Skip to content

Does becoming an AUSTRAC reporting entity trigger the Privacy Act?

Yes, but only for part of what you do. Becoming an AUSTRAC reporting entity doesn't remove your small-business exemption across the whole firm. Privacy Act s 6E(1A) applies the Act "in relation to the activities carried on ... for the purposes of, or in connection with, activities relating to" the AML/CTF Act and its Rules, as if you were an "organisation". The boundary is the activity, not a folder of documents: customer due diligence, ongoing monitoring, reporting and AML record keeping are all inside it, whatever your turnover.

By Jon Oates, Founder of Privaproof · Last updated

General information, not legal advice. Your obligations depend on your circumstances.

Which two provisions decide it?

The outcome is decided by two provisions that work in opposite directions. A practice turning over $3 million or less, with nothing else pulling it in, sat outside the Privacy Act entirely. Tranche 2 changes the second half of that.

Put together: s 6D still protects the practice generally, and s 6E(1A) carves a hole in it for your AML-connected activities. That's a more precise, and more accurate, picture than "the exemption falls away."

What does "deemed an organisation" actually mean?

Being deemed an organisation means that, for your AML/CTF activities, you are treated exactly as if the small-business exemption never applied to you. The reach follows the activity rather than a folder of documents, so it takes in customer due diligence, ongoing customer monitoring, suspicious-matter reporting and AML record keeping, along with the personal information handled in any of them. Your turnover is irrelevant to all of it.

It also means the switch is tied to the activity, not to a form. You don't become an APP entity because you filled in an AUSTRAC enrolment; you're brought in because you provide a designated service (AML/CTF Act s 6(5B), Table 6 item 1: assisting a person to sell, buy or otherwise transfer real estate in the course of carrying on a business) and therefore carry on activities in connection with the AML/CTF Act.

What's covered, and what isn't?

The coverage is targeted at your AML/CTF activities, not the whole firm. OAIC guidance states that small-business reporting entities "are required to comply with the Privacy Act in relation to the activities for the purposes of, or in connection with their obligations under the AML/CTF Act and the AML/CTF Rules", and that they "are not covered by the Privacy Act in relation to the non-AML/CTF business activities they undertake, unless the small business is covered by the Privacy Act for a different reason". So the rest of what you do may genuinely sit outside the Act.

What you are doingInside s 6E(1A)?Why
Customer due diligence: identity and VOI documents, beneficial ownership, PEP and sanctions screeningYesCarried on in connection with the AML/CTF Act
Ongoing customer monitoring and source-of-funds enquiriesYesAn AML/CTF activity, not merely the file it produces
Suspicious-matter reporting and Part 10 record keepingYesActivities relating to the AML/CTF Act and its Rules
Marketing your practice to a general contact listNot by s 6E(1A) aloneNot an activity carried on for your AML/CTF obligations

In a real conveyancing file the AML activity and the ordinary conveyancing work overlap heavily, using the same identity documents and the same settlement records, so drawing the boundary mid-file is harder than it looks. Applying Privacy-Act-standard handling across the whole matter is a practical option, not a legal requirement. A test you can run on your own file today: can you say which record was collected for the AML check, who is allowed to see it, and when it gets destroyed?

Why isn't this really new?

The AML limb of s 6E was inserted in 2006, by Act No 170 of 2006 alongside the AML/CTF Act, and has applied to reporting entities' AML activities ever since, whatever their size. What Tranche 2 changes is who counts as a reporting entity: Table 6 commenced on 31 March 2026, which is when conveyancers and WA settlement agents became reporting entities. The AML/CTF obligations themselves apply from 1 July 2026, and anyone already providing a designated service before that date must apply to enrol with AUSTRAC by 29 July 2026, a date fixed by Sch 3 Part 4 item 12 of the amending Act. The mechanism is old; the audience is new. (For the WA-specific position, see Do WA settlement agents need a privacy policy and AUSTRAC enrolment in 2026?.)

What does it mean you actually have to do?

For those activities you must comply with the APPs: at a minimum an APP 1 privacy policy and APP 5 collection notices, plus the Part IIIC notifiable data breaches scheme for the personal information they cover. The detail on those documents is in the companion guides: Do conveyancers need a privacy policy in 2026?, Privacy policy vs collection notice: do conveyancers need both?, and Do conveyancers need a data breach response plan?. For the AML side of the reforms overall, see AML Tranche 2 for conveyancers.

Common questions

Does the $3 million small-business exemption still apply to me?

For the rest of your practice it can, and s 6D still stands, unless another s 6D(4) limb catches you. It does not protect your AML/CTF activities: s 6E(1A) applies the Privacy Act to those regardless of turnover. Check s 6D(4)(a) as well, because a single financial year above $3 million removes the exemption for good.

Do I become an APP entity when I enrol with AUSTRAC?

The trigger is providing a designated service and carrying on activities in connection with the AML/CTF Act, not the administrative act of enrolling. You're brought in by what you do, not by the form. Enrolment is a separate AUSTRAC obligation with its own deadline: 29 July 2026 for anyone already providing a designated service before 1 July 2026.

Does the Privacy Act now cover my whole practice?

No. s 6E(1A) reaches the activities you carry on for the purposes of, or in connection with, the AML/CTF Act. Work outside those activities, a general marketing list included, is not swept in by this provision on its own, though another s 6D limb could still catch the practice.

Is this the same as the proposed removal of the small-business exemption?

No. This is the existing s 6E(1A) mechanism applied to conveyancers for the first time via Tranche 2, separate from the broader reform proposals to remove the small-business exemption generally, which have not been enacted as at September 2026.


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Sources: Privacy Act 1988 (Cth) ss 6D and 6E(1A), Compilation No. 104; Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) s 6(5B), Table 6; OAIC, privacy guidance for reporting entities under the AML/CTF Act; AUSTRAC, professional designated services.