What must an AML collection notice tell customers when you take their ID?
From 1 July 2026, when an agency providing designated real-estate services collects a customer's identity and due-diligence data for AML/CTF, the Privacy Act covers that data even if turnover is under A$3 million. At or before you take the ID, give an APP 5 notice: who you are; that you're collecting for AML/CTF customer due diligence; usual disclosures; any overseas transfer; and how to access, correct or complain.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
Why is the AML collection point different from other collection points?
Most real-estate collection points, an open-home sheet or a website enquiry, gather a little information so you can provide a service. The AML onboarding point is different in two ways. First, you are collecting sensitive identity documents, driver licences, passports, sometimes proof of source of funds, at the moment you must verify who someone is. Second, the reason you are collecting it is a legal obligation, not just a business need.
That second point changes the privacy picture. A small business under A$3 million turnover is normally exempt from the Privacy Act, but the effect of section 6E(1A) is that once you collect personal information as an AML/CTF reporting entity, that information is treated as covered by the Australian Privacy Principles regardless of turnover. The trigger attaches to the AML identity and customer-due-diligence data specifically, not to your whole CRM or your open-home sheets. Sales work is far more likely to involve designated services than property-management-only work. For the wider picture, see does AML compliance cover your privacy obligations and what to do with the ID documents AUSTRAC makes you collect.
What must an AML collection notice include?
APP 5 sets out the matters a person must be made aware of. For an AML collection point, tailor each one to what actually happens:
| APP 5 matter | For AML onboarding, say |
|---|---|
| Who you are and how to contact you | Agency name, ABN and privacy contact |
| That you are collecting, and the circumstances | You are collecting identity information to onboard you for a property transaction |
| The purposes | Verifying your identity and conducting customer due diligence |
| Required or authorised by law | State plainly that this collection is required to meet AML/CTF obligations, unlike most agency collection which is a condition of service, not law |
| Main consequences of not providing it | You may be unable to act for the customer or proceed with the transaction |
| Your usual disclosures | Identity-verification providers, AUSTRAC where a report is required, and your professional advisers |
| That your privacy policy covers access, correction and complaints | Point to the policy and how to reach the OAIC |
| Likely overseas disclosure | Name it, and the countries, if your verification tool stores or processes data offshore |
The "required or authorised by law" line is the one that makes this notice distinct. For the AML-collected data you can honestly say the collection is required by law, which most agency collection notices cannot.
What are the common AML collection-notice mistakes?
Collecting more than the due-diligence rules need. Taking and keeping full copies of every identity document indefinitely, or gathering financial detail beyond what customer due diligence calls for, is over-collection under APP 3. Collect and retain the minimum the AML rules actually require.
Not disclosing the verification provider. If you run identity checks through a third-party verification service, that is a disclosure your notice must make the customer aware of, including where that provider sits.
Treating a scan folder as storage. Identity documents dropped into an email inbox or an open shared drive are a breach waiting to happen. APP 11 requires reasonable security: access controls and secure storage. See handling the ID documents AUSTRAC makes you collect.
Overseas disclosure through the tool. Many verification platforms store or process data offshore. If yours does, your notice must say so and, where practicable, name the countries (APP 8).
Confusing "keep for seven years" with "keep forever". AML record-keeping requires you to retain certain records for seven years, but the Privacy Act still expects you not to keep personal information longer than you need it. Reconcile the two in a retention approach rather than defaulting to keeping everything.
How does the AML notice fit my wider privacy obligations?
The AML collection notice is not your privacy policy, and it is not your AML/CTF program. It is the short, specific message you give at the identity-collection point; the policy is the standing document behind it, and the AML program is a separate obligation to AUSTRAC. For the fuller context, see collection notices for real estate under APP 5, the privacy and AML compliance calendar, and the overview of Privacy Act compliance for agencies.
Getting the AML notice right is fiddly because it touches identity documents, a verification provider, overseas transfer and a genuine legal-requirement line all at once. The Privaproof Kit's collection notice includes an onboarding and AML variant that names the right disclosures for how your agency actually works, kept current as the Tranche 2 rules bed in, as part of a whole-agency system rather than a generic template.
Common questions
Do we need a separate AML collection notice, or does our normal one cover it?
You need a notice that covers the AML collection point specifically. A general agency collection notice often does not name customer due diligence, the verification provider, or the fact that this particular collection is required by law. You can build the AML point into a broader onboarding notice, but it has to say those things.
We are under A$3 million turnover. Does the Privacy Act really apply to this?
For the AML data, yes. Even where a small business is otherwise exempt, the effect of section 6E(1A) is that personal information you collect as an AML/CTF reporting entity is covered by the Australian Privacy Principles. It attaches to the AML identity and due-diligence data, not to your whole business.
When exactly do we give it?
At or before the point you collect the identity information, the same rule as any APP 5 notice. In practice that means the notice is presented as part of your onboarding step, before the customer hands over their documents.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice. Sources: OAIC APP 5 notification; OAIC small business; AUSTRAC real estate professionals.