AML kit vs privacy kit: what your AML software leaves out
An AML kit does the AUSTRAC job: enrolment, customer identification and KYC collection. The Privacy Act then expects a separate privacy layer for that identity data, because a firm providing a designated service has been an AUSTRAC reporting entity since 31 March 2026, and Privacy Act s 6E(1A) applies the Australian Privacy Principles to the activities it carries on for the purposes of, or in connection with, the AML/CTF Act. Check what your AML product covers, then check whether the privacy policy, collection notices and data-breach plan for that data are covered too.
By Jon Oates, Founder of Privaproof · Last updated
General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.
Two different jobs, two different tools
If your practice provides an AML "designated service", an AML kit does a real and necessary job. It walks you through enrolment with AUSTRAC, helps you build an AML/CTF program, and stands up the customer due diligence workflow: collecting and verifying identity documents, screening for politically exposed persons and sanctions, and recording source-of-funds evidence. A number of vendors serve that market. This page makes no claim about what any particular product does or does not include.
The point this page makes is narrower and easily missed. Collecting all that identity data is itself a privacy event. The moment a designated service makes you a reporting entity, the personal information you gather for AML purposes falls under the Privacy Act, and the Act expects its own set of documents for that data. Collecting the data and holding, disclosing, securing and eventually destroying it to the standard the Privacy Act requires are two different jobs, under two different Acts. Whether your AML product also does the second one is a question to put to your vendor.
Why the gap exists: s 6E(1A) applies the Privacy Act to your AML activities
Under section 6D of the Privacy Act 1988 (Cth), a practice is generally a "small business operator" outside the Act. Turnover is only one of the tests. Section 6D(4) lists six circumstances that take a business out of the exemption: annual turnover of more than $3,000,000 for a financial year (s 6D(4)(a)), providing a health service and holding health information other than in an employee record, disclosing personal information for a benefit or advantage, providing a benefit or advantage to collect it, being a contracted service provider for a Commonwealth contract, and being a credit reporting body. Section 6D(4)(a) runs one way: once turnover has exceeded the threshold for a financial year, a later fall does not restore the exemption. Providing a designated service does not switch the exemption off across your whole firm either. It works through one targeted provision.
Section 6E(1A) provides that if a small business operator "is a reporting entity or an authorised agent of a reporting entity because of anything done in the course of a small business carried on by the small business operator, this Act applies ... in relation to the activities carried on by the small business operator for the purposes of, or in connection with, activities relating to ... the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 ... as if the small business operator were an organisation". So the Australian Privacy Principles reach the identity and KYC/CDD information you collect for the designated service, regardless of your turnover. They do not reach your general tax files, ledgers, payroll or CRM, which stay under the s 6D exemption unless a separate trigger applies to them. The trigger in s 6E(1A) is being a reporting entity, not having AML obligations, which is why it engaged on 31 March 2026 when the professional-services designated services commenced, rather than on 1 July 2026 when the obligations started.
That is the gap the AML/CTF side does not close on its own. A designated service hands you a body of concentrated identity data and, through s 6E(1A), the Privacy Act attaches obligations to that data. An AML/CTF program under Part 1A of the AML/CTF Act is a money-laundering and terrorism-financing risk document; it is not the privacy policy, collection notice or breach plan the Privacy Act asks for. For the full mechanism, see does becoming an AML reporting entity trigger the Privacy Act for accountants? and, for which engagements are caught in the first place, which accounting services are designated?.
What the privacy layer actually contains
Where s 6E engages, the Privacy Act expects a baseline for the AML/KYC data you hold that an AML kit typically leaves out:
- A privacy policy (APP 1.3) that reflects the AML/KYC data you collect for the designated service, and how you manage it.
- Collection notices (APP 5) given at or near the point where you take identity and source-of-funds information, telling people what you collect, why, and who you disclose it to.
- A data-breach response plan for the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. An eligible data breach is unauthorised access to, disclosure of, or loss of the information where a reasonable person would conclude it is likely to result in serious harm to an affected individual (s 26WE(2)), which triggers an assessment (s 26WH) and, where it is an eligible data breach, notification to the Commissioner and to affected individuals (ss 26WK and 26WL). See data-breach obligations for accountants handling TFNs.
- Retention and destruction procedures that reconcile the AML/CTF Act's seven-year record-keeping periods (Part 10) with APP 11.2, which requires an APP entity to destroy or de-identify personal information it no longer needs, except where it "is required by or under an Australian law, or a court/tribunal order, to retain the information". While the AML period runs, that exception applies; once it ends, APP 11.2 does. See how long can an accountant keep a client's TFN?.
- Access, correction and complaint handling so an individual can ask what you hold and have it corrected.
These are Privacy Act documents, not AML/CTF Act documents. Enrolment and customer due diligence sit under the AML/CTF Act and are overseen by AUSTRAC; the documents above sit under the Privacy Act and are overseen by the OAIC. If your AML product also supplies them, that part is covered. If it does not, this is the gap.
You are probably also caught the broader way
Here is the part that is easy to miss if you have already bought an AML kit. The AML trigger is not the only door into the Privacy Act, and it is not the only one that can reach a small practice.
If your practice handles individual clients' or employees' tax file numbers, the Privacy (Tax File Number) Rule 2015, made under s 17 of the Privacy Act, already binds you for that TFN data, with no turnover threshold and no AML trigger needed. That obligation is live now and it predates Tranche 2. It attaches to being a "file number recipient", which does not depend on providing a designated service, so it can apply to a practice that is not an AUSTRAC reporting entity at all. Under s 13(4)(a), an act or practice of a file number recipient that breaches a rule issued under s 17 is an interference with the privacy of an individual, so an affected person can complain to the OAIC. Note the Rule's own limit: under r 5(2) it applies to the TFN information of individuals, not to companies, partnerships, superannuation funds or trusts.
So the AML/CTF side of your obligations covers the AML-data slice, and only if you are a reporting entity at all. The TFN Rule is a separate obligation, under a separate section, with a separate trigger: it applies where you hold an individual's tax file number, whether or not you provide a designated service. See does the Privacy Act apply to accountants under $3 million? and the TFN Rule 2015: what accountants must do.
Keep the two triggers distinct. The TFN Rule is the portable one: it binds any file number recipient for individuals' TFN data, regardless of turnover. The s 6E(1A) AML bridge is the service-specific one, for firms providing a designated service. Neither makes a small practice an APP entity for its whole business. s 6E(1A) is scoped to the activities carried on for the purposes of, or in connection with, the AML/CTF Act, and the TFN Rule is a duty on file number recipients under s 18, separate from the 13 Australian Privacy Principles that s 15 applies to APP entities.
At a glance
| An AML kit | A privacy kit | |
|---|---|---|
| Governing Act | AML/CTF Act 2006, overseen by AUSTRAC | Privacy Act 1988, overseen by the OAIC |
| Main job | Enrol you with AUSTRAC and stand up KYC/CDD collection | Meet the Privacy Act obligations for the personal information you hold |
| Who needs it | Firms providing a designated service in table 6 (AML/CTF Act s 6(5B)) | Any file number recipient, for individuals' TFN data, and any APP entity, including a firm caught for its AML/KYC data by s 6E(1A) |
| Documents produced | AML/CTF program, customer due diligence workflow, screening and retention records | Where you hold individual TFNs: a TFN collection notification (r 8(2)(a)), a handling procedure, security and access controls (r 11(1)), a secure destruction rule (r 11(2)), staff training (r 12) and a breach plan. Where you are an APP entity: a privacy policy (APP 1.3), collection notices (APP 5), a breach plan and a retention schedule |
Complementary, not competing
This is not "buy ours instead of theirs". If you provide a designated service you need the AML side done properly, and an AML kit is the right tool for that. Privaproof does not do AML enrolment and does not assess whether a given engagement is a designated service: that is AUSTRAC's domain and the AML vendors' lane.
Privaproof provides the privacy half: an accountant-specific document set for the TFN Rule and, where it applies, the s 6E AML/KYC data, written for accounting and bookkeeping practices and kept current as the law changes. The two sit side by side. Your AML tool makes you collect the data; the privacy kit is how you hold it to the standard the Privacy Act then expects.
Table 6 of the AML/CTF Act commenced on 31 March 2026, so a firm providing a professional-services designated service became a reporting entity on that day. The AML/CTF obligations themselves, meaning the program, customer due diligence, reporting and record keeping, started on 1 July 2026. AUSTRAC enrolment opened on 31 March 2026, and a firm already providing a designated service before 1 July 2026 had to be enrolled by 29 July 2026, a date fixed by item 12 of Schedule 3 to the amending Act rather than counted from a start date. Confirm your firm's exact position and timing with AUSTRAC.
Common questions
Doesn't my AML kit already cover privacy?
They are separate obligations under separate Acts, so check. An AML kit is built for the AML/CTF Act: enrolment and customer due diligence. The privacy documents that attach to that identity data through Privacy Act s 6E(1A), namely a privacy policy under APP 1.3, collection notices under APP 5 and a data-breach plan under Part IIIC, sit under the Privacy Act and are overseen by the OAIC. Ask your AML vendor which of those documents its product supplies, and cover whatever it does not.
If I only bought an AML kit, what am I missing?
For the AML/KYC data, where s 6E(1A) applies: a privacy policy (APP 1.3), collection notices (APP 5), a data-breach response plan for Part IIIC, and a retention schedule reconciling the AML/CTF Act's seven-year periods with APP 11.2. Separately, if you handle individual clients' or employees' tax file numbers, the TFN Rule adds its own obligations: a notification when you ask for a TFN (r 8(2)(a)), a handling procedure, security and access controls (r 11(1)), secure destruction once you no longer need it (r 11(2)) and staff training (r 12), plus a breach plan, because the Notifiable Data Breaches scheme reaches a file number recipient holding TFN information (s 26WE(1)(d)). Those sit under the Privacy Act, not the AML/CTF Act.
I do not provide a designated service. Do I still need any of this?
Possibly, through the other door. If you handle individual clients' or employees' tax file numbers, the TFN Rule 2015 binds you for that data regardless of turnover and with no AML trigger needed: a notification when you ask for the TFN (r 8(2)(a)), a handling procedure, security and access controls (r 11(1)), secure destruction once you no longer need it (r 11(2)) and staff training (r 12), plus a breach plan, because the Notifiable Data Breaches scheme reaches a file number recipient holding TFN information (s 26WE(1)(d)). You would not need an AML kit, but you would still carry those obligations. The Rule covers individuals' TFNs only, not those of companies, partnerships, superannuation funds or trusts (r 5(2)).
Is Privaproof a rival to my AML software?
No. Privaproof does not do AML enrolment or KYC and does not decide whether an engagement is a designated service. It covers the privacy documents the Privacy Act expects for the data your AML tool makes you collect, and the TFN obligations you carry regardless of AML. The two are complementary.
Keep reading
- Does becoming an AML reporting entity trigger the Privacy Act for accountants?
- AML Tranche 2 for accountants: which services are designated?
- Does the Privacy Act apply to accountants under $3 million?
- The TFN Rule 2015: what accountants must do
- Data-breach obligations for accountants handling TFNs
- Privacy Act compliance for accountants and bookkeepers (the hub)
This is general information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC, and does not tell you whether a specific engagement is a designated service. For advice on your specific circumstances, consult a qualified Australian legal practitioner. The Privacy Act 1988 (Cth), the AML/CTF Act and related guidance change over time, so check you are working from a current version.