If you run a small law practice, accounting firm, conveyancing business or real estate agency, you may have spent years assuming the Privacy Act did not apply to you. Under the small business exemption, businesses with turnover below $3 million generally sat outside it. That changed on 1 July 2026 for firms captured by the AML/CTF Tranche 2 reforms.
The trigger was not a standalone privacy reform. The change came from the expansion of Australia’s Anti-Money Laundering and Counter-Terrorism Financing regime, which brought a range of professional and property-related businesses into the definition of reporting entities. For affected firms, this also changes how the Privacy Act applies to personal information handled in connection with their AML/CTF obligations. The first major deadline was 29 July 2026, when affected businesses were required to enroll with AUSTRAC.
If your firm is affected, this is not simply a compliance paperwork exercise. It has direct implications for how you collect, store, secure and respond to breaches involving client information. Here’s what changed, who is affected and what your business needs to have in place.
What Happened on 1 July 2026?
Two important changes happened at the same time, and the second is the one many small firms have overlooked. First, AML/CTF Tranche 2 took effect. The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 extended Australia’s AML/CTF regime beyond traditional financial institutions to a range of professional and property-related businesses.
Lawyers, accountants, conveyancers, real estate professionals, trust and company service providers, and dealers in precious metals and stones can now fall within the regime when they provide a designated service. Second, becoming an AML/CTF reporting entity can affect the Privacy Act small business exemption.
The Privacy Act contains an exception to the small business exemption for reporting entities under the AML/CTF Act. That means a business cannot simply rely on its turnover being below $3 million if it has become a reporting entity.
For affected firms, the Privacy Act therefore applies to personal information handled for the purposes of, or in connection with, their AML/CTF obligations, regardless of turnover. That distinction matters. The change does not necessarily mean every piece of information held by every affected business is automatically treated in exactly the same way. But for most firms, separating AML/CTF-related information from ordinary client information can be difficult in practice.
Who Is Actually Affected?
The important question is not simply what your job title is. It is whether your business provides a designated service under the AML/CTF framework. The reforms broadly bring the following professional and property-related businesses into scope where they provide designated services:
- Lawyers and conveyancers involved in activities such as conveyancing, forming trusts or companies, or managing client funds
- Accountants providing certain trust and company services, tax structuring, financial planning or financial reporting activities connected with relevant transactions
- Real estate professionals, including agents, buyer’s agents and property developers
- Trust and company service providers
- Dealers in precious metals and stones
If you are unsure whether your business is captured, check your eligibility rather than assuming the small business exemption still protects you.
For real estate businesses and other affected firms, enrolment with AUSTRAC was due by 29 July 2026 for businesses providing designated services from 1 July. Importantly, enrolment is not what creates the underlying obligations; businesses captured by the reforms became subject to the relevant requirements from 1 July.
What Does the Privacy Act Now Require?
The change is more specific than simply saying that every small business has suddenly become fully subject to the Privacy Act.
The exemption falls away for personal information you handle for the purposes of, or in connection with, your AML/CTF obligations.
That can include customer due diligence information, identity verification information and records maintained to demonstrate compliance.
For affected information, businesses need to consider requirements including:
- Privacy policy: APP 1 requires a clear and current privacy policy
- Collection notices: APP 5 requires people to be told what information is being collected and why
- Collection limits: APP 3 requires collection to be reasonably necessary
- Information security: APP 11 requires reasonable steps to protect personal information
- Retention and disposal: information should be destroyed or de-identified when no longer required, while accounting for applicable AML/CTF record-keeping requirements
- Data breach response: affected businesses may now also have obligations under the Notifiable Data Breaches scheme
For many small firms, the practical challenge is separating AML/CTF-related client information from everything else.
That is why bringing the broader practice up to appropriate privacy and security standards can be a more practical approach than trying to maintain complicated boundaries between different categories of client information.
The Notifiable Data Breaches Scheme Now Matters
For affected firms, one of the biggest practical changes is the Notifiable Data Breaches (NDB) scheme.
If personal information is lost or accessed without authorisation and the incident is likely to result in serious harm, the business may need to assess the incident and notify the OAIC and affected individuals.
That creates a very different operational requirement for a small practice that has never previously needed formal breach processes.
You need to be able to:
- Detect a potential security incident
- Identify what information may have been affected
- Assess the likelihood of serious harm
- Take appropriate action
- Meet notification requirements where applicable
- Document what happened and how it was handled
A written breach response plan is therefore only part of the solution.
You also need enough visibility across your systems to know that something has happened in the first place.
That is particularly important for firms holding identity documents, financial information, property records and other sensitive client data.
Why This Is More Than a Compliance Problem
This is where the legal and IT sides of the change meet.
A lawyer or compliance consultant can help you understand your obligations and develop the appropriate policies and procedures.
But a policy cannot secure your Microsoft 365 account.
It cannot enforce multi-factor authentication.
It cannot restrict access to sensitive client folders.
It cannot patch an outdated device.
And it cannot tell you that someone has accessed a system unexpectedly.
That is why the technical controls behind the compliance program matter.
For a small firm holding sensitive client information, reasonable security measures can include:
- Multi-factor authentication
- Strong access controls
- Device and endpoint protection
- Regular patching
- Encryption where appropriate
- Secure and tested backups
- User access reviews
- Security monitoring
- Documented incident response procedures
These controls also align closely with the Essential Eight, which provides a practical cybersecurity baseline for Australian organisations.
For businesses trying to demonstrate that they have taken reasonable steps to protect sensitive information, having appropriate technical controls in place can provide a much stronger position than relying on policies alone.
What Are the Penalties?
Both the Privacy Act and AML/CTF framework carry significant penalties, although the regimes are separate.
Under the Privacy Act, serious or repeated interferences with privacy can attract substantial penalties, including amounts of up to $50 million, three times the benefit obtained, or 30% of adjusted turnover, whichever is highest, depending on the circumstances.
The OAIC can also issue infringement notices for certain lower-level failures.
The AML/CTF framework carries its own civil penalty provisions, with corporate penalties potentially reaching tens of millions of dollars for serious contraventions.
For a small business, however, the practical concern should not simply be the headline maximum penalty.
The more immediate risk is being unable to demonstrate that your business took reasonable steps to protect client information, respond to an incident and meet its compliance obligations.
A privacy policy sitting in a folder is not the same thing as a secure IT environment.
What Your Business Needs to Do
If your firm is affected, the work should be approached in a logical order.
1. Check Whether You Are Captured
Determine whether your business provides a designated service under the AML/CTF framework. Do not assume your turnover automatically excludes you.
2. Enrol With AUSTRAC
If your business is required to enrol, make sure the enrolment requirements have been addressed. For businesses captured from 1 July 2026, the relevant enrolment deadline was 29 July 2026.
3. Appoint an AML/CTF Compliance Officer
Affected businesses need appropriate responsibility and oversight for their AML/CTF compliance program. For smaller practices, this may sit with a principal or senior member of management.
4. Review Your Privacy Policy
Your privacy policy should accurately explain what personal information you collect, why you collect it and how you handle it.
5. Review Client Collection Notices
Make sure your onboarding process clearly explains relevant information collection.
6. Secure Your Systems
This is where your IT environment becomes critical.
Review:
- Multi-factor authentication
- Access controls
- Endpoint protection
- Patching
- Encryption
- Backups
- Monitoring
- User permissions
7. Create a Data Breach Response Plan
Your team should know what happens if sensitive client information is compromised.
8. Review Retention and Disposal
Make sure retention requirements are understood and that information is securely disposed of or de-identified when it is no longer required, subject to applicable record-keeping obligations. The last two areas are where many small firms need technical assistance
Byteway Expert Insight
The pattern we are seeing with Melbourne firms is a clear split between the compliance work and the technical work. A practice may have engaged a consultant, appointed a compliance officer and created a privacy policy. All of that is important. But then you look underneath the policy and discover shared accounts, inconsistent multi-factor authentication, backups that have never been properly tested or no reliable way to identify unusual access to sensitive client information.That gap is where the real risk sits.
The Privacy Act asks whether reasonable steps were taken to protect personal information. A policy alone does not demonstrate that your systems are secure. For most small firms, the answer is not a massive technology transformation. It is getting the fundamentals right: MFA. Access control. Patching. Secure backups. Monitoring. Incident response.
These are not glamorous projects, but they are the controls that help turn a compliance policy into an operating security environment.
How Byteway Helps Legal, Accounting and Property Firms?
This is where Byteway can support the technical side of the compliance process.
Byteway helps Australian legal, accounting, conveyancing and property businesses strengthen the IT and cybersecurity controls that sit underneath their privacy and compliance obligations.
We can assess your current environment and identify gaps across areas such as:
- Multi-factor authentication
- User and administrator access
- Endpoint security
- Device patching
- Backup protection and testing
- Microsoft 365 security
- Network security
- Monitoring
- Incident response
- Essential Eight alignment
Rather than giving you a generic checklist, Byteway can translate the requirements into practical technology changes your business can actually implement.
Where Byteway Fits
Assess
We review your current IT and security environment and identify the highest-priority gaps.
Secure
We help implement practical controls such as MFA, access restrictions, endpoint protection, patching and secure backups.
Monitor
Security monitoring helps provide visibility into potential incidents and unusual activity.
Respond
We help establish the technical processes and documentation needed to respond to security incidents more effectively.
Manage
Through managed IT and cybersecurity services, Byteway can continue managing the underlying environment rather than leaving your team with a one-off checklist.
Your compliance consultant can help build the compliance program.
Byteway helps make sure the technology underneath it is secure, managed and monitored.
Why Work With Byteway?
For a small professional practice, managing separate IT, cybersecurity, internet, backup and communications providers can quickly become complicated.
Byteway brings these technology services together under one provider.
That means your business can have one team responsible for areas such as:
- Managed IT
- Cybersecurity
- Cloud backup
- Business internet
- Telecommunications
- Cloud communications
- Technology management
For firms dealing with sensitive client information, that integrated approach can make it easier to understand who is responsible for the systems protecting your data.
Frequently Asked Questions
Does the small business Privacy Act exemption still apply in 2026?
Not in the same way for businesses that are AML/CTF reporting entities. The $3 million small business exemption still exists generally, but reporting entities are an exception. For affected firms, the Privacy Act applies to personal information handled for or in connection with their AML/CTF obligations, regardless of turnover.
What was the AML/CTF Tranche 2 deadline for real estate agents?
Businesses providing designated services from 1 July 2026 were required to enrol with AUSTRAC by 29 July 2026 in the circumstances covered by the reforms. Importantly, the underlying obligations applied from 1 July rather than beginning only when enrolment was completed.
Do law firms under $3 million turnover need to consider the Privacy Act?
Yes, where the firm is captured as an AML/CTF reporting entity. The relevant Privacy Act requirements apply to personal information handled for or in connection with AML/CTF obligations regardless of the firm’s turnover.
Does the Privacy Act apply to all of my firm’s information?
The change is specifically connected to personal information handled for or in connection with AML/CTF obligations. However, separating that information from other client information can be difficult in practice, which is why many businesses may choose to adopt broader privacy and security controls across their environment.
Does the Notifiable Data Breaches scheme apply to affected small firms?
Where the Privacy Act applies, the NDB scheme can also apply. If a data breach is likely to result in serious harm, the business needs to assess the incident and may need to notify the OAIC and affected individuals.
What security controls should a small firm have?
The appropriate controls depend on the firm’s environment and risk profile, but commonly include multi-factor authentication, access controls, endpoint protection, patching, secure backups, monitoring and an incident response process. The Essential Eight provides a useful cybersecurity baseline for Australian organisations.
What are the penalties for getting this wrong?
The Privacy Act and AML/CTF framework have significant penalty provisions. The practical concern for a small business should be having appropriate policies, security controls, records and response processes in place and being able to demonstrate that reasonable steps were taken.
Is Your Firm Ready?
The compliance policy and the technology protecting your client information are two different pieces of the puzzle.
You may have completed the paperwork and still have significant gaps in the systems holding your most sensitive information.
Byteway can assess where your business currently stands and identify the technical priorities you should address first.
Our Privacy Act and Essential Eight readiness assessment can help you understand:
- Where your current security controls stand
- Which gaps need attention
- How your systems align with practical Essential Eight controls
- Where access, backup or monitoring weaknesses exist
- What should be prioritised first
Secure the Systems Behind Your Compliance Program
Book a free Privacy Act and Essential Eight readiness assessment with Byteway.
We’ll review your environment, explain the gaps in plain language and help you understand what needs to be fixed.
No unnecessary technology. No complicated jargon. Just a clearer path to a more secure IT environment.
👉 Book Your Free Readiness Assessment