(02) 4227 6744
Level One logo.
Header Background

Latest Accounting News

Does Your Small Business Need to Follow AML Privacy Rules?

Does Your Small Business Need to Follow AML Privacy Rules?

.

 If your business will be required to comply with the Anti-Money Laundering and Counter Terrorism Financing Act 2006 (AML Act), you also need to consider your privacy obligations when handling personal information. Even if you operate a small business that would normally be exempt from privacy regulation, the new AML laws could change this.

Specifically, businesses that are reporting entities under the AML framework must comply with the Privacy Act 1988 (Privacy Act) when collecting, using, storing or disclosing personal information for AML purposes. This includes businesses with an annual turnover of less than $3 million.

Understanding how these two frameworks interact is important if your business performs customer due diligence, identity verification or transaction monitoring. This article explains how the AML and privacy frameworks interact and what small businesses need to do to comply with both.

When Does the Privacy Act Apply to Your Business?

The Privacy Act generally regulates how organisations handle personal information through the Australian Privacy Principles (APPs). While many small businesses are normally exempt, that exemption does not apply when you handle personal information to meet AML obligations. If your business is a reporting entity under the AML Act, you must comply with the Privacy Act for activities connected with those obligations.

Activities that may trigger privacy obligations include:

  • collecting personal information for customer due diligence;
  • storing information for AML record-keeping purposes;
  • monitoring transactions and reporting suspicious matters; and
  • conducting personnel due diligence for employees working in AML roles.

Collecting Personal Information for AML Compliance

To meet your AML obligations, your business will often need to collect personal information about customers, employees or other individuals. Under the APPs, you must limit the information you collect to what is reasonably necessary for your functions and activities. In the AML context, this typically means collecting information required for customer due diligence or risk assessments.

During onboarding, you will commonly collect:

  • full name;
  • date of birth;
  • residential address; and
  • identification document details.

However, the requirement to collect information for AML purposes does not give your business unlimited authority to gather any data you want. You should always consider whether the information you are collecting is genuinely necessary for compliance. Collecting excessive or irrelevant information may increase privacy risks and create unnecessary cybersecurity exposure.

Customer Notification

When your business collects personal information, you must notify individuals about how their information will be handled. This is typically done through a collection notice and your privacy policy.

A collection notice should explain:

  • your organisation’s identity and contact details;
  • why you are collecting the information;
  • whether the collection is required by law;
  • how the information may be used or disclosed; and
  • the consequences if the information is not provided.

In the AML context, this may include explaining that information is collected to comply with the AML Act. However, you do not need to provide a collection notice where doing so would be inconsistent with your tipping off obligations under the AML Act.

Using and Disclosing Personal Information

Under the APPs, personal information should generally only be used or disclosed for the primary purpose for which it was collected. For AML activities, this may include:

  • verifying a customer’s identity;
  • assessing money laundering or terrorism financing risks; and
  • meeting reporting obligations.

In some situations, your business may also be required to disclose personal information to regulators.

For example, reporting entities must submit suspicious matter reports to AUSTRAC when certain conditions are met. Because these disclosures are authorised by law, they are permitted under the Privacy Act even if the individual has not provided consent for these disclosures.

If you disclose personal information overseas (including to a third party service provider), you must generally take reasonable steps to ensure that the overseas recipient does not breach the APPs. However, exceptions apply where the disclosure is required or authorised by the AML Act.

Protecting Personal Information

Businesses that handle AML data often hold large volumes of sensitive personal information. This can make them attractive targets for cybercriminals. Under the APPs, you must take reasonable steps to protect personal information from misuse, interference, loss or unauthorised access.

Practical security measures include:

  • using strong password policies and multi-factor authentication;
  • restricting staff access to personal information;
  • keeping software and systems updated;
  • monitoring system activity with audit logs; and
  • implementing a data breach response plan.

Having a clear response plan ensures your business can act quickly if a data breach occurs.

Retaining and Destroying Personal Information

Under the Privacy Act, businesses must take reasonable steps to destroy or de-identify personal information once it is no longer required. However, the AML Act requires certain records to be kept for specified periods to demonstrate compliance. This means your business must retain AML records when required by law. Once the retention period expires and there is no other reason to keep the data, you should securely delete or de-identify it.

Key Statistics

  1. $3 million: the annual turnover threshold below which a business is normally Privacy Act exempt, an exemption that does not apply where the business is an AML/CTF reporting entity.
  2. Close to 100,000: businesses will be regulated by AUSTRAC once the reforms take effect on 1 July 2026, up from around 19,000 today.
  3. Fewer than 5%: of Australian businesses meet the threshold that would bring them within the Privacy Act’s scope under the current small business exemption.

Sources

  1. OAIC (April 2026)
  2. AUSTRAC (March 2026)
  3. Attorney-General’s Department, Privacy Act Review Report 2022 (February 2023)

Key Takeaways

If your business is a reporting entity under the AML regime, you must comply with the Privacy Act when handling personal information for those obligations. This applies even to small businesses that would otherwise be exempt from privacy regulation.

To comply with both frameworks, your business should only collect information that is reasonably necessary, provide clear privacy notices, protect personal data with appropriate security measures, and retain information only for as long as required. Taking these steps will help you meet your AML obligations while maintaining strong privacy practices and protecting the personal information entrusted to your business.

 

 

 

Legal Vision
Georgia MacKay
legalvision.com.au/

 

Latest News

More Archived Articles

Level One Financial Advisers Pty Ltd. AFSL 280061. The information contained on this website is general information only. You agree that your access to, and use of, this site is subject to these terms and all applicable laws, and is at your own risk. This site and its contents are provided to you on an “as is” basis, the site may contain errors, faults and inaccuracies and may not be complete and current. It does not constitute personal financial or taxation advice. When making an investment decision you need to consider whether this information is appropriate to your financial situation, objectives and needs. Liability limited by a scheme approved under Professional Standards Legislation. Disclaimer and Privacy Policy

Doug Tarrant

Doug Tarrant

Principal B Com (NSW) CA CFP SSA AEPS

About Doug

As founder of the firm Doug has over 30 years of experience advising families, businesses and professionals with commercially driven business, taxation and financial advice.

Doug’s advice covers a wide variety of areas including wealth creation, business growth strategies, taxation, superannuation, property investment and estate planning as well as asset protection.

Doug’s clients span a whole range of industries including Investors; Property and Construction; Medical; Retail and Hospitality; IT and Tourism; Engineering and Contracting.

Doug’s qualifications include:

  • Bachelor of Commerce (Accounting) UNSW
  • Fellow of the Institute of Chartered Accountants
  • Certified Financial Planner
  • Self Managed Superannuation Fund Specialist Adviser (SPAA)
  • Self Managed Superannuation Fund Auditor
  • Accredited Estate Planning Specialist
  • AFSL Licensee
  • Registered Tax Agent
Christine Lapkiw

Christine Lapkiw

Senior Associate B Com (Accounting) M Com (Finance) CA

About Christine

Christine has over 25 years of extensive experience advising clients principally on taxation and superannuation related matters and was a founder of the firm when it began in 2004.

Christine’s breadth and depth of knowledge and experience provides clients with the comfort that their affairs are in good hands.

Christine currently heads up the firm’s SMSF division and oversees a team that provide tailored solutions for clients and trustees on all aspect of superannuation including:

  • Establishment of SMSFs
  • Compliance services
  • Property acquisitions
  • Pension structuring
  • SMSF ATO administration and dispute services

Christine’s qualifications include:

  • Bachelor of Commerce (Accounting)
  • Member of the Institute of Chartered Accountants
  • Master of Commerce (Finance)
Michelle Jolliffe

Michelle Jolliffe

Associate - Business Services B Com (Accounting) CA

About Michelle

Michelle has been with the firm in excess of 18 years and is an Associate in our Business Services Division.

Michelle and her team provide taxation and business advice to a wide variety of clients. Technically strong Michelle can assist with all matters in relation to taxation covering Income and Capital Gains Tax; Land Tax; GST; Payroll Tax and FBT.

Michelle is an innovative thinker and problem solver and always brings an in-depth and informed view to the discussion when advising clients.

Michelle has considerable experience with business acquisitions and sales as well as business restructuring.

Michelle’s qualifications include:

  • Bachelor of Commerce (Accounting)
  • Member of the Institute of Chartered Accountants
Joanne Douglas

Joanne Douglas

Certified Financial Planner and Representative CFP SSA Dip FP

About Joanne

Joanne commenced with Level One in 2004 and has developed into one of our Senior Financial Advisers.

With over 20 years of experience, Joanne and her team provide advice across a wide variety of areas including: Superannuation; Retirement Planning; Centrelink; Aged Care; Portfolio Management and Estate Planning.

A real people person Joanne builds strong long term relationships with her clients by gaining an in-depth knowledge of their personal goals and aspirations while providing tailored financial solutions to meet those needs.

Joanne’s qualifications include:

  • Certified Financial Planner (CFP)
  • Self Managed Superannuation Firm Specialist Adviser
  • Diploma of Financial Planning

Disclaimer & Privacy Policy

Disclaimer

The information contained on this web site is general information only. You agree that your access to, and use of, this site is subject to these terms and all applicable laws, and is at your own risk. This site and its contents are provided to you on “as is” basis, the site may contain errors, faults and inaccuracies and may not be complete and current.

It does not constitute personal financial or taxation advice. When making an investment decision you need to consider whether this information is appropriate to your financial situation, objectives and needs.

Level One makes no representations or warranties of any kind, expressed or implied, as to the operation of this site or the information, content, materials or products included on this site, except as otherwise provided under applicable laws. Whilst all care has been taken in the preparation of information contained in this web site, no person, including Level One Taxation & Business Advisors Pty Limited, accepts responsibility for any loss suffered by any person arising from reliance on the information provided.

Privacy

Level One highly values the strong relationships we have with our clients. The collection of data at Level One is being handled with full and proper respect for the privacy of our clients. The data we collect is handled sensitively, securely and with proper regard to privacy laws. Level One does not disclose, distribute or sell the data we collect from our clients to third parties.