What do I do with the ID documents AUSTRAC makes me collect? (the privacy side)
Once you collect a customer's identity documents for AML customer due diligence, that data falls under the Privacy Act, even under $3 million turnover, so you must handle it, not just hold it. Four steps: tell people what and why (collection notice, APP 5), store it securely (APP 11), reconcile the seven-year AML record rule with "don't keep it longer than needed," and have a leak plan (the NDB scheme).
By Jon Oates, Founder of Privaproof · Last updated · Start the free 2-min audit →
General information, not legal advice. Your obligations depend on your circumstances.
Not sure it's you?
Does this apply to you?
Tap what's true for your agency. Nothing is saved.
Orientation only, not a compliance assessment. General information and tools, not legal advice.
Why is this data different?
AML customer due diligence produces a concentrated pile of sensitive identity: driver licences, passports, proof of address. From 1 July 2026, the moment you collect that data as a reporting entity, it is treated as covered by the Australian Privacy Principles, regardless of your turnover (the effect of s 6E(1A) of the Privacy Act). So the same documents AUSTRAC tells you to collect are now personal information you have to manage under the Privacy Act. For the bigger picture, see does AML compliance cover your privacy obligations?
What are the four things you actually do?
1. Tell people at the point you collect it (APP 5)
When you take someone's ID for AML, give them a collection notice: what you're collecting, why (AML/CTF customer due diligence), who you might share it with, and how they can access or correct it. It can be short, and it should be given at or before the moment of collection.
2. Store it securely (APP 11)
You are now holding exactly the kind of data identity thieves want. That means access controls (not a shared drive the whole office can browse), encryption or a reputable secure system rather than email inboxes and desktops, and care with any third-party tool the data passes through.
3. Reconcile "keep for seven years" with "don't keep longer than needed"
This is the trap. The AML/CTF rules require you to keep records for seven years. The Privacy Act (APP 11) says you must not keep personal information once it is no longer needed for a permitted purpose. Both apply. In practice: keep what the AML rules require for as long as they require it, and have a clear process to destroy or de-identify identity data that is no longer needed for either AML or your agency work. The point is that "keep everything forever" is not a compliant default.
4. Have a plan for a leak (the NDB scheme)
A leak of identity documents is close to the worst-case privacy breach, and it is exactly the kind of eligible data breach that the Notifiable Data Breaches scheme requires you to assess and, where the risk is serious, notify. A data-breach response plan written before anything goes wrong is what turns a bad day into a managed one.
What data actually falls in scope?
It is the identity and customer-due-diligence data you collect for AML that is caught this way. Handling it properly does not mean treating every note in your CRM as if it were a passport. Getting that boundary right, tight where it needs to be, is part of doing it well.
| The document AUSTRAC wants | The privacy question it creates |
|---|---|
| Driver licence / passport | Did you give a collection notice? Is it stored securely? |
| Proof of address | How long will you keep it, and when will you destroy it? |
| Verification records | What happens if this data leaks? |
Common questions
How long do I keep customer ID documents?
Keep what the AML/CTF rules require (seven years for the relevant records), then destroy or de-identify identity data that is no longer needed. You reconcile the AML retention rule with the Privacy Act's "don't keep it longer than needed," rather than defaulting to keeping everything indefinitely.
Can I just store scans in my email or a shared folder?
That is the risky default. Identity documents warrant access controls and secure storage; an inbox or an open shared drive is where breaches happen. Use a reputable secure system and limit who can see the data.
Do I need to tell people why I'm taking their ID?
Yes. Under APP 5 you give a collection notice at or before collection, covering what you collect, why (AML customer due diligence), and how they can access or correct it.
What if the ID documents leak?
Assess it under the Notifiable Data Breaches scheme. A leak of identity documents is likely to be an eligible data breach that must be assessed and, where the risk of serious harm is real, notified to the OAIC and the affected people. A data-breach response plan tells you exactly what to do.
This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: OAIC: Australian Privacy Principles (APP 5, APP 11); OAIC: Notifiable Data Breaches scheme; AUSTRAC: real estate professionals.