Skip to content

Does becoming an AML reporting entity trigger the Privacy Act for accountants?

Only for your AML data. If your firm provides an AML "designated service", it has been an AUSTRAC reporting entity since 31 March 2026, and Privacy Act s 6E(1A) then applies the Act, including the Australian Privacy Principles, to the activities you carry on for the purposes of, or in connection with, the AML/CTF Act, which in practice means the identity and KYC information you collect for that service, even under the $3 million small-business exemption. By itself it does not pull your general tax, ledger or payroll records under the Act, though a separate trigger such as the TFN Rule can.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

The mechanism, in plain terms

Under section 6D of the Privacy Act 1988 (Cth), a business whose annual turnover for the previous financial year is $3,000,000 or less is a "small business" (s 6D(1)), and an entity that carries on only small businesses is generally a "small business operator" (s 6D(3)) sitting outside the Act and the Australian Privacy Principles (APPs). That is a general rule, not a closed one: s 6D(4) lists entities that are not small business operators even under the threshold, including a business that has had turnover of more than $3,000,000 for any financial year ending after it started (s 6D(4)(a)), one that provides a health service and holds health information (s 6D(4)(b)), one that discloses personal information for a benefit, service or advantage (s 6D(4)(c)), and a contracted service provider for a Commonwealth contract (s 6D(4)(e)). ⚠️ s 6D(4)(a) does not reverse: one financial year above $3 million takes a practice out of the exemption, and a later fall in turnover does not put it back. For a practice under the threshold with none of those features, the exemption is the usual starting point.

Becoming an AUSTRAC reporting entity does not switch that exemption off across your whole firm. It works through a targeted provision. Section 6E(1A) provides that if a small business operator is a reporting entity, or an authorised agent of a reporting entity, because of anything done in the course of its small business, the Act applies, with any prescribed modifications, "in relation to the activities carried on by the small business operator for the purposes of, or in connection with, activities relating to" the AML/CTF Act or the regulations and AML/CTF Rules under it, "as if the small business operator were an organisation". Two things follow. The provision is activity-scoped, not entity-wide: it catches the AML/CTF-connected activities, not the practice. And what applies to those activities is the whole Act, not only the APPs, so the Australian Privacy Principles and the Notifiable Data Breaches scheme both reach the personal information you handle for AML/CTF: customer identification and know-your-customer records, beneficial-ownership details, and source-of-funds evidence. Your general tax files, ledgers, payroll and CRM stay under the s 6D exemption unless a separate trigger applies to them.

First, are you even a reporting entity?

Not every accountant is. From 31 March 2026, AML/CTF Tranche 2 makes a firm a reporting entity only where it provides a "designated service". The regime regulates services, not professions, so the trigger attaches to what you do on a given engagement, not to the letters after your name.

Preparing tax returns, financial statements and tax advice, along with BAS and GST work, bookkeeping, audit and payroll, are not among the listed designated services. A practice doing only that work is not a reporting entity on that basis, and s 6E(1A) does not engage. The nine professional-services designated services are in s 6(5B) of the AML/CTF Act, and the ones that can reach an accounting practice are creating or restructuring a body corporate or legal arrangement such as a company or trust (item 6), acting on the sale, purchase or transfer of a body corporate or legal arrangement (item 2), receiving, holding, controlling or managing a client’s money or other property as part of a transaction (item 3), organising, planning or executing equity or debt financing for a body corporate or legal arrangement (item 4), selling or transferring a shelf company (item 5), acting as, or arranging another person to act as, a director, secretary, power of attorney, partner or trustee of an express trust (item 7) or a nominee shareholder (item 8), and providing a registered office or principal place of business address (item 9). Item 1 catches assisting a person in a transaction to sell, buy or transfer real estate, so it can reach a practice that does that work too. ⚠️ Holding client money is heavily qualified by s 6(5C), which sets out six circumstances outside item 3, including money that is payment for your own goods or services, money to be received or payable under a court or tribunal order, and the receipt or disbursement of a payment to or from a government body, court, tribunal or licensed insurer (s 6(5D)). ⚠️ Item 7 has its own carve-outs in s 6(5E) for acting in a fiduciary capacity under a court or tribunal order and for acting as the trustee of a regulated debtor’s estate.

⚠️ Be careful with the shorthand that advice is out and only execution is in. The statute does not draw that line. Items 1, 2 and 4 of Table 6 catch "assisting a person in the planning or execution of a transaction", and item 6 catches "assisting a person to plan or execute, or otherwise acting on behalf of a person in, the creation or restructuring of" a body corporate or legal arrangement. Planning is expressly inside those items. General advice that stops short of assisting in the planning of an actual transaction sits outside them, but helping to plan a restructure, a sale or a financing can itself be a designated service. For the full breakdown, see which accounting services are designated?.

What s 6E covers, and what it does not

This is where a lot of AML guidance overstates the position, so here is the scoped version.

In an accounting file, though, the AML data and the general engagement data can overlap: the same identity documents, the same client record. One practical response is to apply Privacy-Act-standard handling across the whole matter rather than draw a fine internal line. That is an operating choice, not a statement of law, and where your line sits is worth confirming for your own firm.

The trap: this is not the only way the Privacy Act reaches you

Do not read "I provide no designated service, so the Privacy Act does not apply to me". It can still apply, through a different and broader door.

If your practice handles individual clients’ or employees’ tax file numbers, the Privacy (Tax File Number) Rule 2015, made by the Information Commissioner under Privacy Act s 17, already binds you for that TFN data. Anyone in possession or control of a record containing tax file number information is a "file number recipient" (s 11), and s 18 provides that a file number recipient "shall not do an act, or engage in a practice, that breaches a rule issued under section 17". There is no turnover threshold and no AML trigger anywhere in that chain, and the obligation predates Tranche 2. Section 13(4)(a) makes a file number recipient’s breach of a s 17 rule an interference with the privacy of an individual, so an affected person can complain to the OAIC. Note the scope: the TFN Rule protects the TFN information of individuals, not the TFNs of companies, partnerships, trusts or super funds. See does the Privacy Act apply to accountants under $3 million? and the TFN Rule 2015: what accountants must do.

So these are two distinct triggers with different scope. The TFN Rule is the portable one: it turns on possession of individuals’ TFN information, not on turnover and not on any AML status. The s 6E(1A) AML bridge is the narrower, service-specific one for the designated-services subset. They are not the only two routes into the Act, since s 6D(4) and the s 6EA opt-in also exist. Keep them separate, and do not merge them into "accountants are now under the Privacy Act because of AML".

At a glance

QuestionAnswer
Does becoming a reporting entity trigger the Privacy Act?Yes, but only for the AML/KYC data, via s 6E, and only if you actually provide a designated service.
From when?Reporting-entity status from 31 March 2026, when tables 5 and 6 commenced, for firms providing a designated service. The four deferred obligation Parts, covering AML/CTF programs, customer due diligence, reporting and record keeping, started 1 July 2026.
Does it cover my whole practice?No. s 6E reaches the AML/CTF-connected personal information, not your general tax, ledger or payroll records.
Does the $3 million exemption still help me?For the rest of the firm, yes, provided nothing else in s 6D(4) applies to you. AML and the TFN Rule are not the only doors: s 6D(4)(b) to (f) cover health services, disclosing or collecting personal information for a benefit, Commonwealth contracted service providers and credit reporting bodies; s 6D(4)(a) takes you out permanently once any financial year tops $3 million; and s 6EA lets a small business operator opt in.
What if I provide no designated service?You are not a reporting entity, so s 6E does not engage. The TFN Rule may still apply to your clients' TFN data.

What this means you need

Where s 6E(1A) engages, the usual baseline applies to the AML-related activities you carry on: an APP 1 privacy policy, APP 5 collection notices at the points where you take identity and source-of-funds information, and reasonable security steps under APP 11.1. The Notifiable Data Breaches scheme in Part IIIC reaches that data as well, because s 6E(1A) applies the whole Act to those activities, and the OAIC recommends a written data-breach response plan as the practical way to meet the assessment and notification timeframes, though the Act does not itself mandate one. Retention is the point most often misread: s 107(3) of the AML/CTF Act requires a reporting entity to retain transaction records for seven years from the day the record is made, and APP 11.2 does not conflict with that, because it does not apply while an entity is required by or under an Australian law to retain the information. The destruction duty revives once the retention period ends. See data-breach obligations for accountants handling TFNs and how long can you keep a client’s TFN?.

AML software is built to get you enrolled with AUSTRAC and to run KYC collection. Whether a given product also supplies the Privacy Act documents for the data it makes you collect is a question worth putting to your own vendor, because the two obligations sit under different Acts and different regulators. That gap is covered in AML kit vs privacy kit: what your AML software leaves out.

AUSTRAC enrolment for newly regulated firms opened on 31 March 2026, the same day tables 5 and 6 commenced. A firm that was already providing a designated service before 1 July 2026 had to be enrolled by 29 July 2026, a date fixed by Schedule 3 Part 4 item 12 of the amending Act rather than counted from the day it started providing the service. Confirm your firm’s exact position and timing with AUSTRAC.

Common questions

Does every accountant become a reporting entity on 31 March 2026?

No. You are a reporting entity only if you provide a designated service, such as forming or restructuring entities, holding client money, or acting as a nominee. Routine tax returns, financial statements, tax advice, BAS, bookkeeping, audit and payroll are not designated services, so a practice doing only that work is not a reporting entity.

If I am a reporting entity, does the Privacy Act cover my whole firm?

No. Section 6E(1A) applies the APPs to the personal information you handle for purposes connected with the AML/CTF Act. That is broader than the identity documents themselves: beneficial-ownership checks, sanctions and politically-exposed-person screening, and the customer risk assessment you record all sit inside it. Your general tax, ledger and payroll records stay under the s 6D small-business exemption unless a separate trigger, such as the TFN Rule, applies to them.

I provide no designated service. Am I clear of the Privacy Act?

Not necessarily. If you handle individual clients' or employees' tax file numbers, the TFN Rule 2015 binds you for that TFN data regardless of turnover and with no AML trigger needed. That is a separate obligation that catches most practices. See does the Privacy Act apply to accountants under $3 million?.

What happens if I get the AML data handling wrong?

Two regulators sit either side of the line: the OAIC handles complaints about interferences with privacy under the Privacy Act, and AUSTRAC administers the AML/CTF Act. Under the Privacy Act an individual may complain to the Commissioner about an act or practice that may be an interference with their privacy (s 36), and the Commissioner’s options run from conciliation through to civil penalty proceedings for serious or repeated interferences (s 13G, s 13H). Maximum penalties are statutory ceilings, not amounts that attach to any particular breach.

Keep reading


This is general information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC, or your obligations under the TPB Code, which are administered by the Tax Practitioners Board. For advice on your specific circumstances, consult a qualified Australian legal practitioner. The Privacy Act 1988 (Cth), the AML/CTF Act and related guidance change over time, so check you are working from a current version.