Skip to content

What do I do with the ID documents AUSTRAC makes me collect? (the privacy side)

Handle it, do not just hold it. An agency brokering the sale, purchase or transfer of real estate has been a reporting entity since 31 March 2026, and s 6E(1A) then applies the Privacy Act to the activities you carry on for AML purposes even under $3 million turnover. Four steps: tell people what and why (collection notice, APP 5), store it securely (APP 11.1), keep the seven-year record s 111 actually asks for rather than the ID image itself, and have a leak plan (the NDB scheme).

By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →

General information, not legal advice. Your obligations depend on your circumstances.

Not sure it's you?

Does this apply to you?

Tap what's true for your agency. Nothing is saved.

Tap what's true above to see where you stand.
Check the Kit against your setupA$539 / year incl GST · founding price, rising to A$649 on 1 Oct 2026

Orientation only, not a compliance assessment. General information and tools, not legal advice.

Why is this data different?

AML customer due diligence produces a concentrated pile of sensitive identity: driver licences, passports, proof of address. Agencies brokering the sale, purchase or transfer of real estate became reporting entities on 31 March 2026, with the AML obligations themselves commencing 1 July 2026. Section 6E(1A) of the Privacy Act then applies the Act, whatever your turnover, "in relation to the activities carried on by the small business operator for the purposes of, or in connection with, activities relating to" the AML/CTF Act. The hook is activity-based, not document-based: the due diligence, the monitoring and the reporting are caught, not just the licence scan. For the bigger picture, see does AML compliance cover your privacy obligations?

What are the four things you actually do?

1. Tell people at the point you collect it (APP 5)

When you take someone's ID for AML, give them a collection notice: what you're collecting, why (AML/CTF customer due diligence), who you might share it with, and how they can access or correct it. It can be short. APP 5.1 asks for it at or before collection or, if that is not practicable, as soon as practicable after.

2. Store it securely (APP 11.1)

APP 11.1 is the test: reasonable steps to protect the information from misuse, interference and loss, and from unauthorised access, modification or disclosure. On an identity pile that means access controls (not a shared drive the whole office can browse), a reputable secure system rather than email inboxes and desktops, and care with any third-party tool the data passes through. In Australian Information Commissioner v Australian Clinical Labs Ltd (No 2) [2025] FCA 1224, A$4.2 million of the A$5.8 million penalty was for the APP 11.1(b) failure alone. Where do your ID scans actually sit?

3. Keep the seven-year AML record, not the ID image

This is the one people get backwards. Both AUSTRAC and the OAIC have said the AML/CTF Act does not require you to keep scanned copies or photocopies of identity documents (OAIC, Privacy guidance for reporting entities under the AML/CTF Act, April 2026, citing AUSTRAC's initial-CDD guidance and s 111 of the AML/CTF Act). Section 111 asks for the extracted detail instead: name, date of birth, residential address, the document's type, number and expiry date, what you did to verify the person, and the outcome of your risk assessment, kept for seven years from the end of the business relationship. Section 108 is different: it requires you to retain a document the customer gave you, or a copy, for seven years after it was given, but only where it relates to the provision or prospective provision of a designated service (s 108(1)(a)) and you commence, or have commenced, providing that service (s 108(1)(b)). Both limbs must be met, so s 108 is not "anything a client sends you". Where neither section applies, APP 11.2 requires reasonable steps to destroy or de-identify the information once you no longer need it and no Australian law requires you to keep it. No AUSTRAC guidance or decided case addresses a client-emailed identity document specifically, so have this reviewed by a qualified Australian legal practitioner before you destroy anything a client sent you.

4. Have a plan for a leak (the NDB scheme)

A leak of identity documents is close to the worst-case privacy breach. Section 26WH(2) puts the duty on you, not the regulator: "a reasonable and expeditious assessment", with all reasonable steps to complete it within 30 days. If you then have reasonable grounds to believe there was an eligible data breach, s 26WK(2) requires a statement to the Commissioner as soon as practicable and s 26WL(2) requires notice to the affected individuals, or to those at risk, or, if neither is practicable, publication of the statement. A data-breach response plan written before anything goes wrong is what decides who starts that 30-day clock.

What actually falls in scope?

The hook is activity-based, not document-based: the customer due diligence, the ongoing monitoring and the reporting you do as a reporting entity are all caught, not just the licence scan. But the OAIC also states that small businesses "are not covered by the Privacy Act in relation to the non-AML/CTF business activities they undertake, unless the small business is covered by the Privacy Act for a different reason", so your open-home sheet is not pulled in by this route. Does your AML pack draw that boundary anywhere?

What you see during CDDThe privacy question it creates
Driver licence / passportDid you give a collection notice? Who can open the file?
The verification record (s 111)Have you kept the particulars for seven years from the end of the relationship?
The image itselfIs either s 108 limb met? If not, when will you destroy or de-identify it?

Common questions

How long do I keep customer ID documents?

Not the copy, by default. AUSTRAC and the OAIC have both said the AML/CTF Act does not require you to keep scanned copies or photocopies of identity documents. Keep the s 111 record instead, the extracted particulars plus what you did to verify the person and the outcome of your risk assessment, for seven years from the end of the business relationship. A document the customer gave you must be retained, or a copy of it, for seven years from the day it was given only where s 108(1)(a) and s 108(1)(b) are both met. Otherwise APP 11.2 requires reasonable steps to destroy or de-identify it once you no longer need it. Get legal advice before you destroy anything a client sent you.

Can I just store scans in my email or a shared folder?

That is the risky default. Identity documents warrant access controls and secure storage; an inbox or an open shared drive is where breaches happen. Use a reputable secure system and limit who can see the data.

Do I need to tell people why I'm taking their ID?

Yes. APP 5.1 asks for a collection notice at or before collection or, if that is not practicable, as soon as practicable after, covering what you collect, why (AML customer due diligence), and how they can access or correct it.

What if the ID documents leak?

Assess it. Section 26WH(2) requires a reasonable and expeditious assessment, with all reasonable steps to complete it within 30 days of becoming aware. If there are reasonable grounds to believe there was an eligible data breach, s 26WK(2) requires a statement to the Commissioner as soon as practicable, and s 26WL(2) requires notice to the affected individuals, or to those at risk, or, if neither is practicable, publication of the statement. A data-breach response plan tells you who does each of those.


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: Privacy Act 1988 (Cth) s 6E(1A), Sch 1 APP 5, APP 11, ss 26WH, 26WK, 26WL; Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) ss 108, 111; OAIC: privacy guidance for reporting entities under the AML/CTF Act; OAIC: Australian Privacy Principles (APP 5, APP 11); OAIC: Notifiable Data Breaches scheme; AUSTRAC: real estate professionals.