The Office of the Australian Information Commissioner (OAIC) has released updated guidance that sharpens the focus on how businesses must balance their Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) obligations with their duties under the Privacy Act.
With the AML/CTF Act expanding to new sectors from 1 July 2026—bringing in law firms, real estate professionals, and accountants—understanding this balance is no longer just a banking issue. It’s a professional service issue.
Here are the key takeaways from the OAIC’s guidance to help you prepare.
1. Collection Must Be “Reasonably Necessary”
One of the most critical points in the guidance relates to when you can actually collect personal information for Know Your Customer (KYC) purposes.
Under the new rules, you cannot simply onboard every client with a full suite of identity checks “just in case.” The OAIC confirms that collection must be objectively reasonably necessary. This means there must be a genuine nexus between the service you are providing and a “designated service” under the AML/CTF Act.
For example:
Practical Tip: For Tranche 2 entities, you must ensure clients engaged for non-designated services are not automatically funnelled into the AML/CTF compliance process. If you do, you risk breaching APP 3.
2. Biometric Verification: Consent is Key
Biometric ID verification (like facial recognition) is a powerful tool for reducing fraud. However, the OAIC has made its position clear: you should seek consent before using biometrics for customer due diligence.
While the AML/CTF regime may “authorise” the collection of sensitive information, the OAIC’s preferred approach is consent. If a client refuses consent, you must have alternative methods available to verify their identity. Relying solely on the “authorised by law” exception carries a clear compliance risk.
3. Stop Storing Copies of ID Documents
This is a significant operational change coming into effect from 31 March 2026.
Historically, many businesses kept scanned copies of passports or driver’s licences. Under the amended record-keeping obligations, this will no longer be justified.
To comply with APP 11 (which requires you to destroy information when it is no longer needed), you must update your processes. Instead of storing full document copies, you should only retain the specific information required to demonstrate compliance, such as:
If your systems currently store full copies of identity documents, now is the time to review your retention processes.
4. The Small Business Exemption Disappears
If your business is a reporting entity under the AML/CTF Act, the “small business exemption” in the Privacy Act does not apply to your AML/CTF activities.
This is crucial for smaller firms entering the regime as part of Tranche 2. Even if you normally qualify for the small business exemption, you will be subject to the full force of the Australian Privacy Principles (APPs) when handling customer information for AML/CTF purposes.
5. Navigating “Tipping Off”
There is a delicate interplay between privacy, transparency, and AML/CTF secrecy provisions (the “tipping off” rules).
When updating your privacy policies or responding to client requests for access to their information (under APP 12), you must ensure you do not inadvertently disclose the existence of a Suspicious Matter Report (SMR) to the customer. The secrecy provisions override privacy obligations in the event of a conflict.
WHAT YOU SHOULD DO NOW
To get ahead of these changes, I recommend focusing on three core areas:
The intersection of privacy and anti-money laundering compliance is becoming increasingly complex. By taking a principles-based approach now – focusing on proportionality, consent, and transparency – you can build a compliance framework that satisfies both the OAIC and AUSTRAC.
Mar 2026