Does becoming an AML reporting entity trigger the Privacy Act for accountants?
Only for your AML data. If your firm provides an AML "designated service", from 1 July 2026 you become an AUSTRAC reporting entity, and Privacy Act s 6E then applies the Australian Privacy Principles to the identity and KYC information you collect for that service, even under the $3 million small-business exemption. It does not pull your general tax, ledger or payroll records under the Act.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
The mechanism, in plain terms
Under section 6D of the Privacy Act 1988 (Cth), a business with annual turnover of $3 million or less is generally a "small business operator" and sits outside the Act and the Australian Privacy Principles (APPs). Most accounting and bookkeeping practices have relied on that exemption.
Becoming an AUSTRAC reporting entity does not switch that exemption off across your whole firm. It works through a targeted provision. Section 6E treats a small business operator that is a reporting entity as an "organisation", an APP entity, but only in relation to the activities it carries on for the purposes of, or in connection with, the AML/CTF Act. So the APPs reach the personal information you handle for AML/CTF: customer identification and know-your-customer records, beneficial-ownership details, and source-of-funds evidence. Your general tax files, ledgers, payroll and CRM stay under the s 6D exemption unless a separate trigger applies to them.
First, are you even a reporting entity?
Most accountants are not. From 1 July 2026, AML/CTF Tranche 2 makes a firm a reporting entity only where it provides a "designated service". The regime regulates services, not professions, so the trigger attaches to what you do on a given engagement, not to the letters after your name.
Preparing tax returns, financial statements and tax advice, along with BAS and GST work, bookkeeping, audit and payroll, are not designated services. A practice doing only that work is not a reporting entity at all, and s 6E never engages. The designated services sit in a table of professional services in the AML/CTF Act and cover things like forming or restructuring companies and trusts, holding or disbursing client money, arranging finance, and acting as or arranging a nominee director, secretary or trustee.
The line is advice-out, execution-in: advising a client on a restructure is not a designated service; actually forming or restructuring the entity, or holding the client's funds, is. For the full breakdown, see which accounting services are designated?.
What s 6E covers, and what it does not
This is where a lot of AML guidance overstates the position, so here is the scoped version.
- In scope: the identity and KYC/CDD information you collect for the designated service. That is where the APPs bite, regardless of turnover.
- Out of scope (via s 6E alone): your general tax files, ledgers, payroll records and marketing lists. Being a reporting entity does not, by force of s 6E, bring those under the Act.
In an accounting file, though, the AML data and the general engagement data often overlap: the same identity documents, the same client record. Many firms find it simplest to apply Privacy-Act-standard handling across the whole matter rather than draw a fine internal line. That is a practical operating choice, not a statement of law, and where your line sits is worth confirming for your own firm.
The trap: this is not the only way the Privacy Act reaches you
Do not read "I provide no designated service, so the Privacy Act does not apply to me". It very likely still does, through a different and broader door.
If your practice handles individual clients' or employees' tax file numbers, the Privacy (Tax File Number) Rule 2015 already binds you for that TFN data, with no turnover threshold and no AML trigger needed. That obligation is live now, it predates Tranche 2, and it catches far more practices than the AML rules do. A breach of the TFN Rule is an interference with the privacy of an individual, so an affected person can complain to the OAIC. See does the Privacy Act apply to accountants under $3 million? and the TFN Rule 2015: what accountants must do.
So there are two distinct triggers with different scope. The TFN Rule is the primary, portable one that catches most practices for individuals' TFN data. The s 6E AML bridge is the narrower, service-specific one for the designated-services subset. Keep them separate, and do not merge them into "accountants are now under the Privacy Act because of AML".
At a glance
| Question | Answer |
|---|---|
| Does becoming a reporting entity trigger the Privacy Act? | Yes, but only for the AML/KYC data, via s 6E, and only if you actually provide a designated service. |
| From when? | 1 July 2026, for firms providing a designated service. |
| Does it cover my whole practice? | No. s 6E reaches the AML/CTF-connected personal information, not your general tax, ledger or payroll records. |
| Does the $3 million exemption still help me? | Yes, for the rest of the firm. s 6D still applies to your non-AML, non-TFN data. |
| What if I provide no designated service? | You are not a reporting entity, so s 6E does not engage. The TFN Rule may still apply to your clients' TFN data. |
What this means you need
Where s 6E engages, the APPs expect the usual baseline for the AML/KYC data you hold: an APP 1 privacy policy, APP 5 collection notices at the points where you take identity and source-of-funds information, and a data-breach response plan, because the Notifiable Data Breaches scheme applies to that concentrated identity and financial data. Retention needs care too, since the AML seven-year record-keeping floor has to be reconciled with the "destroy when no longer needed" principle. See data-breach obligations for accountants handling TFNs and how long can you keep a client's TFN?.
Your AML software gets you enrolled with AUSTRAC and sets up KYC collection. It generally does not deliver these privacy documents for the data it makes you collect. That gap is covered in AML kit vs privacy kit: what your AML software leaves out.
Enrolment for newly regulated firms opened 31 March 2026; existing providers of a designated service enrol by around 29 July 2026. Confirm your firm's exact position and timing with AUSTRAC.
Common questions
Does every accountant become a reporting entity on 1 July 2026?
No. You are a reporting entity only if you provide a designated service, such as forming or restructuring entities, holding client money, or acting as a nominee. Routine tax returns, financial statements, tax advice, BAS, bookkeeping, audit and payroll are not designated services, so a practice doing only that work is not a reporting entity.
If I am a reporting entity, does the Privacy Act cover my whole firm?
No. Section 6E(1A) applies the APPs to the personal information you handle for purposes connected with the AML/CTF Act. That is broader than the identity documents themselves: beneficial-ownership checks, sanctions and politically-exposed-person screening, and the customer risk assessment you record all sit inside it. Your general tax, ledger and payroll records stay under the s 6D small-business exemption unless a separate trigger, such as the TFN Rule, applies to them.
I provide no designated service. Am I clear of the Privacy Act?
Not necessarily. If you handle individual clients' or employees' tax file numbers, the TFN Rule 2015 binds you for that TFN data regardless of turnover and with no AML trigger needed. That is a separate obligation that catches most practices. See does the Privacy Act apply to accountants under $3 million?.
What happens if I get the AML data handling wrong?
A breach can expose you to regulatory and complaint action, with the OAIC handling privacy complaints and AUSTRAC handling the AML/CTF side. Penalties are ceilings rather than certainties, and most matters resolve without a fine, but the concentrated identity and financial data you hold makes getting the handling right worthwhile.
Keep reading
- AML Tranche 2 for accountants: which services are designated?
- Does the Privacy Act apply to accountants under $3 million?
- The Privacy (Tax File Number) Rule 2015: what accountants must do
- Data-breach obligations for accountants handling TFNs
- AML kit vs privacy kit: what your AML software leaves out
- Privacy Act compliance for accountants and bookkeepers (the hub)
This is general information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC, or your obligations under the TPB Code, which are administered by the Tax Practitioners Board. Privaproof's accountant documents are self-authored and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner. The Privacy Act 1988 (Cth), the AML/CTF Act and related guidance change over time, so check you are working from a current version.