The AML change that quietly ended your privacy exemption

Does my small firm still have the small business privacy exemption?
Not for your AML/CTF work. If your firm became a reporting entity under the AML/CTF Act on 1 July 2026, the Privacy Act applies to the personal information you handle for the purposes of, or in connection with, those obligations, regardless of turnover. The coverage is not a blanket loss of the exemption across the whole business, but it does cover client identification, verification and due diligence records, which is where most of your sensitive material lives.
What actually changed on 1 July?
The reform did not rewrite the Privacy Act's small business rule. It widened the definition of who counts as a reporting entity, and the privacy consequence rode along behind that change without being announced separately.
That is why it has gone unnoticed. A firm that read the AUSTRAC material, worked out that it provides a designated service, enrolled, appointed a compliance officer and started building a program has done the visible work properly and has still only dealt with part of what arrived that day. Nothing in the enrolment process asks about your privacy policy.
The professional bodies have been thorough on the AML/CTF side. The privacy side sits with a different regulator, in different guidance, under a different Act, and it lands on firms that have never had to think about the Australian Privacy Principles because the exemption always did the thinking for them.
How far does the coverage actually reach?
Further than the words first suggest. "In connection with" is doing real work in that phrase, and it will normally pull in more than the moment of identity verification: the intake form that collects the information, the file it is stored in, the third party you send it to for verification, the backup that copy sits in, and the eventual disposal of all of it.
Two firms can read the same wording and draw the line in different places, which is the practical problem. Trying to run two standards inside one practice, one for the AML/CTF material and a looser one for everything else, tends to cost more attention than it saves, because someone has to decide which bucket each new piece of information falls into. Some firms respond by applying the Privacy Principles across the practice and removing the question entirely. That is a commercial decision with legal consequences, so take advice on it rather than a view from an article.
What does the firm need to have in place?
Six things, and only the last two involve any real work.
- A privacy policy. Current, clearly expressed, and available free of charge to anyone who asks. It has to say what you collect, why, how you hold it, how someone gets access or a correction, and how they complain.
- A collection notice. Given at or before the time you collect the information, explaining why you are collecting it and what happens to it. The OAIC publishes a template collection notice for reporting entities, which is the fastest legitimate starting point available.
- Collection limited to what is reasonably necessary. Not what the form used to ask for, not what the old checklist collected. What the obligation actually requires.
- A data breach response. You are inside the Notifiable Data Breaches scheme for this information, which means a plan, an assessment process with a statutory clock, and someone who knows they own it before anything goes wrong.
- Destruction or de-identification when the information is no longer needed. This is the one that argues with the filing habit of every professional firm, and it is covered below.
- Someone accountable. In a small practice this is usually the same person who took the AML/CTF compliance officer role. Naming them is free. Leaving it unnamed is how it stays undone.
Why the identity documents are the sharp end
Most firms hold full images of client passports, licences and Medicare cards, because scanning the whole document is what a scanner does and nobody has ever had a reason to stop.
The OAIC's guidance is that the AML/CTF Act does not require you to keep scanned copies or photocopies of identity documents themselves for record-keeping purposes. What the regime is interested in is the information you took from the document and the record of what you verified, not a picture of the document. Privacy Commissioner Carly Kind has singled out unnecessary retention of ID documents as one of the more significant risks to Australians' privacy, on the straightforward basis that these are among the hardest pieces of personal information to replace once they are out.
There is a number worth working out before you decide how urgent this is, and it is your number rather than someone else's. Open wherever your onboarding documents live and count three things:
- How many client files you opened in the last twelve months.
- How many of those hold a full image of an identity document.
- Of those, how many are kept because a record-keeping rule requires it, rather than because nobody has ever deleted anything.
The third figure is the size of the exposure you are carrying for no reason. In most firms it is close to the second figure, and the exercise takes about twenty minutes.
Where this lands in the intake process
On the form, mostly. A collection notice has to be given at or before collection, which means it belongs at the point where the client hands the information over, not buried in a policy page they will never open. If your intake runs through an email thread, there is no reliable moment where the notice gets delivered, and no record that it was.
A structured intake fixes the mechanics rather than the judgement. It presents the notice at collection and logs that it happened, takes the specific fields the obligation calls for, records the verification result and its date, and files the artefacts consistently so that a retention rule can later find them. It also makes the decision to not store a document image a setting rather than a discipline, which is the only version of that decision that survives a busy fortnight.
The same line applies here as in conflict checks and in Tranche 2 generally. A system assembles and records. A person decides what is adequate.
What to do next
Work out whether you are actually a reporting entity, in writing, if you have not already. Everything here follows from that answer and nothing here matters without it.
If you are, do these four in order. Write or update the privacy policy and publish it. Put a collection notice into the intake step where the information is collected. Write a one-page breach plan naming who assesses, who decides and who notifies. Then do the twenty-minute count above and deal with what it shows you.
The first three are documents, and a competent adviser will get you through them quickly. The fourth is a process problem, and it is the one that comes back every month until the intake itself changes. That is the point at which the build is worth having, and it is a small one: a form, a verification step, a filing rule and a retention schedule. Shift would start there, after the decisions are written down and never before.