The Privacy Act exemption your business just lost
Your business was exempt from the Privacy Act. For one part of what you hold, it isn't any more.
·7 August 2026·About 6 minutes
Until this year, a small real estate agency could have lost every copy of every driver's licence and passport it held for a client, and broken no obligation under the Privacy Act. So could a law firm. So could an accounting practice. The Act did not reach them.
From the 1st of July 2026, the AML/CTF Act began applying to certain services these businesses provide. Any business providing one of them becomes what that Act calls a reporting entity, and answers to AUSTRAC. The Privacy Act exempts most small businesses from its obligations, but that exemption has never applied to reporting entities. Become one, and it stops applying to you.
It happened automatically. There was no application to make, no notice to receive and no date anyone chose. The exemption simply stopped covering one part of what your firm holds.
Three questions follow. What the exemption is. How much of your business the Privacy Act now covers. And what it asks of you, before a client does.
What the exemption is
The exemption is deliberate and it is written into the Act itself. The Office of the Australian Information Commissioner states the threshold plainly. "A small business is one with an annual turnover of $3 million or less." And: "Most small businesses are not covered by the Privacy Act, but some are."
But some are. The list of exceptions is short and specific. The OAIC names health service providers. Businesses trading in personal information. Credit reporting bodies. Operators of residential tenancy databases. And, in the same list:
- a reporting entity for the purposes of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006
That line is not new. The mechanism sits in section 6E of the Privacy Act and has been there since 2006, when the AML/CTF Act was made. For twenty years it was a provision about banks, remitters and casinos, with nothing to say to a conveyancer in Ballarat. It has not been rewritten since.
Nothing in the Privacy Act moved. The businesses did when Tranche 2 of AML/CTF commenced on the 1st of July.
How much of your business the Privacy Act now covers
Read the OAIC's guidance for reporting entities carefully and the scope is specific. Small businesses that are reporting entities, and their authorised agents, "are required to comply with the Privacy Act in relation to the activities for the purposes of, or in connection with their obligations under the AML/CTF Act and the AML/CTF Rules".
In relation to. The exemption does not disappear across the whole business. It falls away only for the personal information you handle because of AML/CTF. Client identity documents and the records of verifying them sit inside that. Staff records and marketing lists sit outside it.
This partial quality is the other reason the change goes unnoticed. It is not that the business becomes subject to the Privacy Act in general. One category of its records moves inside, the rest stays exactly where it was, and from the inside nothing about the practice looks any different.
Meanwhile that category has been growing since July, in mailboxes and shared drives and practice systems. Every client onboarded since then has added to it, and nobody had to decide anything for that to happen.
What the Privacy Act now asks of you
There are thirteen Australian Privacy Principles. Four of them govern what happens to a client's identity document.
Collect only what is reasonably necessary. This is the easiest one to get wrong before you have started, because the instinct is to keep the photograph. The OAIC is direct about it: "The AML/CTF Act does not require you to keep scanned copies or photocopies of identity documents themselves for record keeping purposes." The obligation is satisfied by the record of what was checked and how. The picture is a choice, and every copy you keep is another thing to secure.
Tell people what you are doing. Before you collect personal information for AML/CTF purposes, or as soon as practicable afterwards, your clients have to be told. If your business was exempt you may have no privacy statement at all, quite reasonably, or one drafted for a business the Act did not reach. Neither describes what you are now collecting, why, or what happens to it.
Secure it, and dispose of it. Reasonable steps to protect personal information from misuse, interference, loss and unauthorised access. And reasonable steps to destroy or de-identify what is no longer needed. Both halves are obligations. The second is the one almost nobody has a process for, because until now nobody needed one.
Give people access to it. Anyone can ask what personal information you hold about them, and you must respond within a reasonable period. The OAIC's guidelines point to thirty calendar days. That is unanswerable for any firm that cannot establish where the copies are.
Why this one will not wait
Two things give it a different character from most obligations that arrive in professional life.
The first is that it comes with a clock somebody else starts. If you have reasonable grounds to suspect an eligible data breach, you have a maximum of thirty days to assess it, and if serious harm is likely, to notify the OAIC and the people affected. That period does not begin on a date chosen in a planning meeting. It begins on the worst morning of the year, the one you find out on.
The second is newer and less well known. On the 10th of June 2025 a statutory tort for serious invasions of privacy commenced. An individual can bring it themselves. It reaches, in the OAIC's words, "individuals and other entities that may not necessarily be an Australian Privacy Principle entity", and the OAIC states plainly that it "does not have a direct role in administering the tort". There is no regulator standing between the person and the claim, and a court may award damages, an injunction, or an order requiring an apology. One limit is often left out: the invasion must be intentional or reckless. A business that is careless, or that gets phished, has not met that test.
So the tort is not what follows an ordinary breach. It signals that privacy has become something individuals can litigate directly, rather than something they can only complain about.
If your turnover was already above the threshold
Then the exemption was never yours to lose, and none of this is news about your status. All of it is news about your records. A firm already covered by the Privacy Act has spent years managing correspondence, contracts and financial details, with a privacy policy to match. It has not, until now, been the custodian of a growing archive of government identity documents collected because a different Act required the verification. The duty has not changed. The material sitting inside it has, and a policy written before July was not written with this in mind.
Where to start
The AML/CTF Act, the Privacy Act and the new tort all come down to the same three questions, and not one of those questions is a legal one. Where are the copies, who can reach them, and what removes them.
None of this arrived with a deadline, which is exactly what makes it easy to leave. There is no date coming that forces the issue, no form to lodge, nothing that lapses. There is only a set of records that has been quietly accumulating since July, under an Act that had nothing to do with your business until this year. Somebody has to decide to look.
efex does not decide whether the AML/CTF Act applies to your business. That question belongs to you and your own advisers. What we can help with is everything downstream of it: finding the copies wherever they have accumulated, establishing who can open them, strengthening the security around them so a breach is less likely in the first place, and making disposal something a system does rather than something a person is supposed to remember.
Start with what applies to your business: it.efex.com.au/aml-ctf.
Then take the checklist.
Thirteen questions, about three minutes, and no client file is opened.
Thirteen questions. About three minutes. No client files.
Or talk it through first. Thirty minutes, no obligation, with somebody who does this work every day.
These articles explain what the regulators have published and what it commonly means in practice. General information only, not legal or compliance advice.
