ZIP IT Solutions

Compliance

The Privacy Act Now Covers Your Client ID Data, Even Under $3M Turnover

Plenty of small firms in Brisbane, bookkeepers, small accounting practices, sole conveyancers, have never had to think about the Privacy Act. The $3 million turnover small business exemption has covered them for as long as they've been trading. That exemption just got narrower, and it happened alongside the AML/CTF changes covered in our previous post, not through a separate privacy reform.

Ethan Cook

Ethan Cook · 8 September 2026 · 1 min read

Plenty of small firms in Brisbane, bookkeepers, small accounting practices, sole conveyancers, have never had to think about the Privacy Act. The $3 million turnover small business exemption has covered them for as long as they've been trading. That exemption just got narrower, and it happened alongside the AML/CTF changes covered in our previous post, not through a separate privacy reform.

What actually changed, precisely

The $3 million small business exemption hasn't been repealed. A broader removal of it has been proposed as part of a future tranche of privacy reform, but that hasn't been legislated and there's no confirmed date for it. Anyone telling you the small business exemption is gone entirely is ahead of where the law actually is.

What has changed, and this is already in effect, is narrower and specific: if your practice became an AML/CTF reporting entity from 1 July 2026 (see our previous post on what triggers that), the Privacy Act now applies to the personal information you handle in connection with your AML/CTF obligations. Client ID documents, verification records, beneficial ownership details for structures like trusts and companies. That data is now covered by the Australian Privacy Principles regardless of your firm's turnover.

This isn't new in principle. Entities that have always been regulated under the AML/CTF Act, banks, remitters, casinos, have never been able to rely on the small business exemption for their AML-related data handling. What's new is that Tranche 2 has pulled somewhere in the order of 100,000 additional small businesses, according to the OAIC's own estimate, into that same position for the first time.

What it doesn't cover

This is the part that gets muddled in a lot of the coverage floating around at the moment. Becoming an AML/CTF reporting entity doesn't bring your entire business under the Privacy Act. Your marketing database, general client correspondence unrelated to a designated service, HR records, none of that is automatically covered just because part of your practice now handles AML data. The exemption still applies to everything else, assuming you're still under the $3 million threshold and don't fall into one of the other carved-out categories.

The OAIC's own guidance for reporting entities under the AML/CTF Act, updated in April 2026, sets this out with a simple test: is the information personal information, and are you handling it in connection with an AML/CTF obligation? If yes to both, the Privacy Act applies to that handling. If no, look at whether you're covered for some other reason.

What this actually requires you to do

For the AML-related data specifically, you now need:

  • A privacy policy (Australian Privacy Principle 1) covering how this category of information is collected, used, stored and disclosed.
  • Reasonable security steps and a destruction plan (Australian Privacy Principle 11): access controls for documents like passports and driver's licences, and a plan to destroy or de-identify them once the AML/CTF Act's seven-year retention period ends and they're no longer needed.
  • Data breach obligations: if that ID data is exposed, the Notifiable Data Breaches scheme applies to it in the same way it applies to any other regulated personal information.

Where to start

Work out, practically, where your client ID documents actually live right now. Most small firms will find the honest answer is somewhere between "an email attachment nobody moved" and "a shared drive with broader access than it needs." Fixing that, encrypted, access-controlled storage with a defined retention period, is the concrete first step, and it's the part of this that's actually solvable with the right setup rather than a policy document.

Want to apply this to your practice?

We can walk through what this means for your environment on a short call, or start with a Health Check.