Skip to content

Does AML compliance cover your privacy obligations? (real-estate agencies)

No. AML/CTF and the Privacy Act are two separate obligations, and meeting one does not discharge the other. There is also a twist that catches agencies out: from 1 July 2026, becoming an AUSTRAC reporting entity can pull the identity data you collect for AML under the Privacy Act, even if your agency turns over under $3 million. So AML work tends to create privacy obligations, not satisfy them.

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price

Orientation only, not a compliance assessment. General information and tools, not legal advice.

The short answer: no, and there's a twist

AML/CTF (administered by AUSTRAC) and the Privacy Act (administered by the OAIC) are separate regimes. Meeting your AML obligations does not meet your privacy obligations. And there is a twist that catches agencies out: the AML work can quietly expand what the Privacy Act covers for you.

Why can AML increase your privacy obligations?

Many small agencies have relied on the small-business exemption (turnover under $3 million) to stay outside most of the Privacy Act. But when you become a reporting entity under the AML/CTF regime and collect identity documents for customer due diligence, the personal information you collect for that purpose is treated as covered by the Australian Privacy Principles, even if your agency would otherwise be exempt (this is the effect of s 6E(1A) of the Privacy Act).

In plain terms: the KYC/customer-due-diligence data you now have to collect for AML falls under the Privacy Act, regardless of your turnover.

Scope it precisely, because this is where agencies over- or under-react: it is the identity and customer-due-diligence data you collect for AML that is caught this way. It does not automatically mean every scrap of information across your whole business is now regulated. Getting that boundary right is part of doing it properly.

What do you have to do on the privacy side?

Once that identity data is covered, the usual privacy obligations attach to it:

Two obligations, one pile of data

The AML side (AUSTRAC)The privacy side (OAIC)
Enrol, run customer due diligence, verify identityTell people what you collect and why (collection notice, APP 5)
Report suspicious mattersHold that data securely (APP 11)
Keep records for seven yearsDo not keep personal information longer than needed; destroy or de-identify when done
Have an AML/CTF programHave a data-breach response plan for a leak of that ID data (NDB scheme)

The same identity documents sit in the middle of both. AML tells you to collect and keep them; the Privacy Act governs how you must handle, disclose and eventually dispose of them. For the AML side itself, see AML/CTF for real estate agents: your 2026 action checklist; for whether the Privacy Act applies to you at all, see does the Privacy Act apply to real estate agents?.

Common questions

If I am AML-compliant, am I privacy-compliant?

No. They are separate obligations under separate laws with separate regulators. Being enrolled and running AML checks says nothing about whether you have a compliant privacy policy, collection notice, secure handling and a breach plan for the data those checks produce.

I am under $3 million turnover. Doesn't the small-business exemption cover me?

Not for the AML-collected data. Once you collect identity information as an AML reporting entity, that information is treated as covered by the Australian Privacy Principles regardless of your turnover. The exemption does not carry across to it.

What is the single most useful thing to have in place?

A collection notice, a secure-handling and retention approach, and a data-breach plan, all tuned to the identity data AUSTRAC now requires you to collect. That is the privacy half of the same 2026 job.

Who administers each?

AUSTRAC administers the AML/CTF regime; the OAIC administers the Privacy Act and the Australian Privacy Principles. Privaproof helps with the privacy half and does not assess your AML obligations.


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: OAIC: rights and responsibilities (small business); AUSTRAC: real estate professionals; OAIC: Notifiable Data Breaches scheme.