Skip to content

Does becoming an AUSTRAC reporting entity trigger the Privacy Act?

For the data caught by AML, yes. Becoming an AUSTRAC reporting entity doesn't remove your small-business exemption across the whole firm, but Privacy Act s 6E(1A) deems you an "organisation" for the activities you carry on in connection with the AML/CTF Act, so the Privacy Act applies to the personal information you handle for AML, whatever your turnover.

By Jon Oates, Founder of Privaproof · Last updated

General information, not legal advice. Your obligations depend on your circumstances.

Which two provisions decide it?

The outcome is decided by two provisions that work in opposite directions. Most small conveyancing practices have never had to think about the Privacy Act, because two things were true: they turned over less than $3 million, and nothing else pulled them in. Tranche 2 changes the second of those.

Put together: s 6D still protects the practice generally, and s 6E(1A) carves a hole in it for your AML-connected activities. That's a more precise, and more accurate, picture than "the exemption falls away."

What does "deemed an organisation" actually mean?

Being deemed an organisation means that, for your AML/CTF activities, you are treated exactly as if the small-business exemption never applied to you. The APPs apply to the personal information you handle for those activities: customer identification and KYC records, beneficial-ownership details, PEP and sanctions-screening results, and source-of-funds evidence. Your turnover is irrelevant to that data.

It also means the switch is tied to the activity, not to a form. You don't become an APP entity because you filled in an AUSTRAC enrolment; you're brought in because you provide a designated service (the property-transfer service under the AML/CTF Act) and therefore handle personal information in connection with the AML/CTF Act.

What's covered, and what isn't?

The coverage is targeted at the AML/CTF-connected personal information, not the whole firm. This is the point most guidance gets wrong. OAIC guidance is explicit that a reporting entity must comply with the Privacy Act when handling personal information for the purposes of, or in connection with, its AML/CTF obligations. It does not automatically sweep your unrelated records into the Act.

Information you holdBrought under the Privacy Act by s 6E(1A)?Why
Identity / VOI documents collected for CDDYesCollected in connection with your AML/CTF obligations
KYC, beneficial-ownership, PEP / sanctions resultsYesCore AML customer-due-diligence data
Source-of-funds / source-of-wealth evidenceYesCollected for AML customer due diligence
A general marketing list unrelated to AMLNot by s 6E(1A) aloneNot handled "for" your AML/CTF activities

In a real conveyancing file the AML data and the transaction data overlap heavily (the same identity documents, the same settlement records), so many firms find it simplest to apply Privacy-Act-standard handling across the whole matter. That is a practical choice, not a legal requirement, and where the line sits is worth professional advice.

Why isn't this really new?

Section 6E(1A) has switched the Privacy Act on for reporting entities' AML data since the AML/CTF regime began in 2006. Banks, remitters and other existing reporting entities have been bound by it regardless of size. What Tranche 2 changes is who counts as a reporting entity: from 1 July 2026, conveyancers and WA settlement agents are added to that list for the first time. The mechanism is old; the audience is new. (For the WA-specific position, see Do WA settlement agents need a privacy policy and AUSTRAC enrolment in 2026?.)

What does it mean you actually have to do?

For the AML-connected data, you must comply with the APPs: at a minimum an APP 1 privacy policy and APP 5 collection notices, plus the Notifiable Data Breaches scheme for the sensitive dataset you now hold. The detail on those documents is in the companion guides: Do conveyancers need a privacy policy in 2026?, Privacy policy vs collection notice: do conveyancers need both?, and Do conveyancers need a data breach response plan?. For the AML side of the reforms overall, see AML Tranche 2 for conveyancers.

Common questions

Does the $3 million small-business exemption still apply to me?

For your practice generally, yes: s 6D still stands. But it doesn't protect the personal information you handle for AML/CTF: s 6E(1A) applies the Privacy Act to that data regardless of turnover.

Do I become an APP entity when I enrol with AUSTRAC?

The trigger is providing a designated service and handling personal information in connection with the AML/CTF Act, not the administrative act of enrolling. You're brought in by what you do, not by the form.

Does the Privacy Act now cover my whole practice?

No. The coverage is targeted at your AML/CTF-connected personal information. Unrelated data, like a general marketing list, isn't swept in by s 6E(1A) on its own.

Is this the same as the proposed removal of the small-business exemption?

No. This is the existing s 6E(1A) mechanism applied to conveyancers for the first time via Tranche 2, separate from the broader reform proposals to remove the small-business exemption generally, which are not law as at 2026.


This is general information, not legal advice. Privaproof provides privacy tools and general information; it is not a law practice and does not provide legal advice, and it does not assess your AML/CTF obligations, which are administered by AUSTRAC. Privaproof's conveyancer materials are self-authored and are not independently reviewed by a solicitor. Sources: OAIC, privacy guidance for reporting entities under the AML/CTF Act; Privacy Act 1988 (Cth) s 6E(1A) and s 6D; AUSTRAC, professional designated services.