Peter Price Logo

Latest News

Does Your Small Business Need to Follow AML Privacy Rules?

Compliance with new anti-money laundering (AML) laws may subject your small business to additional privacy obligations it did not face before.

.

 If your business will be required to comply with the Anti-Money Laundering and Counter Terrorism Financing Act 2006 (AML Act), you also need to consider your privacy obligations when handling personal information. Even if you operate a small business that would normally be exempt from privacy regulation, the new AML laws could change this.

Specifically, businesses that are reporting entities under the AML framework must comply with the Privacy Act 1988 (Privacy Act) when collecting, using, storing or disclosing personal information for AML purposes. This includes businesses with an annual turnover of less than $3 million.

Understanding how these two frameworks interact is important if your business performs customer due diligence, identity verification or transaction monitoring. This article explains how the AML and privacy frameworks interact and what small businesses need to do to comply with both.

When Does the Privacy Act Apply to Your Business?

The Privacy Act generally regulates how organisations handle personal information through the Australian Privacy Principles (APPs). While many small businesses are normally exempt, that exemption does not apply when you handle personal information to meet AML obligations. If your business is a reporting entity under the AML Act, you must comply with the Privacy Act for activities connected with those obligations.

Activities that may trigger privacy obligations include:

  • collecting personal information for customer due diligence;
  • storing information for AML record-keeping purposes;
  • monitoring transactions and reporting suspicious matters; and
  • conducting personnel due diligence for employees working in AML roles.

Collecting Personal Information for AML Compliance

To meet your AML obligations, your business will often need to collect personal information about customers, employees or other individuals. Under the APPs, you must limit the information you collect to what is reasonably necessary for your functions and activities. In the AML context, this typically means collecting information required for customer due diligence or risk assessments.

During onboarding, you will commonly collect:

  • full name;
  • date of birth;
  • residential address; and
  • identification document details.

However, the requirement to collect information for AML purposes does not give your business unlimited authority to gather any data you want. You should always consider whether the information you are collecting is genuinely necessary for compliance. Collecting excessive or irrelevant information may increase privacy risks and create unnecessary cybersecurity exposure.

Customer Notification

When your business collects personal information, you must notify individuals about how their information will be handled. This is typically done through a collection notice and your privacy policy.

A collection notice should explain:

  • your organisation’s identity and contact details;
  • why you are collecting the information;
  • whether the collection is required by law;
  • how the information may be used or disclosed; and
  • the consequences if the information is not provided.

In the AML context, this may include explaining that information is collected to comply with the AML Act. However, you do not need to provide a collection notice where doing so would be inconsistent with your tipping off obligations under the AML Act.

Using and Disclosing Personal Information

Under the APPs, personal information should generally only be used or disclosed for the primary purpose for which it was collected. For AML activities, this may include:

  • verifying a customer’s identity;
  • assessing money laundering or terrorism financing risks; and
  • meeting reporting obligations.

In some situations, your business may also be required to disclose personal information to regulators.

For example, reporting entities must submit suspicious matter reports to AUSTRAC when certain conditions are met. Because these disclosures are authorised by law, they are permitted under the Privacy Act even if the individual has not provided consent for these disclosures.

If you disclose personal information overseas (including to a third party service provider), you must generally take reasonable steps to ensure that the overseas recipient does not breach the APPs. However, exceptions apply where the disclosure is required or authorised by the AML Act.

Protecting Personal Information

Businesses that handle AML data often hold large volumes of sensitive personal information. This can make them attractive targets for cybercriminals. Under the APPs, you must take reasonable steps to protect personal information from misuse, interference, loss or unauthorised access.

Practical security measures include:

  • using strong password policies and multi-factor authentication;
  • restricting staff access to personal information;
  • keeping software and systems updated;
  • monitoring system activity with audit logs; and
  • implementing a data breach response plan.

Having a clear response plan ensures your business can act quickly if a data breach occurs.

Retaining and Destroying Personal Information

Under the Privacy Act, businesses must take reasonable steps to destroy or de-identify personal information once it is no longer required. However, the AML Act requires certain records to be kept for specified periods to demonstrate compliance. This means your business must retain AML records when required by law. Once the retention period expires and there is no other reason to keep the data, you should securely delete or de-identify it.

Key Statistics

  1. $3 million: the annual turnover threshold below which a business is normally Privacy Act exempt, an exemption that does not apply where the business is an AML/CTF reporting entity.
  2. Close to 100,000: businesses will be regulated by AUSTRAC once the reforms take effect on 1 July 2026, up from around 19,000 today.
  3. Fewer than 5%: of Australian businesses meet the threshold that would bring them within the Privacy Act’s scope under the current small business exemption.

Sources

  1. OAIC (April 2026)
  2. AUSTRAC (March 2026)
  3. Attorney-General’s Department, Privacy Act Review Report 2022 (February 2023)

Key Takeaways

If your business is a reporting entity under the AML regime, you must comply with the Privacy Act when handling personal information for those obligations. This applies even to small businesses that would otherwise be exempt from privacy regulation.

To comply with both frameworks, your business should only collect information that is reasonably necessary, provide clear privacy notices, protect personal data with appropriate security measures, and retain information only for as long as required. Taking these steps will help you meet your AML obligations while maintaining strong privacy practices and protecting the personal information entrusted to your business.

 

 

 

Legal Vision
Georgia MacKay
legalvision.com.au/

 

Hot Issues

Tax

  • Individual, Sole Trader and Company Tax Returns
  • Partnership and Trust Tax returns
  • Annual Reporting
  • Business and Tax Advisory Services
  • Management of ATO Correspondence
  • Self-Managed Superannuation Funds tax returns
  • Investment properties - tax and negative gearing
  • HELP (higher education loans) debts
  • Estate Returns and Financial Statements
  • Interim Management Accounts and Reporting
  • Testamentary Trusts
  • Tax effective business structures
  • GST Advice
  • Capital Gains Tax Advice
  • Taxation Audit Advice
  • Fringe Benefit Tax
  • Liaise with the ATO on your behalf
Contact Us

SMSF

  • The setting up of a SMSF and all administration tasks such as preparation of your trust deed and the completion and lodgement of relevant ATO statements.
  • Ensuring your SMSF is compliant with current superannuation laws and regulations
  • Appointment of Trustees
  • Arrange the Audit of your SMSF
  • Preparation of financial statements
  • Lodgement of tax returns
Contact Us

Business Accounting

  • Accounting and bookkeeping
  • Accounting software advice and assistance
  • Business & company tax returns
  • Statutory Account
  • Management Accounts
  • Taxation – GST & PAYG advice, BAS preparation
  • Liaise with the ATO on your behalf
  • Tax Audit advice
  • Business ‘start up’ advice
  • Prepare Business plans and financial budgets and review these regularly
  • Measure your performance against industry benchmarks
  • Trust & company structures
  • Queensland Building & Construction Commission reviews
Contact Us

Tax & Accounting Consultancy

  • Strategic advice to managers about the financial implications of projects
  • Development and Monitoring of KPI's
  • KPI reporting
  • Explaining the financial consequences of business decisions
  • Formulating business budgets and business plans and strategies
  • Monitoring spending, financial control and Cashflow projection
  • Conducting internal business audits
  • Monthly/quarterly management reports
  • Product costing reviews.
Contact Us

Business Advisory

  • Business takeovers
  • Valuation of business
  • Due diligence reports
  • Due diligence services
  • Business risk profiles
  • Specialist Tax advice
  • Tax planning
Contact Us

Corporate Compliance

  • The formation of trusts and new company registrations
  • Preparation of annual company statements
  • Attending to ASIC returns and regular filings on your behalf
  • Filing of any company changes or change of directors
  • Business name registrations and maintenance
  • Renewal of business name/s and other registrations
  • Share allotments/transfers/buy-backs
  • Unit Trusts and allotment/transfer of units and change of Trustee
  • Family Trust set up and change of Trustees
  • Provision of registered office services for service of notices
Contact Us

Tax Diary

General Calculators

 

Accounting Videos

Tax Deductions

Documents & Forms

Please click the links below to download.

Downloadable data forms to help you maximise your return

Latest Newsletter

2026 EOFY Newsletter

Secure File Transfer

Secure File Transfer is a facility that allows the safe and secure exchange of confidential files or documents between you and us.

Email is very convenient in our business world, there is no doubting that. However email messages and attachments can be intercepted by third parties, putting your privacy and identity at risk if used to send confidential files or documents. Secure File Transfer eliminates this risk.

Login to Secure File Transfer, or contact us if you require a username and password.

Disclaimer

Information provided on this web site is general in nature and does not constitute financial advice.

Peter Price & Associates has taken reasonable care in providing this information, unless expressly stated, it should not be construed as being specific to your investment objectives, financial situation or particular needs.

Peter Price & Associates will endeavour to update the web site as needed. However, information can change without notice and Peter Price & Associates does not guarantee the accuracy of information on the web site, including information provided by third parties, at any particular time.

This information is prepared for residents of Australia only. Any currency references are references to Australian dollars unless otherwise specified.

Unless otherwise specified, copyright of information provided on this web site is owned by Peter Price & Associates. You may not alter or modify this information in any way, including the removal of this copyright notice.

This web site does not offer securities or other financial products, nor does it invite subscriptions for securities or other financial products to any person outside Australia. Peter Price & Associates does not guarantee the repayment of capital or any particular return from, or any increase in, the value of any Peter Price & Associates products unless otherwise expressly agreed.

Further, Peter Price & Associates disclaims any liability for loss, damage, cost or other expense which you may incur as a result of any information provided on this web site, to the extent that such liability is not excluded by law.

Terms of Payment

Peter Price & Associates Pty Ltd adopts a strict 14 day payment term for all accounts rendered. Full payment of fees must be made 14 days from date of each invoice, unless otherwise agreed upon by Peter Price & Associates Pty Ltd.

You have the options of paying by credit card (Master Card or Visa Card), cash, cheque, money order, direct credit, or we can deduct our fees from your ATO refund. Please contact us for account details if your choose to direct credit to our account, we can also accept credit card payments via phone.

In the event that your payment is late, to the extent permitted by law, interest and charges for late payment will begin to accrue after 30 days from the due date. Payment plans can be arranged to avoid disruption to services. Any costs incurred by debt collectors will be added to outstanding fees payable.