Skip to content

AML kit vs privacy kit: what your AML software leaves out

An AML kit gets your firm enrolled with AUSTRAC and sets up your customer identification and KYC collection. It does not deliver the privacy policy, collection notices and data-breach plan the Privacy Act then expects for that identity data, because from 1 July 2026 Privacy Act s 6E applies the Australian Privacy Principles to the AML/KYC information a designated service makes you collect. That privacy layer is the half your AML software leaves out.

By Jon Oates, Founder of Privaproof · Last updated

General information, document templates and tools you tailor, not legal advice. Privaproof is not a law practice.

Two different jobs, two different tools

If your practice provides an AML "designated service" from 1 July 2026, an AML kit does a real and necessary job. It walks you through enrolment with AUSTRAC, helps you build an AML/CTF program, and stands up the customer due diligence workflow: collecting and verifying identity documents, screening for politically exposed persons and sanctions, and recording source-of-funds evidence. The AML-software market is crowded and competent at this: the enrolment and KYC pack from vendors such as AMLCompliant, Axior and the wider identity-verification field is built for exactly that task.

The point this page makes is narrower and easily missed. Collecting all that identity data is itself a privacy event. The moment a designated service makes you a reporting entity, the personal information you gather for AML purposes falls under the Privacy Act, and the Act expects a set of documents an AML kit generally does not include. Your AML tool makes you collect the data. It does not tell you how to hold, disclose, secure and eventually destroy it to the standard the Privacy Act now requires.

Why the gap exists: s 6E turns your AML data into Privacy Act data

Under section 6D of the Privacy Act 1988 (Cth), a practice turning over $3 million or less is generally a "small business operator" outside the Act. Providing a designated service does not switch that exemption off across your whole firm. It works through one targeted provision.

Section 6E treats a small business operator that is a reporting entity as an "organisation", an APP entity, but only for the activities it carries on for the purposes of, or in connection with, the AML/CTF Act. So the Australian Privacy Principles reach the identity and KYC/CDD information you collect for the designated service, regardless of your turnover. They do not reach your general tax files, ledgers, payroll or CRM, which stay under the s 6D exemption unless a separate trigger applies to them.

That is the mechanism the AML kit does not close out. It hands you a body of concentrated identity data and, through s 6E, the Privacy Act attaches obligations to that data that the AML program on its own does not satisfy. For the full mechanism, see does becoming an AML reporting entity trigger the Privacy Act for accountants? and, for which engagements are caught in the first place, which accounting services are designated?.

What the privacy layer actually contains

Where s 6E engages, the Privacy Act expects a baseline for the AML/KYC data you hold that an AML kit typically leaves out:

None of these are what an AML platform is designed to produce. Its job ends at enrolment and KYC collection. The privacy layer begins there.

You are probably also caught the broader way

Here is the part that catches even firms who have already bought an AML kit. The AML trigger is not the only door into the Privacy Act, and for most practices it is not even the main one.

If your practice handles individual clients' or employees' tax file numbers, the Privacy (Tax File Number) Rule 2015 already binds you for that TFN data, with no turnover threshold and no AML trigger needed. That obligation is live now, it predates Tranche 2, and it catches far more practices than the AML rules do, because nearly every accounting or bookkeeping practice handles individual TFNs while only a subset provides a designated service. A breach of the TFN Rule is an interference with the privacy of an individual, so an affected person can complain to the OAIC.

So an AML kit, even a good one, addresses only the narrow AML-data slice of your privacy exposure, and only if you are a reporting entity at all. It does nothing for the TFN obligations you almost certainly already carry. See does the Privacy Act apply to accountants under $3 million? and the TFN Rule 2015: what accountants must do.

Keep the two triggers distinct. The TFN Rule is the primary, portable one that catches most practices for individuals' TFN data. The s 6E AML bridge is the narrower, service-specific one for the designated-services subset. Neither one makes a small firm a full APP entity subject to all 13 Australian Privacy Principles.

At a glance

An AML kitA privacy kit
Main jobEnrol you with AUSTRAC and stand up KYC/CDD collectionMeet the Privacy Act obligations for the data that collection creates
Who needs itOnly firms providing a designated service from 1 July 2026Any practice handling individual TFNs (TFN Rule), plus the AML/KYC data where s 6E engages
Documents producedAML/CTF program, customer due diligence workflow, screening recordsPrivacy policy (APP 1), collection notices (APP 5), data-breach plan (NDB), retention schedule
RegulatorAUSTRACOAIC
What it leaves outThe privacy policy, collection notices and breach plan for the identity data it makes you collectThe AML enrolment and KYC workflow itself

Complementary, not competing

This is not "buy ours instead of theirs". If you provide a designated service you need the AML side done properly, and an AML kit is the right tool for that. Privaproof does not do AML enrolment and does not assess whether a given engagement is a designated service: that is AUSTRAC's domain and the AML vendors' lane.

What Privaproof is building is the privacy half: an accountant-specific document set for the TFN Rule and, where it applies, the s 6E AML/KYC data, written for accounting and bookkeeping practices and kept current as the law changes. The two sit side by side. Your AML tool makes you collect the data; the privacy kit is how you hold it to the standard the Privacy Act then expects.

*Enrolment for newly regulated firms opened 31 March 2026; existing providers of a designated service enrol by around 29 July 2026. Confirm your firm's exact position and timing with AUSTRAC.

Common questions

Doesn't my AML kit already cover privacy?

Generally no. An AML kit is built to enrol you with AUSTRAC and run customer due diligence. It makes you collect identity, beneficial-ownership and screening information, but the Privacy Act obligations that attach to all of it through s 6E(1A), namely a privacy policy, collection notices and a data-breach plan, are usually not part of the AML product. That privacy layer is a separate job.

If I only bought an AML kit, what am I missing?

For the AML/KYC data, the APP 1 privacy policy, APP 5 collection notices, an NDB-ready data-breach response plan, and a retention schedule reconciling the AML seven-year floor with "destroy when no longer needed". Separately, if you handle individual clients' or employees' tax file numbers, you also carry TFN Rule obligations that an AML kit does not touch at all.

I do not provide a designated service. Do I still need any of this?

Very likely yes, but through the other door. If you handle individual TFNs, the TFN Rule 2015 binds you for that data regardless of turnover and with no AML trigger needed. You would not need an AML kit, but you would still have real privacy obligations for the TFN information you hold.

Is Privaproof a rival to my AML software?

No. Privaproof does not do AML enrolment or KYC and does not decide whether an engagement is a designated service. It covers the privacy documents the Privacy Act expects for the data your AML tool makes you collect, and the TFN obligations you carry regardless of AML. The two are complementary.

Keep reading


This is general information and compliance tools, not legal advice. Privaproof is not a law practice and does not provide legal advice. This page does not assess your obligations under the AML/CTF Act itself, which are administered by AUSTRAC, and does not tell you whether a specific engagement is a designated service. Privaproof's accountant documents are self-authored and are not independently reviewed by a solicitor. For advice on your specific circumstances, consult a qualified Australian legal practitioner. The Privacy Act 1988 (Cth), the AML/CTF Act and related guidance change over time, so check you are working from a current version.