AML & PRIVACY

The privacy obligation hiding inside AML Tranche 2

From 1 July 2026, practices that provide designated services became reporting entities under Australia's AML/CTF regime. For practices under the $3 million threshold, that brought their AML/CTF activities within the Privacy Act for the first time. For larger firms, it added new information to their files and new points where the two regimes conflict.

We help practices and the bodies that support them meet both sets of obligations, with CPD training for staff and privacy documents built for AML/CTF work.

Find the right option for your practice

  • Small property practices

    New to the Privacy Act? The practice pack gives you the AML Privacy Toolkit and CPD training for up to 10 staff in one purchase.

  • Larger firms

    Already covered by the Privacy Act? See what AML/CTF has added to your files, and train your staff with a firm licence.

  • Conveyancers with the Toolkit

    Have the AML Privacy Toolkit through your AIC membership? The team pack trains up to 10 staff to use it.

  • Associations and professional bodies

    Licensing for your members, tailored to your sector.

THE GAP NO-ONE IS TALKING ABOUT

AML training is everywhere.
The privacy consequence is not.

Most AML/CTF training covers customer due diligence, reporting and record keeping. Little of it covers what the Privacy Act requires once your practice holds that information: what you must tell clients, how long you can keep it, who you can share it with, and what to do if it is lost or stolen. OAIC regulatory penalties for Privacy Act non-compliance are not covered by PI insurance.

What existing AML training covers

✔  AUSTRAC enrolment obligations

✔  Customer due diligence basics

✔  Suspicious matter reporting

✔  Record keeping requirements

❌   Privacy Act obligations on identity data

❌   The VOI vs Privacy Act conflict

❌   Ready-to-use privacy policy templates

❌   Data breach notification obligations

What Law and Cyber covers

✔  Why AML Tranche 2 triggers Privacy Act obligations

✔  What identity data you must and must not retain

✔  Reconciling the VOI/Privacy Act conflict (unique to this course)

✔  Collection notices and privacy policy requirements

✔  Data retention limits and deletion obligations

✔  Data breach response and NDB scheme obligations

✔  Digital ID as a privacy-compliant alternative

✔  Ready-to-use governance templates

THE PACKAGE

Training and documents, built to work together

  • Where Privacy Law Meets AML

    Online CPD training in two one-hour modules, for everyone who handles client ID. Module 1 covers the legal foundations. Module 2 follows a real file through to the consequences.

  • AML Privacy Toolkit

    Two plain-language guides and eight templates drafted for AML/CTF property work, each with instructions. Written for practices that were outside the Privacy Act until 1 July 2026.

Eight documents, each with instructions

The Toolkit has two parts: plain-language guides to your privacy obligations as an AML/CTF reporting entity, followed by eight templates ready to adapt to your practice.

Part A

Your Privacy Obligations Explained

Concise plain-language guidance on your privacy obligations

A plain-language guide to your privacy obligations as an AML/CTF reporting entity. Explains how the Privacy Act applies to your practice, what the Australian Privacy Principles require, and how your AML/CTF and privacy obligations interact.

Document Purpose Audience
Privacy Collection Notice Tells clients what personal information is collected, why it is needed, who it may be shared with, and how to access or correct their records. Provided at client onboarding. Clients
Privacy Policy The practice's primary public-facing privacy document. Covers all Australian Privacy Principles, offshore disclosure obligations and the practice's position under the GDPR. Published on the practice website. Clients / Public
Internal Privacy Policy Explains what staff must do to meet APP obligations. Covers why the practice is subject to the Privacy Act regardless of annual turnover. Staff
Privacy and Data Handling Procedures Ten step-by-step procedures covering client onboarding, verification of identity, access requests, complaints handling, use of offshore tools, services to UK/EU/EEA clients, and breach response. Staff
Data Breach Response Plan Step-by-step guide to managing a breach from containment through to OAIC notification. Includes a decision tree for assessing whether a breach is notifiable under the NDB scheme. Principal / Senior staff
Third-Party Disclosure Register Working register of every third-party provider receiving personal information from the practice. Records data residency and the legal basis for each disclosure. Principal
Personal Information Destruction Schedule Working register tracking when each category of personal information must be destroyed or de-identified. Includes a destruction log meeting the OAIC's requirement for documented destruction processes. Principal
GDPR and UK GDPR Privacy Notice Provided to clients who identify as UK, EU or EEA residents. Sets out their additional rights and the lawful basis on which their personal information is processed. UK / EU / EEA clients

Part B: Implementation Documents

All documents are available for immediate download and implementation

WHO IS THIS FOR?

Tailored for impacted professions

Available now for lawyers and conveyancers handling property transactions. We are developing versions for other professions that provide designated services, and can tailor the materials for your sector.

FOR PROFESSIONAL BODIES & ASSOCIATIONS

Sector-wide compliance for your members

Law & Cyber licenses its AML privacy training and documents to professional bodies, industry associations and insurers, so members have a coordinated way to meet their obligations. AICNSW has licensed the AML Privacy Toolkit for its members, and on behalf of the Tasmanian and Northern Territory institutes.

The materials are written for property transactions, but we can tailor them to other sectors that provide designated services, including real estate agents, accountants, property developers and other areas of legal practice. A licence can cover the Toolkit, the course, or both

ABOUT LAW & CYBER

Australia's leading specialist in cyber risk and privacy for the legal profession

Law and Cyber was founded by Simone Herbert-Lowe, a practising solicitor with 30 years experience in professional indemnity, cyber risk governance and legal practice regulation. Prior to founding Law and Cyber, Simone was Manager of Strategy and Innovation at Lawcover. She has authored articles and regulatory submissions on professional responsibility, cyber risk and resilience and Digital ID and contributed expert evidence to the Joint Parliamentary Committee on Law Enforcement in 2024.

10,000+

Course completions across legal, financial services and property sectors

8 YEARS

Specialist expertise at the intersection of cyber risk, privacy and legal practice

Law & Cyber Women in Law Awards Winner 2022
Law & Cyber Women in Law Awards finalist 2022
Law & Cyber Women in Law Awards finalist 2023
Law & Cyber Women in Law Awards finalist 2025
  • Customised materials

    Profession-specific framework and templates tailored to your membership

  • Co-branded delivery

    Presented under your association's name with Law and Cyber acknowledgement

  • Implementation webinar

    Live session for your members to ensure effective uptake

  • Annual renewal

    Regulatory updates delivered annually as the landscape evolves

The law changed on 1 July - the small business privacy exception no longer applies if you provide designated services under AML

The practice package is available now - staff privacy training coming soon

Materials are provided for general educational and guidance purposes only and do not constitute legal advice. They reflect the regulatory framework as at the date of publication. Copyright 2026 Law and Cyber Pty Ltd (ABN 68 629 258 377). Liability limited by a scheme approved under Professional Standards Legislation.