• Facebook Logo
  • LinkedIn Logo
  • MYOB Logo
  • XERO Logo
  • Reckon Logo
  • (08) 9535 5900

Articles

Does Your Small Business Need to Follow AML Privacy Rules?

Compliance with new anti-money laundering (AML) laws may subject your small business to additional privacy obligations it did not face before.

.

 If your business will be required to comply with the Anti-Money Laundering and Counter Terrorism Financing Act 2006 (AML Act), you also need to consider your privacy obligations when handling personal information. Even if you operate a small business that would normally be exempt from privacy regulation, the new AML laws could change this.

Specifically, businesses that are reporting entities under the AML framework must comply with the Privacy Act 1988 (Privacy Act) when collecting, using, storing or disclosing personal information for AML purposes. This includes businesses with an annual turnover of less than $3 million.

Understanding how these two frameworks interact is important if your business performs customer due diligence, identity verification or transaction monitoring. This article explains how the AML and privacy frameworks interact and what small businesses need to do to comply with both.

When Does the Privacy Act Apply to Your Business?

The Privacy Act generally regulates how organisations handle personal information through the Australian Privacy Principles (APPs). While many small businesses are normally exempt, that exemption does not apply when you handle personal information to meet AML obligations. If your business is a reporting entity under the AML Act, you must comply with the Privacy Act for activities connected with those obligations.

Activities that may trigger privacy obligations include:

  • collecting personal information for customer due diligence;
  • storing information for AML record-keeping purposes;
  • monitoring transactions and reporting suspicious matters; and
  • conducting personnel due diligence for employees working in AML roles.

Collecting Personal Information for AML Compliance

To meet your AML obligations, your business will often need to collect personal information about customers, employees or other individuals. Under the APPs, you must limit the information you collect to what is reasonably necessary for your functions and activities. In the AML context, this typically means collecting information required for customer due diligence or risk assessments.

During onboarding, you will commonly collect:

  • full name;
  • date of birth;
  • residential address; and
  • identification document details.

However, the requirement to collect information for AML purposes does not give your business unlimited authority to gather any data you want. You should always consider whether the information you are collecting is genuinely necessary for compliance. Collecting excessive or irrelevant information may increase privacy risks and create unnecessary cybersecurity exposure.

Customer Notification

When your business collects personal information, you must notify individuals about how their information will be handled. This is typically done through a collection notice and your privacy policy.

A collection notice should explain:

  • your organisation’s identity and contact details;
  • why you are collecting the information;
  • whether the collection is required by law;
  • how the information may be used or disclosed; and
  • the consequences if the information is not provided.

In the AML context, this may include explaining that information is collected to comply with the AML Act. However, you do not need to provide a collection notice where doing so would be inconsistent with your tipping off obligations under the AML Act.

Using and Disclosing Personal Information

Under the APPs, personal information should generally only be used or disclosed for the primary purpose for which it was collected. For AML activities, this may include:

  • verifying a customer’s identity;
  • assessing money laundering or terrorism financing risks; and
  • meeting reporting obligations.

In some situations, your business may also be required to disclose personal information to regulators.

For example, reporting entities must submit suspicious matter reports to AUSTRAC when certain conditions are met. Because these disclosures are authorised by law, they are permitted under the Privacy Act even if the individual has not provided consent for these disclosures.

If you disclose personal information overseas (including to a third party service provider), you must generally take reasonable steps to ensure that the overseas recipient does not breach the APPs. However, exceptions apply where the disclosure is required or authorised by the AML Act.

Protecting Personal Information

Businesses that handle AML data often hold large volumes of sensitive personal information. This can make them attractive targets for cybercriminals. Under the APPs, you must take reasonable steps to protect personal information from misuse, interference, loss or unauthorised access.

Practical security measures include:

  • using strong password policies and multi-factor authentication;
  • restricting staff access to personal information;
  • keeping software and systems updated;
  • monitoring system activity with audit logs; and
  • implementing a data breach response plan.

Having a clear response plan ensures your business can act quickly if a data breach occurs.

Retaining and Destroying Personal Information

Under the Privacy Act, businesses must take reasonable steps to destroy or de-identify personal information once it is no longer required. However, the AML Act requires certain records to be kept for specified periods to demonstrate compliance. This means your business must retain AML records when required by law. Once the retention period expires and there is no other reason to keep the data, you should securely delete or de-identify it.

Key Statistics

  1. $3 million: the annual turnover threshold below which a business is normally Privacy Act exempt, an exemption that does not apply where the business is an AML/CTF reporting entity.
  2. Close to 100,000: businesses will be regulated by AUSTRAC once the reforms take effect on 1 July 2026, up from around 19,000 today.
  3. Fewer than 5%: of Australian businesses meet the threshold that would bring them within the Privacy Act’s scope under the current small business exemption.

Sources

  1. OAIC (April 2026)
  2. AUSTRAC (March 2026)
  3. Attorney-General’s Department, Privacy Act Review Report 2022 (February 2023)

Key Takeaways

If your business is a reporting entity under the AML regime, you must comply with the Privacy Act when handling personal information for those obligations. This applies even to small businesses that would otherwise be exempt from privacy regulation.

To comply with both frameworks, your business should only collect information that is reasonably necessary, provide clear privacy notices, protect personal data with appropriate security measures, and retain information only for as long as required. Taking these steps will help you meet your AML obligations while maintaining strong privacy practices and protecting the personal information entrusted to your business.

 

 

 

Legal Vision
Georgia MacKay
legalvision.com.au/