AML/CTF and the Privacy Act
Obligations commenced 1 July 2026

The identity documents your firm collects for AML/CTF are now covered by the Privacy Act.

These documents must now be held securely, restricted to those who need access, and disposed of once they are no longer required. The obligation applies to every copy, wherever it has ended up.

Are your systems configured to protect the information, restrict access, manage retention and provide evidence if something goes wrong? Find out in just 3 minutes with our 13-question checklist.

  • Hold securely
  • Restrict access
  • Manage retention
  • Prepare for breach response
  • Evidence the controls
Start here
When you verify a client's identity, what happens to the document?
Start the checklist

13 questions, about 3 minutes. No client files or documents are required.

WHAT THE LEGISLATION SAYS - YOUR NEW REQUIREMENTS

AML/CTF requires you to collect the record. The Privacy Act governs how you secure it.

AML/CTF Act

Administered by AUSTRAC

Since 1 July 2026, captured businesses must identify, verify and retain required customer records for seven years. A photocopy or scan isn't always required if the details are recorded.

  • Identify and verify the customer
  • Keep appropriate records of the identification carried out
  • Retain required records for seven years

You don't have to copy documents (for example you can record details of a driver's licence or passport rather than photocopying them).

AUSTRAC guidance, initial customer due diligence for individuals
Up to $36.4m maximum civil penalty per contravention of the AML/CTF Act, for a body corporate

Privacy Act

Administered by the OAIC

When personal information is handled for AML/CTF purposes, reporting entities must protect, limit access, and destroy or de-identify it once it's no longer needed.

  • Take reasonable steps to protect the information from misuse, interference, loss and unauthorised access
  • Limit collection to what is reasonably necessary, and manage who can access it
  • Maintain appropriate notices and privacy settings
  • Destroy or de-identify copies once they are no longer needed, unless another Australian law requires retention

You should take reasonable steps to destroy (or de-identify) copies of full identification documents (such as driver's licences or passports) after you no longer need them for your AML/CTF obligations or for another purpose under the Privacy Act or the Australian Privacy Principles (APPs).

OAIC privacy guidance for reporting entities under the AML/CTF Act
Up to $50m maximum penalty for serious or repeated interference with privacy, for a body corporate — or 30% of adjusted turnover if greater

What this means for your business

Every business captured under AML/CTF is now subject to these obligations, regardless of turnover. The same identity records may be subject to AML/CTF and privacy obligations at the same time. Both obligations require secure storage, controlled access, appropriate retention and evidence of compliance.

Here is a practical sequence for putting that in place.

Action plan

What your business needs to do now

Ten practical steps to ensure your business is ready.

Steps 1–5 are for you and your advisor, steps 6–10 relate to your IT systems. Complete the short checklist to understand where your firm stands against steps 6–10. It's only 13 questions, and takes just 3 minutes to complete. If you'd rather have one of our specialists review your systems with you, book a no obligation consultation with us today.