Last checked 25 September 2026 against the Privacy Act 1988 compilation C2026C00227, the Privacy and Other Legislation Amendment Act 2024 (C2024A00128), the AML/CTF Act 2006 compilation C2026C00274 and the OAIC guidance for reporting entities updated 28 August 2026
APP 1.4 the law, read in the authorised textOAIC guidance the regulator's published guidance, which is not law
Does the Privacy Act apply to your practice?
A business with annual turnover of $3,000,000 or less is generally a small business operator and outside the Privacy Act, unless one of the cases in s 6D(4) applies.1 s 6D(1) s 6D(4) A practice above that threshold is generally covered for all its handling of personal information.
A small practice that provides a Table 6 designated service is covered for that part of its work. If a small business operator is a reporting entity under the AML/CTF Act, the Privacy Act applies to its activities for the purposes of, or in connection with, the AML/CTF Act, Regulations or Rules as if it were an organisation.2 s 6E(1A) AML/CTF obligations applied from 1 July 2026 to the professional services in AML/CTF Act s 6 Table 6.3 AML/CTF Act s 6 Item 1 covers assisting a person to plan or carry out a transaction to sell, buy or otherwise transfer real estate, or acting for them in it, in the course of a business. Receiving, holding or managing a client's money as part of that transaction can also be a designated service (item 3), subject to the exclusions in AML/CTF Act s 6(5C).
If the Privacy Act applies to you only because of s 6E(1A), the OAIC says your policy need only describe your AML/CTF handling.4 OAIC
What the policy must contain
APP 1.3 requires a clearly expressed and up-to-date privacy policy about how you manage personal information, and APP 1.4 lists what it must contain. APP 1.5 requires you to make it available free of charge and in an appropriate form, usually on your website.5 APP 1.3 APP 1.4
| APP 1.4 requires | What to write about AML/CTF handling |
|---|---|
| (a) The kinds of personal information you collect and hold | Know-your-customer details: names, dates of birth, addresses, identity document details and verification results; details of beneficial owners and people acting for a client; politically exposed person and sanctions screening results |
| (b) How you collect and hold it | From the client, from people acting for the client, from any verification or screening service or agent you use, and from another firm whose procedure you rely on; where the records are kept |
| (c) The purposes | Customer due diligence, ongoing monitoring, reporting to AUSTRAC and record-keeping under the AML/CTF Act and Rules |
| (d) Access and correction | How to ask, and who to ask |
| (e) Complaints | How to complain about a breach of the APPs, and how you will deal with the complaint |
| (f) and (g) Overseas disclosure | Whether a provider, such as a cloud system or verification service, is likely to receive the information overseas, and the countries, if it is practicable to name them |
Sources for the table: Privacy Act Schedule 1, APP 1.4,5 and the OAIC's guidance for reporting entities.4 OAIC
Before any overseas disclosure, APP 8.1 requires reasonable steps to ensure the recipient does not breach the APPs.5 APP 8.1
Where customer due diligence data fits
Before providing a designated service, you must establish on reasonable grounds the customer's identity; the identity of anyone on whose behalf the customer receives the service, and of anyone acting for the customer; for a customer that is not an individual, its beneficial owners; whether any of them is a politically exposed person or designated for targeted financial sanctions; and the nature and purpose of the business relationship or occasional transaction.3 AML/CTF Act s 28 For Table 6 item 1, your customer is the person you act for.3
Where a client is a company or trust, you collect information about its owners and controllers through the client. APP 5.2(b) requires reasonable steps to tell a person when you collect about them from someone else, and the circumstances.5 APP 5.2 The OAIC's guidance accepts that collecting directly from beneficial owners may be unreasonable or impracticable.4 OAIC
Three further points from the OAIC's guidance:4 OAIC
- When a sale falls through. In the OAIC's example, a multi-disciplinary law firm collects know-your-customer information at onboarding because the engagement may involve selling a client's house. That collection is permitted even if no sale happens, and the records must still be kept. Doing customer due diligence on all customers at onboarding "merely because this is helpful, desirable or convenient" is unlikely to meet the reasonably necessary test in APP 3.2.
- Sensitive information. Screening for politically exposed persons can collect sensitive information, such as whether a person belongs to a political association. APP 3.4(a) allows that without consent where the AML/CTF Act or Rules require or authorise it.
- No ID copies needed. The AML/CTF Act does not require scanned copies or photocopies of identity documents. Keep the details and the verification outcome, and destroy or de-identify copies once no longer needed. APP 11.2
Customer due diligence records are kept for 7 years from the end of the business relationship or the completion of the occasional transaction.3 AML/CTF Act s 111
The collection notice
The policy is general. APP 5.1 separately requires reasonable steps, at or before collection, to notify the APP 5.2 matters, including who you are, the purposes, the main consequences of not providing the information, your usual disclosures and any overseas recipients.5 APP 5.1 Where the law requires the collection, one of those matters is that fact and the name of the law (APP 5.2(c)): here, the AML/CTF Act or Rules. For a conveyancer, the main consequence is usually that you cannot start providing the designated service until customer due diligence is done.3
The OAIC says you need not give notice content that would tip off a client.4 OAIC Disclosing that a suspicious matter report has been or must be made, where that could prejudice an investigation, is an offence.3 AML/CTF Act s 123
From 10 December 2026: automated decisions
APP 1.7 to 1.9 commence on 10 December 2026, the day after the 24-month period that began with Royal Assent on 10 December 2024.6 POLA Act s 2 If a computer program makes, or does a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect a person's rights or interests, using personal information about them, the policy must describe the kinds of personal information used and the kinds of decisions.6 POLA Act Sch 1 item 88 Check whether any electronic verification or screening service you use decides, or all but decides, whether you can act for a client. See automated decision-making disclosure.
Breaches and penalties
If you are aware of reasonable grounds to suspect an eligible data breach, you must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days of becoming aware.7 s 26WH(2) See the data breach response plan.
A missing policy, or one without the APP 1.4 contents, is a matter under s 13K: a civil penalty of up to 200 penalty units ($72,800) for a person other than a body corporate and 1,000 penalty units ($364,000) for a body corporate, at $364 a unit for conduct on or after 1 July 2026, or an infringement notice.7 s 13K See Privacy Act penalties 2026.
Start here
Read AML tranche 2 and the Privacy Act for the full KYC picture. For your AML/CTF program, see AML/CTF for conveyancers. More in the Privacy Act section. Every source we use: sources.
AMLCompliant is published by Wani Meridian Pty Ltd, an independent private business. We are not affiliated with, or endorsed by, the Office of the Australian Information Commissioner, AUSTRAC, the Attorney-General's Department or any other government body. This guide is general information, not legal advice.
Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.
Sources
Law is quoted from the authorised text on the Federal Register of Legislation, opened 25 September 2026. OAIC pages are guidance, not law. They open in a new window, and linking to them does not mean the OAIC endorses this page.
-
Privacy Act 1988 ss 6C(1), 6D(1) and 6D(4), compilation No. 104 (C2026C00227), compilation date 4 June 2026. legislation.gov.au/C2004A03712/latest/text
-
Privacy Act 1988 s 6E(1A).
-
Anti-Money Laundering and Counter-Terrorism Financing Act 2006, compilation C2026C00274: AML/CTF Act s 6 Table 6 (items 1 and 3), AML/CTF Act s 6(5C), AML/CTF Act s 28, AML/CTF Act s 111(2) and AML/CTF Act s 123. Commencement: AML/CTF Amendment Act 2024 (C2024A00110), Schedule 3, item 11. legislation.gov.au/C2006A00169/latest/text
-
OAIC, "Privacy guidance for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act", updated 28 August 2026, including its Example 1 (a multi-disciplinary law firm onboarding a client who may sell a house). Guidance, not law. oaic.gov.au
-
Privacy Act 1988, Schedule 1 (Australian Privacy Principles), APP 1.3 to 1.5, 3.2, 3.4, 5.1, 5.2, 8.1 and 11.2.
-
Privacy and Other Legislation Amendment Act 2024 (C2024A00128), s 2 table items 1 and 7; Schedule 1, Part 15, items 87 to 89. legislation.gov.au/C2024A00128/latest/text
-
Privacy Act 1988 ss 13K, 26WH(2) and 80UB; Regulatory Powers Act s 82(5)(a); Crimes Act s 4AA and the Crimes (Amount of a Penalty Unit) Instrument 2026 (F2026N00424).