By -

Snapshot

  • From 1 July 2026, legal practices providing designated services under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 become reporting entities and are simultaneously brought under the Privacy Act 1988, regardless of annual turnover.
  • The privacy obligations that arise are not a separate compliance project sitting alongside AML/CTF reform. They are triggered by the same client onboarding and due diligence work the practice is already doing.
  • Legal practices that are now AML/CTF reporting entities and have not addressed privacy governance now face regulatory penalty exposure and Notifiable Data Breaches scheme obligations.

Anti-money laundering and counter-terrorism financing (‘AML/CTF’) tranche 2 reform has generated significant attention across the legal profession. The privacy consequence that arrived with it has received far less focus. For many law practices, 1 July 2026 did not just mark the start of AML/CTF obligations, it marks the first time the Australian Privacy Principles (‘APPs’) under the Privacy Act 1988 (Cth) (‘Privacy Act’) have ever applied to their practice. (There is a special rule relating to breaches of tax file numbers that small firms have previously been subject to – but not the APPs.)

A structural change, not an administrative one

Until recently, the small business exemption under the Privacy Act meant practices with an annual turnover below $3 million had no obligation to comply with the Australian Privacy Principles, publish a privacy policy, issue a collection notice or maintain a data breach response plan. For the majority of smaller legal practices in Australia, privacy compliance has not been a statutory obligation. That changed on 1 July 2026.

You've reached the end of this article preview

There's more to read! Subscribe to LSJ today to access the rest of our updates, articles and multimedia content.

Subscribe to LSJ

Already an LSJ subscriber or Law Society member? Sign in to read the rest of the article.

Sign in to read more