Privacy Act 2026 — by industry
Privacy Policy for Law Firms: The 2026 Australian Compliance Guide
What an Australian law firm's privacy policy needs in 2026 under the Privacy Act 1988 — including AML Tranche 2 KYC from 1 July 2026 and the 10 December 2026 automated decision-making disclosure, alongside your existing confidentiality duties. Plain English, source-checked.
Law firms already operate under strict confidentiality and professional-conduct rules. The Privacy Act 1988 is a separate obligation — and in 2026, AML/CTF Tranche 2 and the new automated-decision-making rules make a compliant privacy policy a clear priority for practices that provide designated services.
Why 2026 matters for legal practices
If you provide a designated service, AML/CTF Tranche 2 makes you a reporting entity from 1 July 2026. Capture is service-based, not occupation-based — a solicitor who never touches a designated service may not be caught — but if you are, the Privacy Act applies to the personal information you collect for AML/CTF regardless of turnover. See AML Tranche 2 and the Privacy Act. (Source: AUSTRAC.)
What your policy must cover (APP 1)
- What you collect: client identity, matter information, financial and KYC details,
beneficial-ownership data, trust-account information.
- Why: providing legal services, meeting court/regulatory obligations, and AML/CTF
due diligence.
- Who you disclose to: courts, counsel, third parties acting for the matter,
AUSTRAC where required, and any overseas recipients.
- Access, correction and complaints, with the path to the OAIC (kept separate from
professional-conduct complaint channels).
- Security and retention.
The general method is in how to write a privacy policy that complies in 2026.
Confidentiality vs the Privacy Act
These coexist. Your duty of confidentiality protects client information within the retainer; the Privacy Act governs how you collect, use, store and disclose personal information as an APP entity. Your privacy policy should reflect both without conflating them.
Automated decision-making
If your practice uses software to make or substantially support decisions that significantly affect people, the 10 December 2026 ADM disclosure obligation may apply. See the ADM guide.
Breach response
Legal files are highly sensitive. Build your 30-day breach-assessment process under the Notifiable Data Breaches scheme — see the data-breach response plan.
Run the free checker, then self-audit your policy with the free checklist.
General information only, not legal or compliance advice. Current to June 2026; confirm your obligations at oaic.gov.au and austrac.gov.au or with a qualified adviser. Last verified: 8 June 2026.
Run the free ML/TF risk assessment →