Legal: the access request you may not answer, and may not explain
A client asks what you hold on them. One act says answer. The other says do not say why you cannot.
·25 August 2026·About 8 minutes
The email arrives on a Thursday and does not look like anything unusual. She is a former client, a conveyancing matter that settled two years ago. She would like a copy of everything the practice holds about her. It appears she is moving her affairs to another firm and wants her file.
Most of it is routine. Correspondence, the contract, the settlement statement, trust records.
The part that is not routine is a folder nobody has opened since the matter closed. In it are photographs of her driver's licence and the front page of her passport, taken at the time her identity was verified, filed where the person who did the verifying happened to file them. There is very likely a second copy in a mailbox, because that is how the images arrived.
From the 1st of July 2026, obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 apply to certain services that legal practices provide. The Office of the Australian Information Commissioner has published guidance for firms in that position. Under one instrument the practice owes that former client an answer. Under another, in defined circumstances, it may owe her silence, and may not be permitted to tell her why.
The obligation that says answer
Australian Privacy Principle 12 gives an individual a right to access the personal information an organisation holds about them. The OAIC's APP Guidelines say an organisation must respond "within a reasonable period after the request is made", and suggest thirty calendar days as a general guide.
Refusal is possible but it is not free. Where access is refused, the Guidelines require a written notice setting out "the reasons for the refusal, except to the extent that it would be unreasonable to do so", along with information about how to complain. The exceptions to access include the situation where "giving access would be unlawful", or where "denying access is required or authorised by or under an Australian law or a court/tribunal order".
There is a threshold question that many smaller practices will not have considered, and the OAIC has answered it. Its guidance for reporting entities states that small businesses which are reporting entities under the AML/CTF Act, and their authorised agents, "are required to comply with the Privacy Act in relation to the activities for the purposes of, or in connection with their obligations under the AML/CTF Act and the AML/CTF Rules".
In other words, whatever a practice's turnover, the identity records it collects for AML/CTF purposes sit inside the Privacy Act. Anyone whose planning assumed the small business exemption would carry them through now has a gap.
The obligation that says do not
Section 123 of the AML/CTF Act is the tipping-off provision. In its earlier form, as MinterEllison's Tony Coburn, Prayas Pradhan, Malcolm Shackell and Wesley Lalich described it, the section made it a criminal offence "to disclose information from which it could be inferred that a reporting entity has lodged a suspicious matter report with AUSTRAC concerning a person".
That form has gone. The replacement prohibits disclosure "where this would or could reasonably be expected to prejudice an investigation" of an offence or of proceeds of crime legislation. The same authors expected the change to "reduce the number of practical problems which currently arise under section 123". The new section 123 took effect on 31 March 2025, a year ahead of most of the rest of the amending legislation.
Reduced problems are not the same as no problems, and the OAIC's guidance names the one that matters here. Under the heading dealing with access to personal information, it says:
“You must not provide access to personal information or explain why you are denying access if it would breach the tipping off offence in section 123 of the AML/CTF Act.”
— OAIC guidance for reporting entities
And on the notice itself:
“If you are refusing to give access to personal information because it is inconsistent with your legal obligations (for example tipping off), your written notice must not explain why you have refused access.”
— OAIC guidance for reporting entities
The general rule is the opposite of that. A refusal notice sets out its reasons, "except to the extent it would be unreasonable to do so", and the same guidance names an inconsistency with tipping off obligations as exactly that exception. So the ordinary discipline of a refusal, that the practice explains itself and that the reason is the first thing the client is entitled to, is the one thing that cannot happen here, because the reason is the disclosure. The notice goes out without it, and a firm can find itself declining a client's lawful request while declining, equally, to say why, in a profession whose standing rests on being able to account to the person in front of it.
Anton Moiseienko, Associate Professor of Law and Research Director at the Australian National University, has made the related point about reporting itself, noting that "the obligation to file a suspicious matter report might conflict with legal professional privilege". The access request is the same tension, arriving from the client's side of the desk rather than the regulator's.
The conflict most firms are preparing for, which is not the one they have
Ask what AML/CTF and privacy do to each other and the answer usually comes back as retention. One law says keep the identity documents for seven years. The other says destroy what is no longer needed. It is the framing most of the available commentary uses, and a firm acting on it would reasonably conclude it needs somewhere safe to keep licence photographs for the better part of a decade.
The OAIC's February 2026 guidance takes most of it away in a single sentence:
“The AML/CTF Act does not require you to keep scanned copies or photocopies of identity documents themselves for record keeping purposes.”
— OAIC, February 2026 guidance
What the guidance says should be kept instead is the information taken from the document: names, date of birth, residential address, date of expiry, and the passport or licence number, together with documentation of the verification procedure that was followed. The seven-year record is the data and the method. It was never the photograph.
Two qualifications matter. The first is historical, and the wording repays attention. The guidance says that "copies of identification documents made prior to 31 March 2026 are records for the purposes of AML/CTF Act, and reporting entities are authorised to continue to keep these for 7 years following the end of the business relationship or 7 years after the date of the last occasional transaction". Authorised, not required. A firm holding older copies is permitted to keep them. It is not obliged to, and that distinction is the difference between an archive a practice chose and an archive it believes it inherited.
The second is the Privacy Act's own instruction, which the guidance puts plainly: destroy or de-identify personal information once it is not needed for any other purpose the entity is permitted to hold it for.
So the retention conflict is, in large part, a misreading. The cost of it is not academic. An archive of licence photographs held for seven years is precisely the holding that turns an ordinary breach into a serious one, and on the OAIC's guidance the Act did not ask for it.
For property practices, a third instrument
There is one place where copies genuinely must be kept, and it is not an act.
Practices that lodge electronically operate under participation rules made under the Electronic Conveyancing National Law. The Australian Registrars' National Electronic Conveyancing Council's guidance on retention of evidence states that "evidence supporting a Conveyancing Transaction must be kept for at least seven years from the date of Lodgement", and for standing or batch authorisations, seven years from the last transaction lodged.
That evidence may include "originals, copies or records of" the documents relied on, and the guidance requires it to be "legible, stored safely and securely, and accessible".
This binds subscribers participating in electronic conveyancing. It does not bind the profession generally, and a practice with no property work is not caught by it. For the firms it does bind, the position is awkward and largely unremarked: they may hold photographs of identity documents under a participation rule, subject to a Privacy Act duty to secure them and eventually dispose of them, and answerable to a client who can ask for all of it at any time.
Every one of these questions has the same prerequisite
Access, refusal, retention, destruction. Each is a different obligation, and each is unanswerable in the same way. None of them can be discharged by a practice that cannot establish where the copies are.
That is rarely one place. The practice management system holds some. Mailboxes and sent items hold more, because clients send photographs of licences by email and always have. There is usually a shared drive. There is often a scan folder on the copier that nobody has looked at in years. There are backups, and occasionally a phone.
Katie Miller, Deputy Chief Executive Officer of AUSTRAC, put the accountability question in terms that travel well beyond her own agency's remit. "You can outsource the doing and the execution," she told the Law Society Journal, "but you can't outsource the liability and responsibility."
David Allen, Solicitor Director at Haille Paine, made the practical version of the same point in the same article. "It's not as simple as ... 'here's your checklist, here's your policy, job's done.'"
Both point at the same gap. The policy work gets done, often well. The question of where the documents physically are tends not to get asked, because it has never belonged to anybody in particular.
Where this leaves a practice
With a question that is not legal at all. Before a firm can answer an access request, refuse one properly, produce a seven-year record, or destroy what it no longer needs, it has to know every place a client's identity documents are held. That is not an interpretation of either act. It is the precondition for meeting them, and it lives in configuration rather than in a program document.
At efex we can help with the technology requirements above: finding the copies, establishing who can reach them, making retention something the system does rather than something a person remembers, and keeping the systems that hold those records configured to keep people out. The quickest way to lose control of who can see a client’s identity documents is for somebody outside the firm to get in.
Our AML/CTF technology and data checklist asks thirteen questions and takes about three minutes to complete. It opens no client file and uploads nothing. Two of its questions are the ones this article turns on: whether the firm could locate every copy of one client's identity documents if asked today, and every place one could be sitting right now. Start the checklist.
Read what applies to legal practices at it.efex.com.au/aml-ctf/legal.
Thirteen questions. About three minutes. No client files.
Or talk it through first. Thirty minutes, no obligation, with somebody who does this work every day.
These articles explain what the regulators have published and what it commonly means in practice. General information only, not legal or compliance advice.
