Last checked 25 September 2026 against the Privacy Act 1988 compilation C2026C00227, the Privacy and Other Legislation Amendment Act 2024 (C2024A00128), the AML/CTF Act 2006 compilation C2026C00274 and the OAIC guidance for reporting entities updated 28 August 2026
APP 1.4 the law, read in the authorised textOAIC guidance the regulator's published guidance, which is not law
Does the Privacy Act apply to your firm?
A business with annual turnover of $3,000,000 or less is generally a small business operator and outside the Privacy Act, unless one of the cases in s 6D(4) applies.1 s 6D(1) s 6D(4) A firm above that threshold is generally covered for all its handling of personal information.
A small firm that provides a Table 6 designated service is covered for that part of its work. If a small business operator is a reporting entity under the AML/CTF Act, the Privacy Act applies to its activities for the purposes of, or in connection with, the AML/CTF Act, Regulations or Rules as if it were an organisation.2 s 6E(1A) AML/CTF obligations applied from 1 July 2026 to the professional services in AML/CTF Act s 6 Table 6.3 AML/CTF Act s 6 For an accounting firm those can include creating or restructuring companies and trusts (item 6); acting as, or arranging for someone to act as, a director, secretary or trustee (item 7); providing a registered office address (item 9); and helping a client buy or sell a company (item 2) or real estate (item 1). Tax returns, BAS, payroll and bookkeeping are not listed items. See Is my business a reporting entity?
If the Privacy Act applies to you only because of s 6E(1A), the OAIC says your policy need only describe your AML/CTF handling.4 OAIC
What the policy must contain
APP 1.3 requires a clearly expressed and up-to-date privacy policy about how you manage personal information, and APP 1.4 lists what it must contain. APP 1.5 requires you to make it available free of charge and in an appropriate form, usually on your website.5 APP 1.3 APP 1.4
| APP 1.4 requires | What to write about AML/CTF handling |
|---|---|
| (a) The kinds of personal information you collect and hold | Know-your-customer details: names, dates of birth, addresses, identity document details and verification results; details of beneficial owners, directors and people acting for a client; politically exposed person and sanctions screening results |
| (b) How you collect and hold it | From the client, from the client about its owners and officers, and from any verification or screening service you use; where the records are kept |
| (c) The purposes | Customer due diligence, ongoing monitoring, reporting to AUSTRAC and record-keeping under the AML/CTF Act and Rules |
| (d) Access and correction | How to ask, and who to ask |
| (e) Complaints | How to complain about a breach of the APPs, and how you will deal with the complaint |
| (f) and (g) Overseas disclosure | Whether a provider, such as a cloud system or verification service, is likely to receive the information overseas, and the countries, if it is practicable to name them |
Sources for the table: Privacy Act Schedule 1, APP 1.4,5 and the OAIC's guidance for reporting entities.4 OAIC
Before any overseas disclosure, APP 8.1 requires reasonable steps to ensure the recipient does not breach the APPs.5 APP 8.1
Where customer due diligence data fits
Before providing a designated service, you must establish on reasonable grounds the customer's identity; the identity of anyone on whose behalf the customer receives the service, and of anyone acting for the customer; for a customer that is not an individual, its beneficial owners; whether any of them is a politically exposed person or designated for targeted financial sanctions; and the nature and purpose of the business relationship or occasional transaction.3 AML/CTF Act s 28 When you create a company, the customer includes its beneficial owners and directors; for an express trust, the trustee, settlor and beneficiaries (Table 6 item 6).3
So you collect information about people who are not in the room. APP 5.2(b) requires reasonable steps to tell a person when you collect about them from someone else, and the circumstances.5 APP 5.2 The OAIC's guidance accepts that collecting directly from beneficial owners may be unreasonable or impracticable.4 OAIC
Three further points from the OAIC's guidance:4 OAIC
- Collect only when needed. In the OAIC's accountant example, a new client wants only a non-designated service, so the firm does no customer due diligence at onboarding. Doing it for every client "merely because this is helpful, desirable or convenient" is unlikely to meet the reasonably necessary test in APP 3.2.
- Sensitive information. Screening for politically exposed persons can collect sensitive information, such as whether a person belongs to a political association. APP 3.4(a) allows that without consent where the AML/CTF Act or Rules require or authorise it.
- No ID copies needed. The AML/CTF Act does not require scanned copies or photocopies of identity documents. Keep the details and the verification outcome, and destroy or de-identify copies once no longer needed. APP 11.2
Customer due diligence records are kept for 7 years from the end of the business relationship.3 AML/CTF Act s 111
The collection notice
The policy is general. APP 5.1 separately requires reasonable steps, at or before collection, to notify the APP 5.2 matters, including who you are, the purposes, the main consequences of not providing the information, your usual disclosures and any overseas recipients.5 APP 5.1 Where the law requires the collection, one of those matters is that fact and the name of the law (APP 5.2(c)): here, the AML/CTF Act or Rules.
The OAIC says you need not give notice content that would tip off a client.4 OAIC Disclosing that a suspicious matter report has been or must be made, where that could prejudice an investigation, is an offence.3 AML/CTF Act s 123
From 10 December 2026: automated decisions
APP 1.7 to 1.9 commence on 10 December 2026, the day after the 24-month period that began with Royal Assent on 10 December 2024.6 POLA Act s 2 If a computer program makes, or does a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect a person's rights or interests, using personal information about them, the policy must describe the kinds of personal information used and the kinds of decisions.6 POLA Act Sch 1 item 88 Check whether any verification, screening or risk-rating software you use decides, or all but decides, whether you act for a client. See automated decision-making disclosure.
Breaches and penalties
If you are aware of reasonable grounds to suspect an eligible data breach, you must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days of becoming aware.7 s 26WH(2) See the data breach response plan.
A missing policy, or one without the APP 1.4 contents, is a matter under s 13K: a civil penalty of up to 200 penalty units ($72,800) for a person other than a body corporate and 1,000 penalty units ($364,000) for a body corporate, at $364 a unit for conduct on or after 1 July 2026, or an infringement notice.7 s 13K See Privacy Act penalties 2026.
Start here
Read AML tranche 2 and the Privacy Act for the full KYC picture. For your AML/CTF program, see AML/CTF for accountants. More in the Privacy Act section. Every source we use: sources.
AMLCompliant is published by Wani Meridian Pty Ltd, an independent private business. We are not affiliated with, or endorsed by, the Office of the Australian Information Commissioner, AUSTRAC, the Attorney-General's Department or any other government body. This guide is general information, not legal advice.
Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.
Sources
Law is quoted from the authorised text on the Federal Register of Legislation, opened 25 September 2026. OAIC pages are guidance, not law. They open in a new window, and linking to them does not mean the OAIC endorses this page.
-
Privacy Act 1988 ss 6C(1), 6D(1) and 6D(4), compilation No. 104 (C2026C00227), compilation date 4 June 2026. legislation.gov.au/C2004A03712/latest/text
-
Privacy Act 1988 s 6E(1A).
-
Anti-Money Laundering and Counter-Terrorism Financing Act 2006, compilation C2026C00274: AML/CTF Act s 6 Table 6 (items 1, 2, 6, 7 and 9), AML/CTF Act s 28(2), AML/CTF Act s 111(2) and AML/CTF Act s 123. Commencement: AML/CTF Amendment Act 2024 (C2024A00110), Schedule 3, item 11. legislation.gov.au/C2006A00169/latest/text
-
OAIC, "Privacy guidance for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act", updated 28 August 2026, including its accountant example. Guidance, not law. oaic.gov.au
-
Privacy Act 1988, Schedule 1 (Australian Privacy Principles), APP 1.3 to 1.5, 3.2, 3.4, 5.1, 5.2, 8.1 and 11.2.
-
Privacy and Other Legislation Amendment Act 2024 (C2024A00128), s 2 table items 1 and 7; Schedule 1, Part 15, items 87 to 89. legislation.gov.au/C2024A00128/latest/text
-
Privacy Act 1988 ss 13K, 26WH(2) and 80UB; Regulatory Powers Act s 82(5)(a); Crimes Act s 4AA and the Crimes (Amount of a Penalty Unit) Instrument 2026 (F2026N00424).