By -

AML/CTF Reporting Entities will also have privacy obligations

If you provide a ‘designated service’ under the amended Anti-Money Laundering and Counter-Terrorism Financing Act2006 (Cth) (AML/CTF Act), you’ll also be subject to obligations under the Privacy Act 1988 (Cth) (Privacy Act).[1]

The current privacy exemption

Many small law practices in Australia are not covered by the Privacy Act, due to the longstanding exemption for businesses with an annual turnover of $3 million or less (small businesses).

The Privacy Act exempts small businesses from compliance obligations unless they fall into specified categories, such as if they are a health service provider, credit reporting body, business trading in personal information; if they voluntarily opt in; or if they are a reporting entity (see sections 6C – 6EA of the Privacy Act).

However, from 1 July 2026, this exemption does not apply to the parts of a law practice that provide one or more designated service under the AML/CTF Act. This means that, if your law practice is deemed to be a ‘reporting entity’ under the AML/CTF Act (Reporting Entity), you have obligations under the Privacy Act in relation to the designated services you provide.

To support Reporting Entities, the Office of the Australian Information Commissioner (OAIC) has published ‘Privacy guidance for reporting entities under the AML/CTF Act ’ (OAIC Guidance), as well as a template privacy collection notice . In addition, the Law Society of NSW has produced a privacy policy template that law practices can tailor to their business.

Reforms to the AML/CTF Act – A regulatory gamechanger

The reforms to the AML/CTF Act, commencing in July 2026 for Tranche 2 entities such as lawyers, accountants and real estate agents, extend AML/CTF obligations to cover a law practice that provides one or more designated services as defined in Table 6, section 6 of the AML/CTF Act. It may be helpful to have a look at AUSTRAC’s (the AML/CTF regulator) website for more information about who they regulate.

For a summary of designated services relevant to lawyers, you may also wish to refer to our article, ‘Understanding designated services: when legal services trigger Tranche 2 AML/CTF obligations , as well as our AML/CTF Implementation Guide: for sole practitioners and small practices. In addition, AML/CTF obligations are summarised in our earlier article: Top five tips to prepare for AML reforms.

What this means is that legal practices, particularly small practices, that are Reporting Entities have to simultaneously navigate two new sets of regulatory obligations. They no longer fall within the small business exemption of the Privacy Act, and will need to comply with the 13 Australian Privacy Principles (APP), which govern:

  • the collection, use and disclosure of personal information,
  • a business’s governance and accountability,
  • integrity and correction of personal information, and
  • the rights of individuals to access their personal information.

These law practices will be regulated by AUSTRAC for AML/CTF compliance, and the OAIC for compliance with the Privacy Act.

What are the privacy implications for small law practices that are Reporting Entities?

The AML/CTF Act requires Reporting Entities to collect, verify and retain ‘personal information’ about clients, for example, when conducting customer due diligence (or know-your-customer) checks.

Personal information includes, among other things, an individual’s name, address, phone number or date of birth. The information collected as part of the checks may also include ownership structures (for example, where the ownership structure identifies, or could reasonably identify, a person) and a client’s financial details. This type of information may be required, for example, when assisting a client to buy real estate or a business.

In some instances, a law practice may collect ‘sensitive information’, for example, biometric information.

This raises practice management issues for small law practices that may not currently be subject to the Privacy Act, such as:

  • secure storage of personal and/or sensitive information
  • safeguards to prevent misuse of, or unauthorised access to, personal and/or sensitive information
  • training staff in privacy risks associated with AML/CTF obligations
  • having a data breach response plan, and
  • if the law practice provides both designated services and non-designated services, considering how to manage the client onboarding process, and how to service client retainers, across all services for a seamless customer experience.

OAIC Privacy Guidance

The OAIC Guidance  assists Reporting Entities to understand their key privacy obligations. It must, however, be read together with the Privacy Act, the APP guidelines , and other supporting OAIC resources, as well as AUSTRAC’s reforms guidance .

Practical steps for small law practices

Here are some suggested practical steps to help practices ensure they are compliant with the Privacy Act:

  • conduct a data audit to understand what personal information they collect and hold, and for what purpose,
  • review information handling practices including storage, access and disposal protocols. You are required to let your clients know, among other things, why their personal information is being collected and how it will be used (see our Privacy Policy Template). We also recommend that you use the OAIC’s template privacy collection notice, which you can adapt to suit your practice,
  • assess, test and, where appropriate, strengthen, cyber security systems. This may include setting up multifactor authentication and password complexity requirements, ensuring software is regularly updated and that systems are monitored for security threats,
  • identify where third parties will be handling your clients’ personal information, including overseas entities, and review the terms of those agreements. The agreements should impose specific obligations about the handling of personal information, give you the ability to audit their information handling systems and have mechanisms to ensure they fulfil their obligations,
  • review your current processes for dealing with data breaches and, where appropriate, update or implement your data breach response plan – see the OAIC’s guidance on ‘Data breach preparation and response’,
  • train staff on privacy risks and obligations, and
  • monitor privacy developments and associated risks.

Summary of useful resources

The following are some useful resources from the OAIC that may assist small law practices in preparing to implement a privacy framework.

The Law Society of NSW also has some additional useful material, including:

The Law Society of NSW AML/CTF Resources

Our AML/CTF Hub contains the latest information on AML/CTF, as well as access to complimentary resources and information including CPD claimable, self-paced, interactive on-demand courses .

Our Professional Support Unit (PSU) provides free and confidential guidance to all solicitors regarding their obligations under the Legal Profession Uniform Law in the areas of costs, ethics, regulatory compliance and AML/CTF. Enquiries regarding AML can be made to PSU by telephone on (02) 9926 0249, email at aml@lawsociety.com.au, or in person by appointment.


Carol Prasad is a Professional Support Solicitor (AML) at the Law Society of NSW.
[1] Privacy Act 1988 (Cth) s 6E(1A).