Privacy Act 2026 — by industry

Privacy Policy for Law Firms: The 2026 Australian Compliance Guide

What an Australian law firm's privacy policy needs in 2026 under the Privacy Act 1988 — including AML Tranche 2 KYC from 1 July 2026 and the 10 December 2026 automated decision-making disclosure, alongside your existing confidentiality duties. Plain English, source-checked.

By Daniel Ebiau, AMLCompliant ·

Law firms already operate under strict confidentiality and professional-conduct rules. The Privacy Act 1988 is a separate obligation — and in 2026, AML/CTF Tranche 2 and the new automated-decision-making rules make a compliant privacy policy a clear priority for practices that provide designated services.

If you provide a designated service, AML/CTF Tranche 2 makes you a reporting entity from 1 July 2026. Capture is service-based, not occupation-based — a solicitor who never touches a designated service may not be caught — but if you are, the Privacy Act applies to the personal information you collect for AML/CTF regardless of turnover. See AML Tranche 2 and the Privacy Act. (Source: AUSTRAC.)

What your policy must cover (APP 1)

  • What you collect: client identity, matter information, financial and KYC details,

beneficial-ownership data, trust-account information.

  • Why: providing legal services, meeting court/regulatory obligations, and AML/CTF

due diligence.

  • Who you disclose to: courts, counsel, third parties acting for the matter,

AUSTRAC where required, and any overseas recipients.

  • Access, correction and complaints, with the path to the OAIC (kept separate from

professional-conduct complaint channels).

  • Security and retention.

The general method is in how to write a privacy policy that complies in 2026.

Confidentiality vs the Privacy Act

These coexist. Your duty of confidentiality protects client information within the retainer; the Privacy Act governs how you collect, use, store and disclose personal information as an APP entity. Your privacy policy should reflect both without conflating them.

Automated decision-making

If your practice uses software to make or substantially support decisions that significantly affect people, the 10 December 2026 ADM disclosure obligation may apply. See the ADM guide.

Breach response

Legal files are highly sensitive. Build your 30-day breach-assessment process under the Notifiable Data Breaches scheme — see the data-breach response plan.

Run the free checker, then self-audit your policy with the free checklist.

General information only, not legal or compliance advice. Current to June 2026; confirm your obligations at oaic.gov.au and austrac.gov.au or with a qualified adviser. Last verified: 8 June 2026.

Run the free ML/TF risk assessment →

Frequently asked questions

Do law firms need a Privacy Act privacy policy if they already owe confidentiality?
Yes — client confidentiality and the Privacy Act are different obligations. If you are an APP entity (which AML Tranche 2 will make you from 1 July 2026 once you collect KYC), APP 1 requires a clear, current privacy policy in addition to your professional duties. Sources — AUSTRAC; OAIC.
Are all lawyers captured by AML Tranche 2?
No — capture is service-based, not occupation-based. You are a reporting entity only if you provide a designated service. If you do, the Privacy Act applies to that AML information regardless of turnover. Source — AUSTRAC.
Is this legal advice?
No. General information, current to June 2026. Confirm your obligations with the OAIC, AUSTRAC or a qualified adviser.
law firmprivacy policyprivacy act 1988aml tranche 2app 1