Privacy Act guide · general information, not legal advice

AML tranche 2 and the Privacy Act: KYC data

A small practice that becomes an AML/CTF reporting entity must handle the personal information it collects for AML/CTF under the Privacy Act, whatever its turnover. This guide sets out why, what that covers, and what to change in your onboarding, notices and records.

Last checked 25 September 2026 against the Privacy Act 1988 compilation C2026C00227, the AML/CTF Act 2006 compilation C2026C00274 and the OAIC guidance for reporting entities updated 28 August 2026

s 6E(1A) the law, read in the authorised textOAIC guidance the regulator's published guidance, which is not law

What changed on 1 July 2026

AML/CTF obligations for programs, customer due diligence, reporting and record-keeping applied from 1 July 2026 to the designated services in AML/CTF Act s 6 Tables 5 and 6, which cover real estate and professional services, and to dealers in precious metals and stones.1 Enrolment with AUSTRAC was due by 29 July 2026 for a firm already providing one of those services; a firm that starts later must apply within 28 days of its first designated service.2 AML/CTF Act s 51B Whether you are captured depends on the service, not the job title: see Is my business a reporting entity?

In its Impact Analysis of September 2024, the Attorney-General's Department estimated the reforms would add about 90,000 entities to the AUSTRAC reporting population.3 AGD estimate

Why the Privacy Act applies to your KYC data

A business with annual turnover of $3,000,000 or less is generally a small business and outside the Privacy Act.4 s 6D(1) But if a small business operator is a reporting entity, or an authorised agent of one, because of something done in its small business, the Act applies to its activities for the purposes of, or in connection with, the AML/CTF Act, Regulations or Rules as if it were an organisation.5 s 6E(1A)

The OAIC's guidance gives examples of those activities:6 OAIC

  • collecting, using and storing personal information for customer due diligence;
  • collecting, using, storing and disclosing it for monitoring and reporting;
  • holding it for AML/CTF record-keeping;
  • personnel due diligence, where the employee records exemption does not apply.

The OAIC says the Act does not cover a small business's other activities unless it is covered for another reason. Where the same details are collected for an AML/CTF purpose and another purpose, the OAIC says the Act applies to them.6

Removing the small business exemption is not law. The exposure draft Bill the Attorney-General's Department released for consultation on 31 August 2026 does not repeal it, and as at 25 September 2026 no Bill removing it had been introduced to Parliament.7 AGD

What to put in place

Privacy obligations that attach to AML/CTF handling
What The rule What the OAIC's guidance adds
Privacy policy APP 1.3 and 1.4: a clearly expressed, up-to-date policy with the listed contents A small business covered only by s 6E(1A) need only describe its AML/CTF handling
Collection notices APP 5.1: at or before collection, take reasonable steps to notify the APP 5.2 matters Name the AML/CTF Act or Rules as the law requiring collection; no notice content where it would tip off
Collect only what you need APP 3.2: only what is reasonably necessary for your functions or activities Doing due diligence on all customers at onboarding "merely because this is helpful, desirable or convenient" is unlikely to meet the test
Keep it secure APP 11.1: reasonable steps to protect it Have a data breach response plan
Destroy or de-identify APP 11.2: when no longer needed, unless a law requires you to keep it Destroy or de-identify copies of ID documents once no longer needed
Overseas providers APP 8.1: reasonable steps before disclosing overseas Check contracts with cloud and verification providers
Access requests APP 12 Do not give access, or explain a refusal, where that would tip off

Sources for the table: Privacy Act Schedule 18 and the OAIC's guidance for reporting entities.6 OAIC

ID copies and the 7-year records

The AML/CTF Act sets retention periods for the records it requires:9

  • transaction records: 7 years from the day the record is made; AML/CTF Act s 107
  • documents a customer gives you about a transaction: 7 years; AML/CTF Act s 108
  • customer due diligence records: 7 years from the end of the business relationship or the occasional transaction; AML/CTF Act s 111
  • records showing compliance with your AML/CTF program obligations (Part 1A): 7 years after they are no longer relevant. AML/CTF Act s 116

APP 11.2 does not require you to destroy information an Australian law requires you to keep.8 APP 11.2 What the law requires is the record, not necessarily a copy of the document. The OAIC's guidance says the AML/CTF Act does not require scanned copies or photocopies of identity documents. Keep the details you need, for example the name, date of birth, address, document number and expiry, the type of document, what you did to identify the customer, and the outcome of verification and risk assessment. Take reasonable steps to destroy or de-identify copies once no longer needed.6 OAIC See AML/CTF record-keeping requirements.

Tipping off and privacy

It is an offence to disclose that a suspicious matter report has been, or must be, given, or related information, where the disclosure would or could reasonably be expected to prejudice an investigation. The penalty is imprisonment for 2 years or 120 penalty units, or both.10 AML/CTF Act s 123 A legal practitioner or qualified accountant may disclose in good faith to dissuade a customer from conduct that is or could be an offence.10 Your AML/CTF policies must include safeguards against tipping off.11 Rules 5-13

Privacy duties give way where they would conflict. The OAIC's guidance says you need not give a collection notice where it would tip off, must not give access or explain a refusal where that would tip off, and should apply the data-breach notification rules only to the extent consistent with AML/CTF secrecy and tipping-off provisions.6 OAIC s 26WP

Start here

The OAIC's own template collection notice for reporting entities is free on its website. Each sector edition of our AML/CTF kit includes a drafted collection notice for customer due diligence that refers to the OAIC's guidance. For breaches, see the data breach response plan. More in the Privacy Act section. Every source we use: sources.

AMLCompliant is published by Wani Meridian Pty Ltd, an independent private business. We are not affiliated with, or endorsed by, the Office of the Australian Information Commissioner, AUSTRAC, the Attorney-General's Department or any other government body. This guide is general information, not legal advice.

Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.

Sources

Law is quoted from the authorised text on the Federal Register of Legislation, opened 25 September 2026. OAIC, AUSTRAC and Attorney-General's Department pages are guidance, not law, and open in a new window.

  1. Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (C2024A00110), Schedule 3, item 11; AML/CTF Act 2006 s 6, compilation C2026C00274. legislation.gov.au/C2024A00110/latest/text

  2. AML/CTF Amendment Act 2024, Schedule 3, item 12; AML/CTF Act s 51B(1). Both dates have passed. legislation.gov.au/C2006A00169/latest/text

  3. Attorney-General's Department, Impact Analysis for the AML/CTF reforms (September 2024), published by the Office of Impact Analysis. An estimate, not a count. oia.pmc.gov.au

  4. Privacy Act 1988 ss 6C(1) and 6D(1); other cases in s 6D(4). Compilation No. 104 (C2026C00227). legislation.gov.au/C2004A03712/latest/text

  5. Privacy Act 1988 s 6E(1A).

  6. OAIC, "Privacy guidance for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act", updated 28 August 2026. Guidance, not law. oaic.gov.au

  7. Attorney-General's Department, "Privacy reform: consultation on exposure draft legislation", and the Exposure Draft Privacy Amendment (Personal Data Protection) Bill 2026. An exposure draft is not law. consultations.ag.gov.au

  8. Privacy Act 1988, Schedule 1 (Australian Privacy Principles), APP 1.3, 1.4, 3.2, 5.1, 5.2, 8.1, 11.1, 11.2 and 12.

  9. AML/CTF Act 2006 ss 107, 108, 111 and 116, compilation C2026C00274. Records must be in English or readily convertible into English.

  10. AML/CTF Act 2006 s 123(1), (2) and (4).

  11. Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (F2025L01026), rule 5-13. legislation.gov.au/F2025L01026/latest/text

Questions

Why does the Privacy Act apply to my small firm?

If a small business operator is a reporting entity because of something done in its small business, the Privacy Act applies to its activities for the purposes of, or in connection with, the AML/CTF Act, Regulations and Rules as if it were an organisation (Privacy Act s 6E(1A)). Turnover does not matter for those activities.

Must we keep copies of ID documents?

No. The OAIC's guidance says the AML/CTF Act does not require scanned copies or photocopies of identity documents, and that you should take reasonable steps to destroy or de-identify copies once no longer needed. Keep the details you need, the type of document, what you did and the outcome of verification. Those records are kept for 7 years under AML/CTF Act s 111.

What if a collection notice would tip off a customer?

The OAIC's guidance says you do not need to provide information in a collection notice where that would be inconsistent with your tipping-off obligations. The tipping-off offence is in AML/CTF Act s 123.

Is there a template notice?

Yes. The OAIC publishes a template privacy collection notice for AML/CTF reporting entities, free on its website. Each sector edition of our AML/CTF kit also includes a drafted collection notice for customer due diligence that refers to the OAIC's guidance.