Australian AML/CTF · Explainer

Privacy and AML information

Privacy duties apply to personal information used for AML obligations, including in small reporting entities. Collection, use, security and retention need separate decisions.

General information only, not legal, compliance, or other professional advice. Does not confirm compliance.

Privacy duties also apply to AML work

Australian reporting entities must comply with privacy requirements when handling personal information for their AML/CTF obligations. Small-business status does not remove this coverage.

The OAIC explains that this includes small reporting entities and their authorised agents. Other business activities may have separate grounds for Privacy Act coverage.

Source: Office of the Australian Information Commissioner: Do reporting entities need to comply with the Privacy Act and the APPs?.

Identify the purpose and necessary information

The OAIC says collection must be reasonably necessary for the organisation’s functions and activities, including its AML duties.

An AML purpose does not justify collecting every available personal detail. Sensitive information has additional requirements and exceptions.

Identify the specific purpose before collecting the information. Apply the relevant privacy requirements to each use or disclosure.

Source: Office of the Australian Information Commissioner: Sections B, D and F.

Protect and retain the information lawfully

APP 11 requires reasonable security steps. AML retention duties do not permit unrestricted access or unrelated use.

Take reasonable steps to destroy or de-identify information when no permitted purpose or applicable retention requirement remains. Do not delete records that the law requires.

The record category and its statutory trigger matter. The retention article explains those periods.

Sources: Office of the Australian Information Commissioner: Sections I and J; Australian Government, Federal Register of Legislation: 107, 108, 111, 116 and 119.

Consider purpose, protection and retention
  • Collection

    Identify the purpose and reasonably necessary personal information.

  • Protection

    Apply reasonable security steps and control use and disclosure.

  • Retention

    Apply the record category and legal retention requirement.

Consider purpose, protection and retention

AML duties do not permit unrestricted collection or access. Do not delete a record that the law requires you to keep.

Separate evidence questions. An answer to one does not settle the others.

Example: a proposed extra field

In a fictional practice, staff propose collecting a customer’s family medical history during identity verification.

The manager asks what function requires the information. Staff identify no relevant purpose and remove the proposed field.

The example shows a collection decision. It does not establish that all personal information about relatives is unnecessary in every AML case.

Source: Office of the Australian Information Commissioner: Sections B and D.

Sources and scope

Sources checked on 2026-09-13. This page is not continuously updated. Check the linked legislation and AUSTRAC guidance for current requirements.

How we prepare articles

This page does not cover: Detailed CDD record requirements; A complete privacy assessment; Data breach notification procedures.

Common AML/CTF terms