What must an AML collection notice tell customers when you take their ID?
An agency providing a designated real-estate service has been an AUSTRAC reporting entity since 31 March 2026, and the customer due diligence obligations started 1 July 2026. Section 6E(1A) then applies the Privacy Act to the activities you carry on for AML/CTF purposes, whatever your turnover. At or before you take the ID, give an APP 5 notice: who you are; that you're collecting for AML/CTF customer due diligence; that the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 requires it, named, because APP 5.2(c) asks for the name; usual disclosures; any overseas transfer; and how to access, correct or complain.
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
Why is the AML collection point different from other collection points?
Most real-estate collection points, an open-home sheet or a website enquiry, gather a little information so you can provide a service. The AML onboarding point is different in two ways. First, you are collecting identity documents, driver licences, passports, sometimes proof of source of funds, at the moment you must verify who someone is, and if your verification tool face-matches the ID photo, that match is biometric information, which is sensitive information under section 6(1). Second, the reason you are collecting it is a legal obligation, not just a business need.
That second point changes the privacy picture. A business turning over A$3 million or less is often outside the Privacy Act, though section 6D(4) lists other ways out of that exemption and (4)(a) does not reverse if turnover later falls. Section 6E(1A) is a separate route in: once you are an AML/CTF reporting entity, the Act applies to the activities you carry on for the purposes of, or in connection with, the AML/CTF Act. Read it as activity-scoped, not as a rule about one folder of identity data. It is also genuinely limited: Table 5 turns on brokering or effecting a sale, purchase or transfer, and a lease of 30 years or less is not real estate for that Act, so property-management-only work sits largely outside it. For the wider picture, see does AML compliance cover your privacy obligations and what to do with the ID documents AUSTRAC makes you collect.
What must an AML collection notice include?
APP 5.2 lists ten matters, lettered (a) to (j), that a person must be made aware of. For an AML collection point, tailor each one to what actually happens:
| APP 5 matter | For AML onboarding, say |
|---|---|
| Who you are and how to contact you | Agency name, ABN and privacy contact |
| That you collected it from someone else, and the circumstances (APP 5.2(b)) | Where a verification or screening provider, not the customer, was the source |
| The purposes | Verifying your identity and conducting customer due diligence |
| Required or authorised by law (APP 5.2(c)) | Name the law: the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. APP 5.2(c) asks for the name of the Australian law, so "as required by law" on its own does not answer it |
| Main consequences of not providing it | You may be unable to act for the customer or proceed with the transaction |
| Your usual disclosures | Identity-verification providers, AUSTRAC where a report is required, and your professional advisers |
| That your privacy policy covers access, correction and complaints | Point to the policy and how to reach the OAIC |
| Likely overseas disclosure | Name it, and the countries, if your verification tool stores or processes data offshore |
The "required or authorised by law" line is what makes this notice distinct, and APP 5.2(c) asks for the name of the Australian law, not just the fact of one. Does the notice you use today name the Anti-Money Laundering and Counter-Terrorism Financing Act 2006?
What are the common AML collection-notice mistakes?
Collecting more than the due-diligence rules need. Taking and keeping full copies of every identity document indefinitely, or gathering financial detail beyond what customer due diligence calls for, fails the APP 3.2 test, which for a private agency is "reasonably necessary" and nothing wider. Collect and retain the minimum the AML rules actually require.
Not disclosing the verification provider. If you run identity checks through a third-party verification service, that is a usual disclosure your notice must cover (APP 5.2(f)), and where the provider is also a source of information about the customer, APP 5.2(b) applies too.
Treating a scan folder as storage. An email inbox or an open shared drive is a hard place to show that your steps to protect ID documents are reasonable in the circumstances, which is what APP 11.1 asks. That clause carries the only civil penalty a court has imposed under the Privacy Act: A$4.2 million of the A$5.8 million against an ASX-listed pathology company over 223,000 people (Australian Clinical Labs (No 2) [2025] FCA 1224). See handling the ID documents AUSTRAC makes you collect.
Overseas disclosure through the tool. Check where your verification provider stores and processes the data. If any goes offshore, APP 5.2(i) requires your notice to say so and 5.2(j) to name the countries where practicable, and APP 8 governs the disclosure.
Confusing "keep for seven years" with "keep forever". Part 10 of the AML/CTF Act requires seven-year retention, including of a document the customer gives you for a designated service, and APP 11.2(d) makes room for it. APP 11.2 still requires you to destroy or de-identify whatever the seven-year rule does not reach. A retention schedule separating the two is the reconciliation.
How does the AML notice fit my wider privacy obligations?
The AML collection notice is not your privacy policy, and it is not your AML/CTF program. It is the short, specific message you give at the identity-collection point; the policy is the standing document behind it, and the AML program is a separate obligation to AUSTRAC. For the fuller context, see collection notices for real estate under APP 5, the privacy and AML compliance calendar, and the overview of Privacy Act compliance for agencies.
Getting the AML notice right is fiddly because it touches identity documents, a verification provider, overseas transfer and a genuine legal-requirement line all at once. The Privaproof Kit's collection notice includes an onboarding and AML variant that names the right disclosures for how your agency actually works, kept current as the Tranche 2 rules bed in, as part of a whole-agency system rather than a generic template.
Common questions
Do we need a separate AML collection notice, or does our normal one cover it?
You need a notice that covers the AML collection point specifically. Does yours name customer due diligence as a purpose (APP 5.2(d)), your verification provider as a usual disclosure (APP 5.2(f)), and the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (APP 5.2(c))? You can build the AML point into a broader onboarding notice, but it has to answer all three.
We are under A$3 million turnover. Does the Privacy Act really apply to this?
Yes, for your AML/CTF work. Even where a business is otherwise a small business operator, section 6E(1A) applies the Privacy Act to the activities it carries on for the purposes of, or in connection with, the AML/CTF Act. That reaches the due diligence, monitoring, reporting and record keeping, not just the identity file, and not the rest of the business.
When exactly do we give it?
At or before the point you collect the identity information, or as soon as practicable after if that is not practicable, which is the APP 5.1 rule for any collection notice. In practice the notice is presented as part of your onboarding step, before the customer hands over their documents.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice. Sources: OAIC APP 5 notification; OAIC small business; AUSTRAC real estate professionals.