Privacy Act guide · general information, not legal advice

Privacy policy for law firms (2026)

If your practice provides a designated service under the AML/CTF Act, such as conveyancing or setting up companies and trusts, the Privacy Act applies to the client information you collect for AML/CTF purposes, whatever your turnover. This guide sets out what your privacy policy must contain, where customer due diligence fits, and what changes on 10 December 2026.

Last checked 25 September 2026 against the Privacy Act 1988 compilation C2026C00227, the Privacy and Other Legislation Amendment Act 2024 (C2024A00128), the AML/CTF Act 2006 compilation C2026C00274 and the OAIC guidance for reporting entities updated 28 August 2026

APP 1.4 the law, read in the authorised textOAIC guidance the regulator's published guidance, which is not law

Does the Privacy Act apply to your firm?

A business with annual turnover of $3,000,000 or less is generally a small business operator and outside the Privacy Act, unless one of the cases in s 6D(4) applies.1 s 6D(1) s 6D(4) A firm above that threshold is generally covered for all its handling of personal information.

A small firm that provides a Table 6 designated service is covered for that part of its work. If a small business operator is a reporting entity under the AML/CTF Act, the Privacy Act applies to its activities for the purposes of, or in connection with, the AML/CTF Act, Regulations or Rules as if it were an organisation.2 s 6E(1A) AML/CTF obligations applied from 1 July 2026 to the professional services in AML/CTF Act s 6 Table 6.3 AML/CTF Act s 6 For a law firm those can include acting in a transaction to sell, buy or transfer real estate (item 1) or a company or trust (item 2); receiving, holding or managing a client's money as part of a transaction (item 3), subject to the exclusions in AML/CTF Act s 6(5C); creating or restructuring companies and trusts (item 6); and acting as, or arranging for someone to act as, a director or secretary of a company, a partner or a trustee of an express trust (item 7).

If the Privacy Act applies to you only because of s 6E(1A), the OAIC says your policy need only describe your AML/CTF handling.4 OAIC

What the policy must contain

APP 1.3 requires a clearly expressed and up-to-date privacy policy about how you manage personal information, and APP 1.4 lists what it must contain. APP 1.5 requires you to make it available free of charge and in an appropriate form, usually on your website.5 APP 1.3 APP 1.4

APP 1.4 contents, with the AML/CTF handling a law firm describes
APP 1.4 requires What to write about AML/CTF handling
(a) The kinds of personal information you collect and hold Know-your-customer details: names, dates of birth, addresses, identity document details and verification results; details of beneficial owners, directors, trustees and people acting for a client; politically exposed person and sanctions screening results
(b) How you collect and hold it From the client, from the client about its owners and officers, and from any verification or screening service you use; where the records are kept
(c) The purposes Customer due diligence, ongoing monitoring, reporting to AUSTRAC and record-keeping under the AML/CTF Act and Rules
(d) Access and correction How to ask, and who to ask
(e) Complaints How to complain about a breach of the APPs, and how you will deal with the complaint
(f) and (g) Overseas disclosure Whether a provider, such as a cloud system or verification service, is likely to receive the information overseas, and the countries, if it is practicable to name them

Sources for the table: Privacy Act Schedule 1, APP 1.4,5 and the OAIC's guidance for reporting entities.4 OAIC

Before any overseas disclosure, APP 8.1 requires reasonable steps to ensure the recipient does not breach the APPs.5 APP 8.1

Where customer due diligence data fits

Before providing a designated service, you must establish on reasonable grounds the customer's identity; the identity of anyone on whose behalf the customer receives the service, and of anyone acting for the customer; for a customer that is not an individual, its beneficial owners; whether any of them is a politically exposed person or designated for targeted financial sanctions; and the nature and purpose of the business relationship or occasional transaction.3 AML/CTF Act s 28 When you create a company, the customer includes its beneficial owners and directors; for an express trust, the trustee, settlor and beneficiaries (Table 6 item 6).3

So you collect information about people who are not your client. APP 5.2(b) requires reasonable steps to tell a person when you collect about them from someone else, and the circumstances.5 APP 5.2 The OAIC's guidance accepts that collecting directly from beneficial owners may be unreasonable or impracticable.4 OAIC

Three further points from the OAIC's guidance:4 OAIC

  • Mixed practices. In the OAIC's example, a client of a multi-disciplinary law firm wants family law advice, which is not a designated service, and mentions he may sell his house, which is. Collecting know-your-customer information at onboarding is permitted because the engagement may involve the sale, and the records must be kept even if no sale happens. Doing customer due diligence on every client "merely because this is helpful, desirable or convenient" is unlikely to meet the reasonably necessary test in APP 3.2.
  • Sensitive information. Screening for politically exposed persons can collect sensitive information, such as whether a person belongs to a political association. APP 3.4(a) allows that without consent where the AML/CTF Act or Rules require or authorise it.
  • No ID copies needed. The AML/CTF Act does not require scanned copies or photocopies of identity documents. Keep the details and the verification outcome, and destroy or de-identify copies once no longer needed. APP 11.2

Customer due diligence records are kept for 7 years from the end of the business relationship or the completion of the occasional transaction.3 AML/CTF Act s 111

The collection notice

The policy is general. APP 5.1 separately requires reasonable steps, at or before collection, to notify the APP 5.2 matters, including who you are, the purposes, the main consequences of not providing the information, your usual disclosures and any overseas recipients.5 APP 5.1 Where the law requires the collection, one of those matters is that fact and the name of the law (APP 5.2(c)): here, the AML/CTF Act or Rules.

The OAIC says you need not give notice content that would tip off a client.4 OAIC Disclosing that a suspicious matter report has been or must be made, where that could prejudice an investigation, is an offence. A legal practitioner may disclose information about a client's affairs, in good faith, to dissuade the client from conduct that is or could be an offence.3 AML/CTF Act s 123

From 10 December 2026: automated decisions

APP 1.7 to 1.9 commence on 10 December 2026, the day after the 24-month period that began with Royal Assent on 10 December 2024.6 POLA Act s 2 If a computer program makes, or does a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect a person's rights or interests, using personal information about them, the policy must describe the kinds of personal information used and the kinds of decisions.6 POLA Act Sch 1 item 88 Check whether any verification, screening or client-intake software you use decides, or all but decides, whether you act for a client. See automated decision-making disclosure.

Breaches and penalties

If you are aware of reasonable grounds to suspect an eligible data breach, you must carry out a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 days of becoming aware.7 s 26WH(2) See the data breach response plan.

A missing policy, or one without the APP 1.4 contents, is a matter under s 13K: a civil penalty of up to 200 penalty units ($72,800) for a person other than a body corporate and 1,000 penalty units ($364,000) for a body corporate, at $364 a unit for conduct on or after 1 July 2026, or an infringement notice.7 s 13K See Privacy Act penalties 2026.

Start here

Read AML tranche 2 and the Privacy Act for the full KYC picture. For your AML/CTF program, see AML/CTF for legal practices. More in the Privacy Act section. Every source we use: sources.

AMLCompliant is published by Wani Meridian Pty Ltd, an independent private business. We are not affiliated with, or endorsed by, the Office of the Australian Information Commissioner, AUSTRAC, the Attorney-General's Department or any other government body. This guide is general information, not legal advice.

Independent. Not affiliated with, or endorsed by, AUSTRAC or the Australian Government.

Sources

Law is quoted from the authorised text on the Federal Register of Legislation, opened 25 September 2026. OAIC pages are guidance, not law. They open in a new window, and linking to them does not mean the OAIC endorses this page.

  1. Privacy Act 1988 ss 6C(1), 6D(1) and 6D(4), compilation No. 104 (C2026C00227), compilation date 4 June 2026. legislation.gov.au/C2004A03712/latest/text

  2. Privacy Act 1988 s 6E(1A).

  3. Anti-Money Laundering and Counter-Terrorism Financing Act 2006, compilation C2026C00274: AML/CTF Act s 6 Table 6 (items 1, 2, 3, 6 and 7), AML/CTF Act s 6(5C), AML/CTF Act s 28, AML/CTF Act s 111(2) and AML/CTF Act s 123(1), (2) and (4). Commencement: AML/CTF Amendment Act 2024 (C2024A00110), Schedule 3, item 11. legislation.gov.au/C2006A00169/latest/text

  4. OAIC, "Privacy guidance for reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act", updated 28 August 2026, including its multi-disciplinary law firm example. Guidance, not law. oaic.gov.au

  5. Privacy Act 1988, Schedule 1 (Australian Privacy Principles), APP 1.3 to 1.5, 3.2, 3.4, 5.1, 5.2, 8.1 and 11.2.

  6. Privacy and Other Legislation Amendment Act 2024 (C2024A00128), s 2 table items 1 and 7; Schedule 1, Part 15, items 87 to 89. legislation.gov.au/C2024A00128/latest/text

  7. Privacy Act 1988 ss 13K, 26WH(2) and 80UB; Regulatory Powers Act s 82(5)(a); Crimes Act s 4AA and the Crimes (Amount of a Penalty Unit) Instrument 2026 (F2026N00424).

Questions

Do we need a separate AML collection notice?

In practice, yes. The privacy policy describes your handling in general; a collection notice is given at or before the time you collect (APP 5.1). The OAIC says reporting entities must have a privacy policy and collection notices that explain how they handle personal information for their AML/CTF obligations, and it publishes a free template collection notice for reporting entities. If you use our AML/CTF kit, the legal practice edition includes a drafted collection notice for customer due diligence that refers to the OAIC's guidance.

What about client identity data?

Collect it when the matter may involve a designated service, not for every client by default. The OAIC's guidance says the AML/CTF Act does not require scanned copies or photocopies of identity documents: keep the details you need, the type of document, what you did and the outcome of verification, and take reasonable steps to destroy or de-identify copies once no longer needed (APP 11.2). Customer due diligence records are kept for 7 years from the end of the business relationship or the completion of the occasional transaction (AML/CTF Act s 111). Say all of this in your policy.

What must APP 1 contain?

APP 1.4 lists seven items: the kinds of personal information you collect and hold; how you collect and hold it; the purposes for which you collect, hold, use and disclose it; how a person can access it and seek its correction; how a person can complain about a breach of the APPs and how you will deal with the complaint; whether you are likely to disclose it to overseas recipients; and, if so, the countries where they are likely to be, if it is practicable to name them.

How long do we keep KYC records?

Customer due diligence records are kept for 7 years from the end of the business relationship or the completion of the occasional transaction (AML/CTF Act s 111). The OAIC's guidance says the AML/CTF Act does not require copies of identity documents: keep the details you need and the outcome of verification, and take reasonable steps to destroy or de-identify copies once no longer needed.