part, your turnover does not matter.
The hinge: KYC is personal information
To meet your new AML/CTF obligations, you will collect more personal information than ever before — identity documents, beneficial-ownership details, source-of-funds information, ongoing customer due diligence records. That is exactly the kind of data the Privacy Act governs.
And here is the key fact: once you are an AML/CTF reporting entity, you must comply with the Privacy Act for that AML/CTF personal information regardless of turnover. That brings around 100,000 small businesses under the Privacy Act from 1 July 2026 — independent of the broader, still-proposed removal of the $3M small-business exemption. This is the certain route, not the speculative one. (Sources: AUSTRAC; OAIC guidance for organisations.)
The dates that matter
| Date | What happens |
|---|---|
| 31 March 2026 | AUSTRAC enrolment opened for newly regulated entities |
| 1 July 2026 | AML/CTF obligations commence for Tranche 2 sectors — and Privacy Act obligations attach to the personal information you collect for them |
| 29 July 2026 | Deadline to apply to enrol with AUSTRAC (within 28 days of first providing a designated service) |
Note: the correct enrolment deadline is 29 July 2026, not 29 June. If you have seen "29 June" anywhere, it is a transposition error. (Source: AUSTRAC.)
What "Privacy Act compliance" actually means here
Because you are now an APP entity for this information, you should expect to:
- Have a compliant privacy policy (APP 1) that describes what personal
information you collect, why, and how you handle it — including your AML/KYC collection.
- Give collection notices (APP 5) at the point you collect identity and KYC
information.
- Handle access, correction and complaints in line with the APPs, with complaints
ultimately able to go to the OAIC.
- Meet the Notifiable Data Breaches scheme — assess a suspected eligible breach
within 30 days and notify the OAIC and affected individuals if serious harm is likely. KYC document stores are an obvious target. See the data-breach response plan guide.
- If you use any tool to help make decisions that significantly affect people
(e.g. risk-scoring a customer), get ready for the ADM disclosure obligation from 10 December 2026 — see ADM disclosure in your privacy policy.
Treat privacy and AML as one project
The smart move is not to run two separate compliance projects. You are standing up customer onboarding, identity verification and record-keeping for AML anyway — bake the privacy obligations in at the same time. The collection notice you write for KYC is a privacy document and an AML document at once.
Industry-specific walkthroughs: real estate · accounting · law firms · conveyancers.
Start here
Run the free checker — tell it you are a Tranche 2 firm and it will lay out your AML and privacy obligations and deadlines together. Then grab the free readiness checklist so nothing slips between the two regimes.
General information only, not legal or compliance advice. Current to June 2026; confirm your obligations with AUSTRAC (austrac.gov.au), the OAIC (oaic.gov.au) or a qualified adviser before acting. Last verified: 8 June 2026.
Run the free ML/TF risk assessment →