The small-business exemption does not cover your AML file
Yes. Once a small business is a reporting entity, the Privacy Act applies to the personal information it handles for its AML/CTF obligations, even if annual turnover is $3 million or less. The Office of the Australian Information Commissioner says the ordinary small-business exemption does not cover that AML work. Other work in the same business can stay outside the Privacy Act unless a separate reason brings it in.
Quick answer
AML files are in. The rest of a small business is not in, unless some other Privacy Act reason already covered it. Have a privacy policy for the AML handling, and do not keep document images you do not need.
Accountants and agencies under the old small-business line want to know if enrolment drags the whole practice into the Privacy Act. Checked against the OAIC's privacy guidance for reporting entities on 5 October 2026. The OAIC published that guidance on 27 February 2026 and updated it on 28 August 2026. This is general information, not legal advice. This page does not reproduce that guidance. How you explain the check is how to talk about AML with clients. What you keep from a check is what an AML check covers. What you must not say about a report is tipping off. The sector map is /tranche-2.
The exemption stops at the AML file
The OAIC says the Privacy Act applies to personal information handling in relation to, or in connection with, AML/CTF Act obligations, regardless of whether the entity falls within the small-business definition. Small businesses are generally those with annual turnover of $3 million or less, and they are generally exempt. Reporting entities, and their authorised agents, must comply with the Australian Privacy Principles for the activities they undertake to meet the AML/CTF Act and Rules. The OAIC's examples include collection and storage for customer due diligence, monitoring and reporting, AML/CTF record keeping, and personnel due diligence where the employee-record exemption does not apply.
The same guidance says a small business is not covered for its non-AML activities unless it is covered for a different reason, such as being a health service provider or trading in personal information. Where one collection is for both an AML purpose and an ordinary business purpose, the OAIC says the Privacy Act applies to that personal information. A real estate agency in the OAIC's case study, with turnover of $1.1 million and no residential tenancy database, must comply for customer due diligence and personnel due diligence, and need not comply for other handling that is unrelated to AML/CTF. Read your own facts against that split. Do not announce that “the whole firm is now under the Privacy Act” and do not announce that “we are still exempt”.
What changes in the filing cabinet
- Have a privacy policy and a collection notice that explain the AML handling. The OAIC says you do not put information in a collection notice where that would be inconsistent with tipping off.
- Limit what you collect to what is reasonably necessary for the AML/CTF obligations and your other functions.
- Do not keep spare copies of identity documents. From 1 July 2026 for Tranche 2, the OAIC says the Act does not require scanned copies for the AML record. Keep the details you need, the type of document, what you did, and the outcome.
- Secure the file. Reasonable steps, and a data-breach plan. This page does not decide whether any particular loss is notifiable.
- Destroy or de-identify when you no longer have a permitted purpose, including an AML purpose. Other laws may still require a retention period. The OAIC points at that exception. It does not set your destruction date in this article.
Privacy Act coverage, as the OAIC describes it for small reporting entities. This table does not reproduce the guidance.
| Handling | Covered? | Note |
|---|---|---|
| Customer due diligence for a designated service | Yes | Even under $3 million turnover |
| A report and the record of it | Yes | A notice must not tip the client off |
| Unrelated office admin, if you are only a small business | No, unless another Privacy Act reason applies | Do not blur the two files |
| Copies of passports you do not need | Do not keep them for AML's sake | The OAIC says the Act does not require the copy |
Dates worth writing on the policy
The OAIC says that from 31 March 2026, changes for current reporting entities may affect how personal information is handled, and that from 1 July 2026 the Privacy Act also applies to Tranche 2 entities once they become reporting entities. The “no need to keep the document image” point is tied to those commencements: 31 March 2026 for Tranche 1 and 1 July 2026 for Tranche 2. Copies made before 31 March 2026 can be a different record. If your policy still says “scan every licence and keep it for seven years”, rewrite the sentence against the OAIC page before you keep doing it out of habit.
FreeAML is not your privacy officer. Emailing a link, rather than collecting a shoebox of images, fits the direction of travel the OAIC describes. The firm still writes the policy, still gives the notice, and still decides retention. The client pays the check. The privacy work is not an extra SKU.
Where this page stops
This page is the small-business question. It is not the data-breach decision, which is discussed as a boundary in notifiable data breaches and CDD files.
What the client pays
On FreeAML the firm suite is A$0. The firm emails the client a link. Verification is client-pays. On the public list a personal KYC check is A$20 and a company or trust KYB check is A$40. There is no subscription. Confirm the live amounts on FreeAML pricing. FreeAML does not sell a privacy-policy subscription. The verification the client completes is client-pays.
📚 Related Resources
Free KYC Check →
Verify customer identity in 60 seconds. Government ID + AML screening.
Free AML Program →
Board-ready AML/CTF Program template. All 10 AUSTRAC sections included.
Risk Assessment Generator →
AI-powered ML/TF risk assessment. 20-page compliant report in 5 minutes.
Free AML Training →
Online courses for staff. CPD-certified certificates included.
AUSTRAC Reporting Tools →
File SMRs, TTRs, IFTIs directly to AUSTRAC. Pre-filled forms.
Frequently Asked Questions
Collect less paper. The check is still client-pays.
The firm suite is A$0. The client pays A$20 for KYC or A$40 for KYB. A privacy policy is the firm's own document.
View pricingQuestions: team@freeaml.com.au