AML & PRIVACY
The privacy obligation hiding inside AML Tranche 2
From 1 July 2026, practices that provide designated services became reporting entities under Australia's AML/CTF regime. For practices under the $3 million threshold, that brought their AML/CTF activities within the Privacy Act for the first time. For larger firms, it added new information to their files and new points where the two regimes conflict.
We help practices and the bodies that support them meet both sets of obligations, with CPD training for staff and privacy documents built for AML/CTF work.
Find the right option for your practice
-
Small property practices
New to the Privacy Act? The practice pack gives you the AML Privacy Toolkit and CPD training for up to 10 staff in one purchase.
-
Larger firms
Already covered by the Privacy Act? See what AML/CTF has added to your files, and train your staff with a firm licence.
-
Conveyancers with the Toolkit
Have the AML Privacy Toolkit through your AIC membership? The team pack trains up to 10 staff to use it.
-
Associations and professional bodies
Licensing for your members, tailored to your sector.
THE GAP NO-ONE IS TALKING ABOUT
AML training is everywhere.
The privacy consequence is not.
Most AML/CTF training covers customer due diligence, reporting and record keeping. Little of it covers what the Privacy Act requires once your practice holds that information: what you must tell clients, how long you can keep it, who you can share it with, and what to do if it is lost or stolen. OAIC regulatory penalties for Privacy Act non-compliance are not covered by PI insurance.
What existing AML training covers
✔ AUSTRAC enrolment obligations
✔ Customer due diligence basics
✔ Suspicious matter reporting
✔ Record keeping requirements
❌ Privacy Act obligations on identity data
❌ The VOI vs Privacy Act conflict
❌ Ready-to-use privacy policy templates
❌ Data breach notification obligations
What Law and Cyber covers
✔ Why AML Tranche 2 triggers Privacy Act obligations
✔ What identity data you must and must not retain
✔ Reconciling the VOI/Privacy Act conflict (unique to this course)
✔ Collection notices and privacy policy requirements
✔ Data retention limits and deletion obligations
✔ Data breach response and NDB scheme obligations
✔ Digital ID as a privacy-compliant alternative
✔ Ready-to-use governance templates
THE PACKAGE
Training and documents, built to work together
-
Where Privacy Law Meets AML
Online CPD training in two one-hour modules, for everyone who handles client ID. Module 1 covers the legal foundations. Module 2 follows a real file through to the consequences.
-
AML Privacy Toolkit
Two plain-language guides and eight templates drafted for AML/CTF property work, each with instructions. Written for practices that were outside the Privacy Act until 1 July 2026.
Eight documents, each with instructions
The Toolkit has two parts: plain-language guides to your privacy obligations as an AML/CTF reporting entity, followed by eight templates ready to adapt to your practice.
Part A
Your Privacy Obligations Explained
Concise plain-language guidance on your privacy obligations
A plain-language guide to your privacy obligations as an AML/CTF reporting entity. Explains how the Privacy Act applies to your practice, what the Australian Privacy Principles require, and how your AML/CTF and privacy obligations interact.
| Document | Purpose | Audience |
|---|---|---|
| Privacy Collection Notice | Tells clients what personal information is collected, why it is needed, who it may be shared with, and how to access or correct their records. Provided at client onboarding. | Clients |
| Privacy Policy | The practice's primary public-facing privacy document. Covers all Australian Privacy Principles, offshore disclosure obligations and the practice's position under the GDPR. Published on the practice website. | Clients / Public |
| Internal Privacy Policy | Explains what staff must do to meet APP obligations. Covers why the practice is subject to the Privacy Act regardless of annual turnover. | Staff |
| Privacy and Data Handling Procedures | Ten step-by-step procedures covering client onboarding, verification of identity, access requests, complaints handling, use of offshore tools, services to UK/EU/EEA clients, and breach response. | Staff |
| Data Breach Response Plan | Step-by-step guide to managing a breach from containment through to OAIC notification. Includes a decision tree for assessing whether a breach is notifiable under the NDB scheme. | Principal / Senior staff |
| Third-Party Disclosure Register | Working register of every third-party provider receiving personal information from the practice. Records data residency and the legal basis for each disclosure. | Principal |
| Personal Information Destruction Schedule | Working register tracking when each category of personal information must be destroyed or de-identified. Includes a destruction log meeting the OAIC's requirement for documented destruction processes. | Principal |
| GDPR and UK GDPR Privacy Notice | Provided to clients who identify as UK, EU or EEA residents. Sets out their additional rights and the lawful basis on which their personal information is processed. | UK / EU / EEA clients |
Part B: Implementation Documents
All documents are available for immediate download and implementation
WHO IS THIS FOR?
Tailored for impacted professions
Available now for lawyers and conveyancers handling property transactions. We are developing versions for other professions that provide designated services, and can tailor the materials for your sector.
-
Property lawyers and conveyancers face the most complex compliance picture. You know VOI obligations under the Real Property Act and ARNECC, but those rules were built before the Privacy Act applied to small practices. There is a direct conflict between what VOI requires and what the Privacy Act now prohibits.
VOI requires you to hold copies of identity documents. The Privacy Act says you must not retain copies.
Many practices are currently storing scanned passports they should not be holding.
Your 7-year ARNECC retention obligation and Privacy Act deletion obligations must be reconciled.
Even if you only handle property matters incidentally in family law or wills matters, these requirements now apply to you.
-
Photocopying a client's passport may now be a Privacy Act breach. Most practices do not know this.
Your existing privacy policy almost certainly does not address AML-related data handling.
OAIC regulatory penalties for Privacy Act non-compliance are not covered by most PI policies.
Every staff member who handles client identity data needs to understand these obligations.
-
Most real estate agencies under $3M in revenue have had no Privacy Act obligations until now. From 1 July they will be collecting identity verification data from every client under a regime they have never had to navigate. For principal agents, the personal exposure is real.
Most small agencies have no privacy policy at all. One must be in place before 1 July.
Collection notices must be given to clients at or before the point of collecting their information.
Every staff member handling identity data needs to understand their obligations.
OAIC regulatory penalties for Privacy Act non-compliance are not covered by most PI policies.
-
-
Item description
FOR PROFESSIONAL BODIES & ASSOCIATIONS
Sector-wide compliance for your members
Law & Cyber licenses its AML privacy training and documents to professional bodies, industry associations and insurers, so members have a coordinated way to meet their obligations. AICNSW has licensed the AML Privacy Toolkit for its members, and on behalf of the Tasmanian and Northern Territory institutes.
The materials are written for property transactions, but we can tailor them to other sectors that provide designated services, including real estate agents, accountants, property developers and other areas of legal practice. A licence can cover the Toolkit, the course, or both
ABOUT LAW & CYBER
Australia's leading specialist in cyber risk and privacy for the legal profession
Law and Cyber was founded by Simone Herbert-Lowe, a practising solicitor with 30 years experience in professional indemnity, cyber risk governance and legal practice regulation. Prior to founding Law and Cyber, Simone was Manager of Strategy and Innovation at Lawcover. She has authored articles and regulatory submissions on professional responsibility, cyber risk and resilience and Digital ID and contributed expert evidence to the Joint Parliamentary Committee on Law Enforcement in 2024.
10,000+
Course completions across legal, financial services and property sectors
8 YEARS
Specialist expertise at the intersection of cyber risk, privacy and legal practice
-
Customised materials
Profession-specific framework and templates tailored to your membership
-
Co-branded delivery
Presented under your association's name with Law and Cyber acknowledgement
-
Implementation webinar
Live session for your members to ensure effective uptake
-
Annual renewal
Regulatory updates delivered annually as the landscape evolves
The law changed on 1 July - the small business privacy exception no longer applies if you provide designated services under AML
The practice package is available now - staff privacy training coming soon
Materials are provided for general educational and guidance purposes only and do not constitute legal advice. They reflect the regulatory framework as at the date of publication. Copyright 2026 Law and Cyber Pty Ltd (ABN 68 629 258 377). Liability limited by a scheme approved under Professional Standards Legislation.