AML/CTF Reforms Just Pulled 100,000+ Legal and Property Firms Into the Privacy Act. Here’s What Changes.
If you run a small law practice, accounting firm, conveyancing business or real estate agency, you may have spent years assuming the Privacy Act did not apply to you. Under the small business exemption, businesses with turnover below $3 million generally sat outside it. That changed on 1 July 2026 for firms captured by the AML/CTF Tranche 2 reforms. The trigger was not a standalone privacy reform. The change came from the expansion of Australia’s Anti-Money Laundering and Counter-Terrorism Financing regime, which brought a range of professional and property-related businesses into the definition of reporting entities. For affected firms, this also changes how the Privacy Act applies to personal information handled in connection with their AML/CTF obligations. The first major deadline was 29 July 2026, when affected businesses were required to enroll with AUSTRAC. If your firm is affected, this is not simply a compliance paperwork exercise. It has direct implications for how you collect, store, secure and respond to breaches involving client information. Here’s what changed, who is affected and what your business needs to have in place. What Happened on 1 July 2026? Two important changes happened at the same time, and the second is the one many small firms have overlooked. First, AML/CTF Tranche 2 took effect. The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 extended Australia’s AML/CTF regime beyond traditional financial institutions to a range of professional and property-related businesses. Lawyers, accountants, conveyancers, real estate professionals, trust and company service providers, and dealers in precious metals and stones can now fall within the regime when they provide a designated service. Second, becoming an AML/CTF reporting entity can affect the Privacy Act small business exemption. The Privacy Act contains an exception to the small business exemption for reporting entities under the AML/CTF Act. That means a business cannot simply rely on its turnover being below $3 million if it has become a reporting entity. For affected firms, the Privacy Act therefore applies to personal information handled for the purposes of, or in connection with, their AML/CTF obligations, regardless of turnover. That distinction matters. The change does not necessarily mean every piece of information held by every affected business is automatically treated in exactly the same way. But for most firms, separating AML/CTF-related information from ordinary client information can be difficult in practice. Who Is Actually Affected? The important question is not simply what your job title is. It is whether your business provides a designated service under the AML/CTF framework. The reforms broadly bring the following professional and property-related businesses into scope where they provide designated services: If you are unsure whether your business is captured, check your eligibility rather than assuming the small business exemption still protects you. For real estate businesses and other affected firms, enrolment with AUSTRAC was due by 29 July 2026 for businesses providing designated services from 1 July. Importantly, enrolment is not what creates the underlying obligations; businesses captured by the reforms became subject to the relevant requirements from 1 July. What Does the Privacy Act Now Require? The change is more specific than simply saying that every small business has suddenly become fully subject to the Privacy Act. The exemption falls away for personal information you handle for the purposes of, or in connection with, your AML/CTF obligations. That can include customer due diligence information, identity verification information and records maintained to demonstrate compliance. For affected information, businesses need to consider requirements including: For many small firms, the practical challenge is separating AML/CTF-related client information from everything else. That is why bringing the broader practice up to appropriate privacy and security standards can be a more practical approach than trying to maintain complicated boundaries between different categories of client information. The Notifiable Data Breaches Scheme Now Matters For affected firms, one of the biggest practical changes is the Notifiable Data Breaches (NDB) scheme. If personal information is lost or accessed without authorisation and the incident is likely to result in serious harm, the business may need to assess the incident and notify the OAIC and affected individuals. That creates a very different operational requirement for a small practice that has never previously needed formal breach processes. You need to be able to: A written breach response plan is therefore only part of the solution. You also need enough visibility across your systems to know that something has happened in the first place. That is particularly important for firms holding identity documents, financial information, property records and other sensitive client data. Why This Is More Than a Compliance Problem This is where the legal and IT sides of the change meet. A lawyer or compliance consultant can help you understand your obligations and develop the appropriate policies and procedures. But a policy cannot secure your Microsoft 365 account. It cannot enforce multi-factor authentication. It cannot restrict access to sensitive client folders. It cannot patch an outdated device. And it cannot tell you that someone has accessed a system unexpectedly. That is why the technical controls behind the compliance program matter. For a small firm holding sensitive client information, reasonable security measures can include: These controls also align closely with the Essential Eight, which provides a practical cybersecurity baseline for Australian organisations. For businesses trying to demonstrate that they have taken reasonable steps to protect sensitive information, having appropriate technical controls in place can provide a much stronger position than relying on policies alone. What Are the Penalties? Both the Privacy Act and AML/CTF framework carry significant penalties, although the regimes are separate. Under the Privacy Act, serious or repeated interferences with privacy can attract substantial penalties, including amounts of up to $50 million, three times the benefit obtained, or 30% of adjusted turnover, whichever is highest, depending on the circumstances. The OAIC can also issue infringement notices for certain lower-level failures. The AML/CTF framework carries its own civil penalty provisions, with corporate penalties potentially reaching tens of millions of dollars for serious contraventions. For a small business, however, the









