Home » Blog » Your AML/CTF privacy obligations go further than most reporting entities expect

Your AML/CTF privacy obligations go further than most reporting entities expect

From 1 July 2026, a new category of Australian businesses became subject to Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act) obligations for the first time. Most of those businesses are thinking about what information to collect from clients. Fewer are asking what they are required to do with it once they have it.

That gap is where a lot of the risk sat.

Privacy obligations come with the territory

Most small businesses do not have to follow the Privacy Act. There is a general rule that says if your business turns over less than $3 million a year, the Act does not apply to you. Simple enough.

But there is an exception. If your business has to collect personal information because of AML/CTF obligations (like verifying who your clients are), the Privacy Act applies to that information. It does not matter how small your business is. The exemption disappears the moment AML/CTF obligations come into the picture.

For a specific group of businesses (real estate professionals, dealers in precious metals and stones, lawyers, conveyancers, accountants and trust and company service providers), obligations switched on from 1 July 2026. When they did, so did the privacy obligations that come with them.

Collecting more information does not mean better compliance

When businesses first hear about AML/CTF obligations, a common instinct is to collect as much information as possible. More data feels like better protection. The Office of the Australian Information Commissioner’s (OAIC) position is the opposite.

Privacy law requires you to collect only what is reasonably necessary. That means you should only be gathering AML/CTF information when you are actually providing a service that triggers the obligation. Running every client through the same identity verification process does not meet the standard.

A regional accounting firm uses one onboarding form for every new client. Only some of those clients are receiving services that trigger AML/CTF obligations, but all of them are being asked for identity documents. The clients who just want help with their tax return have no obligation to provide that information. Collecting it anyway does not meet the reasonably necessary standard.

The point is this. More data does not mean safer. It means more exposure. Every piece of personal information you hold that you did not need to collect is a liability, not an asset.

This is especially true when AML/CTF information passes through external platforms or third-party verification services. Privacy obligations follow the data, not just the collection point. The same accountability questions that apply when reviewing how your vendors handle your data apply here, too.

Before you update your policies, understand what you actually hold

Many organisations jump straight into updating their privacy policy when they hear about new obligations. The problem is that you cannot write an accurate policy about how you handle information until you know what you hold, where it lives and who can get to it.

Mapping that does not need to be complicated. At its most basic, you are trying to understand:

  • What AML/CTF personal information do you collect and why?
  • Where it is stored. Your own systems, a third-party platform, a shared drive, or an email inbox.
  • Who has access to it, and whether that access is necessary
  • How long you keep it and what happens to it when you no longer need it.

Overseas storage and third-party platforms deserve specific attention. If client information collected for AML/CTF purposes is processed offshore (through a document verification service or cloud platform based outside Australia), you are still responsible for how it is handled. Assuming the platform takes care of it is not enough.

For organisations that need help building that picture, Advanta’s practical GRC frameworks are built for exactly this kind of structured review.

Your privacy policy probably does not cover this yet

If your privacy policy was written before AML/CTF obligations were on your radar, it almost certainly does not cover how you collect, use, share or store AML/CTF-related information. That is a gap worth closing. And sooner rather than later.

The OAIC has released a template privacy collection notice specifically for businesses with AML/CTF obligations. It is a reasonable starting point, but it is not a copy-and-paste solution. A notice that does not accurately describe what your organisation actually does is making a promise to clients that does not match reality.

At a minimum, a privacy collection notice should tell people why you are collecting their information, what you are collecting, who you might share it with, and where they can read your full privacy policy.

In our experience, this is one of the areas where the gap between what a privacy policy says and what happens in practice is widest. Advanta’s privacy advisory support can help turn that into documentation that is accurate, current and defensible.

Keeping full copies of ID documents is creating risk, not reducing it

Most businesses keep scanned copies of passports and driver's licences because it seems like the cautious thing to do. The OAIC guidance is clear that it was not required. The AML/CTF Act requires a record of the relevant information (name, date of birth, document number), not a copy of the document itself.

That distinction matters. A scanned passport sitting in a shared drive or an email inbox is a far more serious breach than a record of verified details. The personal information exposed is more sensitive, the impact on the individual is greater, and the reputational cost to your business is harder to manage.

Review where full ID copies are sitting (document portals, email threads, CRM attachments, third-party onboarding platforms) and build a documented process for destroying or de-identifying them once they are no longer needed. That should not be left to whoever happens to be handling the file.

“There’s a practical question underneath a lot of AML/CTF readiness work that doesn’t always get asked: do our current processes actually reflect what we’re telling people we do with their information? That gap, between the privacy notice and the reality, is where a lot of the risk sits”.
-
Adam Cliffe, Advanta Advisory. 

Where to start

These are not compliance checkboxes. They are the questions a leader should be able to answer, and where the gaps are is where the work is.

  • Do AML/CTF obligations actually apply to our services?
    Not all services trigger obligations. This is the right first question. It shapes everything else
  • Are we collecting only what is required?
    Test this against what happens in practice during onboarding, not just what the policy describes.
  • Does our privacy policy cover our AML/CTF information handling?
    If it was written before this was on your radar, assume it does not.
  • Do our privacy notices reflect what we actually do?
    A notice written generically, or not updated when onboarding changed, is likely out of step with reality.
  • Are we holding full copies of ID documents we do not need?
    Check shared drives, email inboxes, CRM attachments, and third-party platforms. Not just formal document stores.
  • Do we know where client information goes after it is collected?
    Third-party platforms, verification services and overseas processing all need to be accounted for.
  • Do staff know when AML/CTF information should and should not be collected?
    The gap between policy and practice usually sits here.
  • Are our retention and destruction practices written down and followed consistently?
    If the answer is “it depends on who is handling it”, that is a gap to close.

AML/CTF obligations and privacy obligations are not separate jobs. They are the same job. Organisations that treat privacy as something to tidy up after the compliance work is done will find themselves going back through everything under time pressure. Organisations that cannot answer the questions above are not just carrying operational risk, they are carrying regulatory and reputational exposure that grows every day the gap remains.

Those questions are not technical. They belong on the agenda, not in the IT queue.

For structured guidance on AML/CTF privacy obligations, Advanta’s privacy advisory support offers practical support tailored to the size and context of your organisation.

Frequently Asked Questions

Do AML/CTF reporting entities need to comply with the Privacy Act?

Yes. Businesses with AML/CTF obligations must comply with the Privacy Act when handling personal information for those purposes, including small businesses that would otherwise be exempt from the Act.

Can reporting entities keep copies of passports or driver's licences?

Not necessarily. The AML/CTF Act does not require businesses to keep scanned copies or photocopies of identity documents. A record of the relevant information is what is required, not the document itself.

What should a privacy collection notice include for AML/CTF customer due diligence?

A collection notice should explain why personal information is being collected, what is collected, how it is collected, who it may be shared with and where to find the organisation's full privacy policy.

Does the Privacy Act apply to all small businesses with AML/CTF obligations?

Yes. Even if a small business is normally exempt from the Privacy Act because it turns over less than $3 million a year, that exemption does not apply to personal information handled for AML/CTF purposes.

What is a Tranche 2 entity under the AML/CTF Act?

Tranche 2 entities are a group of businesses brought into the AML/CTF regime from 1 July 2026. They include certain real estate professionals, dealers in precious metals, stones, and products, and professional services providers such as lawyers, conveyancers, accountants and trust and company service providers.


Stay up to date

Subscribe to our newsletter for IT news, case studies and promotions