Back to Blog
Compliance
October 4, 20269 min read

Notifiable data breach and CDD files

Customer due diligence files hold identity information. Whether a loss of those files is a notifiable data breach is a privacy decision this page does not make.

Quick answer

Treat the file as personal information and limit who can open it. Do not keep extra copies of document images in inboxes. If something goes missing, tell the compliance officer and the person in the firm who handles privacy. This page does not decide that a breach is notifiable, does not list a regulator’s steps, and does not lodge a statement for you.

People search “data breach AML CDD records” when a CDD file leaves the office and someone asks this page to decide if the loss is a notifiable data breach. Checked against AUSTRAC’s glossary entry for KYC information on 4 October 2026. This is general information, not legal advice. This page does not reproduce that guidance. What the file is for, as customer due diligence, is AUSTRAC customer due diligence. What a completed check contains is what an AML check covers. The sector map is /tranche-2.

The file is identity information

Data breach AML CDD records is the moment a firm realises the customer file is not just a compliance PDF. It holds identity information about a person. KYC information, in AUSTRAC’s glossary, is the AML side of what you collected. Privacy law asks a different question about a loss or an unauthorised open; this page will not answer that question, and it will not pretend the glossary is a notifiable-breach test.

What a two-partner firm can do without a ruling is ordinary control. Name who may open a CDD file. Do not forward document images into personal inboxes. Do not keep a second copy because the first one felt safer; if a file leaves that circle, tell the compliance officer and the person who owns privacy for the firm; whether the event is notifiable, and any statement that follows, belongs to that privacy process and to advice; nothing here lodges it.

  • Limit the circle. The people who need the file can open it. The rest of the firm cannot browse it.
  • Do not multiply copies. An extra image in an inbox is another thing that can leave. The check result does not require a private archive.
  • Escalate inside. The officer and the privacy owner hear about a loss. They are not asked to take a conclusion from this article.
  • Do not self-assess from a blog. This page does not decide the notification and does not list a regulator’s steps.

AML record beside a privacy question

Two regimes touching one file. This table does not reproduce AUSTRAC’s glossary or any privacy test.

QuestionWhose questionThis page
What KYC information isYour program, against the glossaryDoes not reproduce the glossary
Who may open the CDD fileThe firm’s own controlSays to limit the circle
Is this loss notifiable?The firm’s privacy processDoes not decide
Lodging a statementWhoever that process namesDoes not lodge it

Where this page stops

This page is the boundary between a CDD file and a privacy decision. It is not how a professional firm runs the check. That page is KYC verification for professional firms.

What the client pays

On FreeAML the firm suite is A$0. The firm emails the client a link. Verification is client-pays. On the public list a personal KYC check is A$20 and a company or trust KYB check is A$40. Use KYB when the customer is a company or a trust. A privacy assessment and any statement to a regulator are not included in the firm suite. Confirm the live amounts on FreeAML pricing. FreeAML does not decide that a breach is notifiable or lodge a statement for you.

Frequently Asked Questions

Keep fewer copies. The check is still client-pays.

The firm suite is A$0. The client pays KYC or KYB. A privacy notification is not that product.

View pricing

Questions: team@freeaml.com.au