Snapshot
- From 1 July 2026, legal practices providing designated services under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 become reporting entities and are simultaneously brought under the Privacy Act 1988, regardless of annual turnover.
- The privacy obligations that arise are not a separate compliance project sitting alongside AML/CTF reform. They are triggered by the same client onboarding and due diligence work the practice is already doing.
- Legal practices that are now AML/CTF reporting entities and have not addressed privacy governance now face regulatory penalty exposure and Notifiable Data Breaches scheme obligations.
Anti-money laundering and counter-terrorism financing (‘AML/CTF’) tranche 2 reform has generated significant attention across the legal profession. The privacy consequence that arrived with it has received far less focus. For many law practices, 1 July 2026 did not just mark the start of AML/CTF obligations, it marks the first time the Australian Privacy Principles (‘APPs’) under the Privacy Act 1988 (Cth) (‘Privacy Act’) have ever applied to their practice. (There is a special rule relating to breaches of tax file numbers that small firms have previously been subject to – but not the APPs.)
A structural change, not an administrative one
Until recently, the small business exemption under the Privacy Act meant practices with an annual turnover below $3 million had no obligation to comply with the Australian Privacy Principles, publish a privacy policy, issue a collection notice or maintain a data breach response plan. For the majority of smaller legal practices in Australia, privacy compliance has not been a statutory obligation. That changed on 1 July 2026.
