Skip to content

AML kit vs privacy kit: what your AML software leaves out

An AML kit does the AUSTRAC job: enrolment, customer identification and KYC collection. The Privacy Act then expects a separate privacy layer for that identity data, because a firm providing a designated service has been an AUSTRAC reporting entity since 31 March 2026, and Privacy Act s 6E(1A) applies the Australian Privacy Principles to the activities it carries on for the purposes of, or in connection with, the AML/CTF Act. Check what your AML product covers, then check whether the privacy policy, collection notices and data-breach plan for that data are covered too.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

Two different jobs, two different tools

If your practice provides an AML "designated service", an AML kit does a real and necessary job. It walks you through enrolment with AUSTRAC, helps you build an AML/CTF program, and stands up the customer due diligence workflow: collecting and verifying identity documents, screening for politically exposed persons and sanctions, and recording source-of-funds evidence. A number of vendors serve that market. This page makes no claim about what any particular product does or does not include.

The point this page makes is narrower and easily missed. Collecting all that identity data is itself a privacy event. The moment a designated service makes you a reporting entity, the personal information you gather for AML purposes falls under the Privacy Act, and the Act expects its own set of documents for that data. Collecting the data and holding, disclosing, securing and eventually destroying it to the standard the Privacy Act requires are two different jobs, under two different Acts. Whether your AML product also does the second one is a question to put to your vendor.

Why the gap exists: s 6E(1A) applies the Privacy Act to your AML activities

Under section 6D of the Privacy Act 1988 (Cth), a practice is generally a "small business operator" outside the Act. Turnover is only one of the tests. Section 6D(4) lists six circumstances that take a business out of the exemption: annual turnover of more than $3,000,000 for a financial year (s 6D(4)(a)), providing a health service and holding health information other than in an employee record, disclosing personal information for a benefit or advantage, providing a benefit or advantage to collect it, being a contracted service provider for a Commonwealth contract, and being a credit reporting body. Section 6D(4)(a) runs one way: once turnover has exceeded the threshold for a financial year, a later fall does not restore the exemption. Providing a designated service does not switch the exemption off across your whole firm either. It works through one targeted provision.

Section 6E(1A) provides that if a small business operator "is a reporting entity or an authorised agent of a reporting entity because of anything done in the course of a small business carried on by the small business operator, this Act applies ... in relation to the activities carried on by the small business operator for the purposes of, or in connection with, activities relating to ... the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 ... as if the small business operator were an organisation". So the Australian Privacy Principles reach the identity and KYC/CDD information you collect for the designated service, regardless of your turnover. They do not reach your general tax files, ledgers, payroll or CRM, which stay under the s 6D exemption unless a separate trigger applies to them. The trigger in s 6E(1A) is being a reporting entity, not having AML obligations, which is why it engaged on 31 March 2026 when the professional-services designated services commenced, rather than on 1 July 2026 when the obligations started.

That is the gap the AML/CTF side does not close on its own. A designated service hands you a body of concentrated identity data and, through s 6E(1A), the Privacy Act attaches obligations to that data. An AML/CTF program under Part 1A of the AML/CTF Act is a money-laundering and terrorism-financing risk document; it is not the privacy policy, collection notice or breach plan the Privacy Act asks for. For the full mechanism, see does becoming an AML reporting entity trigger the Privacy Act for accountants? and, for which engagements are caught in the first place, which accounting services are designated?.

What the privacy layer actually contains

Where s 6E engages, the Privacy Act expects a baseline for the AML/KYC data you hold that an AML kit typically leaves out:

These are Privacy Act documents, not AML/CTF Act documents. Enrolment and customer due diligence sit under the AML/CTF Act and are overseen by AUSTRAC; the documents above sit under the Privacy Act and are overseen by the OAIC. If your AML product also supplies them, that part is covered. If it does not, this is the gap.

You are probably also caught the broader way

Here is the part that is easy to miss if you have already bought an AML kit. The AML trigger is not the only door into the Privacy Act, and it is not the only one that can reach a small practice.

If your practice handles individual clients' or employees' tax file numbers, the Privacy (Tax File Number) Rule 2015, made under s 17 of the Privacy Act, already binds you for that TFN data, with no turnover threshold and no AML trigger needed. That obligation is live now and it predates Tranche 2. It attaches to being a "file number recipient", which does not depend on providing a designated service, so it can apply to a practice that is not an AUSTRAC reporting entity at all. Under s 13(4)(a), an act or practice of a file number recipient that breaches a rule issued under s 17 is an interference with the privacy of an individual, so an affected person can complain to the OAIC. Note the Rule's own limit: under r 5(2) it applies to the TFN information of individuals, not to companies, partnerships, superannuation funds or trusts.

So the AML/CTF side of your obligations covers the AML-data slice, and only if you are a reporting entity at all. The TFN Rule is a separate obligation, under a separate section, with a separate trigger: it applies where you hold an individual's tax file number, whether or not you provide a designated service. See does the Privacy Act apply to accountants under $3 million? and the TFN Rule 2015: what accountants must do.

Keep the two triggers distinct. The TFN Rule is the portable one: it binds any file number recipient for individuals' TFN data, regardless of turnover. The s 6E(1A) AML bridge is the service-specific one, for firms providing a designated service. Neither makes a small practice an APP entity for its whole business. s 6E(1A) is scoped to the activities carried on for the purposes of, or in connection with, the AML/CTF Act, and the TFN Rule is a duty on file number recipients under s 18, separate from the 13 Australian Privacy Principles that s 15 applies to APP entities.

At a glance

An AML kitA privacy kit
Governing ActAML/CTF Act 2006, overseen by AUSTRACPrivacy Act 1988, overseen by the OAIC
Main jobEnrol you with AUSTRAC and stand up KYC/CDD collectionMeet the Privacy Act obligations for the personal information you hold
Who needs itFirms providing a designated service in table 6 (AML/CTF Act s 6(5B))Any file number recipient, for individuals' TFN data, and any APP entity, including a firm caught for its AML/KYC data by s 6E(1A)
Documents producedAML/CTF program, customer due diligence workflow, screening and retention recordsWhere you hold individual TFNs: a TFN collection notification (r 8(2)(a)), a handling procedure, security and access controls (r 11(1)), a secure destruction rule (r 11(2)), staff training (r 12) and a breach plan. Where you are an APP entity: a privacy policy (APP 1.3), collection notices (APP 5), a breach plan and a retention schedule

Complementary, not competing

This is not "buy ours instead of theirs". If you provide a designated service you need the AML side done properly, and an AML kit is the right tool for that. Privaproof does not do AML enrolment and does not assess whether a given engagement is a designated service: that is AUSTRAC's domain and the AML vendors' lane.

Privaproof provides the privacy half: an accountant-specific document set for the TFN Rule and, where it applies, the s 6E AML/KYC data, written for accounting and bookkeeping practices and kept current as the law changes. The two sit side by side. Your AML tool makes you collect the data; the privacy kit is how you hold it to the standard the Privacy Act then expects.

Table 6 of the AML/CTF Act commenced on 31 March 2026, so a firm providing a professional-services designated service became a reporting entity on that day. The AML/CTF obligations themselves, meaning the program, customer due diligence, reporting and record keeping, started on 1 July 2026. AUSTRAC enrolment opened on 31 March 2026, and a firm already providing a designated service before 1 July 2026 had to be enrolled by 29 July 2026, a date fixed by item 12 of Schedule 3 to the amending Act rather than counted from a start date. Confirm your firm's exact position and timing with AUSTRAC.

Common questions

Doesn't my AML kit already cover privacy?

They are separate obligations under separate Acts, so check. An AML kit is built for the AML/CTF Act: enrolment and customer due diligence. The privacy documents that attach to that identity data through Privacy Act s 6E(1A), namely a privacy policy under APP 1.3, collection notices under APP 5 and a data-breach plan under Part IIIC, sit under the Privacy Act and are overseen by the OAIC. Ask your AML vendor which of those documents its product supplies, and cover whatever it does not.

If I only bought an AML kit, what am I missing?

For the AML/KYC data, where s 6E(1A) applies: a privacy policy (APP 1.3), collection notices (APP 5), a data-breach response plan for Part IIIC, and a retention schedule reconciling the AML/CTF Act's seven-year periods with APP 11.2. Separately, if you handle individual clients' or employees' tax file numbers, the TFN Rule adds its own obligations: a notification when you ask for a TFN (r 8(2)(a)), a handling procedure, security and access controls (r 11(1)), secure destruction once you no longer need it (r 11(2)) and staff training (r 12), plus a breach plan, because the Notifiable Data Breaches scheme reaches a file number recipient holding TFN information (s 26WE(1)(d)). Those sit under the Privacy Act, not the AML/CTF Act.

I do not provide a designated service. Do I still need any of this?

Possibly, through the other door. If you handle individual clients' or employees' tax file numbers, the TFN Rule 2015 binds you for that data regardless of turnover and with no AML trigger needed: a notification when you ask for the TFN (r 8(2)(a)), a handling procedure, security and access controls (r 11(1)), secure destruction once you no longer need it (r 11(2)) and staff training (r 12), plus a breach plan, because the Notifiable Data Breaches scheme reaches a file number recipient holding TFN information (s 26WE(1)(d)). You would not need an AML kit, but you would still carry those obligations. The Rule covers individuals' TFNs only, not those of companies, partnerships, superannuation funds or trusts (r 5(2)).

Is Privaproof a rival to my AML software?

No. Privaproof does not do AML enrolment or KYC and does not decide whether an engagement is a designated service. It covers the privacy documents the Privacy Act expects for the data your AML tool makes you collect, and the TFN obligations you carry regardless of AML. The two are complementary.

Keep reading


This is general information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC, and does not tell you whether a specific engagement is a designated service. For advice on your specific circumstances, consult a qualified Australian legal practitioner. The Privacy Act 1988 (Cth), the AML/CTF Act and related guidance change over time, so check you are working from a current version.